QrConnector

Draft: this legal text is currently under legal review and is not yet final.

Data Processing Agreement (DPA)

Last updated: 4 October 2026

1. Parties and subject matter

This agreement is between the restaurant as controller (“Customer”) and Toprak Özkale, Sole proprietorship (Türkiye), as processor (“we”). It becomes part of the contract when the Terms of Use are accepted at registration and governs the processing of personal data on behalf of the Customer under Article 28 GDPR.

It does not cover the Customer’s own account and payment data, for which we are controller (see the Privacy Policy).

2. Nature, purpose and duration of processing

  • Subject matter: providing the digital menu and counting views, search terms and clicks for the Customer.
  • Categories of data subjects: guests who open the Customer’s menu; where applicable, persons whose data is contained in content uploaded by the Customer.
  • Categories of data: technical usage data (IP address in server logs, device/browser, time), page views, search terms, clicks; data contained in content, if any.
  • Duration: the term of the service contract.

3. Instructions and processor obligations

  • We process personal data only on documented instructions from the Customer; the instructions result from this agreement and use of the service. We do not use the data for our own purposes.
  • All persons authorised to process data are bound to confidentiality.
  • We apply the technical and organisational measures described in section 6.
  • We assist the Customer with data subject requests, data protection impact assessments and notification of personal data breaches, to the extent reasonable.
  • We notify the Customer of personal data breaches without undue delay.
  • After the contract ends, we delete the data; statutory retention duties remain unaffected.
  • We make available the information needed to demonstrate compliance and allow audits by the Customer after reasonable notice.
  • We inform the Customer if we consider an instruction unlawful.

4. Sub-processors

The Customer gives general authorisation for the following sub-processors. We inform the Customer of intended changes in advance; the Customer may object on important data protection grounds. Contracts under Article 28 GDPR exist with sub-processors.

Sub-processorServiceLocation
SupabaseDatabase, authentication, file storage[check Supabase region]
VercelHostingUSA / global network
ResendEmail deliveryUSA
SentryError monitoringEU region
GoogleTranslation (Gemini API)USA
OpenRouterAI image enhancement (optional)USA

5. Transfers to third countries

We provide the service from Türkiye, for which there is no adequacy decision of the EU Commission. For this transfer, the standard contractual clauses (Decision (EU) 2021/914), Module 2 (controller to processor), apply and form an annex to this agreement. Transfers to sub-processors in the USA rely on the EU-US Data Privacy Framework where certified, and otherwise on standard contractual clauses.

6. Technical and organisational measures

  • Encrypted transmission (TLS) for all connections.
  • Tenant separation in the database through row-level security; customers see only their own data.
  • Passwords are stored only as a hash; sign-in through vetted providers.
  • Access to production systems only for authorised persons; keys and credentials are not stored in source code.
  • Error monitoring with masking of personal data; no session recording.
  • Rate limiting against abuse.
  • Regular backups at the database provider.

7. Liability and term

Liability follows the Terms of Use and Article 82 GDPR. This agreement ends with the service contract.