Choose your location

    DATA PROCESSING AGREEMENT

    This Data Processing Agreement is divided into two parts: Part 1 governs the processing of Customer Personal Data by Deliverect as a processor, on behalf of Customer and/or Franchisees as controller(s), in connection with the Services (as defined below); and Part 2 governs the processing of Personal Data by Deliverect and Customer as independent controllers for fraud detection purposes in connection with Deliverect Direct.

    The terms of this agreement shall govern the processing of Personal Data (as defined by General Data Protection Regime (EU) 2016/679 (“GDPR”)) that Customer and/or Franchisees (as applicable) transfer to Deliverect for the provision of Deliverect Direct (including for the provision of CRM services), Dispatch (including when Customer or Franchisee use Deliverect for couriers app), or DfRS (only when Personal Data comes from Customer’s direct online sales channels, including apps/websites) (collectively the “Services”) (“Customer Personal Data”). All undefined, capitalized terms will have the meaning given to them in the FSA. The terms, “Third Country”, “Member State”, "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" shall have the same meaning as in GDPR. 

    References to “Franchisees” in this agreement are only applicable to the extent that Customer has Franchisees that have signed an opt-in agreement to become a party to the FSA, otherwise, references to “Franchisees” can be disregarded and not applicable. References to “Franchisees” also include entities that have been approved by Deliverect as Customer Affiliates, as defined in the Deliverect Terms of Service (“TOS”). For Customers that do not have a standalone FSA with Deliverect, references to the FSA in this exhibit shall be understood as references to the TOS.

    PART 1 – CONTROLLER TO PROCESSOR (C2P) RELATIONSHIP

    1. Scope. Customer and Franchisee instructed Deliverect to Process Customer Personal Data, to the extent that such processing is done in and required for the performance of the FSA or the provision of the Services hired by Customer under the FSA. Deliverect acknowledges that Customer Personal Data cannot be used by Deliverect outside of the scope of this data processing agreement. Processing carried out by the Parties as independent controllers for fraud detection purposes in connection with Deliverect Direct is not governed by this Part 1, and is instead addressed separately in Part 2 below.

    2. Roles of the Parties. Deliverect is the Processor of Customer Personal Data processed in connection with the Services (as set forth above), and Customer and/or Franchisees (as the case may be) are the Controller of such Customer Personal Data.

    3. Deliverect’s Privacy & Cookie Policy. Customer and Franchisees agree to the terms of Deliverect Privacy and Cookie Policy available at https://www.deliverect.com/privacy-and-cookie-policy.

    4. Data Protection Laws. Customer, Franchisees, and Deliverect shall comply with the GDPR and/or the applicable data protection laws in the performance of the FSA. Customer and Franchisee warrant and guarantee that the terms and instructions given to Deliverect regarding the processing of Customer Personal Data are not contrary to GDPR or any data protection laws, or to the legal rights of Data Subjects and that all Customer Personal Data transferred by Customer or Franchisees to Deliverect is lawfully collected and transmitted and may lawfully be used, processed, stored and transferred for the purpose of the performance of the FSA and the provision of the Services. Deliverect shall inform Customer if, in Deliverect’s opinion, the Processing instructions from the Customer infringe GDPR. 

    5. Representations and Warranties.

      1. Of Customer and Franchisees: Customer and Franchisee represent and warrant that they have appropriate legal basis to collect, process, and share Customer Personal Data with Deliverect. 

      2. Of Deliverect: Deliverect warrants and guarantees that (a) it shall refrain from processing Customer Personal Data other than on Customer’s or Franchisee’s documented instructions, (b) it shall not use Customer Personal Data for any other purpose other than for the performance of the FSA and the provision of the Services, and (c) except for the Affiliates insofar as Deliverect deems this necessary or useful to fulfill its Processing obligations or to perform the FSA or provide the Services, shall not transfer Customer Personal Data to a Third Country or an international organization, unless required to do so by Union or Member State Law to which Deliverect is subject and provided Deliverect informs Customer or Franchisees upfront of that legal requirement, unless that law prohibits such information on important grounds of public interest. If Customer Personal Data processed under the FSA is transferred from a country within the European Economic Area to a country outside the European Economic Area, the Parties shall ensure that the Personal Data is adequately protected. To achieve this, the Parties shall, unless agreed otherwise, rely on EU approved standard contractual clauses for the transfer of personal data.

    6. Technical and Organizational Measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Deliverect warrants that it shall, in relation to Customer Personal Data, implement appropriate technical and organizational measures to ensure a level of security reasonably appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR. Deliverect shall implement appropriate security measures (technical, logical and organizational), and confirms that, to its best knowledge, these measures provide an appropriate security level, taking into account the state of the art and the security threats that are known or should reasonably be known by Deliverect. Deliverect shall ensure that persons authorized to process the Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

    7. Sub-Processors. Customer and Franchisees hereby gives a general authorization to Deliverect to engage (or disclose any Customer Personal Data to) any Sub-Processor, insofar as Deliverect deems this necessary or useful to fulfill its Processing obligations or to perform its obligations under the FSA, being understood that Deliverect shall remain liable towards Customer for the performance of each Sub-Processor. Deliverect shall ensure that each Sub-Processor performs all the obligations under the FSA, as they apply to Processing of Customer Personal Data carried out by that Sub-Processor, as they apply to Deliverect. 

    8. Processes to Comply with Rights of Data Subject Rights. Taking into account the nature of the Processing, Deliverect shall assist Customer and/or Franchisees by implementing appropriate technical and organizational measures for the fulfillment of Customer's obligations to respond to requests to exercise Data Subject rights under Data Protection Laws (including right of access to its personal data and a right to request corrections). 

    9. Data Breach. Deliverect shall notify Customer and Franchisees (if applicable) within forty-eight (48) hours upon discovery, of any unauthorized access to, acquisition or disclosure of Customer Personal Data, or a breach of security or confidentiality with respect to Customer Personal Data in Delivererect’s control or possession (“Data Security Incident ''). Deliverect shall cooperate with Customer and Franchisees (if applicable) and assist in the investigation, mitigation and remediation of each Data Security Incident, taking into account the information and technical means available to Deliverect. Customer and Franchisee will reasonably reimburse Deliverect for any expenses specifically made upon Customer’s and/or Franchisee’s request, if the Data Security Incident is not attributable to Deliverect. 

    10. Data Protection Impact Assessments. Deliverect shall provide reasonable assistance to Customer and Franchisees with any data protection impact assessments and prior consultations with Supervisory Authorities or other competent data privacy authorities, which Customer reasonably considers to be required by Article 35 or 36 of the GDPR, in each case solely in relation to the Processing of Customer Personal Data by, and taking into account the nature of the Processing and information available to Deliverect. 

    11. Deletion of Customer Personal Data. Deliverect shall, at the request of Customer or Franchisee, return or delete and procure the deletion of all copies of Customer Personal Data. Deliverect may however retain certain Customer Personal Data to the extent required by Data Protection Laws, EU or Member State Laws, and for such period as required under Data Protection Laws, EU or Member State Laws. 

    12. Audits. Deliverect shall make available to Customer and Franchisees on request all information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and shall allow for and contribute to audits, including inspections, by Customer, Franchisee, or an auditor mandated by Customer or Franchisee in relation to the Processing of Customer Personal Data by Deliverect. The cost of any such audits or inspections shall be borne by Customer and/or Franchisee respectively.  

    13. Description of Data Processing

      1. Categories of Data Subjects: Deliverect will process data from end users and clients of Customer and/or Franchisees, and/or from couriers of Customer and Franchisees that may be assigned to provide delivery services in connection with Dispatch and Deliverect for couriers app. Where Customer or Franchisees use Deliverect Direct, Deliverect will also process data from end users who have placed orders through Customer's or Franchisees’ Direct storefronts to create user profiles using order history for customer relationship management (CRM) purposes. 

      2. Types / Categories of Personal Data: Name, email address, phone number, address, order details, and geo-location. For CRM and order history profiling in connection with Deliverect Direct, Deliverect shall Process the following additional categories of personal data on Customer's behalf (i) Order history data, including: itemised order contents, order frequency, order value, preferred ordering times, preferred menu items, and order channel preferences; (ii) Customer preference and behavioural data, customisation choices, promotional code usage, and loyalty programme interactions, where applicable; (iii) Account and engagement data, including: account creation date, login frequency, communication preferences, and opt-in or opt-out status for marketing communications; and (iv) Derived data, including: customer segments, preference profiles, and behavioural scores generated through analysis of the above categories, scoped strictly to Customer's end user base.

      3. Subject matter, nature and purpose of the Processing: To provide the Services for the benefit of Customer. For CRM and order history profiling in connection with Deliverect Direct, the Processing carried out on Customer's behalf shall include: (i) the aggregation and analysis of end user order history to build individual customer profiles for CRM purposes; (ii) the segmentation of end users based on ordering behaviour and preferences to support Customer's customer relationship management, retention, and personalisation activities; and (iii) the generation of derived insights from order history to assist Customer in understanding and serving its end user base. Such processing shall be carried out solely on Customer's instructions and for Customer's benefit, shall be scoped strictly to Customer's own end user base, and shall not be used by Deliverect for any cross-customer or independent purpose.

      4. Duration of the Processing: The duration of the FSA or as otherwise required under applicable law. In respect of CRM and order history profiling carried out on Customer's instructions, personal data and derived profiles shall be retained for the period specified by Customer, or in the absence of such specification, for the duration of the FSA. Upon expiry of the applicable retention period, Deliverect shall delete or anonymise such data in accordance with Customer's instructions and the terms of this Agreement.

    PART 2 – CONTROLLER TO CONTROLLER (C2C) FOR FRAUD PROFILING

    This Part 2 (the “C2C DPA”) governs the processing of Personal Data by Deliverect and Customer as independent controllers in connection with fraud detection activities carried out in relation to Deliverect Direct. This Part 2 forms part of the FSA between Deliverect and Customer (or, for Customers that do not have a standalone FSA with Deliverect, the TOS). Capitalized terms not otherwise defined in this Part 2 have the meaning given to them in the preamble above or in the FSA.

    1. Scope. This C2C DPA governs Deliverect's and Customer’s processing of Personal Data as  independent controllers for the purposes set out below. For Deliverect, the processing is focused on fraud detection, encompassing: (i) analysis of website and session behaviour to identify suspicious or anomalous activity prior to or during the ordering process ("Website Behaviour Fraud Detection"); and (ii) analysis of post-order interactions, including refund requests, cancellations, and disputed transactions, to detect patterns indicative of fraudulent or abusive behaviour ("Post-Order Fraud Detection", and together with Website Behaviour Fraud Detection, "Fraud Detection"). For Customer, the processing is focused on: (i) managing its own customer relationships and order fulfilment through Deliverect Direct; and (ii) where applicable, conducting its own fraud prevention activities in respect of Customer's own end user base, including the use of fraud signals received from Deliverect solely for that purpose. 

    2. Roles of the Parties. The Parties acknowledge that in connection with the provision of Deliverect Direct, both Customer and Deliverect process Personal Data of Customer's end users as independent controllers, each determining the purposes and means of their respective processing activities independently.

    3. Data Protection Laws. Each party shall comply with its respective obligations under applicable data protection legislation, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), independently and without reliance on the other party's compliance.

    4. Description of Processing by Deliverect

      1. Categories of Data Subjects: End users of Customer who interact with Customer's Deliverect Direct storefronts, including users who browse, transact, or place orders through Customer's Direct-powered storefronts and online ordering channels.

      2. Categories of Personal Data: For the purposes of Fraud Detection, Deliverect may process the following categories of Personal Data as an independent controller:

        1. Identity data, including: name, email address, and phone number;

        2. Transaction data, including: order details, order value, order frequency, order cancellation history, refund request history, disputed transactions, and chargeback indicators;

        3. Device and session data, including: IP address, device identifiers, browser type and version, operating system, session duration, page navigation patterns, click behaviour, and timestamps of interactions;

        4. Location data, including: delivery address and geo-location signals associated with the ordering session; and

        5. Derived data, including: risk scores and fraud flags generated through automated analysis of the above categories, held in pseudonymised form at rest.

      3. Purpose of Processing: Deliverect processes Personal Data described in this section as an independent controller for the sole purpose of Fraud Detection, specifically to ensure the security and integrity of the Deliverect platform across its customer base. Deliverect shall not use Personal Data processed under this C2C DPA for any commercial, marketing, or other purpose beyond Fraud Detection.

      4. Lawful Basis. Deliverect relies on legitimate interests under Art. 6(1)(f) GDPR as the lawful basis for Fraud Detection processing. Deliverect has conducted and documented a Legitimate Interest Assessment ("LIA") in respect of this processing, framed at the platform level. A summary of the LIA is available upon request.

      5. Retention Period: Deliverect shall retain Personal Data and derived fraud profiles processed under this C2C DPA for a period of 18 months from the date of the last flagged activity associated with the relevant profile, following which such data shall be deleted or anonymised, unless retention is required for the establishment, exercise, or defence of legal claims. For the avoidance of doubt, the retention period set out in this clause shall apply independently of the termination or expiry of this C2C DPA or the FSA, as further described in the Term and Termination section below.

    5. Description of Processing by Customer

      1. Categories of Data Subjects: End users of Customer who interact with Customer's Direct storefront, including users who browse, transact, or place orders through Customer's Direct-powered storefronts or online ordering channels.

      2. Categories of Personal Data: For the purposes of its own fraud detection activities, which is related to protecting Customer’s revenue, Customer may process the following categories of personal data as an independent controller: 

        1. Identity data, including: name, email address, and phone number;

        2. Transaction data, including: order details, order value, order frequency, order cancellation history, refund request history, and disputed transactions;

        3. Device and session data, including: IP address, device identifiers, browser type and version, and timestamps of interactions; and

        4. Fraud signals received from Deliverect, limited to: risk scores and fraud flags as described in this C2C DPA, which Customer may use solely for the purpose of informing its own fraud prevention decisions in respect of its own end user base.

      3. Purpose of Processing: Customer processes Personal Data described herein as an independent controller for the purpose of conducting its own fraud prevention activities in respect of Customer's own user base, including the use of fraud signals received from Deliverect solely for that purpose.

      4. Lawful Basis: Customer is independently responsible for identifying and documenting an appropriate lawful basis under applicable data protection law for its own processing activities described herein. Customer represents and warrants to Deliverect that it has established and documented such a lawful basis prior to commencing any processing activity described in this clause.

      5. Retention Period: Customer is independently responsible for defining and documenting retention periods for Personal Data processed under this C2C DPA, in accordance with applicable data protection law and Customer's own data retention policies. In respect of fraud signals and derived data received from Deliverect, Customer shall not retain such data beyond the period strictly necessary for Customer's own fraud prevention purposes, and in any event shall not retain such data for longer than 18 months or other period specified by Deliverect from time to time from the date of receipt, unless retention is required for the establishment, exercise, or defence of legal claims.

    6. Security Measures. Each Party shall implement appropriate technical and organisational measures, including: (i) access controls and authentication; (ii) encryption in transit and at rest where appropriate; (iii) logging and monitoring, and (iv) incident detection and response procedures. 

    7. Data Sharing and Cross-Customer Processing. Customer acknowledges that Deliverect processes Personal Data for Fraud Detection as an independent controller and that such processing may involve the use of fraud signals, risk scores, and derived fraud flags across Deliverect Direct’s customer base for the purpose of identifying and preventing fraudulent behaviour at the platform level. Where Deliverect shares fraud signals or derived data across its customer base, only risk scores and fraud flags shall be shared cross-customer. Deliverect shall not share raw Personal Data, order details, or identity data of Customer's end users with other Deliverect customers or their end users. Customer shall not instruct Deliverect in respect of the Fraud Detection processing governed by this C2C DPA. Deliverect determines the purposes and means of Fraud Detection processing independently, subject to the guardrails and restrictions set out in this C2C DPA.

    8. Parties’ Obligations. 

      1. Legitimate Interest Assessment: Where either party relies on legitimate interests under the applicable data protection laws as the lawful basis for processing under this C2C DPA, that party shall: (i) conduct and maintain a documented legitimate interest assessment (“LIA”) in respect of its relevant processing activities; (ii) review and update the LIA at least annually or upon any material change to the relevant processing activities; and (iii) make a summary of the LIA available to the other party upon reasonable written request.

      2. Transparency: Each party shall maintain and publish a privacy notice that: (i) discloses its independent controller status for the processing activities described in this C2C DPA; (b) identifies the categories of personal data processed, the purpose of processing, and the lawful basis relied upon; (c) identifies the other party as a separate independent controller where end users' Personal Data is shared between the parties; and (d) informs end users of their rights in respect of each party's processing, including the right to object where legitimate interests is relied upon

      3. Purpose Limitation: Each party shall process personal data under this C2C DPA solely for the purposes described in its respective processing description herein. In particular: (i) Deliverect shall not use fraud profiles or derived data for any commercial, marketing, personalisation, or other purpose beyond Fraud Detection; (ii) Customer shall not use fraud signals or derived data received from Deliverect for any purpose beyond Customer's own fraud prevention activities in respect of Customer's own end user base. 

      4. Data Minimisation. Each party shall ensure that Personal Data processed under this C2C DPA is limited to what is strictly necessary for the purposes of their respective processing activities as set forth in this C2C DPA. In particular: (i) Deliverect shall limit cross-customer sharing to risk scores and fraud flags, and shall not share raw Personal Data or order details cross-customer; and (ii) Customer shall limit its use of fraud signals received from Deliverect to what is strictly necessary for Customer's own fraud prevention activities.

      5. Pseudonymisation and Security. In addition to the general security measures set out in Section 6, Deliverect shall pseudonymise fraud profile data at rest. Customer shall implement appropriate security measures in respect of fraud signals and derived data received from Deliverect, consistent with the sensitivity of such data.

      6. Data Subject Rights: Each party shall implement and maintain workflows to handle data subject requests in respect of its own processing activities under this C2C DPA, including requests for access, erasure, objection, and restriction. In particular: (i) each party shall respond to data subject requests within the timeframes required under applicable data protection law; (ii) where a data subject request received by one party relates to processing activities carried out by the other party, the receiving party shall promptly notify the other party and direct the data subject accordingly. Such notification shall be made without undue delay and in any event within five (5) business days of receipt of the data subject request, and shall include sufficient information to enable the other party to identify the data subject and the nature of the request; (iii) Deliverect may refuse an erasure request in respect of a fraud profile where retention is necessary for the establishment, exercise, or defence of legal claims, provided that such refusal is communicated to the data subject in writing with the specific grounds for refusal and information about their right to lodge a complaint with the relevant supervisory authority; and (iv) Customer may similarly refuse an erasure request in respect of fraud signals or derived data received from Deliverect where retention is necessary for the establishment, exercise, or defence of legal claims, subject to the same notification requirements as set out in this clause. 

      7. Right to Object: Each party shall route objection requests in respect of its own legitimate interests processing to a human reviewer. Each party may refuse an objection where it can demonstrate compelling legitimate grounds that override the data subject's interests, including where the data subject is the subject of a confirmed or ongoing fraud investigation. Each party shall be independently responsible for assessing and responding to objection requests in respect of its own processing activities.

      8. DPIA: Where a party's processing activities under this C2C DPA are likely to result in a high risk to the rights and freedoms of natural persons, that party shall conduct and maintain a Data Protection Impact Assessment ("DPIA") in respect of such processing activities. Each party shall make a summary of its DPIA available to the other party upon reasonable written request.

      9. Sub-processors: Each party shall ensure that any third-party processors engaged in connection with its processing activities under this C2C DPA are bound by data protection obligations consistent with applicable data protection laws. 

      10. ROPA. Each party shall register its own processing activities under this C2C DPA in its respective record of processing activities. 

      11. Lawful Basis. Each party shall identify, document, and maintain an appropriate lawful basis under applicable data protection law for its own processing activities described in this C2C DPA, independently of the other party. Each party represents and warrants to the other that it has established such a lawful basis prior to commencing processing under this C2C DPA.

    9. Personal Data Breach Notification. Each party shall notify the other without undue delay upon becoming aware of a Personal Data Breach affecting Personal Data within scope of this C2C DPA, to the extent that such notification is necessary to enable the other party to meet its own breach notification obligations under applicable data protection law. Notification under this section shall include, to the extent available at the time of notification: a description of the nature of the breach, the categories and approximate number of data subjects affected, the categories and approximate number of personal data records affected, the likely consequences of the breach, and the measures that are being taken to mitigate the impact of the breach. For the purposes of this section, 'Personal Data Breach' means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.

    10. Liability and Indemnity. Each party shall be independently liable for its own compliance with applicable data protection law in respect of its controller processing activities under this C2C DPA. Where a data subject or supervisory authority brings a claim or enforcement action arising from the processing activities of one party, that party shall bear sole responsibility for such claim, unless the claim arises directly from a breach by the other party of its obligations under this C2C DPA. Subject to the terms of the FSA, each party shall indemnify and hold harmless the other party from and against any fines, penalties, damages, or costs arising from that party's failure to comply with its obligations under this C2C DPA or applicable data protection law. Nothing in this section shall be construed to expand either party's liability beyond the limitations set out in the FSA, except to the extent that applicable data protection law imposes liability that cannot be contractually limited.

    11. Term and Termination. This C2C DPA shall remain in force for the duration of the FSA, unless terminated earlier  as set forth herein. Either party may terminate this C2C DPA on 30 days' written notice if the other party materially breaches its obligations under this C2C DPA and fails to remedy such breach within the notice period. Upon termination or expiry of this C2C DPA: (i) Customer shall delete or anonymise any personal data processed under this C2C DPA within a reasonable period, subject to any retention obligations required under applicable data protection law or for the establishment, exercise, or defence of legal claims; (ii) Deliverect, as independent controller, shall retain fraud profiles and associated Personal Data processed under this C2C DPA in accordance with its own retention policy, independently of the termination of this C2C DPA or the FSA. Termination of this C2C DPA or the Agreement shall not obligate Deliverect to delete or anonymise fraud profiles where retention is supported by Deliverect's legitimate interest basis or required for the establishment, exercise, or defence of legal claims. 

    12. General

      1. Entire Agreement: This C2C DPA, together with the FSA, constitutes the entire agreement between the parties in respect of the subject matter hereof and supersedes any prior arrangements relating to the independent controller processing of personal data for Fraud Detection purposes.

      2. Conflict: In the event of any conflict between this C2C DPA and the FSA, this C2C DPA shall prevail in respect of the Fraud Detection processing activities governed herein.

      3. Amendments: Deliverect may amend this C2C DPA by providing 30 days' written notice to Customer. Non-material amendments may be made without notice. Given that amendments to this C2C DPA may trigger compliance obligations for Customer as an independent controller, Customer is encouraged to review all notices of amendment carefully and to assess the implications for its own compliance programme before the amended terms take effect. Continued use of Deliverect Direct following the expiry of the notice period shall constitute Customer's acceptance of the amended terms, provided that such acceptance does not relieve Customer of its independent compliance obligations under applicable data protection law.

      4. Governing Law: This C2C DPA shall be governed by [governing law to be confirmed], consistent with the governing law of the Agreement.