SOUS
Powering Commerce for F&B
Schedule 1: Data Processing Agreement (DPA)
Forming part of the SOUS Merchant Terms of Service
Last updated: July 2026 | Version 1.2 | Governed by Dutch law | Amsterdam courts
This Data Processing Agreement ("DPA") is Schedule 1 to the SOUS Merchant Terms of Service ("Terms").
It applies wherever SOUS processes personal data of Customers on behalf of the Merchant as a processor
within the meaning of Article 28 GDPR. Capitalised terms not defined herein have the meanings given
to them in the Terms. In the event of conflict, this DPA prevails in respect of data protection matters.
This DPA is accepted by the Merchant as part of the Terms upon completion of onboarding or
digital acceptance of the Terms. No separate signature is required.
1. Parties and Roles
The parties to this DPA are:
Data Controller | The Merchant, as identified in the SOUS Portal upon registration. |
|---|---|
Data Processor | Acroya B.V. (trading as SOUS), Vijzelstraat 77A, 1017 HG Amsterdam, The Netherlands, KvK 85080276. |
As between the parties, the Merchant acts as the data controller and SOUS acts as the data processor in relation to the processing of personal data of Customers in connection with the Services, as further described in Clause 11 of the Terms. SOUS acts as an independent data controller only in respect of: (i) its own account management and billing data; (ii) aggregated and anonymised analytics derived from platform usage; and (iii) processing required for SOUS's own legal compliance obligations.
2. Subject Matter and Duration
SOUS processes personal data of Customers on behalf of the Merchant for the purpose of providing the Services as described in the Terms and this DPA. The processing begins upon commencement of the Merchant's Subscription Plan and continues for the duration of the Terms. Upon termination of the Terms for any reason, SOUS shall, at the Merchant's written election, either return or securely delete all Customer Data within thirty (30) days of termination, except to the extent SOUS is required to retain it under applicable law. In such case, SOUS shall notify the Merchant in writing of the nature and duration of such retention.
3. Nature, Purpose, and Details of Processing
The nature and purpose of SOUS's processing of personal data on behalf of the Merchant, together with the categories of personal data and data subjects involved, are set out in Appendix A to this DPA. The processing is limited to what is strictly necessary for the purposes set out in Appendix A and in Clause 11.3 of the Terms.
4. Obligations of SOUS as Processor
SOUS shall, in its capacity as data processor:
4.1 Instructions
Process personal data only on the documented instructions of the Merchant, as set out in the Terms and this DPA, unless required to do otherwise by applicable law. If SOUS is required by law to carry out any processing not covered by the Merchant's instructions, SOUS shall inform the Merchant prior to such processing unless prohibited by law from doing so.
4.2 Confidentiality
Ensure that all SOUS personnel authorised to process personal data are bound by appropriate confidentiality obligations (whether contractual or statutory) and are familiar with their data protection responsibilities. Access to personal data is restricted to those personnel who need it in order to perform the Services.
4.3 Security
Implement and maintain appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The specific measures implemented by SOUS are described in Appendix C to this DPA. SOUS may update these measures from time to time, provided that the security level is not reduced below the standard set out in Appendix C.
4.4 Sub-processors
SOUS may engage sub-processors only in accordance with Clause 5 of this DPA. SOUS shall impose equivalent data protection obligations on each sub-processor and remains fully responsible for the performance of each sub-processor as if SOUS were performing the processing itself.
4.5 Data Subject Rights Assistance
To the extent SOUS receives a request from a data subject relating to Customer Data processed on behalf of the Merchant, SOUS shall forward such request to the Merchant without undue delay and in any event within three (3) business days of receipt. SOUS shall not independently respond to such a request unless legally required to do so. SOUS shall provide reasonable assistance to the Merchant in responding to data subject requests, taking into account the nature of the processing and the information available to SOUS.
4.6 Assistance with Compliance Obligations
Taking into account the nature of the processing and the information available to SOUS, SOUS shall provide reasonable assistance to the Merchant in ensuring compliance with the obligations under Articles 32 to 36 GDPR, including in relation to:
security of processing (Article 32 GDPR);
notification of personal data breaches to supervisory authorities (Article 33 GDPR);
communication of personal data breaches to data subjects (Article 34 GDPR);
data protection impact assessments (Article 35 GDPR); and
prior consultation with supervisory authorities (Article 36 GDPR).
4.7 Personal Data Breach Notification
SOUS shall notify the Merchant without undue delay and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting Customer Data processed on behalf of the Merchant. Such notification shall include, to the extent available at the time of notification, the information set out in Article 33(3) GDPR, including: (a) the nature of the breach; (b) the categories and approximate number of data subjects and records concerned; (c) the likely consequences; and (d) the measures taken or proposed to address the breach. SOUS shall cooperate with the Merchant and provide ongoing updates as further information becomes available.
4.8 Audit Rights
SOUS shall make available to the Merchant all information reasonably necessary to demonstrate compliance with its obligations under this DPA and shall allow for, and contribute to, audits and inspections conducted by the Merchant or an auditor mandated by the Merchant, subject to the following conditions:
the Merchant shall give SOUS at least fourteen (14) business days' prior written notice of any intended audit;
audits shall be conducted during normal business hours, in a manner that minimises disruption to SOUS's operations;
the Merchant's auditor shall be subject to appropriate confidentiality obligations;
the costs of any audit shall be borne by the Merchant, unless the audit reveals a material breach by SOUS of this DPA, in which case SOUS shall bear its own reasonable costs; and
SOUS may satisfy the audit obligation by providing up-to-date third-party certifications or audit reports (such as SOC 2 or ISO 27001, once available) in lieu of an on-site inspection, provided such reports adequately address the scope of the audit request.
4.9 Deletion or Return on Termination
As set out in Clause 2 of this DPA and Clause 11.9 of the Terms, upon termination of the Terms for any reason, SOUS shall at the Merchant's written election either return or securely delete all Customer Data within thirty (30) days. SOUS shall confirm in writing once deletion or return has been completed.
5. Sub-Processors
5.1 Authorised Sub-Processors
The Merchant hereby grants SOUS general authorisation to engage the sub-processors listed in Appendix B to this DPA. SOUS shall ensure that each sub-processor is bound by a written agreement imposing data protection obligations at least equivalent to those set out in this DPA, in accordance with Article 28(4) GDPR.
5.2 Changes to Sub-Processors
SOUS shall notify the Merchant at least fourteen (14) days in advance of any intended addition or replacement of a sub-processor, by notifying the Merchant's designated administrative contact by email. The Merchant may object to such a change on reasonable data protection grounds within fourteen (14) days of such notification. If the Merchant raises a reasonable objection, the parties shall seek to resolve the matter in good faith. If the parties cannot agree within a further fourteen (14) days, either party may terminate the relevant Subscription Plan on thirty (30) days' written notice.
5.3 Liability for Sub-Processors
SOUS remains fully liable to the Merchant for the performance of each sub-processor's data protection obligations under this DPA as if SOUS were performing the processing itself, in accordance with Article 28(4) GDPR.
6. International Transfers
SOUS shall not transfer personal data to a country outside the European Economic Area (EEA) unless an appropriate transfer safeguard is in place in accordance with Chapter V GDPR. The transfer mechanisms applicable to each sub-processor are set out in Appendix B. SOUS relies primarily on:
Standard Contractual Clauses (SCCs) adopted by the European Commission (Commission Implementing Decision (EU) 2021/914) for transfers to non-adequate third countries; and
The EU–US Data Privacy Framework adequacy decision (10 July 2023) where the relevant recipient is certified under that framework.
SOUS shall carry out transfer impact assessments where required and shall implement supplementary technical and organisational measures (such as encryption in transit and at rest) where the outcome of a transfer impact assessment requires it. Further details of transfer safeguards per sub-processor are available on request at [email protected].
7. Merchant's Obligations as Controller
The Merchant, as data controller, is responsible for:
ensuring that there is a valid legal basis for all processing of Customer Data under the Terms and this DPA, and documenting such legal basis in accordance with Article 30 GDPR;
providing all required privacy notices to Customers prior to or at the point of data collection, in accordance with Articles 13 and 14 GDPR, including information about SOUS's role as processor;
ensuring that any instructions given to SOUS comply with applicable data protection law;
maintaining records of processing activities to the extent required by Article 30 GDPR; and
notifying SOUS without undue delay and in any event within forty-eight (48) hours of becoming aware of any personal data breach affecting Customer Data that may affect SOUS's obligations as processor or the integrity of the Services, in accordance with Clause 12.5 of the Terms.
8. Liability
Each party shall be liable to data subjects in accordance with Article 82 GDPR for damage caused by processing that infringes the GDPR. As between the parties, the liability provisions of Clause 18 of the Terms apply to all claims under or in connection with this DPA, including claims relating to data protection matters, subject to the liability cap set out in Clause 18.8 of the Terms. The liability cap does not apply in the case of wilful misconduct or gross negligence, as provided in Clause 18.2 of the Terms.
9. Governing Law and Jurisdiction
This DPA is governed by and construed in accordance with the laws of the Netherlands. Any disputes arising out of or in connection with this DPA shall be submitted exclusively to the competent courts of Amsterdam, in accordance with Clause 21 of the Terms.
10. Miscellaneous
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect. This DPA forms an integral part of the Terms and is accepted by the Merchant upon digital acceptance of the Terms. No separate signature is required. In the event of conflict between this DPA and the Terms on data protection matters, this DPA prevails.
Appendix A – Details of Processing
The following table sets out the details of SOUS's processing of personal data on behalf of the Merchant, in accordance with Article 28(3) GDPR.
Processing activity | Categories of personal data | Categories of data subjects | Purpose |
|---|---|---|---|
Order and transaction processing | Full name | End-customers of Merchant | Fulfilment of Direct Agreements; payment facilitation |
Logistics and delivery coordination | Full name | End-customers of Merchant | Coordination with logistics providers (SoCool, SendCloud, Uber Direct) for fulfilment |
Payment processing | Payment method metadata | End-customers of Merchant | Processing payments via Stripe, Adyen (EEA merchants) or Paystack (South African merchants); refund and dispute handling |
Customer authentication (where enabled) | Email address | End-customers of Merchant (registered accounts only) | Enabling customer login functionality via Firebase |
Customer relationship management (CRM) | Full name | End-customers of Merchant | CRM tools within the Merchant Portal; enabling merchant-to-customer communications |
Gift card issuance and redemption | Order reference | End-customers of Merchant | Gift card processing via Gifty |
Business listings & visibility (Spotlight) | Business profile & listing data; review content and reviewer display names; review-response contact data; connected Google Analytics metrics where the Merchant authorises access via OAuth (may include online identifiers) | End-customers/reviewers of Merchant; Merchant personnel | Publishing and syncing business listings; managing and responding to reviews (incl. AI-assisted) and visibility insights via Uberall and Ceyo |
Platform security and fraud prevention | IP address | End-customers of Merchant; Merchant personnel | DDoS protection (Cloudflare); fraud detection; platform integrity |
Merchant personnel (portal access) | Name | Merchant's authorised portal users | Providing and securing access to the Merchant Portal; account management |
Google APIs. The only direct Google OAuth connection is to Google Analytics, accessed on a read-only basis and limited to the scope the Merchant authorises, used solely to provide the Spotlight visibility insights described above. Business listings (including Google Business Profile) are managed via Uberall rather than a direct Google OAuth connection. Data accessed from Google APIs is not sold, not used for advertising, and not used to train or improve artificial intelligence or machine learning models. This use adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Appendix B – Authorised Sub-Processors
The following sub-processors are authorised as of the version date of this DPA. The current sub-processor list is updated in accordance with Clause 5.2 of this DPA. Merchants will be notified of any changes by email at least fourteen (14) days in advance. The current list is available on request at [email protected].
Processor | Role | Data categories | Location | Transfer safeguard |
|---|---|---|---|---|
Stripe | Payment processing, payouts, KYC/KYB (dedicated connected account per Merchant) | Payment metadata; merchant identity; payout details | USA / EEA | EU–US DPF; SCCs |
Adyen N.V. | Payment acquiring/processing; per-merchant connected/sub-merchant account setup (primary provider for EEA merchants) | Payment metadata; merchant identity; payout details | Netherlands (EEA) | Within EEA |
Paystack | Payment processing; per-merchant account setup (South African merchants only) | Payment metadata; merchant identity; payout details | South Africa | POPIA (SA); SCCs for any EEA data |
Solvimon | Usage-based billing and invoicing only (billing layer; no funds flow or connected-account setup) | Merchant account & billing data | Netherlands (EEA) | Within EEA |
Google Cloud Platform | Cloud hosting, database, storage, task queues, logging | All platform data; server logs; stored files | EEA (primary); USA for certain services | Adequacy / SCCs |
Vercel | Merchant Portal frontend hosting | Portal usage data; server logs | USA / global CDN | SCCs |
Saleor | Commerce engine: cart, checkout, vouchers, order events | Product data; cart/order data; end-customer identifiers | EEA | Within EEA |
Shopify | Merchant discovery channel; product sync and order webhooks | Product catalogue; order data | USA / Canada | SCCs |
Firebase (Google) | Customer authentication | Credentials; session tokens | EEA (primary) | Adequacy / SCCs |
SoCool | Nationwide chilled logistics (NL) | Order/delivery data; recipient address; time windows | Netherlands (EEA) | Within EEA |
SendCloud | Aggregated multi-carrier logistics | Shipment data; recipient address | Netherlands (EEA) | Within EEA |
Uber Portier B.V. / Uber Eats NL B.V. | On-demand delivery (Uber Direct) | Recipient name; delivery address; order contents; proof of delivery | Netherlands (EEA) | Within EEA |
Gifty | Gift card issuance, ledger and fulfilment | Order reference; gift card identifiers; redemption data | Netherlands (EEA) | Within EEA |
Uberall | Business directory integration and review management | Business profile data; review content; review-generation contact data | Netherlands / EEA | Within EEA |
Ceyo | Prompt tracking and GEO/SEO visibility insights | Prompt data; merchant brand/profile data; visibility outputs | Netherlands / EEA | Within EEA |
Cloudflare | DDoS protection, CDN, web security | IP addresses; request metadata | USA / global | SCCs |
Sentry | Error monitoring and diagnostics | Error logs; stack traces; session context | USA | SCCs |
PostHog | Product analytics | Usage events; device identifiers; anonymised IPs | EEA | Within EEA |
Funds flow, payout and KYC/KYB via per-merchant connected/sub-merchant accounts are handled by Stripe, Adyen and Paystack. Solvimon is the billing layer only. Merchant-billing records held by Solvimon and the payment providers relate to the Merchant's own account data, for which SOUS acts as an independent controller (see Clause 1); they are listed here for transparency.
Published business-listing platforms (e.g. Google Business Profile, Google Maps, Apple Maps, TripAdvisor) receive listing data as independent controllers under their own terms and are not sub-processors of SOUS.
Appendix C – Technical and Organisational Measures (TOMs)
The following technical and organisational measures are implemented by SOUS as data processor, in accordance with Article 32 GDPR and Clause 4.3 of this DPA. These measures are subject to periodic review and improvement. The overall security level will not be reduced below the standard described herein.
Measure category | Description |
|---|---|
Encryption in transit | All data transmitted between users, the SOUS platform, and third-party services is encrypted using TLS 1.2 or higher (HTTPS). All API communications are encrypted. |
Encryption at rest | Sensitive data fields are encrypted at rest within the Google Cloud infrastructure. Storage volumes and database snapshots are encrypted using AES-256. |
Access controls | Role-based access controls (RBAC) limit access to personal data to authorised personnel on a strict need-to-know basis. Secrets and credentials are managed via Google Cloud Secret Manager. Remote access to infrastructure requires individual private-key authentication; direct password-based access is not permitted. |
Infrastructure security | The SOUS backend runs on Google Cloud Platform with horizontal auto-scaling and is protected by Cloudflare DDoS mitigation and web application firewall (WAF) services. All inbound webhooks are validated using signature verification and idempotency controls to prevent forged or replayed events. |
Secure development | All code changes require mandatory peer review and automated testing prior to deployment. A controlled CI/CD process governs staging-to-production promotion. Dependency and infrastructure scanning is performed continuously via Aikido and Snyk. Code quality is monitored using CodeScene. |
Data separation | Each merchant's data is logically separated within the platform. The principle of functional separation between service and development environments is maintained. Data used in development and testing is anonymised. |
Availability and resilience | Regular database snapshots are taken and stored in geographically distributed locations. The infrastructure can be restored through automated procedures. SOUS targets a monthly uptime of at least 99% for the platform, measured at the server handover point. |
Incident response | SOUS maintains an incident response process. In the event of a personal data breach, SOUS will notify the Merchant within 48 hours and the Autoriteit Persoonsgegevens within 72 hours where required under Article 33 GDPR. |
Personnel obligations | SOUS personnel with access to personal data are bound by confidentiality obligations and receive regular data protection awareness training. Access rights are reviewed periodically and revoked upon role change or departure. |
Monitoring and logging | All access to personal data is logged centrally. Logs are retained for 90 days on a rolling basis for security incident investigation purposes. Monitoring is performed via Google Cloud Logging and Sentry. |
© 2026 Acroya B.V. trading as SOUS. Schedule 1 to the SOUS Merchant Terms of Service.