Acroya B.V. trading as SOUS
Vijzelstraat 77A, 1017 HG Amsterdam, The Netherlands
Introductory Note
SOUS operates as both a data controller and, in certain contexts, a data processor. This Privacy Policy sets out how SOUS collects and processes personal data across all three contexts in which personal data is processed on or through the SOUS platform: (i) visitors to the SOUS marketing website; (ii) merchants who use the SOUS Merchant Portal and related services; and (iii) end-customers who purchase products or services through a SOUS-powered storefront.
Where SOUS processes personal data on behalf of a merchant (i.e., acting as a data processor in respect of that merchant’s end-customers), the merchant is the data controller for that data and SOUS processes it in accordance with the terms of the Data Processing Agreement (DPA) entered into with that merchant. This Policy provides the transparency information required under Articles 13 and 14 of the GDPR in relation to that processing.
1. Who We Are
The data controller for personal data processed in connection with the SOUS marketing website, the Merchant Portal, and SOUS platform services is:
SOUS is established in the Netherlands and is subject to the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Dutch Implementation Act (Uitvoeringswet AVG). Where SOUS processes personal data of individuals in the United Kingdom, it also complies with the UK GDPR and the Data Protection Act 2018.
SOUS does not currently appoint a Data Protection Officer (DPO) or an EU/UK representative. If this changes, this Policy will be updated accordingly.
Where SOUS processes personal data of individuals located in the Gulf Cooperation Council (GCC) region (including the UAE and KSA), this Policy is intended to meet the applicable transparency and data subject rights requirements under the UAE Federal Decree-Law No. 45/2021 on Personal Data Protection (UAE PDPL) and the KSA Personal Data Protection Law (KSA PDPL). In case of conflict, the more protective standard applies.
2. Scope and Structure of This Policy
This Policy applies to personal data processed in each of the following contexts:
- Website visitors: individuals who visit www.poweredbysous.com or any SOUS marketing page, whether to browse, request a demo, subscribe to updates, or purchase a subscription.
- Merchants: food and beverage entrepreneurs and businesses that have registered for and use the SOUS platform, including the Merchant Portal, Spotlight (business listing management), and associated services.
- End-customers: individuals who purchase products, experiences, or digital goods through a SOUS-powered storefront embedded in a merchant’s website, or who interact with a merchant’s SOUS-based commerce infrastructure.
The table in Section 3 below maps each processing purpose to the relevant category of data subjects and legal basis. Sections 6 through 10 address cookies, data sharing, international transfers, retention, and data subject rights respectively.
Where SOUS acts as a processor on behalf of a merchant for the personal data of end-customers, the merchant’s own privacy notice (which SOUS recommends all merchants publish in accordance with Article 13 GDPR) will govern the primary transparency relationship with that end-customer. This Policy supplements that notice by identifying SOUS as the sub-processor and describing the safeguards SOUS has in place.
3. Personal Data We Collect
3.1 Website Visitors
- Contact and business details: name, job title, company name, email address, telephone number (provided via contact forms, demo booking, or newsletter sign-up).
- Correspondence: content of any enquiries, support requests, or communications submitted through the website.
- Subscription and billing data: billing name, company identifiers (e.g., VAT number), billing address, selected plan, and subscription status. Payment card data is processed directly by Stripe; SOUS does not receive or store full card details.
- Device and usage data: IP address, device identifiers, browser type and version, operating system, time zone, pages viewed, click and scroll behaviour, referral source, and session duration, collected via cookies and analytics SDKs.
- Server log data: automatically generated access logs recording request metadata (browser/OS, referrer URL, hostname, timestamp, IP address), retained for security and operational purposes only.
3.2 Merchants
- Business identity data: legal entity name, trading name, registered address, VAT number, KvK (Chamber of Commerce) number, and contact details of authorised representatives.
- KYC and verification data: identity and business verification information collected and processed by Stripe as part of merchant onboarding and KYC/KYB compliance.
- Platform configuration data: product catalogues (including physical products, digital goods, vouchers, and experiences), pricing, logistics settings, fulfilment rules, and availability configurations.
- Financial and transactional data: invoices, payout records, fee statements, and subscription billing history.
- Customer relationship data: merchant-owned CRM data, including end-customer contact details and communication preferences managed through the Merchant Portal.
- Business listing data (Spotlight): business profile information (name, address, opening hours, menus, images, social profiles) published to external directories and review platforms via Uberall.
- Communications and support: correspondence with SOUS support, onboarding records, and any other communications exchanged in the course of the contractual relationship.
3.3 End-Customers
End-customer data is processed by SOUS primarily in its capacity as a data processor on behalf of the relevant merchant. The categories of data typically processed include:
- Order data: name, delivery address, order contents, selected delivery method, and order status.
- Payment data: payment method metadata and transaction references (full payment card processing is handled by Stripe; SOUS does not store card numbers or CVVs).
- Logistics data: delivery preferences, time windows, and tracking information transmitted to logistics providers (SoCool, SendCloud).
- Gift card data: gift card identifiers and redemption records (processed via Gifty).
- Communication preferences: opt-in status for merchant communications, managed within the Merchant Portal CRM.
- Authentication data: account credentials and session tokens for end-customers who create a customer login (where this feature is enabled by the merchant).
3.4 Data We Do Not Collect
SOUS does not intentionally collect special category data (as defined in Article 9 GDPR), nor personal data relating to children under the age of 16, through any part of the platform. Food preference or dietary information submitted as part of a product order is treated as operational order data and is not processed for profiling purposes. If you believe that special category data or children’s data has been inadvertently submitted, please contact us immediately at [email protected].
4. Purposes of Processing and Legal Bases
The table below sets out each purpose for which SOUS processes personal data, the categories of data subjects to whom it applies, and the applicable legal basis under Article 6 GDPR (and, where relevant, Article 9 GDPR for special categories).
Where SOUS relies on legitimate interests as the legal basis, it has carried out a balancing assessment and is satisfied that its interests are not overridden by the interests or fundamental rights of the data subjects concerned. Copies of relevant legitimate interests assessments are available upon request.
Where processing is based on consent, data subjects have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal can be exercised as described in Section 10 below.
5. Cookies and Tracking Technologies
SOUS uses cookies and similar tracking technologies on its marketing website and, where applicable, on the merchant-facing portal. The following categories of cookies are used:
- Strictly necessary cookies: required for the operation of the website and platform (e.g., authentication session tokens, payment security cookies set by Stripe). These are deployed without requiring consent.
- Analytics and performance cookies: used to measure website traffic and platform usage (e.g., Google Analytics 4, PostHog). These are deployed only with your prior consent where required by applicable law, including the Dutch Telecommunications Act (Telecommunicatiewet) and, for visitors from Germany, § 25 TTDSG.
- Functional cookies: used to remember your preferences and settings. Deployed on the basis of legitimate interests where strictly necessary for platform functionality, or on the basis of consent where not.
Google Analytics 4 (GA4)
We use GA4 for aggregated website analytics with IP anonymisation enabled. User and event data retention is set to 14 months. You may withdraw consent via the Cookie Settings link in the website footer or by using Google’s opt-out browser add-on (available at tools.google.com/dlpage/gaoptout).
Stripe
If you purchase a subscription plan on the SOUS website, Stripe deploys strictly necessary cookies for payment security and fraud prevention. These operate without additional consent as they are necessary to provide the requested service.
PostHog
PostHog is used for product analytics within the platform. Where PostHog collects personal data (e.g., pseudonymous device identifiers), it does so under SOUS’s instructions as a data processor. IP addresses are anonymised prior to storage.
Managing Your Cookie Preferences
You may manage or withdraw your consent to non-essential cookies at any time via the Cookie Settings link in the website footer or through your browser settings. Note that disabling certain cookies may affect the functionality of the website or platform.
6. Data Sharing and Third-Party Processors
6.1 General Principles
SOUS shares personal data with third parties only to the extent necessary to deliver its services, comply with legal obligations, or protect its legitimate interests. All third-party service providers acting as data processors are engaged under data processing agreements that comply with Article 28 GDPR and impose equivalent data protection obligations.
All merchant, product, order, and customer data is canonicalised and stored within SOUS-controlled systems. Third-party platforms are integrated via APIs but do not act as the system of record for SOUS platform data.
6.2 Processor and Partner Overview
The table below identifies the key processors and partners used by SOUS, their roles, the categories of data shared, their location, and the applicable transfer safeguard where data is transferred outside the EEA.
6.3 Business Listing Management (Spotlight) and Uberall Sub-Processors
Where a merchant subscribes to SOUS Spotlight, SOUS transmits business profile data (such as business name, address, opening hours, menu information, and images) to Uberall (uberall B.V., Amsterdam), which in turn distributes it to third-party business directories including Google Maps, Apple Maps, TripAdvisor, Bing, and other partner networks. SOUS and Uberall have entered into a Data Processing Addendum (DPA) pursuant to Article 28 GDPR (signed 8 September 2025, Order Q-13874), under which SOUS is the controller and Uberall is the processor.
Uberall itself processes data primarily within the EEA. However, Uberall engages a number of US-based sub-processors (as disclosed in Appendix 2 of the Uberall DPA, status August 2024), including SendGrid/Twilio (email communications), Pendo.io (analytics and in-application notifications), ChurnZero (data analysis), Heap Inc. (data analysis), and Google Cloud EMEA Limited (repository and communication functions). Where these sub-processors involve transfers of personal data outside the EEA, Uberall relies on SCCs and, where applicable, the EU–US Data Privacy Framework.
Third-party directory platforms (Google Maps, Apple Maps, TripAdvisor, etc.) receive and process business profile data as independent data controllers under their own privacy policies. SOUS does not control how external platforms display, rank, or retain listing data once published. Merchants may request correction or removal of listing data through the Merchant Portal or by contacting [email protected]. SOUS will use reasonable efforts to transmit such requests to Uberall, but cannot guarantee removal from all third-party platforms.
6.4 AI-Assisted Features and Associated Sub-Processors
SOUS uses AI-assisted features through two service providers, each with their own sub-processor chain:
- Uberall AI-powered features: Where a merchant uses AI Review Response, AI-Generated Auto Responses, or other AI-powered features within SOUS Spotlight, Uberall uses OpenAI OpCo LLC (San Francisco, USA) as a sub-processor for AI model inference. This transfer is governed by SCCs (Commission Implementing Decision (EU) 2021/914). Merchants should be aware that review text and business profile data are transmitted to OpenAI for processing. AI-generated responses are suggestions only and should be reviewed for accuracy before publication. SOUS does not use end-customer review data for training AI models, and Uberall’s sub-processor agreement with OpenAI prohibits use of data for model training purposes.
- Ceyo AI: SOUS uses Ceyo AI Inc. (a US corporation) for AI prompt tracking and GEO/SEO visibility insights on behalf of merchants. The Ceyo SLA (dated 12 April 2025) provides that all merchant data, prompts, outputs and derivatives are SOUS’s property, and that Ceyo may only use anonymised, aggregated data for internal improvement purposes. Ceyo’s SLA commits to storing data within the EEA or using approved international transfer mechanisms, and to using GDPR-compliant sub-processors. However, the Ceyo SLA expressly acknowledges that Ceyo’s service relies on third-party LLM providers (including OpenAI, Google, and Anthropic), whose availability is outside Ceyo’s SLA scope. SOUS is in the process of obtaining a formal Article 28-compliant DPA from Ceyo AI Inc. with a complete sub-processor annex. Until that DPA is in place, the data protection provisions of the Ceyo SLA apply.
6.5 Logistics: Uber Direct
SOUS has entered into an Uber Direct Merchant Agreement (Order Form, effective 27 April 2026) with Uber Portier B.V. and Uber Eats NL B.V. (together, “Uber”) for on-demand delivery services in the Netherlands. When a merchant’s end-customer places an order fulfilled via Uber Direct, SOUS transmits the relevant delivery data (recipient name, delivery address, delivery instructions, and order contents) to Uber to enable fulfilment. Uber Portier B.V. is a Dutch entity; personal data is processed primarily within the EEA. Any onward transfers within the wider Uber group are governed by Uber’s own data protection terms and applicable transfer mechanisms under Uber’s General Terms (available at www.uber.com/legal).
6.6 Other Disclosures
In addition to the processors listed above, SOUS may disclose personal data in the following circumstances:
- Legal compliance: where required by applicable law, court order, or regulatory authority, or to assert or defend legal claims.
- Corporate transactions: in connection with a merger, acquisition, asset sale, or restructuring, subject to appropriate confidentiality obligations and, where required, notification to data subjects.
- Professional advisers: to lawyers, auditors, accountants, and insurers, on a strictly need-to-know basis and subject to professional confidentiality obligations.
- Protection of rights: where reasonably necessary to protect the rights, property, or safety of SOUS, its merchants, end-customers, or the public.
6.7 Google User Data and Google API Services
Where a merchant authorises SOUS to connect to their Google account in connection with SOUS Spotlight, SOUS accesses Google Analytics data via Google OAuth on a read-only basis, limited to the scope authorised by the merchant. This data is used solely to provide visibility, search, and performance insights to the merchant within the Merchant Portal.
SOUS’s access to and use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. In particular, SOUS does not sell Google user data, does not use it for advertising, and does not use it to train or improve generalised artificial intelligence or machine learning models. A merchant may revoke SOUS’s access at any time through their Google account settings or via the Merchant Portal.
For the avoidance of doubt, this is distinct from SOUS’s use of Google Analytics 4 for its own marketing-website analytics described in Section 5, and from the publication of business listing data to Google directories via Uberall described in Section 6.3.
7. International Transfers of Personal Data
As indicated in the processor table in Section 6.2, certain SOUS service providers are located outside the European Economic Area (EEA), primarily in the United States. Where personal data is transferred to a country that has not received an adequacy decision from the European Commission, SOUS ensures that appropriate safeguards are in place in accordance with Chapter V GDPR. These safeguards include:
- Standard Contractual Clauses (SCCs): SOUS uses the European Commission’s standard contractual clauses (Commission Implementing Decision (EU) 2021/914) as the primary transfer mechanism for transfers to processors in non-adequate third countries.
- EU–US Data Privacy Framework (DPF): where a recipient is certified under the EU–US DPF and/or its UK Extension, SOUS may rely on the European Commission’s adequacy decision of 10 July 2023.
- Transfer Impact Assessments (TIAs): SOUS conducts transfer impact assessments for transfers to high-risk jurisdictions and implements supplementary technical and organisational measures (such as encryption in transit and at rest, and pseudonymisation) where the risk assessment requires it.
- UK GDPR: transfers to the United Kingdom are made under the European Commission’s adequacy decision of 28 June 2021. For transfers from the UK to third countries, SOUS relies on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.
You may obtain further information about the specific transfer mechanisms applicable to a particular processor by contacting us at [email protected]. Certain information may be redacted for reasons of commercial confidentiality.
8. Data Retention
SOUS retains personal data only for as long as is necessary for the purposes set out in this Policy, taking into account legal obligations, contractual requirements, and operational needs. The following retention schedule applies:
At the end of the applicable retention period, personal data is securely deleted or anonymised. Where anonymisation is not technically feasible, data is pseudonymised and access restricted to the minimum necessary personnel.
Retention periods may be extended where necessary for the establishment, exercise, or defence of legal claims, or where required by a competent authority.
9. Security
SOUS implements technical and organisational measures appropriate to the nature of the personal data it processes and the risks involved, in accordance with Article 32 GDPR. These measures include:
- Encryption: all data is encrypted in transit using TLS/HTTPS. Sensitive data fields are encrypted at rest within the platform’s Google Cloud infrastructure.
- Access controls: role-based access controls limit access to personal data to authorised personnel and service components on a strict need-to-know basis. Secrets and credentials are managed via Google Cloud Secret Manager.
- Infrastructure security: SOUS’s backend runs on Google Cloud Platform with horizontal auto-scaling and is protected by Cloudflare DDoS mitigation and web application firewall (WAF) services.
- Secure development: all code changes require mandatory peer review and automated testing prior to deployment. Dependency and infrastructure scanning is performed continuously via Aikido and Snyk.
- Webhook and API security: all inbound webhooks from third-party providers (including Saleor, Stripe, SoCool, and SendCloud) are validated using idempotency and signature verification to prevent forged or replayed events.
- Incident response: SOUS maintains an incident response process. In the event of a personal data breach that triggers notification obligations under Article 33 GDPR, SOUS will notify the relevant supervisory authority within 72 hours of becoming aware and will notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
SOUS does not currently hold formal security certifications (such as ISO 27001 or SOC 2). These are anticipated as the platform scales and regulatory requirements increase. SOUS’s current security posture is based on a defence-in-depth model appropriate for a seed-stage platform handling payments and personal data.
10. Your Rights as a Data Subject
10.1 Rights Under the GDPR (EEA and UK)
If you are located in the EEA or the UK, you have the following rights in respect of your personal data under the GDPR and UK GDPR, subject to applicable conditions and exemptions:
- Right of access (Art. 15 GDPR): to obtain confirmation of whether SOUS processes your personal data and, if so, to receive a copy of that data together with supplementary information about the processing.
- Right to rectification (Art. 16 GDPR): to have inaccurate or incomplete personal data corrected.
- Right to erasure (Art. 17 GDPR): to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected.
- Right to restriction of processing (Art. 18 GDPR): to request that processing be restricted in certain circumstances, for example while the accuracy of data is disputed.
- Right to data portability (Art. 20 GDPR): to receive personal data that you have provided to SOUS in a structured, commonly used, and machine-readable format, and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means.
- Right to object (Art. 21 GDPR): to object at any time to processing based on legitimate interests, including the right to object to direct marketing (which is absolute and must be honoured without delay).
- Right to withdraw consent (Art. 7(3) GDPR): where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.
- Right not to be subject to automated decision-making (Art. 22 GDPR): SOUS does not make decisions that produce legal or similarly significant effects based solely on automated processing.
To exercise any of the above rights, please contact us at [email protected]. We will respond within one month of receipt of your request. This period may be extended by a further two months where requests are complex or numerous, in which case we will notify you of the extension and the reasons for it within the first month.
We may need to verify your identity before responding to your request. We will not charge a fee for responding to a request unless it is manifestly unfounded or excessive.
10.2 Right to Lodge a Complaint
If you are in the EEA, you have the right to lodge a complaint with your local data protection supervisory authority. SOUS’s lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), which can be contacted at:
Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag
www.autoriteitpersoonsgegevens.nl | +31 (0)70 888 85 00
If you are in the UK, you may lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk.
10.3 Rights Under GCC Laws (UAE and KSA)
If you are located in the UAE or KSA, you may have equivalent rights under the UAE PDPL or KSA PDPL, including rights of access, correction, and deletion of your personal data, and the right to lodge a complaint with your competent local authority. Please contact us at [email protected] and we will respond within the timelines required by your applicable local law.
11. Marketing Communications and B2B Outreach
SOUS sends email newsletters and marketing updates only to individuals who have actively opted in to receive such communications. You may unsubscribe at any time by clicking the unsubscribe link in any marketing email or by contacting [email protected].
SOUS may conduct B2B sales outreach to contact details obtained from public sources (such as restaurant websites and business directories) or via lead-generation partners, where permitted under applicable e-privacy rules and on the basis of legitimate interests. Such outreach will always include a clear and easy mechanism to opt out of future communications.
SOUS does not sell personal data to third parties for marketing purposes, nor does it permit third parties to market their own products or services directly to SOUS’s merchants or end-customers without explicit consent.
12. Children
The SOUS platform is directed at food and beverage businesses and their adult customers. SOUS does not knowingly collect or process personal data of children under the age of 16 (or such other age as may be prescribed by applicable law). If you believe that a child has provided personal data through any part of the platform without appropriate parental consent, please contact us immediately at [email protected] and we will take prompt steps to delete such data.
13. Third-Party Links and External Platforms
The SOUS website and platform may contain links to third-party websites, platforms, or marketplaces (such as Just Eat Takeaway.com). SOUS is not responsible for the privacy practices of such third parties. You should review the privacy policy of any third-party platform before providing personal data to it.
Where SOUS integrates with third-party platforms (such as Shopify, Uberall-connected directories, or logistics providers) to deliver its services, those platforms’ terms and privacy policies will apply to their own data processing. SOUS takes reasonable steps to ensure that such platforms operate to an adequate standard of data protection, as described in the processor overview in Section 6.2.
14. Changes to This Policy
SOUS may update this Privacy Policy from time to time to reflect changes in its processing activities, applicable law, or regulatory guidance. The “Last updated” date at the top of this Policy indicates when it was most recently revised.
Material changes — that is, changes that significantly affect your rights or the way SOUS processes your personal data — will be communicated via a prominent notice on the SOUS website and, where appropriate, by direct notification to merchants and registered users. We encourage you to review this Policy periodically.
Continued use of the SOUS platform following notification of a material change constitutes acceptance of the updated Policy, to the extent permitted by applicable law.
15. How to Contact Us
For any questions, requests, or complaints relating to this Privacy Policy or SOUS’s processing of your personal data, please contact us at:
Acroya B.V. trading as SOUS
Vijzelstraat 77A, 1017 HG Amsterdam, The Netherlands
Email: [email protected]
Website: www.poweredbysous.com
We will acknowledge your request promptly and aim to respond substantively within one calendar month.
© 2026 Acroya B.V. trading as SOUS. All rights reserved.