Data Processing Agreement (DPA)
GDPR Art. 28 data processing agreement between AI Waiter and its restaurant customers.
This Data Processing Agreement (the «DPA») forms part of the Terms of Service between AI Waiter / waiter24.ai (the «Processor», «we») and the customer (the «Controller», «you») and is accepted when the account is created. It governs the processing of your guests' personal data through the Service, as required by Art. 28 GDPR.
1. Subject matter and duration
We process personal data of your guests on your behalf to provide the AI chat assistant and related features (ordering, reservations, loyalty, feedback, support). The DPA applies for as long as your account exists and until all guest data has been deleted or returned.
2. Nature and purpose of processing
Collection, storage, structuring and transmission of chat conversations and related service data in order to generate AI responses, process orders and reservations, operate the loyalty programme and provide analytics to you.
3. Categories of data and data subjects
- Data subjects: your guests and website visitors who use the chat.
- Data categories: chat messages and metadata; name, phone number, delivery address and other order details the guest provides; reservation details; loyalty balance keyed to a phone number; post-order ratings and comments; images the guest uploads. Dietary recommendations (health data) are processed transiently with the guest's explicit consent and are never stored.
4. Our obligations as processor
- We process guest data only on your documented instructions, as embodied in the Service configuration you control, unless Union, Member State or Ukrainian law requires otherwise.
- Persons authorised to process the data are bound by confidentiality obligations.
- We implement the technical and organisational measures described on the Security page (TLS in transit, encryption of stored keys, tenant isolation, access controls, backups, log retention limits).
- We assist you, insofar as reasonably possible, in responding to data-subject requests (access, rectification, erasure, portability, objection) and in meeting your obligations under Arts. 32–36 GDPR.
- We notify you without undue delay after becoming aware of a personal data breach affecting your guests' data.
- Upon termination of your account we delete or, at your request made before termination, return the guest data, and delete existing copies unless law requires further storage.
- We make available the information necessary to demonstrate compliance and allow audits, which as a first step are satisfied through documentation and written answers; on-site audits require reasonable notice and must not endanger other customers' data.
5. Sub-processors
You grant a general authorisation for the sub-processors below. We will inform registered customers of intended changes (e-mail or in-product notice) at least 14 days in advance, giving you the opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic (or the AI provider you configure via BYOK) | Generation of AI responses | USA (SCCs) |
| Hosting / infrastructure providers | Servers, storage, backups | EU / Ukraine |
| Postmark, Brevo or Resend (per configuration) | Transactional e-mail | EU / USA (SCCs) |
| Paddle / LiqPay | Payment processing (your billing data, not guest data) | UK-EU / Ukraine |
| Telegram, Meta (WhatsApp) | Message delivery — only where you enable those channels | per their terms |
6. International transfers
Where processing involves providers outside the EU/EEA or Ukraine (e.g. AI providers in the USA), transfers rely on appropriate safeguards, in particular the standard contractual clauses offered by those providers.
7. Your obligations as controller
You are responsible for the lawfulness of the processing, for informing your guests (privacy notice on your website), for obtaining any required consents, and for configuring the Service (e.g. chat-log retention, age verification, diet-plan feature) in line with the law applicable to your business.
8. Contact
Questions about this DPA: [email protected]
Last updated: 14 July 2026