Data processing agreement (DPA)
Note
This is a convenience translation. The German version of this agreement is the legally binding one.
Preamble
This data processing agreement (DPA) governs the processing of personal data by Oleksandr Rybalchenko, An d. Ottosäule 14, 85521 Ottobrunn, Deutschland ("Processor") on behalf of the customer ("Controller") when using the service Kellno. It is part of the contract for the use of Kellno and is concluded by agreeing to the General Terms and Conditions (Art. 28(9) GDPR).
§ 1 Subject matter, duration, nature and purpose
(1) The subject matter is the processing of personal data of the Controller's guests who open its digital menu or use the AI waiter. Processing serves to deliver the menu in the guest's language, to answer questions about the menu and to produce usage statistics for the Controller.
(2) The duration of processing corresponds to the term of the main contract.
(3) The data subjects are the Controller's guests.
(4) The following are processed: technical connection data (IP address, browser and device type, browser language, time), anonymised usage events (view, opened categories and dishes, selection, rating) with a short hash that changes daily and cannot be reversed, and the texts guests enter into the AI waiter. Special categories of personal data (Art. 9 GDPR) are not subject to processing; guests are asked not to enter personal data.
(5) The processing of the Controller's own data (customer account, billing) is not carried out on its behalf but under the Processor's own responsibility in accordance with the privacy policy.
§ 2 Instructions
(1) The Processor processes the data only on documented instructions from the Controller, unless required to do otherwise by Union or Member State law; in that case it informs the Controller of that legal requirement before processing, unless that law prohibits such information.
(2) The instructions follow from the main contract, this DPA and the settings the Controller makes in the customer area. Further individual instructions are given in text form.
(3) If the Processor considers that an instruction infringes data protection provisions, it informs the Controller without undue delay and may suspend execution until the instruction is confirmed or changed.
§ 3 Confidentiality
The Processor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
§ 4 Security of processing
(1) The Processor takes the technical and organisational measures required under Art. 32 GDPR. They are described in Annex 1.
(2) The Processor may adapt the measures to technical progress provided the agreed level of protection is not undercut.
§ 5 Sub-processors
(1) The Controller grants general authorisation to engage further processors (sub-processors). The sub-processors engaged when the contract is concluded are listed in Annex 2.
(2) The Processor informs the Controller in text form at least 30 days in advance of the intended addition or replacement of a sub-processor. The Controller may object for important data protection reasons. If no amicable solution can be found, either party may terminate the main contract with effect from the change.
(3) The Processor contractually imposes on each sub-processor data protection obligations essentially equivalent to those of this DPA and remains responsible to the Controller for their compliance.
§ 6 Transfers to third countries
Processing outside the European Union and the European Economic Area only takes place if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision of the European Commission or standard contractual clauses. The countries concerned are set out in Annex 2.
§ 7 Assistance to the Controller
(1) The Processor assists the Controller, as far as possible, by appropriate technical and organisational measures in responding to requests from data subjects exercising their rights (Art. 12 to 22 GDPR). If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay.
(2) Taking into account the nature of processing and the information available to it, the Processor assists the Controller in complying with the obligations under Art. 32 to 36 GDPR.
(3) As usage statistics are kept without identifiers that can be permanently attributed to individual guests, and conversations with the AI waiter are not stored, it is generally not possible to attribute stored data to a particular person (Art. 11 GDPR).
§ 8 Personal data breaches
The Processor notifies the Controller in text form of personal data breaches affecting the data processed on its behalf without undue delay after becoming aware of them. The notification contains, as far as possible, the information referred to in Art. 33(3) GDPR.
§ 9 Deletion and return
(1) Usage events are deleted no later than 120 days after they are recorded. Conversations with the AI waiter are not stored by the Processor.
(2) After the end of the main contract the Processor deletes the personal data processed on behalf of the Controller, unless Union or Member State law requires storage. If the Controller deletes its account, the data is deleted immediately.
§ 10 Evidence and audits
(1) On request the Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR.
(2) The Processor allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it and bound to confidentiality. Audits are announced with reasonable notice, take place during normal business hours and should not disproportionately disrupt operations. As a rule, the presentation of current evidence, certificates or reports is sufficient.
§ 11 Obligations of the Controller
The Controller is responsible for the lawfulness of processing and for safeguarding the rights of data subjects. It informs its guests about the processing in an appropriate manner; a reference to the privacy information linked from the menu is possible for this purpose.
§ 12 Final provisions
(1) Liability is governed by the provisions of the main contract unless Art. 82 GDPR provides otherwise.
(2) In the event of contradictions between this DPA and the main contract, this DPA prevails in matters of data protection.
(3) The choice of law and place of jurisdiction of the main contract apply. The German version is authoritative.
Annex 1 — Technical and organisational measures
Access and permissions: sign-in with email address and password (stored only as a hash) or Google account. Strict separation of customers: every query in the customer area is limited to the customer's own restaurant; row-level access restriction is enabled for all tables in the database. Administrative access is limited to expressly authorised accounts.
Transmission and storage: encrypted transmission only (HTTPS with HSTS). Storage in data centres of the providers named in Annex 2. Access keys to services are kept only in the operating environment, not in the source code.
Data minimisation: guests are served without cookies and without storage on their device. IP addresses are not stored in the database; statistics use a short hash that changes daily and cannot be reversed. Conversations with the AI waiter are not stored. Error reports contain no IP addresses, cookies or content.
Availability and resilience: automatic availability checks at short intervals; new versions only go live after passing a check; automatic restart on failure; request limits per connection to protect against overload and misuse.
Deletion: automatic deletion of usage events after 120 days; complete deletion of all data of a restaurant by the customer itself in the customer area.
Review: automated tests and checks with every change to the software; error monitoring.
Annex 2 — Sub-processors
Supabase Inc., USA — database and file storage. Place of processing: United Kingdom (London). Basis: adequacy decision of the European Commission for the United Kingdom.
Railway Corporation, USA — operation of the application (hosting), server log files. Basis for transfers to the USA: standard contractual clauses or the EU-U.S. Data Privacy Framework.
OpenAI Ireland Limited, Ireland, and OpenAI, L.L.C., USA — generation of the AI waiter's answers and translations. Basis for transfers to the USA: standard contractual clauses.
Functional Software, Inc. (Sentry), USA — error monitoring, where activated. Place of processing: European Union.
Cloudflare, Inc., USA — protection against automated sign-ups, where activated; concerns only the customer area, not guests.
Last updated
October 2026