Version 2026-08-05-review.1
Data Processing Addendum
Article 28 data-processing terms for personal data QRaff processes on behalf of a Merchant.
- Status
- review
- Canonical SHA-256
- 6820caa678b29382d612c97f614cc2d279ef3d146b72a124a6b8c088a89503c4
1. Scope and parties
This Data Processing Addendum ("DPA") supplements the Merchant SaaS Terms between Nickel Ceramics Veronika Veremichyk, NIP 5833551465 ("QRaff", "Processor") and the accepting Merchant ("Merchant", "Controller"). It applies only where QRaff processes Personal Data on the Merchant's documented behalf.
Terms such as Controller, Processor, Data Subject, Personal Data, processing and supervisory authority have the meanings given in Regulation (EU) 2016/679 (GDPR). If the Merchant processes data for another controller, QRaff acts as its subprocessor and the Merchant confirms it is authorized to appoint QRaff.
2. Documented instructions
QRaff will process Merchant Personal Data only to provide, secure, maintain and support the configured QRaff services; to carry out actions initiated by authorized users; and under other documented lawful instructions agreed by the parties. The Agreement, this DPA, product configuration and support instructions together form the documented instructions.
QRaff will promptly inform the Merchant if, in QRaff's opinion, an instruction infringes applicable data-protection law, unless prohibited by law. QRaff may process data where required by Union or Member State law and will notify the Merchant of that requirement before processing unless the law prohibits notice.
3. Confidentiality and access
QRaff will ensure that persons authorized to process Merchant Personal Data are bound by confidentiality obligations and receive access only where needed for their duties. QRaff will maintain role-based access and administrative controls appropriate to the service.
4. Security measures
Taking account of the state of the art, implementation cost, processing context and risks, QRaff will maintain appropriate technical and organizational measures. These include, as applicable:
- encrypted transport, managed encryption at rest where provided by the hosting service, and protected credential storage;
- logical tenant and channel separation, least-privilege authorization and controlled production access;
- authentication, session controls, audit or operational logs, dependency maintenance and vulnerability remediation;
- backups, recovery procedures, availability monitoring and incident response;
- data minimization, retention controls and secure deletion workflows;
- regular review of material subprocessors and their contractual security commitments.
5. Personal-data breach
QRaff will notify the Merchant without undue delay after becoming aware of a Personal Data breach affecting Merchant Personal Data. The notice will provide available information reasonably needed for the Merchant's GDPR Articles 33 and 34 duties, including the nature of the breach, likely consequences, measures taken or proposed, and a contact point. Information may be supplied in phases as the investigation proceeds.
6. Data-subject requests and compliance assistance
Taking account of the nature of processing, QRaff will provide reasonable assistance through product functionality or support so the Merchant can respond to requests to access, rectify, erase, restrict, port or object to processing. If QRaff receives a request relating primarily to Merchant-controlled data, QRaff will direct it to the Merchant unless legally required to respond.
QRaff will provide reasonable information and assistance for security assessments, breach notifications, data-protection impact assessments and prior consultations where the processing and information available to QRaff make this necessary. The Merchant remains responsible for deciding whether a DPIA or consultation is required.
7. Subprocessors
The Merchant gives general written authorization for QRaff to engage subprocessors necessary to provide the service. The current review register is published at https://qraff.com/subprocessors and identifies core providers and separately identifies merchant-directed integrations whose legal roles may differ.
QRaff will impose data-protection obligations on each subprocessor that are no less protective than the relevant obligations in this DPA and remains responsible for its subprocessors' performance of those obligations. QRaff will give at least 14 days' advance notice of a new or replacement material subprocessor where reasonably possible. The Merchant may object during that period on reasonable data-protection grounds. The parties will seek a reasonable alternative; if none is available, either party may discontinue the affected feature without penalty for future unused service.
8. International transfers
QRaff will ensure that restricted transfers of Merchant Personal Data outside the EEA use a lawful transfer mechanism, such as an adequacy decision or the European Commission's 2021 Standard Contractual Clauses, together with supplementary safeguards where required. Where QRaff acts as Processor and the Merchant as Controller, Module Two applies; where both act as processors, Module Three applies. The Polish supervisory authority competent for the Merchant will remain competent where GDPR requires.
9. Audits and information
QRaff will make available information reasonably necessary to demonstrate compliance with GDPR Article 28. No more than once annually, unless required by a regulator or following a material incident, the Merchant may request a proportionate remote audit or relevant third-party assurance. Any on-site inspection requires reasonable notice, confidentiality, minimal disruption and allocation of costs agreed in advance.
10. Return, deletion and duration
This DPA remains in force while QRaff processes Merchant Personal Data. On termination, QRaff will make available product-supported export options and, at the Merchant's choice, delete or return Merchant Personal Data, unless Union or Member State law requires retention. Data in backups will be isolated from ordinary use and deleted on the normal backup-expiry cycle. Acceptance evidence, billing, fraud-prevention and security records controlled by QRaff are outside this processor deletion instruction and remain governed by QRaff's privacy notice and legal retention duties.
Annex 1 — Processing details
Subject matter and purpose: operation of the Merchant's configured digital venue, ordering, reservation, loyalty, review, analytics, communication, staff, delivery and integration workflows. Duration: the service term plus documented export, backup-expiry and deletion periods.
- Data subjects: guests and customers; prospective guests; reservation participants; delivery recipients; Merchant owners, administrators, managers, staff and couriers; people communicating with the Merchant.
- Data categories: names and contact details; account and role data; order, reservation, delivery and loyalty records; reviews and support communications; venue interaction and consented analytics events; device, session, network and security metadata; payment references and statuses (not full card details handled by the payment provider); content submitted to enabled AI features.
- Operations: collection, recording, organization, hosting, retrieval, transmission, display, analysis, support, restriction, export and deletion as instructed through the service.
- Special-category data: not intentionally required. The Merchant must not intentionally submit special-category data unless the parties first document a lawful need and appropriate safeguards.
Annex 2 — Controller instructions and responsibilities
The Merchant determines the purposes and lawful bases for guest and staff processing, provides required privacy information, manages consents where applicable, configures retention and permissions, and ensures its instructions are lawful. The Merchant must not use the service to process unlawful content or data beyond what is necessary for venue operations.
12. Order of precedence and contact
This DPA prevails over conflicting processor terms in the Merchant SaaS Terms. Applicable Standard Contractual Clauses prevail over both where required. Data-protection questions and notices may be sent to support@qraff.com or the registered address above.