Data Processing Agreement (DPA)

Last updated: 7 September 2026

This agreement (“DPA”) forms an integral part of the Terms of Service and applies as soon as you — the restaurant, the “Controller” — use qartine to process your customers' personal data. qartine (Kube IT Consulting FZCO, the “Processor”) processes that data on your behalf, in accordance with Article 28 GDPR.

1. Roles

You are the controller of your customers' (diners') data. qartine acts as processor, solely on your instructions and to provide you the service.

2. Subject-matter, duration, nature and purpose

Subject-matter: providing the multilingual QR menu and ordering. Duration: the term of your account. Nature and purpose: hosting your menu, serving the public page, receiving orders and, if enabled, running a loyalty list — on your behalf.

3. Data and data subjects

Data subjects: your venue's diners. Data: name and, with their explicit consent, phone and email (order / loyalty), plus order details. No special categories are required — do not add any in free-text fields.

4. Instructions

qartine processes data only on your documented instructions (your use of the service and your written requests). qartine informs you if, in its view, an instruction infringes the GDPR.

5. Confidentiality

Persons authorised to process the data are bound by confidentiality.

6. Security (Art. 32)

Encryption in transit (HTTPS), hashed passwords, access control, EU hosting of images and menus, monitored infrastructure, and automatic deletion of order data 24h after the order.

7. Sub-processors

You authorise the use of: Stripe (payment), Resend (email), Cloudflare (storage/CDN) and a machine-translation service (OpenRouter/DeepSeek, MyMemory fallback) — to which only menu text is sent, never personal data. qartine imposes equivalent obligations on each and notifies you of changes so you may object.

8. International transfers

qartine is established in the United Arab Emirates (a third country with no adequacy decision). Necessary transfers rely on the European Commission's Standard Contractual Clauses and appropriate supplementary measures; menus and images are hosted in the EU.

9. Assistance

qartine helps you respond to data-subject requests (access, erasure, portability — via the built-in export and delete features) and with your obligations under Art. 32–36.

10. Data breaches

qartine notifies you without undue delay after becoming aware of a personal-data breach. Contact: [email protected].

11. Deletion / return

You can export the data at any time from your dashboard. On termination, the data remains exportable for at least thirty (30) days and is then deleted, save for any legal retention obligation. Immediate deletion can be requested at any time.

12. Audit

qartine makes available the information necessary to demonstrate compliance with Article 28 and submits to reasonable audits carried out by you or on your behalf, on at least thirty (30) days' written notice, no more than once a year (save for an established security incident), during business hours and at your cost, without access to other customers' data.

13. Relationship with the Terms of Service

This DPA forms an integral part of the Terms of Service and prevails over them on any personal-data matter. For everything else — in particular the limitations and exclusions of liability — the Terms of Service apply, and the parties' aggregate liability under the agreement and under this DPA remains subject to the cap they set, to the extent permitted by law.

The governing law and the competent courts are those of the Terms of Service.