Data Processing Addendum
- Version:
- 1
- Last updated:
- 15 September 2026
- Effective date:
- 15 September 2026
This Data Processing Addendum ("DPA") forms part of the Menuzi Terms of Service and applies whenever Menuzi processes personal data on your behalf. It is designed to meet Article 28 of the EU General Data Protection Regulation (GDPR) and the processor requirements of Egypt's Personal Data Protection Law (PDPL). The English version prevails in case of any discrepancy with a translation.
Parties and roles
You (the business holding the Menuzi account) are the controller of the personal data of your guests that is processed through your published menus. Menuzi (your contracting party under the Terms: Bytes Maestros AB, or Menuzi Software Solutions LLC for accounts in Egypt) is the processor. For the data of your own account and team members, Menuzi is an independent controller, as described in the Privacy Policy; that data is outside this DPA.
Subject matter and details of processing
| Item | Details |
|---|---|
| Subject matter | Serving your published menus to guests, relaying guest orders to you, and producing menu analytics for you |
| Duration | For as long as you use the Service, plus the deletion period below |
| Nature and purpose | Hosting, delivery, storage, order relay, aggregation and reporting |
| Data subjects | Guests who view or order from your published menus |
| Categories of data | Technical data (IP address, browser and device type, approximate location, referrer, language); a pseudonymous daily visitor identifier derived from the IP address and browser; menu interactions (sections and items opened); for orders: the items ordered, the service option, the table number entered, the branch, the order number and timestamps |
| Special categories | None are requested. You must not configure your menus to collect them. |
Instructions
Menuzi processes guest data only on your documented instructions. Your instructions are the Terms of Service, this DPA, and the settings you choose in the product (for example, publishing a menu or enabling ordering on a branch). Menuzi will inform you if, in its opinion, an instruction infringes applicable data-protection law, and may process data where required by EU, Member State or Egyptian law after informing you of that requirement unless the law prohibits it.
Menuzi's own processing. Menuzi processes a limited set of guest traffic data for its own purposes as an independent controller, as described in the Privacy Policy: security and abuse prevention (including rate limiting), error monitoring, aggregated service-improvement statistics, and verifying that accounts are used within their subscription. That processing is outside your instructions and outside this DPA, and Menuzi is responsible for it.
Your obligations
You are responsible for the lawfulness of the processing you instruct: for having a legal basis for processing your guests' data, for giving your guests the notice the law requires, for ensuring that your instructions to Menuzi comply with applicable data-protection law, and for not configuring your menus to collect special categories of personal data.
Confidentiality
Menuzi ensures that persons authorised to process guest data are bound by confidentiality obligations and process it only as needed to provide the Service.
Security
Menuzi implements appropriate technical and organisational measures, including encryption in transit, role-based access control, rate limiting on public endpoints, pseudonymisation of visitor identifiers, separation of environments, and error monitoring that avoids personal data. The current measures are summarised in the Privacy Policy under "How we protect your data".
Subprocessors
You authorise Menuzi to engage the subprocessors listed on our Subprocessors page. Menuzi will update that page and notify account owners by email before a new subprocessor starts processing guest data. If you object on reasonable data-protection grounds and no alternative is available, you may terminate the affected part of the Service before the change takes effect. Menuzi remains responsible for its subprocessors and imposes data-protection obligations on them that are no less protective than this DPA.
Assistance
Taking into account the nature of the processing, Menuzi will assist you with appropriate technical and organisational measures in responding to guests' requests to exercise their rights, and in meeting your obligations regarding security, breach notification, data-protection impact assessments and prior consultation. Menuzi will forward to you without undue delay any request from a guest that it can attribute to your menus. Assistance beyond what the Service provides may be charged at a reasonable rate.
Personal data breaches
Menuzi will notify you without undue delay, and in any event within 48 hours of becoming aware, of a personal data breach affecting guest data processed on your behalf, and will provide the information reasonably needed for you to meet your own notification obligations.
Deletion and return
Menuzi keeps guest orders and analytics aggregates as part of your account data. On request, and in any event when your account is closed, Menuzi may delete guest data after 30 days and deletes or anonymises it within 90 days, except where the law requires longer retention. You may ask us for a copy of your order and analytics data before closing your account.
Information and audits
Menuzi makes available the information necessary to demonstrate compliance with this DPA and answers reasonable written audit questions once per year. Where that is not sufficient, you may, at your own cost and on 30 days' notice, conduct or mandate an audit limited to the processing under this DPA, during business hours, without unreasonably disrupting the Service, and subject to confidentiality.
International transfers
Guest data is processed in the EU and, by some subprocessors, in the United States; our edge network and analytics provider operate globally. Transfers outside the EEA are covered by the EU Standard Contractual Clauses (module three, processor to processor, or module two where applicable) and the subprocessors' data-protection commitments.
Customers in Egypt
Where your contracting party is Menuzi Software Solutions LLC, this DPA also serves as the written processing agreement required under the PDPL. You acknowledge that guest data is processed on infrastructure outside Egypt and instruct Menuzi to carry out those transfers under the PDPL's cross-border-transfer rules and any licence the Personal Data Protection Center requires, as those rules come into force, with the safeguards described above.
Liability and term
Each party is liable under this DPA in accordance with the Terms of Service, including its limitation of liability. Nothing in this DPA limits either party's liability towards data subjects under Article 82 GDPR or the PDPL. This DPA applies for as long as Menuzi processes guest data on your behalf and ends when that data has been deleted or anonymised. In case of conflict, this DPA prevails over the Terms for the processing it governs. Questions: privacy@menuzi.com.
