Version 1.0, 4 September 2026 · Draft pending legal review. Applies as an annex to the subscription.
This agreement is made between the customer business (the "Controller") and Oveliks (the "Processor") pursuant to article 28 of Regulation (EU) 2016/679. It covers processing carried out to deliver the digital menu and table ordering services.
Nature: hosting, storing, displaying and relaying guest orders and requests to staff, producing anonymous statistics. Purpose: delivering the service. Duration: for the subscription term and up to 12 months after cancellation (retention period), unless earlier deletion is requested.
Guests: order content, remarks, requests, ratings, table session identifier, language, device class. The Controller's staff and managers: email, name, phone, dashboard actions.
Processes data only on the Controller's documented instructions and to provide the service. Ensures confidentiality of its personnel. Implements the measures in section 7. Assists the Controller with data subject requests and impact assessments. Deletes or returns data at the end (section 8). Provides the information needed to demonstrate compliance.
Approved: Supabase Inc. (database, authentication, storage, Frankfurt region, EU), Cloudflare Inc. (network and hosting, EU jurisdiction), Resend (email), DeepL SE and Google Ireland Ltd (menu text translation, only when triggered by the Controller). Oveliks gives 30 days' notice of sub-processor changes; the Controller may object in writing, in which case the parties seek a solution or the agreement is terminated.
Data is stored within the EU. Any access from third countries by sub-processors is covered by the European Commission's Standard Contractual Clauses or an adequacy decision.
Encryption in transit and at rest, per-account data isolation (Row Level Security), role-based access control, two-step verification for Oveliks administration, daily backups kept 7 days plus nightly copies kept 90 days, audit logging, rate limits and anti-abuse mechanisms, data minimisation for guests.
Oveliks notifies the Controller without undue delay and at the latest within 48 hours of becoming aware of a personal data breach, with the information available. At termination the Controller may export its data (menus, items, orders). After the 12-month retention period, or earlier on request, data is permanently deleted except where law requires otherwise.
The liability limitations of the main agreement apply. Data protection contact: info@oveliks.com.



