Art. 28 GDPR
Deutsche Fassung (verbindlich)Data Processing Agreement
Note: a draft covering the platform’s current scope, not yet reviewed by legal counsel — the same standing caveat as our terms and the Impressum. Review by a lawyer is recommended before this is relied on with a business at scale.
This is the contract that governs what EZRegulars may do with the personal data of a partner business’s customers. It is not the same thing as our privacy policy, which explains to individuals how their data is used.
1. Who this is between
This data processing agreement (Auftragsverarbeitungsvertrag, Art. 28 GDPR) is between:
The business using EZRegulars to take orders — the controller.
ezRegulars, Inhaberin: Kusuma Narasimhamurthy, Stockmannstraße 34, 81477 München, Germany — the processor.
It takes effect when the business accepts it during setup, and it forms part of our terms of service.
The business using EZRegulars to take orders — the controller.
ezRegulars, Inhaberin: Kusuma Narasimhamurthy, Stockmannstraße 34, 81477 München, Germany — the processor.
It takes effect when the business accepts it during setup, and it forms part of our terms of service.
2. Who is responsible for what
The business decides why and how its customers’ data is used: it chooses to offer ordering over WhatsApp, sets its menu and prices, and fulfils the orders. That makes the business the controller of its customers’ personal data. EZRegulars processes that data only to run the service for the business, which makes us the processor. Where we process a business owner’s own account data — their email address and login — we act as controller for that, and our privacy policy covers it.
3. What we process, and why
Subject matter: operating a WhatsApp ordering service on the business’s behalf.
Duration: for as long as the business uses EZRegulars, and then as described in §12.
Nature and purpose: receiving and replying to messages from the business’s customers, taking orders and table bookings, telling the business’s staff about them, sending order status updates, and where the business accepts card payment, creating a payment link and confirming the result.
Categories of data subject: the business’s own customers, and the members of the business’s staff whose phone numbers it configures to receive order notifications.
Types of personal data: phone number; first and last name; delivery address where given; order history (items, prices, fulfilment and payment method, timestamps); consent records; chosen reply language; and a short-lived summary of the current conversation needed to keep track of an order. For staff: phone number, and the order notifications sent to it.
We do not ask for, and the service has no use for, special categories of data under Art. 9 GDPR.
Duration: for as long as the business uses EZRegulars, and then as described in §12.
Nature and purpose: receiving and replying to messages from the business’s customers, taking orders and table bookings, telling the business’s staff about them, sending order status updates, and where the business accepts card payment, creating a payment link and confirming the result.
Categories of data subject: the business’s own customers, and the members of the business’s staff whose phone numbers it configures to receive order notifications.
Types of personal data: phone number; first and last name; delivery address where given; order history (items, prices, fulfilment and payment method, timestamps); consent records; chosen reply language; and a short-lived summary of the current conversation needed to keep track of an order. For staff: phone number, and the order notifications sent to it.
We do not ask for, and the service has no use for, special categories of data under Art. 9 GDPR.
4. We only act on the business’s instructions
We process the business’s customer data only on its documented instructions. Those instructions are: this agreement, our terms of service, and the configuration the business sets in the portal — its menu, prices, opening hours, staff numbers and payment settings. Anything beyond that should be sent to ezregulars@gmail.com, which is the channel of record; anything agreed by phone we will confirm back in writing. We keep instructions for as long as they apply and for three calendar years afterwards.
We will not use the data for our own purposes, and we will not sell it or share it with anyone beyond the sub-processors listed in §7. We do not make copies of it beyond what running and backing up the service requires.
If we believe an instruction breaches the GDPR or German data protection law, we will say so without delay, and we may pause that instruction until the business has reviewed and either confirmed or changed it.
Where the law requires us to process the data differently — a lawful order from an authority, for instance — we will tell the business before we do, unless the law forbids us from saying so. How such an order is handled is set out in our internal process for requests from public authorities.
Changes to what we process, or to how, are agreed between us in writing or in a documented electronic form.
We will not use the data for our own purposes, and we will not sell it or share it with anyone beyond the sub-processors listed in §7. We do not make copies of it beyond what running and backing up the service requires.
If we believe an instruction breaches the GDPR or German data protection law, we will say so without delay, and we may pause that instruction until the business has reviewed and either confirmed or changed it.
Where the law requires us to process the data differently — a lawful order from an authority, for instance — we will tell the business before we do, unless the law forbids us from saying so. How such an order is handled is set out in our internal process for requests from public authorities.
Changes to what we process, or to how, are agreed between us in writing or in a documented electronic form.
5. Confidentiality
Everyone with access to the business’s customer data is bound to keep it confidential, during their work and after it ends. Today that is one person: the owner of ezRegulars. Anyone added later — an employee, a contractor — is made familiar with the data protection rules that apply to them and put under a written confidentiality obligation before being given access, and this agreement is updated to say so.
Data protection officer: ezRegulars has not appointed one, because the legal conditions requiring an appointment under Art. 37 GDPR and §38 BDSG are not met at our size. If that changes we will appoint one and tell our business customers who it is.
Data protection officer: ezRegulars has not appointed one, because the legal conditions requiring an appointment under Art. 37 GDPR and §38 BDSG are not met at our size. If that changes we will appoint one and tell our business customers who it is.
6. How the data is kept safe
The measures in place under Art. 32 GDPR:
In transit and at rest. All traffic runs over TLS, including connections to the database. Stored data is encrypted at rest by our database provider.
Separation. Every database query is scoped to a single business, so one business on the platform cannot read another’s customers, orders or menu.
Access. Production credentials are held only by the owner of ezRegulars and are not shared. Portal accounts sign in with a password hashed using scrypt with a per-password salt, or with Google. Sessions are bearer tokens that can be revoked.
Abuse resistance. Repeated failed sign-ins for an address are rate limited. Public registration is protected by a CAPTCHA. Incoming WhatsApp webhooks are verified against Meta’s signature and payment webhooks against the payment provider’s signing secret, so neither can be forged.
Resilience. The database provider maintains point-in-time recovery, so data can be restored after accidental loss or corruption.
Minimisation. We collect only what taking and fulfilling an order requires. Free-text conversation content is kept only as long as the order it belongs to needs it.
Review. We review and test whether these measures are still effective at least once a year, and whenever something happens that warrants it, as Art. 32(1)(d) requires. We tell the business the result on request.
These measures reflect the current scale of the service — one operator, a small number of businesses — and will be strengthened as it grows. We will not reduce them below the level described here while this agreement is in force, and will agree any material change with the business in writing beforehand.
The business, for its part, keeps what it learns about our security measures confidential, during this agreement and after it ends — describing them in detail is only safe if that description does not circulate. Both sides keep any agreements about these measures, and any audit records, for as long as they apply and for three calendar years afterwards.
In transit and at rest. All traffic runs over TLS, including connections to the database. Stored data is encrypted at rest by our database provider.
Separation. Every database query is scoped to a single business, so one business on the platform cannot read another’s customers, orders or menu.
Access. Production credentials are held only by the owner of ezRegulars and are not shared. Portal accounts sign in with a password hashed using scrypt with a per-password salt, or with Google. Sessions are bearer tokens that can be revoked.
Abuse resistance. Repeated failed sign-ins for an address are rate limited. Public registration is protected by a CAPTCHA. Incoming WhatsApp webhooks are verified against Meta’s signature and payment webhooks against the payment provider’s signing secret, so neither can be forged.
Resilience. The database provider maintains point-in-time recovery, so data can be restored after accidental loss or corruption.
Minimisation. We collect only what taking and fulfilling an order requires. Free-text conversation content is kept only as long as the order it belongs to needs it.
Review. We review and test whether these measures are still effective at least once a year, and whenever something happens that warrants it, as Art. 32(1)(d) requires. We tell the business the result on request.
These measures reflect the current scale of the service — one operator, a small number of businesses — and will be strengthened as it grows. We will not reduce them below the level described here while this agreement is in force, and will agree any material change with the business in writing beforehand.
The business, for its part, keeps what it learns about our security measures confidential, during this agreement and after it ends — describing them in detail is only safe if that description does not circulate. Both sides keep any agreements about these measures, and any audit records, for as long as they apply and for three calendar years afterwards.
7. Sub-processors
The business gives general authorisation for us to use the sub-processors below. We remain responsible to the business for what they do.
Meta Platforms Ireland Limited — delivers the WhatsApp messages themselves. Ireland and, for the WhatsApp Business Platform, the United States.
Google — hosts the application (Google Cloud Run, Belgium) and provides the AI model that interprets a customer’s free-text message (Gemini API, United States).
Neon Inc. — hosts the database. Data is stored in Frankfurt, Germany; Neon may access it from the United States.
Netlify — hosts the business portal’s web front-end. United States. Order data is fetched by the browser directly from our own servers, so Netlify does not store it.
Stripe — processes card payments. We send Stripe only an order reference and an amount, no customer personal data; Stripe collects the payer’s card details directly from them as an independent controller.
Each sub-processor is chosen with care, in particular for whether its technical and organisational measures are adequate under Art. 32 GDPR, and is bound by a written contract imposing obligations equivalent to those in this agreement. We are liable to the business for a sub-processor’s failure to meet them as if it were our own. Evidence of how a sub-processor was assessed is available on request.
We will give the business reasonable notice before adding or replacing a sub-processor. The business may object on reasonable data protection grounds; if it does, we will not use that sub-processor for its data, and if that leaves us unable to provide the service, either party may end it without penalty.
Meta Platforms Ireland Limited — delivers the WhatsApp messages themselves. Ireland and, for the WhatsApp Business Platform, the United States.
Google — hosts the application (Google Cloud Run, Belgium) and provides the AI model that interprets a customer’s free-text message (Gemini API, United States).
Neon Inc. — hosts the database. Data is stored in Frankfurt, Germany; Neon may access it from the United States.
Netlify — hosts the business portal’s web front-end. United States. Order data is fetched by the browser directly from our own servers, so Netlify does not store it.
Stripe — processes card payments. We send Stripe only an order reference and an amount, no customer personal data; Stripe collects the payer’s card details directly from them as an independent controller.
Each sub-processor is chosen with care, in particular for whether its technical and organisational measures are adequate under Art. 32 GDPR, and is bound by a written contract imposing obligations equivalent to those in this agreement. We are liable to the business for a sub-processor’s failure to meet them as if it were our own. Evidence of how a sub-processor was assessed is available on request.
We will give the business reasonable notice before adding or replacing a sub-processor. The business may object on reasonable data protection grounds; if it does, we will not use that sub-processor for its data, and if that leaves us unable to provide the service, either party may end it without penalty.
8. Transfers outside the EEA
Some of the sub-processors above process or access data in the United States. Those transfers rely on the safeguards those providers offer — the EU–US Data Privacy Framework where the provider is certified, and otherwise the European Commission’s standard contractual clauses. The one transfer worth calling out plainly: the text a customer types while ordering is sent to Google’s Gemini API to work out what they mean, and that processing takes place in the United States.
9. Helping the business answer its customers
If one of the business’s customers asks for a copy of their data, asks for it to be corrected or deleted, objects to processing, or exercises any other right under Chapter III GDPR, we will help the business respond — within the limits of what the service can do, and without undue delay. If such a request reaches us directly, we will not answer it ourselves; we will pass it to the business, because the business is the controller. Staff and customer data can also be deleted through the business portal and through the deletion route published at ezregulars.com/data-deletion.
10. Disruptions and data breaches
We tell the business without undue delay about any disruption, any breach of this agreement or of data protection law by us or anyone working for us, and any suspicion of either. For a personal data breach affecting the business’s customer data we will notify it within 24 hours of becoming aware. The notification will describe what happened, which categories of data and roughly how many people are affected, the likely consequences, and what we are doing about it — as far as we know at the time, updated as we learn more. Reporting to the supervisory authority under Art. 33, and telling the affected people under Art. 34, are the business’s decisions as controller; we will give it what it needs to make them, and will not make such a report on its behalf unless it instructs us to.
11. Impact assessments
If the business needs to carry out a data protection impact assessment or consult its supervisory authority under Art. 35 or 36 GDPR, we will provide the information about our processing that it reasonably needs. Much of it is already on this page.
12. When the business leaves
On request, and in any case within 30 days of the business ending its use of EZRegulars, we will delete the personal data we hold on its behalf, or return it first if the business asks. The exception is anything German law requires us to keep — records with tax or accounting relevance, for example — which we retain only for as long as that obligation lasts and for no other purpose. We will confirm in writing when deletion is done.
13. Showing our work
We will give the business the information it needs to satisfy itself that we are meeting these obligations, and will allow audits or inspections it carries out or mandates. In practice we expect most questions to be answerable from this page and our privacy policy; where they are not, ask and we will answer. An on-site audit should be arranged with reasonable notice and at a reasonable frequency.
14. If the data is put at risk by someone else
If the business’s customer data is ever endangered by something outside this agreement — a seizure or attachment by a third party, insolvency proceedings, or any comparable event — we will tell the business immediately, and tell whoever is acting that the data belongs to the business and not to us.
We will never withhold the business’s data to enforce a claim of our own. The right of retention under §273 BGB is excluded for the business’s customer data and for anything it is stored on. An unpaid invoice is a matter between us and the business; it is not a reason to keep hold of its customers’ data.
We will never withhold the business’s data to enforce a claim of our own. The right of retention under §273 BGB is excluded for the business’s customer data and for anything it is stored on. An unpaid invoice is a matter between us and the business; it is not a reason to keep hold of its customers’ data.
15. Ending this agreement
This agreement runs for as long as the business uses EZRegulars, and either side may end it on the notice set out in our terms of service.
The business may end it immediately, without notice, if we seriously breach data protection law or this agreement, if we cannot or will not carry out one of its instructions, or if we refuse the audit rights in §13. Failing the obligations in this agreement that come from Art. 28 GDPR counts as a serious breach.
What happens to the data afterwards is §12.
The business may end it immediately, without notice, if we seriously breach data protection law or this agreement, if we cannot or will not carry out one of its instructions, or if we refuse the audit rights in §13. Failing the obligations in this agreement that come from Art. 28 GDPR counts as a serious breach.
What happens to the data afterwards is §12.
16. Liability, precedence and language
Art. 82 GDPR governs liability; beyond that, our terms of service do. Where this agreement and the terms of service conflict on the handling of the business’s customer data, this agreement wins. Nothing here limits liability that cannot be limited under German law.
Language. Our customers are businesses in Germany, so the German version is the binding one. This English text is provided for convenience; where the two differ, the German wording applies.
Language. Our customers are businesses in Germany, so the German version is the binding one. This English text is provided for convenience; where the two differ, the German wording applies.
17. Changes
We will update this page as the service changes, and will tell businesses about material changes — a new sub-processor, a change to the security measures, a change to what we process — before they take effect. The version a business accepted is recorded against its account. Last updated: 15 September 2026.
18. Contact
Data protection questions, and any instruction under §4: ezregulars@gmail.com. Postal address in §1.