Privacy Policy

Version 1.2 | Last updated: July 2026

Privacy Policy

Version 1.2 | Last updated: July 2026

Acroya B.V. trading as SOUS

Vijzelstraat 77A, 1017 HG Amsterdam, The Netherlands

Introductory Note

SOUS operates as both a data controller and, in certain contexts, a data processor. This Privacy Policy sets out how SOUS collects and processes personal data across all three contexts in which personal data is processed on or through the SOUS platform: (i) visitors to the SOUS marketing website; (ii) merchants who use the SOUS Merchant Portal and related services; and (iii) end-customers who purchase products or services through a SOUS-powered storefront.

Where SOUS processes personal data on behalf of a merchant (i.e., acting as a data processor in respect of that merchant’s end-customers), the merchant is the data controller for that data and SOUS processes it in accordance with the terms of the Data Processing Agreement (DPA) entered into with that merchant. This Policy provides the transparency information required under Articles 13 and 14 of the GDPR in relation to that processing.

1. Who We Are

The data controller for personal data processed in connection with the SOUS marketing website, the Merchant Portal, and SOUS platform services is:

Legal entity

Acroya B.V. trading as “SOUS”

Registered address

Vijzelstraat 77A, 1017 HG Amsterdam, The Netherlands

Chamber of Commerce (KvK)

85080276

General / privacy contact

Website

www.poweredbysous.com

Legal entity

Registered address

Acroya B.V. trading as “SOUS”

Vijzelstraat 77A, 1017 HG Amsterdam, The Netherlands

Legal entity

Chamber of Commerce (KvK)

Acroya B.V. trading as “SOUS”

85080276

Legal entity

General / privacy contact

Acroya B.V. trading as “SOUS”

Legal entity

Website

Acroya B.V. trading as “SOUS”

www.poweredbysous.com

SOUS is established in the Netherlands and is subject to the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Dutch Implementation Act (Uitvoeringswet AVG). Where SOUS processes personal data of individuals in the United Kingdom, it also complies with the UK GDPR and the Data Protection Act 2018.

SOUS does not currently appoint a Data Protection Officer (DPO) or an EU/UK representative. If this changes, this Policy will be updated accordingly.

Where SOUS processes personal data of individuals located in the Gulf Cooperation Council (GCC) region (including the UAE and KSA), this Policy is intended to meet the applicable transparency and data subject rights requirements under the UAE Federal Decree-Law No. 45/2021 on Personal Data Protection (UAE PDPL) and the KSA Personal Data Protection Law (KSA PDPL). In case of conflict, the more protective standard applies.

2. Scope and Structure of This Policy

This Policy applies to personal data processed in each of the following contexts:

- Website visitors: individuals who visit www.poweredbysous.com or any SOUS marketing page, whether to browse, request a demo, subscribe to updates, or purchase a subscription.

- Merchants: food and beverage entrepreneurs and businesses that have registered for and use the SOUS platform, including the Merchant Portal, Spotlight (business listing management), and associated services.

- End-customers: individuals who purchase products, experiences, or digital goods through a SOUS-powered storefront embedded in a merchant’s website, or who interact with a merchant’s SOUS-based commerce infrastructure.

The table in Section 3 below maps each processing purpose to the relevant category of data subjects and legal basis. Sections 6 through 10 address cookies, data sharing, international transfers, retention, and data subject rights respectively.

Where SOUS acts as a processor on behalf of a merchant for the personal data of end-customers, the merchant’s own privacy notice (which SOUS recommends all merchants publish in accordance with Article 13 GDPR) will govern the primary transparency relationship with that end-customer. This Policy supplements that notice by identifying SOUS as the sub-processor and describing the safeguards SOUS has in place.

3. Personal Data We Collect
3.1 Website Visitors

- Contact and business details: name, job title, company name, email address, telephone number (provided via contact forms, demo booking, or newsletter sign-up).

- Correspondence: content of any enquiries, support requests, or communications submitted through the website.

- Subscription and billing data: billing name, company identifiers (e.g., VAT number), billing address, selected plan, and subscription status. Payment card data is processed directly by Stripe; SOUS does not receive or store full card details.

- Device and usage data: IP address, device identifiers, browser type and version, operating system, time zone, pages viewed, click and scroll behaviour, referral source, and session duration, collected via cookies and analytics SDKs.

- Server log data: automatically generated access logs recording request metadata (browser/OS, referrer URL, hostname, timestamp, IP address), retained for security and operational purposes only.

3.2 Merchants

- Business identity data: legal entity name, trading name, registered address, VAT number, KvK (Chamber of Commerce) number, and contact details of authorised representatives.

- KYC and verification data: identity and business verification information collected and processed by Stripe as part of merchant onboarding and KYC/KYB compliance.

- Platform configuration data: product catalogues (including physical products, digital goods, vouchers, and experiences), pricing, logistics settings, fulfilment rules, and availability configurations.

- Financial and transactional data: invoices, payout records, fee statements, and subscription billing history.

- Customer relationship data: merchant-owned CRM data, including end-customer contact details and communication preferences managed through the Merchant Portal.

- Business listing data (Spotlight): business profile information (name, address, opening hours, menus, images, social profiles) published to external directories and review platforms via Uberall.

- Communications and support: correspondence with SOUS support, onboarding records, and any other communications exchanged in the course of the contractual relationship.

3.3 End-Customers

End-customer data is processed by SOUS primarily in its capacity as a data processor on behalf of the relevant merchant. The categories of data typically processed include:

- Order data: name, delivery address, order contents, selected delivery method, and order status.

- Payment data: payment method metadata and transaction references (full payment card processing is handled by Stripe; SOUS does not store card numbers or CVVs).

- Logistics data: delivery preferences, time windows, and tracking information transmitted to logistics providers (SoCool, SendCloud).

- Gift card data: gift card identifiers and redemption records (processed via Gifty).

- Communication preferences: opt-in status for merchant communications, managed within the Merchant Portal CRM.

- Authentication data: account credentials and session tokens for end-customers who create a customer login (where this feature is enabled by the merchant).

3.4 Data We Do Not Collect

SOUS does not intentionally collect special category data (as defined in Article 9 GDPR), nor personal data relating to children under the age of 16, through any part of the platform. Food preference or dietary information submitted as part of a product order is treated as operational order data and is not processed for profiling purposes. If you believe that special category data or children’s data has been inadvertently submitted, please contact us immediately at [email protected].

4. Purposes of Processing and Legal Bases

The table below sets out each purpose for which SOUS processes personal data, the categories of data subjects to whom it applies, and the applicable legal basis under Article 6 GDPR (and, where relevant, Article 9 GDPR for special categories).

Purpose

Examples

Data subjects

Legal basis (GDPR)

Operate and deliver the Platform

Serve website pages and the merchant portal
Run the storefront widget and checkout
Process and fulfil orders
Handle payments and payouts via Stripe

Website visitors; Merchants; End-customers

Art. 6(1)(b) – contract performance; Art. 6(1)(f) – legitimate interests

Merchant account management

Onboarding and identity/KYC verification (via Stripe)
Subscription billing and invoicing
Providing access to the Merchant Portal
Financial reporting and reconciliation

Merchants

Art. 6(1)(b) – contract; Art. 6(1)(c) – legal obligation (tax/accounting)

End-customer order fulfilment

Processing orders and payments
Logistics and delivery coordination (SoCool/SendCloud)
Sending order confirmations and tracking updates
Gift card issuance and redemption (Gifty)

End-customers

Art. 6(1)(b) – contract (with merchant); Art. 6(1)(f) – legitimate interests of merchant

Business listing management (Spotlight)

Publishing and synchronising business profiles to Google Maps, Apple Maps, TripAdvisor and other directories via Uberall
Managing and responding to reviews (including AI-assisted responses via Google Gemini)
AI prompt tracking and visibility insights (Ceyo)

Merchants

Art. 6(1)(b) – contract; Art. 6(1)(f) – legitimate interests

Analytics and platform improvement

Aggregated usage analytics (PostHog)
Error monitoring and performance diagnostics (Sentry)
Code quality and operational monitoring

Website visitors; Merchants; End-customers

Art. 6(1)(a) – consent (non-essential cookies); Art. 6(1)(f) – legitimate interests (aggregated/technical analytics)

Marketing and B2B outreach

Sending newsletters and product updates to subscribers
B2B sales outreach to food & beverage business contacts
Demo bookings and follow-up communications

Website visitors; Prospects; Merchants

Art. 6(1)(a) – consent (newsletters); Art. 6(1)(f) – legitimate interests (B2B outreach)

Security, fraud prevention and legal compliance

DDoS protection and web security (Cloudflare)
Webhook validation and API security
Detecting and preventing fraud and abuse
Responding to legal requests; enforcing our terms

All data subjects

Art. 6(1)(c) – legal obligation; Art. 6(1)(f) – legitimate interests

CRM and customer communication

Managing merchant CRM data within the platform
Enabling merchants to manage end-customer communication preferences
Email marketing tools (planned 2026)

Merchants; End-customers

Art. 6(1)(b) – contract; Art. 6(1)(a) – consent (where applicable)

Purpose

Operate and deliver the Platform

Examples

Serve website pages and the merchant portal
Run the storefront widget and checkout
Process and fulfil orders
Handle payments and payouts via Stripe

Data subjects

Website visitors; Merchants; End-customers

Legal basis (GDPR)

Art. 6(1)(b) – contract performance; Art. 6(1)(f) – legitimate interests

Purpose

Merchant account management

Examples

Onboarding and identity/KYC verification (via Stripe)
Subscription billing and invoicing
Providing access to the Merchant Portal
Financial reporting and reconciliation

Data subjects

Merchants

Legal basis (GDPR)

Art. 6(1)(b) – contract; Art. 6(1)(c) – legal obligation (tax/accounting)

Purpose

End-customer order fulfilment

Examples

Processing orders and payments
Logistics and delivery coordination (SoCool/SendCloud)
Sending order confirmations and tracking updates
Gift card issuance and redemption (Gifty)

Data subjects

End-customers

Legal basis (GDPR)

Art. 6(1)(b) – contract (with merchant); Art. 6(1)(f) – legitimate interests of merchant

Purpose

Business listing management (Spotlight)

Examples

Publishing and synchronising business profiles to Google Maps, Apple Maps, TripAdvisor and other directories via Uberall
Managing and responding to reviews (including AI-assisted responses via Google Gemini)
AI prompt tracking and visibility insights (Ceyo)

Data subjects

Merchants

Legal basis (GDPR)

Art. 6(1)(b) – contract; Art. 6(1)(f) – legitimate interests

Purpose

Analytics and platform improvement

Examples

Aggregated usage analytics (PostHog)
Error monitoring and performance diagnostics (Sentry)
Code quality and operational monitoring

Data subjects

Website visitors; Merchants; End-customers

Legal basis (GDPR)

Art. 6(1)(a) – consent (non-essential cookies); Art. 6(1)(f) – legitimate interests (aggregated/technical analytics)

Purpose

Marketing and B2B outreach

Examples

Sending newsletters and product updates to subscribers
B2B sales outreach to food & beverage business contacts
Demo bookings and follow-up communications

Data subjects

Website visitors; Prospects; Merchants

Legal basis (GDPR)

Art. 6(1)(a) – consent (newsletters); Art. 6(1)(f) – legitimate interests (B2B outreach)

Purpose

Security, fraud prevention and legal compliance

Examples

DDoS protection and web security (Cloudflare)
Webhook validation and API security
Detecting and preventing fraud and abuse
Responding to legal requests; enforcing our terms

Data subjects

All data subjects

Legal basis (GDPR)

Art. 6(1)(c) – legal obligation; Art. 6(1)(f) – legitimate interests

Purpose

CRM and customer communication

Examples

Managing merchant CRM data within the platform
Enabling merchants to manage end-customer communication preferences
Email marketing tools (planned 2026)

Data subjects

Merchants; End-customers

Legal basis (GDPR)

Art. 6(1)(b) – contract; Art. 6(1)(a) – consent (where applicable)

Where SOUS relies on legitimate interests as the legal basis, it has carried out a balancing assessment and is satisfied that its interests are not overridden by the interests or fundamental rights of the data subjects concerned. Copies of relevant legitimate interests assessments are available upon request.

Where processing is based on consent, data subjects have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal can be exercised as described in Section 10 below.

5. Cookies and Tracking Technologies

SOUS uses cookies and similar tracking technologies on its marketing website and, where applicable, on the merchant-facing portal. The following categories of cookies are used:

- Strictly necessary cookies: required for the operation of the website and platform (e.g., authentication session tokens, payment security cookies set by Stripe). These are deployed without requiring consent.

- Analytics and performance cookies: used to measure website traffic and platform usage (e.g., Google Analytics 4, PostHog). These are deployed only with your prior consent where required by applicable law, including the Dutch Telecommunications Act (Telecommunicatiewet) and, for visitors from Germany, § 25 TTDSG.

- Functional cookies: used to remember your preferences and settings. Deployed on the basis of legitimate interests where strictly necessary for platform functionality, or on the basis of consent where not.

Google Analytics 4 (GA4)

We use GA4 for aggregated website analytics with IP anonymisation enabled. User and event data retention is set to 14 months. You may withdraw consent via the Cookie Settings link in the website footer or by using Google’s opt-out browser add-on (available at tools.google.com/dlpage/gaoptout).

Stripe

If you purchase a subscription plan on the SOUS website, Stripe deploys strictly necessary cookies for payment security and fraud prevention. These operate without additional consent as they are necessary to provide the requested service.

PostHog

PostHog is used for product analytics within the platform. Where PostHog collects personal data (e.g., pseudonymous device identifiers), it does so under SOUS’s instructions as a data processor. IP addresses are anonymised prior to storage.

Managing Your Cookie Preferences

You may manage or withdraw your consent to non-essential cookies at any time via the Cookie Settings link in the website footer or through your browser settings. Note that disabling certain cookies may affect the functionality of the website or platform.

6. Data Sharing and Third-Party Processors
6.1 General Principles

SOUS shares personal data with third parties only to the extent necessary to deliver its services, comply with legal obligations, or protect its legitimate interests. All third-party service providers acting as data processors are engaged under data processing agreements that comply with Article 28 GDPR and impose equivalent data protection obligations.

All merchant, product, order, and customer data is canonicalised and stored within SOUS-controlled systems. Third-party platforms are integrated via APIs but do not act as the system of record for SOUS platform data.

6.2 Processor and Partner Overview

The table below identifies the key processors and partners used by SOUS, their roles, the categories of data shared, their location, and the applicable transfer safeguard where data is transferred outside the EEA.

Processor / Partner

Role

Data categories

Location

Transfer safeguard

Stripe

Payments, payouts, KYC/KYB; dedicated connected account per merchant

Payment metadata
Merchant identity
Payout details

USA / EEA

EU–US Data Privacy Framework; SCCs

Google Cloud Platform

Cloud hosting, database (Cloud SQL/Postgres), storage (GCS), task queues, logging, Cloud Run

All platform data
Server logs
Stored files

EEA (primary); USA for certain services

Adequacy decision / SCCs

Vercel

Hosting of Merchant Portal frontend

Portal usage data
Server logs

USA / global CDN

SCCs

Saleor

Commerce engine: cart, checkout, vouchers, order events

Product data
Cart/order data
End-customer identifiers

EEA

Within EEA – no transfer

Shopify

Merchant discovery channel; product sync and order webhooks

Product catalogue
Order data

USA / Canada

SCCs

Uberall (uberall B.V., Amsterdam)

Business directory integration (Google Maps, Apple Maps, TripAdvisor, etc.) and review management. DPA signed 8 September 2025 (Order Q-13874). Uberall has appointed a DPO: [email protected]

Business profile data
Review content
Review generation contact data
Social post data (where applicable)

Netherlands / EEA (primary); some sub-processors in USA – see Section 6.4

Within EEA (Uberall’s own processing); SCCs / EU-US DPF for US sub-processors

OpenAI OpCo LLC (via Uberall)

AI sub-processor used by Uberall for AI-powered features, including AI Review Response, AI-Generated Auto Responses, and AI Messages features

Review text
Business profile snippets
Message content (where applicable)

USA

SCCs (EU SCC 2021/914)

Ceyo AI Inc.

AI prompt tracking and GEO/SEO visibility insights on behalf of merchants. Governed by SLA dated 12 April 2025 (Dutch law). Note: Ceyo uses third-party LLMs (including OpenAI, Google, Anthropic) as part of its service; a formal sub-processor list under an Art. 28-compliant DPA is to be confirmed – see legal note in Section 6.4

AI prompt data
Merchant brand/profile data
Visibility scores and outputs

USA (Ceyo AI Inc. is a US corporation); data stored within EEA or under approved transfer mechanisms per SLA

SCCs (per Ceyo SLA commitment); formal DPA with Art. 28 sub-processor annex to be put in place

Uber Portier B.V. / Uber Eats NL B.V.

On-demand delivery services (Uber Direct). Order Form signed April 2026, territory: Netherlands. End-customer delivery data transmitted per order

Recipient name and delivery address
Order contents
Delivery instructions
Proof of delivery data

Netherlands / EEA (Uber Portier B.V.); potential onward transfers within Uber group

EU entity (Uber Portier B.V.); SCCs / adequacy for any onward Uber group transfers

SoCool

Nationwide chilled logistics (NL)

Order/delivery data
Recipient address
Time windows

Netherlands (EEA)

Within EEA – no transfer

SendCloud

Aggregated multi-carrier logistics

Shipment data
Recipient address

Netherlands (EEA)

Within EEA – no transfer

Gifty

Gift card issuance, ledger management, fulfilment

Order reference
Gift card identifiers
Redemption data

Netherlands (EEA)

Within EEA – no transfer

Firebase (Google)

Authentication services

User credentials
Session tokens

EEA (primary)

Adequacy / SCCs

Cloudflare

DDoS protection, CDN, web security

IP addresses
Request metadata

USA / global

SCCs

PostHog

Product and usage analytics

Usage events
Device identifiers
Anonymised IPs

EEA (self-hosted option)

Within EEA / SCCs

Sentry

Error monitoring and performance diagnostics

Error logs
Stack traces
Session context

USA

SCCs

Email delivery provider (SendCloud / transactional email)

Transactional and marketing email delivery

Email address
Name
Preferences

EEA

Within EEA – no transfer

Processor / Partner

Stripe

Role

Payments, payouts, KYC/KYB; dedicated connected account per merchant

Data categories

Payment metadata
Merchant identity
Payout details

Location

USA / EEA

Transfer safeguard

EU–US Data Privacy Framework; SCCs

Processor / Partner

Google Cloud Platform

Role

Cloud hosting, database (Cloud SQL/Postgres), storage (GCS), task queues, logging, Cloud Run

Data categories

All platform data
Server logs
Stored files

Location

EEA (primary); USA for certain services

Transfer safeguard

Adequacy decision / SCCs

Processor / Partner

Vercel

Role

Hosting of Merchant Portal frontend

Data categories

Portal usage data
Server logs

Location

USA / global CDN

Transfer safeguard

SCCs

Processor / Partner

Saleor

Role

Commerce engine: cart, checkout, vouchers, order events

Data categories

Product data
Cart/order data
End-customer identifiers

Location

EEA

Transfer safeguard

Within EEA – no transfer

Processor / Partner

Shopify

Role

Merchant discovery channel; product sync and order webhooks

Data categories

Product catalogue
Order data

Location

USA / Canada

Transfer safeguard

SCCs

Processor / Partner

Uberall (uberall B.V., Amsterdam)

Role

Business directory integration (Google Maps, Apple Maps, TripAdvisor, etc.) and review management. DPA signed 8 September 2025 (Order Q-13874). Uberall has appointed a DPO: [email protected]

Data categories

Business profile data
Review content
Review generation contact data
Social post data (where applicable)

Location

Netherlands / EEA (primary); some sub-processors in USA – see Section 6.4

Transfer safeguard

Within EEA (Uberall’s own processing); SCCs / EU-US DPF for US sub-processors

Processor / Partner

OpenAI OpCo LLC (via Uberall)

Role

AI sub-processor used by Uberall for AI-powered features, including AI Review Response, AI-Generated Auto Responses, and AI Messages features

Data categories

Review text
Business profile snippets
Message content (where applicable)

Location

USA

Transfer safeguard

SCCs (EU SCC 2021/914)

Processor / Partner

Ceyo AI Inc.

Role

AI prompt tracking and GEO/SEO visibility insights on behalf of merchants. Governed by SLA dated 12 April 2025 (Dutch law). Note: Ceyo uses third-party LLMs (including OpenAI, Google, Anthropic) as part of its service; a formal sub-processor list under an Art. 28-compliant DPA is to be confirmed – see legal note in Section 6.4

Data categories

AI prompt data
Merchant brand/profile data
Visibility scores and outputs

Location

USA (Ceyo AI Inc. is a US corporation); data stored within EEA or under approved transfer mechanisms per SLA

Transfer safeguard

SCCs (per Ceyo SLA commitment); formal DPA with Art. 28 sub-processor annex to be put in place

Processor / Partner

Uber Portier B.V. / Uber Eats NL B.V.

Role

On-demand delivery services (Uber Direct). Order Form signed April 2026, territory: Netherlands. End-customer delivery data transmitted per order

Data categories

Recipient name and delivery address
Order contents
Delivery instructions
Proof of delivery data

Location

Netherlands / EEA (Uber Portier B.V.); potential onward transfers within Uber group

Transfer safeguard

EU entity (Uber Portier B.V.); SCCs / adequacy for any onward Uber group transfers

Processor / Partner

SoCool

Role

Nationwide chilled logistics (NL)

Data categories

Order/delivery data
Recipient address
Time windows

Location

Netherlands (EEA)

Transfer safeguard

Within EEA – no transfer

Processor / Partner

SendCloud

Role

Aggregated multi-carrier logistics

Data categories

Shipment data
Recipient address

Location

Netherlands (EEA)

Transfer safeguard

Within EEA – no transfer

Processor / Partner

Gifty

Role

Gift card issuance, ledger management, fulfilment

Data categories

Order reference
Gift card identifiers
Redemption data

Location

Netherlands (EEA)

Transfer safeguard

Within EEA – no transfer

Processor / Partner

Firebase (Google)

Role

Authentication services

Data categories

User credentials
Session tokens

Location

EEA (primary)

Transfer safeguard

Adequacy / SCCs

Processor / Partner

Cloudflare

Role

DDoS protection, CDN, web security

Data categories

IP addresses
Request metadata

Location

USA / global

Transfer safeguard

SCCs

Processor / Partner

PostHog

Role

Product and usage analytics

Data categories

Usage events
Device identifiers
Anonymised IPs

Location

EEA (self-hosted option)

Transfer safeguard

Within EEA / SCCs

Processor / Partner

Sentry

Role

Error monitoring and performance diagnostics

Data categories

Error logs
Stack traces
Session context

Location

USA

Transfer safeguard

SCCs

Processor / Partner

Email delivery provider (SendCloud / transactional email)

Role

Transactional and marketing email delivery

Data categories

Email address
Name
Preferences

Location

EEA

Transfer safeguard

Within EEA – no transfer

6.3 Business Listing Management (Spotlight) and Uberall Sub-Processors

Where a merchant subscribes to SOUS Spotlight, SOUS transmits business profile data (such as business name, address, opening hours, menu information, and images) to Uberall (uberall B.V., Amsterdam), which in turn distributes it to third-party business directories including Google Maps, Apple Maps, TripAdvisor, Bing, and other partner networks. SOUS and Uberall have entered into a Data Processing Addendum (DPA) pursuant to Article 28 GDPR (signed 8 September 2025, Order Q-13874), under which SOUS is the controller and Uberall is the processor.

Uberall itself processes data primarily within the EEA. However, Uberall engages a number of US-based sub-processors (as disclosed in Appendix 2 of the Uberall DPA, status August 2024), including SendGrid/Twilio (email communications), Pendo.io (analytics and in-application notifications), ChurnZero (data analysis), Heap Inc. (data analysis), and Google Cloud EMEA Limited (repository and communication functions). Where these sub-processors involve transfers of personal data outside the EEA, Uberall relies on SCCs and, where applicable, the EU–US Data Privacy Framework.

Third-party directory platforms (Google Maps, Apple Maps, TripAdvisor, etc.) receive and process business profile data as independent data controllers under their own privacy policies. SOUS does not control how external platforms display, rank, or retain listing data once published. Merchants may request correction or removal of listing data through the Merchant Portal or by contacting [email protected]. SOUS will use reasonable efforts to transmit such requests to Uberall, but cannot guarantee removal from all third-party platforms.

6.4 AI-Assisted Features and Associated Sub-Processors

SOUS uses AI-assisted features through two service providers, each with their own sub-processor chain:

- Uberall AI-powered features: Where a merchant uses AI Review Response, AI-Generated Auto Responses, or other AI-powered features within SOUS Spotlight, Uberall uses OpenAI OpCo LLC (San Francisco, USA) as a sub-processor for AI model inference. This transfer is governed by SCCs (Commission Implementing Decision (EU) 2021/914). Merchants should be aware that review text and business profile data are transmitted to OpenAI for processing. AI-generated responses are suggestions only and should be reviewed for accuracy before publication. SOUS does not use end-customer review data for training AI models, and Uberall’s sub-processor agreement with OpenAI prohibits use of data for model training purposes.

- Ceyo AI: SOUS uses Ceyo AI Inc. (a US corporation) for AI prompt tracking and GEO/SEO visibility insights on behalf of merchants. The Ceyo SLA (dated 12 April 2025) provides that all merchant data, prompts, outputs and derivatives are SOUS’s property, and that Ceyo may only use anonymised, aggregated data for internal improvement purposes. Ceyo’s SLA commits to storing data within the EEA or using approved international transfer mechanisms, and to using GDPR-compliant sub-processors. However, the Ceyo SLA expressly acknowledges that Ceyo’s service relies on third-party LLM providers (including OpenAI, Google, and Anthropic), whose availability is outside Ceyo’s SLA scope. SOUS is in the process of obtaining a formal Article 28-compliant DPA from Ceyo AI Inc. with a complete sub-processor annex. Until that DPA is in place, the data protection provisions of the Ceyo SLA apply.

6.5 Logistics: Uber Direct

SOUS has entered into an Uber Direct Merchant Agreement (Order Form, effective 27 April 2026) with Uber Portier B.V. and Uber Eats NL B.V. (together, “Uber”) for on-demand delivery services in the Netherlands. When a merchant’s end-customer places an order fulfilled via Uber Direct, SOUS transmits the relevant delivery data (recipient name, delivery address, delivery instructions, and order contents) to Uber to enable fulfilment. Uber Portier B.V. is a Dutch entity; personal data is processed primarily within the EEA. Any onward transfers within the wider Uber group are governed by Uber’s own data protection terms and applicable transfer mechanisms under Uber’s General Terms (available at www.uber.com/legal).

6.6 Other Disclosures

In addition to the processors listed above, SOUS may disclose personal data in the following circumstances:

- Legal compliance: where required by applicable law, court order, or regulatory authority, or to assert or defend legal claims.

- Corporate transactions: in connection with a merger, acquisition, asset sale, or restructuring, subject to appropriate confidentiality obligations and, where required, notification to data subjects.

- Professional advisers: to lawyers, auditors, accountants, and insurers, on a strictly need-to-know basis and subject to professional confidentiality obligations.

- Protection of rights: where reasonably necessary to protect the rights, property, or safety of SOUS, its merchants, end-customers, or the public.

6.7 Google User Data and Google API Services

Where a merchant authorises SOUS to connect to their Google account in connection with SOUS Spotlight, SOUS accesses Google Analytics data via Google OAuth on a read-only basis, limited to the scope authorised by the merchant. This data is used solely to provide visibility, search, and performance insights to the merchant within the Merchant Portal.

SOUS’s access to and use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. In particular, SOUS does not sell Google user data, does not use it for advertising, and does not use it to train or improve generalised artificial intelligence or machine learning models. A merchant may revoke SOUS’s access at any time through their Google account settings or via the Merchant Portal.

For the avoidance of doubt, this is distinct from SOUS’s use of Google Analytics 4 for its own marketing-website analytics described in Section 5, and from the publication of business listing data to Google directories via Uberall described in Section 6.3.

7. International Transfers of Personal Data

As indicated in the processor table in Section 6.2, certain SOUS service providers are located outside the European Economic Area (EEA), primarily in the United States. Where personal data is transferred to a country that has not received an adequacy decision from the European Commission, SOUS ensures that appropriate safeguards are in place in accordance with Chapter V GDPR. These safeguards include:

- Standard Contractual Clauses (SCCs): SOUS uses the European Commission’s standard contractual clauses (Commission Implementing Decision (EU) 2021/914) as the primary transfer mechanism for transfers to processors in non-adequate third countries.

- EU–US Data Privacy Framework (DPF): where a recipient is certified under the EU–US DPF and/or its UK Extension, SOUS may rely on the European Commission’s adequacy decision of 10 July 2023.

- Transfer Impact Assessments (TIAs): SOUS conducts transfer impact assessments for transfers to high-risk jurisdictions and implements supplementary technical and organisational measures (such as encryption in transit and at rest, and pseudonymisation) where the risk assessment requires it.

- UK GDPR: transfers to the United Kingdom are made under the European Commission’s adequacy decision of 28 June 2021. For transfers from the UK to third countries, SOUS relies on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.

You may obtain further information about the specific transfer mechanisms applicable to a particular processor by contacting us at [email protected]. Certain information may be redacted for reasons of commercial confidentiality.

8. Data Retention

SOUS retains personal data only for as long as is necessary for the purposes set out in this Policy, taking into account legal obligations, contractual requirements, and operational needs. The following retention schedule applies:

Data category

Retention period

Rationale

Website visitor / analytics data

14 months

GA4 / PostHog default; sufficient for seasonal comparison

Enquiry and demo records (non-customers)

24 months

Reasonable sales cycle; delete earlier on request

Merchant account data (active)

Duration of contract + 7 years

Contractual relationship; statutory accounting and tax obligations

Merchant account data (terminated)

7 years post-termination

Legal obligation (Dutch Burgerlijk Wetboek, Art. 2:10; tax law)

End-customer order and transaction data

7 years

Tax and accounting obligations; consumer law claims window

Payment and financial records

7 years

Statutory obligation (Dutch tax law; Stripe audit requirements)

Marketing subscriptions

Until unsubscribe; suppression list indefinitely

Consent withdrawal; suppression list required to honour opt-outs

Security and server logs

90 days (rolling)

Incident investigation; proportionate to security purposes

KYC/identity verification records (via Stripe)

As required by applicable AML/KYC regulations

Legal obligation; Stripe retains under its own regulated obligations

Business listing data (Spotlight)

Duration of Spotlight subscription + 30 days

Active service delivery; grace period for re-activation

Data category

Website visitor / analytics data

Retention period

14 months

Rationale

GA4 / PostHog default; sufficient for seasonal comparison

Data category

Enquiry and demo records (non-customers)

Retention period

24 months

Rationale

Reasonable sales cycle; delete earlier on request

Data category

Merchant account data (active)

Retention period

Duration of contract + 7 years

Rationale

Contractual relationship; statutory accounting and tax obligations

Data category

Merchant account data (terminated)

Retention period

7 years post-termination

Rationale

Legal obligation (Dutch Burgerlijk Wetboek, Art. 2:10; tax law)

Data category

End-customer order and transaction data

Retention period

7 years

Rationale

Tax and accounting obligations; consumer law claims window

Data category

Payment and financial records

Retention period

7 years

Rationale

Statutory obligation (Dutch tax law; Stripe audit requirements)

Data category

Marketing subscriptions

Retention period

Until unsubscribe; suppression list indefinitely

Rationale

Consent withdrawal; suppression list required to honour opt-outs

Data category

Security and server logs

Retention period

90 days (rolling)

Rationale

Incident investigation; proportionate to security purposes

Data category

KYC/identity verification records (via Stripe)

Retention period

As required by applicable AML/KYC regulations

Rationale

Legal obligation; Stripe retains under its own regulated obligations

Data category

Business listing data (Spotlight)

Retention period

Duration of Spotlight subscription + 30 days

Rationale

Active service delivery; grace period for re-activation

At the end of the applicable retention period, personal data is securely deleted or anonymised. Where anonymisation is not technically feasible, data is pseudonymised and access restricted to the minimum necessary personnel.

Retention periods may be extended where necessary for the establishment, exercise, or defence of legal claims, or where required by a competent authority.

9. Security

SOUS implements technical and organisational measures appropriate to the nature of the personal data it processes and the risks involved, in accordance with Article 32 GDPR. These measures include:

- Encryption: all data is encrypted in transit using TLS/HTTPS. Sensitive data fields are encrypted at rest within the platform’s Google Cloud infrastructure.

- Access controls: role-based access controls limit access to personal data to authorised personnel and service components on a strict need-to-know basis. Secrets and credentials are managed via Google Cloud Secret Manager.

- Infrastructure security: SOUS’s backend runs on Google Cloud Platform with horizontal auto-scaling and is protected by Cloudflare DDoS mitigation and web application firewall (WAF) services.

- Secure development: all code changes require mandatory peer review and automated testing prior to deployment. Dependency and infrastructure scanning is performed continuously via Aikido and Snyk.

- Webhook and API security: all inbound webhooks from third-party providers (including Saleor, Stripe, SoCool, and SendCloud) are validated using idempotency and signature verification to prevent forged or replayed events.

- Incident response: SOUS maintains an incident response process. In the event of a personal data breach that triggers notification obligations under Article 33 GDPR, SOUS will notify the relevant supervisory authority within 72 hours of becoming aware and will notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

SOUS does not currently hold formal security certifications (such as ISO 27001 or SOC 2). These are anticipated as the platform scales and regulatory requirements increase. SOUS’s current security posture is based on a defence-in-depth model appropriate for a seed-stage platform handling payments and personal data.

10. Your Rights as a Data Subject
10.1 Rights Under the GDPR (EEA and UK)

If you are located in the EEA or the UK, you have the following rights in respect of your personal data under the GDPR and UK GDPR, subject to applicable conditions and exemptions:

- Right of access (Art. 15 GDPR): to obtain confirmation of whether SOUS processes your personal data and, if so, to receive a copy of that data together with supplementary information about the processing.

- Right to rectification (Art. 16 GDPR): to have inaccurate or incomplete personal data corrected.

- Right to erasure (Art. 17 GDPR): to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected.

- Right to restriction of processing (Art. 18 GDPR): to request that processing be restricted in certain circumstances, for example while the accuracy of data is disputed.

- Right to data portability (Art. 20 GDPR): to receive personal data that you have provided to SOUS in a structured, commonly used, and machine-readable format, and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means.

- Right to object (Art. 21 GDPR): to object at any time to processing based on legitimate interests, including the right to object to direct marketing (which is absolute and must be honoured without delay).

- Right to withdraw consent (Art. 7(3) GDPR): where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.

- Right not to be subject to automated decision-making (Art. 22 GDPR): SOUS does not make decisions that produce legal or similarly significant effects based solely on automated processing.

To exercise any of the above rights, please contact us at [email protected]. We will respond within one month of receipt of your request. This period may be extended by a further two months where requests are complex or numerous, in which case we will notify you of the extension and the reasons for it within the first month.

We may need to verify your identity before responding to your request. We will not charge a fee for responding to a request unless it is manifestly unfounded or excessive.

10.2 Right to Lodge a Complaint

If you are in the EEA, you have the right to lodge a complaint with your local data protection supervisory authority. SOUS’s lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), which can be contacted at:

Autoriteit Persoonsgegevens

Postbus 93374, 2509 AJ Den Haag

www.autoriteitpersoonsgegevens.nl | +31 (0)70 888 85 00

If you are in the UK, you may lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk.

10.3 Rights Under GCC Laws (UAE and KSA)

If you are located in the UAE or KSA, you may have equivalent rights under the UAE PDPL or KSA PDPL, including rights of access, correction, and deletion of your personal data, and the right to lodge a complaint with your competent local authority. Please contact us at [email protected] and we will respond within the timelines required by your applicable local law.

11. Marketing Communications and B2B Outreach

SOUS sends email newsletters and marketing updates only to individuals who have actively opted in to receive such communications. You may unsubscribe at any time by clicking the unsubscribe link in any marketing email or by contacting [email protected].

SOUS may conduct B2B sales outreach to contact details obtained from public sources (such as restaurant websites and business directories) or via lead-generation partners, where permitted under applicable e-privacy rules and on the basis of legitimate interests. Such outreach will always include a clear and easy mechanism to opt out of future communications.

SOUS does not sell personal data to third parties for marketing purposes, nor does it permit third parties to market their own products or services directly to SOUS’s merchants or end-customers without explicit consent.

12. Children

The SOUS platform is directed at food and beverage businesses and their adult customers. SOUS does not knowingly collect or process personal data of children under the age of 16 (or such other age as may be prescribed by applicable law). If you believe that a child has provided personal data through any part of the platform without appropriate parental consent, please contact us immediately at [email protected] and we will take prompt steps to delete such data.

13. Third-Party Links and External Platforms

The SOUS website and platform may contain links to third-party websites, platforms, or marketplaces (such as Just Eat Takeaway.com). SOUS is not responsible for the privacy practices of such third parties. You should review the privacy policy of any third-party platform before providing personal data to it.

Where SOUS integrates with third-party platforms (such as Shopify, Uberall-connected directories, or logistics providers) to deliver its services, those platforms’ terms and privacy policies will apply to their own data processing. SOUS takes reasonable steps to ensure that such platforms operate to an adequate standard of data protection, as described in the processor overview in Section 6.2.

14. Changes to This Policy

SOUS may update this Privacy Policy from time to time to reflect changes in its processing activities, applicable law, or regulatory guidance. The “Last updated” date at the top of this Policy indicates when it was most recently revised.

Material changes — that is, changes that significantly affect your rights or the way SOUS processes your personal data — will be communicated via a prominent notice on the SOUS website and, where appropriate, by direct notification to merchants and registered users. We encourage you to review this Policy periodically.

Continued use of the SOUS platform following notification of a material change constitutes acceptance of the updated Policy, to the extent permitted by applicable law.

15. How to Contact Us

For any questions, requests, or complaints relating to this Privacy Policy or SOUS’s processing of your personal data, please contact us at:

Acroya B.V. trading as SOUS

Vijzelstraat 77A, 1017 HG Amsterdam, The Netherlands

Website: www.poweredbysous.com

We will acknowledge your request promptly and aim to respond substantively within one calendar month.

© 2026 Acroya B.V. trading as SOUS. All rights reserved.