Data Processing Agreement (DPA)
Effective: June 23, 2026 Last updated: June 23, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Customer and Dizblanc LLC and governs the processing of personal data that Dizblanc LLC (the “Processor”) carries out on behalf of the Customer (the “Controller”) when providing Muzan, in accordance with Article 28 of the EU GDPR and the UK GDPR. Capitalized terms not defined here have the meaning given in the GDPR.
1. Definitions and roles
Terms such as “personal data”, “processing”, “data subject”, “controller”, “processor”, “sub-processor”, and “supervisory authority” have the meanings given in the GDPR. “Data Protection Law” means the EU GDPR, the UK GDPR, and any other applicable data-protection law.
For personal data processed on the Customer’s behalf through the Service (for example, staff details the Customer adds, or any data associated with its menus or diners), the Customer is the Controller and we are the Processor. Each party will comply with its obligations under Data Protection Law.
2. Scope and the Customer’s instructions
We process personal data only on the Controller’s documented instructions — including the Terms, this DPA, and use of the Service’s features — and as otherwise needed to provide the Service, unless required to act by law (in which case we will inform the Controller unless legally prohibited). We will inform the Controller if, in our opinion, an instruction infringes Data Protection Law.
3. Confidentiality
We ensure that personnel authorized to process personal data are subject to appropriate confidentiality obligations and process the data only as instructed.
4. Security (Art. 32)
We implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex B, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
5. Sub-processors
The Controller gives general written authorization for us to engage sub-processors to provide the Service. Our current sub-processors are listed in Annex C and on our Subprocessors page.
We will inform the Controller of intended changes (additions or replacements) with reasonable prior notice and give the Controller the opportunity to object on reasonable data-protection grounds; if an objection cannot be resolved, the Controller may terminate the affected Service. We impose on each sub-processor data-protection obligations equivalent to those in this DPA and remain fully liable to the Controller for our sub-processors’ performance.
6. Assistance with data-subject requests
Taking into account the nature of the processing, we will assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights. If we receive such a request directly, we will (unless legally prohibited) direct the data subject to the Controller and not respond except on the Controller’s instructions.
7. Personal data breaches
We will notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on its behalf, and will provide the information reasonably available to help the Controller meet its breach-notification and communication obligations (Arts. 33-34).
8. DPIAs and prior consultation
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance to the Controller with data protection impact assessments (Art. 35) and prior consultations with a supervisory authority (Art. 36).
9. International transfers
We may transfer and process personal data in the United States and other countries. Where we transfer personal data from the EEA, the UK, or Switzerland to a country without an adequacy decision, the transfer is governed by appropriate safeguards — principally the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss amendments as applicable — together with supplementary measures where required. We do not transfer personal data except on the Controller’s instructions or as needed to provide the Service.
10. Audits and information
We make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. To limit disruption, audits are on reasonable prior notice, no more than once per year (unless required by a supervisory authority or following an incident), subject to confidentiality, and may be satisfied by relevant third-party certifications or reports where available.
11. Return and deletion of data
On termination of the Service, and at the Controller’s choice, we will delete or return the personal data processed on its behalf and delete existing copies within 90 days, unless storage is required by law. Backups are deleted on a rolling cycle.
12. Liability and order of precedence
The liability provisions of the Terms apply to this DPA. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails; in the event of a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
Annex A — Details of the processing
- Subject matter: provision of the Service to the Controller.
- Duration: the term of the Terms, plus the retention/deletion periods described above.
- Nature and purpose: hosting, storing, organizing, displaying, and otherwise processing menu content to operate the Service, plus account management and support.
- Categories of data subjects: the Controller’s authorized users and staff; and, where the Controller includes it, other individuals; the Public Menu is designed not to collect diners’ personal data.
- Categories of personal data: identification and contact details of staff/users; account and login data; usage and log data (including IP address); and any personal data the Controller chooses to include in its Content.
- Special categories: none are intended or required; the Controller should not upload special-category data.
- Frequency: continuous, for the duration of the Service.
Annex B — Technical and organizational measures
- Encryption of data in transit (TLS) and encryption at rest provided by our infrastructure providers.
- Access controls on a least-privilege basis, with authentication for administrative access.
- Network and application security provided through managed, reputable infrastructure.
- Backups and recovery capabilities to support resilience and availability.
- Logging and monitoring of relevant system activity.
- Confidentiality obligations for personnel and data-protection terms with sub-processors.
- An incident-response process for detecting, handling, and notifying personal data breaches.
Annex C — Sub-processors
Our current sub-processors (for example, Stripe, Supabase, Vercel, Google Fonts, and Resend) are listed, with their roles, on our Subprocessors page, which forms part of this Annex C. We update that list and notify changes as described in clause 5.
Execution and contact
This DPA is incorporated into and accepted with the Terms. If you require a separately signed copy for your records, contact privacy@muzan.app.