DPA

July 2026 | Version 1.2

DPA

July 2026 | Version 1.2

DPA

July 2026 | Version 1.2

SOUS

Powering Commerce for F&B

Schedule 1: Data Processing Agreement (DPA)

Forming part of the SOUS Merchant Terms of Service

Last updated: July 2026 | Version 1.2 | Governed by Dutch law | Amsterdam courts

This Data Processing Agreement ("DPA") is Schedule 1 to the SOUS Merchant Terms of Service ("Terms").

It applies wherever SOUS processes personal data of Customers on behalf of the Merchant as a processor

within the meaning of Article 28 GDPR. Capitalised terms not defined herein have the meanings given

to them in the Terms. In the event of conflict, this DPA prevails in respect of data protection matters.

This DPA is accepted by the Merchant as part of the Terms upon completion of onboarding or

digital acceptance of the Terms. No separate signature is required.

1. Parties and Roles

The parties to this DPA are:

Data Controller

The Merchant, as identified in the SOUS Portal upon registration.

Data Processor

Acroya B.V. (trading as SOUS), Vijzelstraat 77A, 1017 HG Amsterdam, The Netherlands, KvK 85080276.

As between the parties, the Merchant acts as the data controller and SOUS acts as the data processor in relation to the processing of personal data of Customers in connection with the Services, as further described in Clause 11 of the Terms. SOUS acts as an independent data controller only in respect of: (i) its own account management and billing data; (ii) aggregated and anonymised analytics derived from platform usage; and (iii) processing required for SOUS's own legal compliance obligations.

2. Subject Matter and Duration

SOUS processes personal data of Customers on behalf of the Merchant for the purpose of providing the Services as described in the Terms and this DPA. The processing begins upon commencement of the Merchant's Subscription Plan and continues for the duration of the Terms. Upon termination of the Terms for any reason, SOUS shall, at the Merchant's written election, either return or securely delete all Customer Data within thirty (30) days of termination, except to the extent SOUS is required to retain it under applicable law. In such case, SOUS shall notify the Merchant in writing of the nature and duration of such retention.

3. Nature, Purpose, and Details of Processing

The nature and purpose of SOUS's processing of personal data on behalf of the Merchant, together with the categories of personal data and data subjects involved, are set out in Appendix A to this DPA. The processing is limited to what is strictly necessary for the purposes set out in Appendix A and in Clause 11.3 of the Terms.

4. Obligations of SOUS as Processor

SOUS shall, in its capacity as data processor:

4.1 Instructions

Process personal data only on the documented instructions of the Merchant, as set out in the Terms and this DPA, unless required to do otherwise by applicable law. If SOUS is required by law to carry out any processing not covered by the Merchant's instructions, SOUS shall inform the Merchant prior to such processing unless prohibited by law from doing so.

4.2 Confidentiality

Ensure that all SOUS personnel authorised to process personal data are bound by appropriate confidentiality obligations (whether contractual or statutory) and are familiar with their data protection responsibilities. Access to personal data is restricted to those personnel who need it in order to perform the Services.

4.3 Security

Implement and maintain appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The specific measures implemented by SOUS are described in Appendix C to this DPA. SOUS may update these measures from time to time, provided that the security level is not reduced below the standard set out in Appendix C.

4.4 Sub-processors

SOUS may engage sub-processors only in accordance with Clause 5 of this DPA. SOUS shall impose equivalent data protection obligations on each sub-processor and remains fully responsible for the performance of each sub-processor as if SOUS were performing the processing itself.

4.5 Data Subject Rights Assistance

To the extent SOUS receives a request from a data subject relating to Customer Data processed on behalf of the Merchant, SOUS shall forward such request to the Merchant without undue delay and in any event within three (3) business days of receipt. SOUS shall not independently respond to such a request unless legally required to do so. SOUS shall provide reasonable assistance to the Merchant in responding to data subject requests, taking into account the nature of the processing and the information available to SOUS.

4.6 Assistance with Compliance Obligations

Taking into account the nature of the processing and the information available to SOUS, SOUS shall provide reasonable assistance to the Merchant in ensuring compliance with the obligations under Articles 32 to 36 GDPR, including in relation to:

  • security of processing (Article 32 GDPR);

  • notification of personal data breaches to supervisory authorities (Article 33 GDPR);

  • communication of personal data breaches to data subjects (Article 34 GDPR);

  • data protection impact assessments (Article 35 GDPR); and

  • prior consultation with supervisory authorities (Article 36 GDPR).

4.7 Personal Data Breach Notification

SOUS shall notify the Merchant without undue delay and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting Customer Data processed on behalf of the Merchant. Such notification shall include, to the extent available at the time of notification, the information set out in Article 33(3) GDPR, including: (a) the nature of the breach; (b) the categories and approximate number of data subjects and records concerned; (c) the likely consequences; and (d) the measures taken or proposed to address the breach. SOUS shall cooperate with the Merchant and provide ongoing updates as further information becomes available.

4.8 Audit Rights

SOUS shall make available to the Merchant all information reasonably necessary to demonstrate compliance with its obligations under this DPA and shall allow for, and contribute to, audits and inspections conducted by the Merchant or an auditor mandated by the Merchant, subject to the following conditions:

  • the Merchant shall give SOUS at least fourteen (14) business days' prior written notice of any intended audit;

  • audits shall be conducted during normal business hours, in a manner that minimises disruption to SOUS's operations;

  • the Merchant's auditor shall be subject to appropriate confidentiality obligations;

  • the costs of any audit shall be borne by the Merchant, unless the audit reveals a material breach by SOUS of this DPA, in which case SOUS shall bear its own reasonable costs; and

  • SOUS may satisfy the audit obligation by providing up-to-date third-party certifications or audit reports (such as SOC 2 or ISO 27001, once available) in lieu of an on-site inspection, provided such reports adequately address the scope of the audit request.

4.9 Deletion or Return on Termination

As set out in Clause 2 of this DPA and Clause 11.9 of the Terms, upon termination of the Terms for any reason, SOUS shall at the Merchant's written election either return or securely delete all Customer Data within thirty (30) days. SOUS shall confirm in writing once deletion or return has been completed.

5. Sub-Processors

5.1 Authorised Sub-Processors

The Merchant hereby grants SOUS general authorisation to engage the sub-processors listed in Appendix B to this DPA. SOUS shall ensure that each sub-processor is bound by a written agreement imposing data protection obligations at least equivalent to those set out in this DPA, in accordance with Article 28(4) GDPR.

5.2 Changes to Sub-Processors

SOUS shall notify the Merchant at least fourteen (14) days in advance of any intended addition or replacement of a sub-processor, by notifying the Merchant's designated administrative contact by email. The Merchant may object to such a change on reasonable data protection grounds within fourteen (14) days of such notification. If the Merchant raises a reasonable objection, the parties shall seek to resolve the matter in good faith. If the parties cannot agree within a further fourteen (14) days, either party may terminate the relevant Subscription Plan on thirty (30) days' written notice.

5.3 Liability for Sub-Processors

SOUS remains fully liable to the Merchant for the performance of each sub-processor's data protection obligations under this DPA as if SOUS were performing the processing itself, in accordance with Article 28(4) GDPR.

6. International Transfers

SOUS shall not transfer personal data to a country outside the European Economic Area (EEA) unless an appropriate transfer safeguard is in place in accordance with Chapter V GDPR. The transfer mechanisms applicable to each sub-processor are set out in Appendix B. SOUS relies primarily on:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission (Commission Implementing Decision (EU) 2021/914) for transfers to non-adequate third countries; and

  • The EU–US Data Privacy Framework adequacy decision (10 July 2023) where the relevant recipient is certified under that framework.

SOUS shall carry out transfer impact assessments where required and shall implement supplementary technical and organisational measures (such as encryption in transit and at rest) where the outcome of a transfer impact assessment requires it. Further details of transfer safeguards per sub-processor are available on request at [email protected].

7. Merchant's Obligations as Controller

The Merchant, as data controller, is responsible for:

  • ensuring that there is a valid legal basis for all processing of Customer Data under the Terms and this DPA, and documenting such legal basis in accordance with Article 30 GDPR;

  • providing all required privacy notices to Customers prior to or at the point of data collection, in accordance with Articles 13 and 14 GDPR, including information about SOUS's role as processor;

  • ensuring that any instructions given to SOUS comply with applicable data protection law;

  • maintaining records of processing activities to the extent required by Article 30 GDPR; and

  • notifying SOUS without undue delay and in any event within forty-eight (48) hours of becoming aware of any personal data breach affecting Customer Data that may affect SOUS's obligations as processor or the integrity of the Services, in accordance with Clause 12.5 of the Terms.

8. Liability

Each party shall be liable to data subjects in accordance with Article 82 GDPR for damage caused by processing that infringes the GDPR. As between the parties, the liability provisions of Clause 18 of the Terms apply to all claims under or in connection with this DPA, including claims relating to data protection matters, subject to the liability cap set out in Clause 18.8 of the Terms. The liability cap does not apply in the case of wilful misconduct or gross negligence, as provided in Clause 18.2 of the Terms.

9. Governing Law and Jurisdiction

This DPA is governed by and construed in accordance with the laws of the Netherlands. Any disputes arising out of or in connection with this DPA shall be submitted exclusively to the competent courts of Amsterdam, in accordance with Clause 21 of the Terms.

10. Miscellaneous

If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect. This DPA forms an integral part of the Terms and is accepted by the Merchant upon digital acceptance of the Terms. No separate signature is required. In the event of conflict between this DPA and the Terms on data protection matters, this DPA prevails.

Appendix A – Details of Processing

The following table sets out the details of SOUS's processing of personal data on behalf of the Merchant, in accordance with Article 28(3) GDPR.

Processing activity

Categories of personal data

Categories of data subjects

Purpose

Order and transaction processing

Full name
Delivery address
Order contents and quantity
Selected delivery method
Order status and history
Payment metadata and transaction reference

End-customers of Merchant

Fulfilment of Direct Agreements; payment facilitation

Logistics and delivery coordination

Full name
Delivery address
Delivery time window
Delivery preferences and instructions
Tracking reference

End-customers of Merchant

Coordination with logistics providers (SoCool, SendCloud, Uber Direct) for fulfilment

Payment processing

Payment method metadata
Transaction reference
Partial card identifiers (last 4 digits, where displayed)
Refund and chargeback data

End-customers of Merchant

Processing payments via Stripe, Adyen (EEA merchants) or Paystack (South African merchants); refund and dispute handling

Customer authentication (where enabled)

Email address
Hashed password / session token
Login metadata

End-customers of Merchant (registered accounts only)

Enabling customer login functionality via Firebase

Customer relationship management (CRM)

Full name
Email address
Communication preferences
Opt-in/opt-out status
Order history summary

End-customers of Merchant

CRM tools within the Merchant Portal; enabling merchant-to-customer communications

Gift card issuance and redemption

Order reference
Gift card identifier and balance
Redemption records

End-customers of Merchant

Gift card processing via Gifty

Business listings & visibility (Spotlight)

Business profile & listing data; review content and reviewer display names; review-response contact data; connected Google Analytics metrics where the Merchant authorises access via OAuth (may include online identifiers)

End-customers/reviewers of Merchant; Merchant personnel

Publishing and syncing business listings; managing and responding to reviews (incl. AI-assisted) and visibility insights via Uberall and Ceyo

Platform security and fraud prevention

IP address
Device and browser metadata
Request and session logs
Webhook validation metadata

End-customers of Merchant; Merchant personnel

DDoS protection (Cloudflare); fraud detection; platform integrity

Merchant personnel (portal access)

Name
Email address
Role and access level
Login and session data

Merchant's authorised portal users

Providing and securing access to the Merchant Portal; account management

Google APIs. The only direct Google OAuth connection is to Google Analytics, accessed on a read-only basis and limited to the scope the Merchant authorises, used solely to provide the Spotlight visibility insights described above. Business listings (including Google Business Profile) are managed via Uberall rather than a direct Google OAuth connection. Data accessed from Google APIs is not sold, not used for advertising, and not used to train or improve artificial intelligence or machine learning models. This use adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Appendix B – Authorised Sub-Processors

The following sub-processors are authorised as of the version date of this DPA. The current sub-processor list is updated in accordance with Clause 5.2 of this DPA. Merchants will be notified of any changes by email at least fourteen (14) days in advance. The current list is available on request at [email protected].

Processor

Role

Data categories

Location

Transfer safeguard

Stripe

Payment processing, payouts, KYC/KYB (dedicated connected account per Merchant)

Payment metadata; merchant identity; payout details

USA / EEA

EU–US DPF; SCCs

Adyen N.V.

Payment acquiring/processing; per-merchant connected/sub-merchant account setup (primary provider for EEA merchants)

Payment metadata; merchant identity; payout details

Netherlands (EEA)

Within EEA

Paystack

Payment processing; per-merchant account setup (South African merchants only)

Payment metadata; merchant identity; payout details

South Africa

POPIA (SA); SCCs for any EEA data

Solvimon

Usage-based billing and invoicing only (billing layer; no funds flow or connected-account setup)

Merchant account & billing data

Netherlands (EEA)

Within EEA

Google Cloud Platform

Cloud hosting, database, storage, task queues, logging

All platform data; server logs; stored files

EEA (primary); USA for certain services

Adequacy / SCCs

Vercel

Merchant Portal frontend hosting

Portal usage data; server logs

USA / global CDN

SCCs

Saleor

Commerce engine: cart, checkout, vouchers, order events

Product data; cart/order data; end-customer identifiers

EEA

Within EEA

Shopify

Merchant discovery channel; product sync and order webhooks

Product catalogue; order data

USA / Canada

SCCs

Firebase (Google)

Customer authentication

Credentials; session tokens

EEA (primary)

Adequacy / SCCs

SoCool

Nationwide chilled logistics (NL)

Order/delivery data; recipient address; time windows

Netherlands (EEA)

Within EEA

SendCloud

Aggregated multi-carrier logistics

Shipment data; recipient address

Netherlands (EEA)

Within EEA

Uber Portier B.V. / Uber Eats NL B.V.

On-demand delivery (Uber Direct)

Recipient name; delivery address; order contents; proof of delivery

Netherlands (EEA)

Within EEA

Gifty

Gift card issuance, ledger and fulfilment

Order reference; gift card identifiers; redemption data

Netherlands (EEA)

Within EEA

Uberall

Business directory integration and review management

Business profile data; review content; review-generation contact data

Netherlands / EEA

Within EEA

Ceyo

Prompt tracking and GEO/SEO visibility insights

Prompt data; merchant brand/profile data; visibility outputs

Netherlands / EEA

Within EEA

Cloudflare

DDoS protection, CDN, web security

IP addresses; request metadata

USA / global

SCCs

Sentry

Error monitoring and diagnostics

Error logs; stack traces; session context

USA

SCCs

PostHog

Product analytics

Usage events; device identifiers; anonymised IPs

EEA

Within EEA

Funds flow, payout and KYC/KYB via per-merchant connected/sub-merchant accounts are handled by Stripe, Adyen and Paystack. Solvimon is the billing layer only. Merchant-billing records held by Solvimon and the payment providers relate to the Merchant's own account data, for which SOUS acts as an independent controller (see Clause 1); they are listed here for transparency.

Published business-listing platforms (e.g. Google Business Profile, Google Maps, Apple Maps, TripAdvisor) receive listing data as independent controllers under their own terms and are not sub-processors of SOUS.

Appendix C – Technical and Organisational Measures (TOMs)

The following technical and organisational measures are implemented by SOUS as data processor, in accordance with Article 32 GDPR and Clause 4.3 of this DPA. These measures are subject to periodic review and improvement. The overall security level will not be reduced below the standard described herein.

Measure category

Description

Encryption in transit

All data transmitted between users, the SOUS platform, and third-party services is encrypted using TLS 1.2 or higher (HTTPS). All API communications are encrypted.

Encryption at rest

Sensitive data fields are encrypted at rest within the Google Cloud infrastructure. Storage volumes and database snapshots are encrypted using AES-256.

Access controls

Role-based access controls (RBAC) limit access to personal data to authorised personnel on a strict need-to-know basis. Secrets and credentials are managed via Google Cloud Secret Manager. Remote access to infrastructure requires individual private-key authentication; direct password-based access is not permitted.

Infrastructure security

The SOUS backend runs on Google Cloud Platform with horizontal auto-scaling and is protected by Cloudflare DDoS mitigation and web application firewall (WAF) services. All inbound webhooks are validated using signature verification and idempotency controls to prevent forged or replayed events.

Secure development

All code changes require mandatory peer review and automated testing prior to deployment. A controlled CI/CD process governs staging-to-production promotion. Dependency and infrastructure scanning is performed continuously via Aikido and Snyk. Code quality is monitored using CodeScene.

Data separation

Each merchant's data is logically separated within the platform. The principle of functional separation between service and development environments is maintained. Data used in development and testing is anonymised.

Availability and resilience

Regular database snapshots are taken and stored in geographically distributed locations. The infrastructure can be restored through automated procedures. SOUS targets a monthly uptime of at least 99% for the platform, measured at the server handover point.

Incident response

SOUS maintains an incident response process. In the event of a personal data breach, SOUS will notify the Merchant within 48 hours and the Autoriteit Persoonsgegevens within 72 hours where required under Article 33 GDPR.

Personnel obligations

SOUS personnel with access to personal data are bound by confidentiality obligations and receive regular data protection awareness training. Access rights are reviewed periodically and revoked upon role change or departure.

Monitoring and logging

All access to personal data is logged centrally. Logs are retained for 90 days on a rolling basis for security incident investigation purposes. Monitoring is performed via Google Cloud Logging and Sentry.

© 2026 Acroya B.V. trading as SOUS. Schedule 1 to the SOUS Merchant Terms of Service.

Powering food entrepreneurs

Wir haben es uns zur Aufgabe gemacht, Gastronomie-Unternehmern dabei zu helfen, sichtbarer und erfolgreicher zu werden.

Stay up to date

By signing up you agree to our privacy policy
and terms of service

See how you rank across AI and search

Google, Maps, ChatGPT, Claude, and more

SOUS © All rights reserved

Powering food
entrepreneurs

Wir haben es uns zur Aufgabe gemacht, Gastronomie-Unternehmern dabei zu helfen, sichtbarer und erfolgreicher zu werden.

Stay up to date

By signing up you agree to our privacy policy and terms of service

See how you rank
across AI and search

Google, Maps, ChatGPT,
Claude, and more

SOUS © All rights reserved

Powering food entrepreneurs

Wir haben es uns zur Aufgabe gemacht, Gastronomie-Unternehmern dabei zu helfen, sichtbarer und erfolgreicher zu werden.

Stay up to date

By signing up you agree to our privacy policy
and terms of service

See how you rank across AI and search

Google, Maps, ChatGPT, Claude, and more

SOUS © All rights reserved