1. Parties and scope
This DPA supplements the agreement between the customer (“Customer”) and the PayoutChecker contracting entity (“PayoutChecker”) where PayoutChecker processes personal data on Customer’s behalf in providing the Service.
2. Roles
Customer determines the purposes and means of the underlying restaurant/client data processing and acts as controller/business where applicable. PayoutChecker acts as processor/service provider for Customer Data processed solely to provide, secure, support and improve the contracted Service as permitted by the agreement.
3. Processing details
- Subject matter: restaurant payout/transaction reconciliation.
- Duration: subscription/contract term plus documented retention/deletion period.
- Data subjects: customer personnel, restaurant staff, and potentially restaurant consumers represented in source transaction exports.
- Data types: business contacts, transaction/order identifiers, financial/reconciliation fields, and incidental personal information present in source exports.
- Purpose: parsing, normalization, matching, exception detection, reporting, support, security and authorized service operations.
4. Instructions
PayoutChecker will process Customer Data only on documented instructions in the agreement and Customer’s use/configuration of the Service, unless law requires otherwise.
5. Confidentiality and personnel
PayoutChecker will require authorized personnel with access to Customer Data to be subject to confidentiality obligations and access controls appropriate to their role.
6. Security
PayoutChecker will maintain reasonable technical and organizational safeguards designed to protect Customer Data, including tenant authorization, controlled storage, encrypted transport, logging and access restriction. A detailed security exhibit may be added for enterprise contracts.
7. Subprocessors
Customer authorizes PayoutChecker to use subprocessors necessary to provide the Service. PayoutChecker will maintain a current subprocessor list and impose appropriate data-protection obligations. Enterprise Order Forms may define a notification/objection process.
8. Rights requests
Taking into account the nature of processing, PayoutChecker will reasonably assist Customer with legally required data-subject/consumer requests relating to Customer Data.
9. Security incidents
PayoutChecker will notify Customer without undue delay after confirming a security incident involving Customer Data where notice is required by the agreement/law and will provide reasonably available information for Customer’s response.
10. Deletion/return
At termination or Customer request, PayoutChecker will delete or return Customer Data in accordance with product retention controls, backups and legal requirements. Backup copies may persist for a limited cycle and remain protected.
11. Audits/information
PayoutChecker will make reasonable compliance information available. Audit rights for larger customers should be defined in an Order Form and structured to protect other customers, security and confidentiality.
12. Cross-border processing
If applicable law requires a transfer mechanism for cross-border processing, the parties will implement the legally required mechanism in an Order Form/addendum. Production hosting and subprocessor locations must be documented accurately.
13. Conflicts
If this DPA conflicts with the main agreement on processing of Customer Data, the DPA controls to the extent of that conflict.
