Data Processing Agreement
Effective date: 2026-07-10
This DPA forms part of the Business Terms between the Venue (Controller) and EXCUSEME DOO (Processor) when ExcuseMe processes personal data on the Venue's behalf.
1. Scope and precedence
This DPA applies to guest orders, venue-directed AI conversations, loyalty operations and other Controller data placed in the Service. It does not govern processing for which ExcuseMe independently determines purposes, such as its own account administration, billing, security and legal evidence. Data-protection law prevails over a conflicting commercial term.
The terms controller, processor, personal data, processing, data subject and supervisory authority have their meanings under applicable Serbian data-protection law, EU GDPR or UK GDPR.
2. Processing instructions
Processor will process personal data only:
- to provide, secure, support and delete/return the Service under the agreement and the Controller's documented configuration and instructions;
- as stated in this DPA; or
- where law requires, after informing Controller unless prohibited.
Processor will promptly tell Controller if an instruction appears unlawful and may pause it while the parties resolve the issue. Controller is responsible for lawful instructions, notices, bases, data accuracy, regulated-product rules and data-subject relationships.
3. Processing details
- Subject matter/purpose: hosted QR ordering, fulfilment operations, guest support, AI ordering, optional loyalty, security and related support.
- Duration: the agreement plus deletion/return and backup expiry.
- Data subjects: guests/customers, authorised Venue staff, contacts and persons mentioned in submitted content.
- Data: identifiers/contact details; order/menu choices; table/location and permitted QR geolocation; notes; loyalty promotional points total, consent and transactions; conversation/transcript content; IP, user-agent, session/security data; support content.
- Special data: not intentionally required. Allergy notes may reveal health information; Controller must minimise them, identify an applicable condition/basis and avoid asking for unnecessary diagnosis data.
- Operations: collection, recording, organisation, storage, retrieval, consultation, validation, transmission to approved subprocessors, restriction, aggregation, deletion and anonymisation.
4. Confidentiality and personnel
Processor ensures authorised personnel are bound by confidentiality, receive appropriate privacy/security instruction and access data only as needed. Access is reviewed and removed when no longer required.
5. Security
Taking account of risk, state of the art, cost and processing context, Processor maintains appropriate measures, including separation between customer environments, role isolation, least privilege, secure authentication, encryption in transit, managed encryption at rest, secrets separation, input validation, logging/monitoring, backups, vulnerability remediation, incident response, availability controls and tested restoration processes.
Controller must configure roles and QR/location settings appropriately, protect credentials, keep devices secure, export data responsibly and notify Processor of suspected incidents.
6. Personal-data breach
Processor will notify Controller without undue delay after becoming aware of a personal-data breach affecting Controller data. Notice will include available information on nature, affected data/people, likely consequences, measures and a contact point, with updates as facts develop. Processor's notice is not an admission. Controller remains responsible for regulator and data-subject notices unless it instructs Processor to assist.
7. Subprocessors
Controller gives general written authorisation for the Subprocessor List. Processor will:
- impose substantially equivalent data-protection duties;
- remain responsible for subprocessor performance to the extent required by law;
- give at least 30 days' notice of a new/replacement subprocessor when practicable (urgent security/legal replacement may be shorter); and
- consider a reasoned data-protection objection made before the change.
If no reasonable alternative exists, Controller may terminate the materially affected Service before the new subprocessor begins, without a penalty for the unused affected prepaid subscription period.
8. International transfers
Processor will not make a restricted transfer without a lawful mechanism. Where such a mechanism is required, the parties incorporate the European Commission's 2021 controller-to-processor Standard Contractual Clauses (Module Two), with the UK Addendum for UK transfers. The docking option and the optional general authorisation apply; Serbian law and regulator mechanisms apply where relevant. The information required for the Clauses' annexes is provided by this DPA (the parties, the processing details in Section 3, and the security measures in Section 5) and the Subprocessor List; the competent supervisory authority is the one applicable to the Controller.
Processor performs and documents the transfer assessment and any supplementary measures required for a provider before that provider processes Controller production data under a restricted transfer.
9. Data-subject and regulator assistance
Considering the nature of processing, Processor will provide reasonable technical and organisational help with access, correction, deletion, restriction, portability, objection, consent withdrawal, DPIAs, prior consultation and regulator enquiries. If Processor receives a request relating to Controller data, it will route it to Controller unless authorised or legally required to respond. Additional substantial work outside standard product tools may be charged at agreed rates.
10. Return, deletion and retention
During the term, Controller may use available exports. On termination or written instruction, Processor will delete or return Controller data within a reasonable period, unless law requires retention. Normal retention includes 30-day chat and 90-day QR-security deletion; transaction records may be retained/anonymised for applicable fiscal periods. Isolated backups expire on their normal cycle and remain protected and unavailable for ordinary use.
11. Audit and evidence
Processor will provide current security/privacy documentation and reasonable responses to questionnaires. No more than once annually, unless a breach/regulator requires more, Controller may request an audit by an independent qualified auditor under confidentiality, during business hours, without accessing other customers' data or disrupting the Service. Controller bears its costs; Processor bears costs only where a material breach by Processor is found. Certifications and third-party reports may satisfy the request where appropriate.
12. Liability, term and contact
The DPA lasts while Processor handles Controller data. Liability is governed by the Business Terms, subject to mandatory data-protection law. Changes required by law take effect on notice; material discretionary changes follow the Terms.
Privacy: privacy@excuseme.pro. Incidents: security@excuseme.pro.