Legal
Data processing agreement
Processing on behalf of clients under Article 28 GDPR
This Agreement forms an integral part of the Terms and conditions and applies whenever Ginger Dialogue, Lda. (“Processor”) processes personal data on behalf of the Client (“Controller”) as part of the Services. By purchasing the Services, the Client accepts this Agreement.
1. Subject matter, nature and purpose
The Processor processes personal data only to provide the contracted Services: website hosting, receiving and managing orders and reservations, the phone and messaging assistant, sending notifications, technical support, reporting and marketing on the Client’s behalf.
2. Duration
For the term of the contract and for the time needed to return or delete the data after it ends.
3. Categories of data subjects and data
| Data subjects | Data |
|---|---|
| Client’s end customers | name, phone, email, delivery address, orders, reservations, payments (no full card data), notes and preferences, call recordings or transcripts when enabled |
| Users of the Client’s website and app | technical data, IP address, cookies according to the user’s choices |
| Client’s staff | name, email, access role, activity logs |
The Client should avoid collecting special categories of data. If end customers provide health information (for example allergies) in notes, the Client is responsible for the legal basis and required information; the Processor handles that information only as part of the order.
4. Client (Controller) obligations
- Ensure processing is lawful and has a valid legal basis.
- Inform end customers through its own privacy policy, including about call recording and the use of automated assistants where applicable.
- Give lawful, documented instructions; settings made by the Client on the Platform count as instructions.
- Answer data subject requests, with the Processor’s reasonable support.
- Not upload to the Platform data that is not needed for the Services.
5. Processor obligations
- Process data only on the Client’s documented instructions, unless required by law, and inform the Client if an instruction appears to infringe the law.
- Ensure that people authorised to process the data are bound by confidentiality.
- Apply the security measures in the Annex and keep them appropriate to the risk.
- Provide reasonable assistance to the Client with data subject rights and the obligations in Articles 32 to 36 GDPR.
- Notify the Client of any personal data breach without undue delay and, where possible, within 48 hours of becoming aware of it, with the information available.
- At the end of the contract, at the Client’s choice, return or delete the data within 30 days unless the law requires it to be kept; if no choice is made, the data is deleted.
- Make available the information needed to demonstrate compliance with this Agreement.
6. Sub-processors
The Client gives general authorisation to use sub-processors in the following categories: hosting and cloud, email and SMS, telecom and voice, artificial intelligence, payments, technical support and backups. The Processor imposes equivalent data protection obligations on them by contract and informs the Client of changes at least 15 days in advance. The Client may object on reasonable data protection grounds; if no alternative is possible, either party may terminate the affected service.
7. International transfers
Data is preferably processed in the European Union. Any transfer outside the European Economic Area is based on an adequacy decision or the European Commission’s standard contractual clauses, with supplementary measures where needed.
8. Audits
Once a year, with 30 days’ notice, the Client may request information or carry out an audit, itself or through an independent auditor bound by confidentiality, during normal business hours and without disrupting operations. Audit costs are borne by the Client. Where possible, audits are satisfied with existing documentation and certifications.
9. Liability
Each party’s liability under this Agreement is subject to the exclusions and limitations in the Terms and conditions, without prejudice to Article 82 GDPR and mandatory rules. The Client indemnifies the Processor for damage resulting from unlawful instructions or the Client’s breach of its obligations as Controller.
10. Precedence
In case of conflict between this Agreement and the Terms and conditions on data protection, this Agreement prevails.
Annex – Technical and organisational measures
- Encrypted connections (HTTPS/TLS) and encrypted backups.
- Role-based access control, least-privilege principle and multi-factor authentication for staff.
- Logical separation of each client’s data.
- Regular backups and recovery procedures.
- Security updates, malware protection and monitoring.
- Logging of administrative access.
- Confidentiality agreements and data protection training for staff.
- Internal data breach management procedure.
- Providers selected with adequate security guarantees.