Data Processing Agreement under Article 28 GDPR

Last updated: 27 August 2026

This DPA applies between the customer identified in the main agreement as controller and Carta as processor.

1. Subject matter and duration

Carta processes personal data to provide, store, edit, translate, publish, secure and export digital menus for the term of the main agreement, including the exit and deletion phase.

2. Nature, purpose, data and data subjects

  • Master and contact data of restaurant operators and contacts
  • User, role, authentication and approval data
  • Restaurant, menu, image, translation and free-text data
  • Usage events and technical metadata
  • Data subjects: staff, contacts, restaurant guests and depicted persons
  • Special-category and criminal-offence data are excluded without an additional agreement

3. Instructions

Carta processes only on documented instructions, including for third-country transfers, unless legally required otherwise. Instructions that appear unlawful are promptly reported and, where necessary, suspended pending clarification.

4. Confidentiality

Authorised persons are bound to confidentiality, granted access on a need-to-know basis and appropriately instructed.

5. Security under Article 32 GDPR

  • TLS-encrypted transmission
  • Role-based authentication and tenant isolation through database policies
  • Private file storage and controlled media delivery
  • Keys and secrets only in protected environment management
  • Logging of publications and administrative deletion operations
  • Patch and dependency management
  • Rate limits and abuse prevention
  • Controlled deletion and export processes
  • Before production launch: regular backups, restoration tests, incident response and periodic TOM review

6. Sub-processors

The customer grants general authorisation for the providers listed below. Carta gives at least 14 days’ notice of a material addition or replacement and permits a reasoned data-protection objection. Carta imposes equivalent duties on sub-processors and remains responsible.

  • Vercel Inc. – Hosting, Edge-Auslieferung und Logs
  • Supabase, Inc. – Datenbank, Authentifizierung und Dateispeicher; erwartete Region Zürich, Schweiz, noch zu bestätigen
  • Anthropic, PBC – KI-Extraktion, Übersetzung und Assistent; USA
  • Resend, Inc. – Versand von Anmeldecodes; USA

7. Third-country transfers

Transfers outside the EU/EEA occur only in compliance with Chapter V GDPR, particularly under an adequacy decision, valid EU-US DPF certification or Standard Contractual Clauses with any required transfer assessment and supplementary measures. Switzerland is treated as adequate while the relevant adequacy decision remains valid.

8. Data subject rights

Carta promptly forwards requests received directly to the customer and assists through appropriate technical and organisational measures. Carta does not respond itself unless acting as controller or instructed to do so.

9. Assistance under Articles 32 to 36

Carta provides risk-appropriate assistance with security, breach notifications, data protection impact assessments and prior consultation. Personal data breaches affecting commissioned data are notified to the customer without undue delay with the available required information.

10. Deletion and return

After termination, Carta makes data available at the customer’s choice and deletes them under the exit schedule. The transition period is no more than 30 calendar days, followed by a retrieval period of at least 30 calendar days. Once the backup system is established, backups are overwritten within no more than a further 90 days unless retention is legally required.

11. Evidence and audits

Carta provides required information, current TOMs, sub-processor and transfer information. Audits take place on reasonable notice, generally once annually, under confidentiality and without disproportionate disruption. Cause-based audits following incidents remain available. Each party bears its own costs; customer-requested extraordinary external costs are charged only if agreed in advance.

12. Customer duties

The customer ensures lawfulness, transparency and instructions, minimises data, manages user access and fulfils data-subject duties. It does not submit excluded data and informs Carta of special risks.

13. Final terms

If this DPA conflicts with the terms, it prevails for commissioned data processing. Liability is governed by the main agreement to the extent permitted by law; mandatory rights under Article 82 GDPR remain unaffected.