Legal

Data processing agreement

The agreement under Art. 28 GDPR for SIDES customer data your application touches through the API.

Version
1.0
In force since
Document
Data processing agreement

1. Who is what, in this arrangement

This agreement applies where your application, through the SIDES LABS API, processes personal data that belongs to a SIDES customer — their staff, their guests, their orders.

The roles are worth stating plainly, because getting them wrong is the usual way an Art. 28 agreement becomes decorative:

  • the SIDES customer is the controller for the data about their own business and their guests;
  • SimplyDelivery GmbH processes that data for them under its own agreement with them, and concludes this agreement with you on the authorisation they have given;
  • you, the business partner, process it as a further processor, on instruction, for the purpose your application documents.

For the data in your own SIDES LABS account — your users, your company details, your billing — the roles are the other way round and this agreement does not apply: there SimplyDelivery is the controller, and the privacy policy describes it.

2. Subject, duration and purpose

The subject is the processing your application performs on data retrieved through the SIDES LABS API. The purpose is the function your listing describes and nothing beyond it.

It lasts as long as the partner contract, and ends with it. There is no processing after the end of the contract except what section 9 requires.

3. Data and data subjects

Which categories you actually receive depends on the endpoints your tier and your scopes allow. Typically:

  • Data subjects — employees of a SIDES customer, and their guests or ordering customers.
  • Categories — contact details, order and delivery data, times, amounts, and where the customer's own configuration includes them, notes attached to an order.

Special categories of data within the meaning of Art. 9 GDPR are not part of this arrangement. If an endpoint ever returned them, processing them would need its own agreement.

4. Processing on instruction

You process the data only on documented instructions. The documented instruction is this agreement together with the API documentation: an endpoint's documented purpose is the instruction for the data it returns.

You will not, without a separate instruction:

  • use the data for your own purposes, including improving your own product;
  • combine it with data from another source to produce information the purpose does not require;
  • transfer it to a third country without a valid transfer mechanism;
  • use it to contact a data subject other than on the customer's behalf.

Where you believe an instruction breaches data protection law, you tell us without undue delay and may suspend that part of the processing until it is resolved.

5. Confidentiality

You ensure that everyone who processes the data is bound to confidentiality, and that the obligation survives the end of their engagement. Access is limited to those who need it for the purpose.

6. Technical and organisational measures

You take the measures Art. 32 GDPR requires, appropriate to the risk. At a minimum:

  • transport encryption for every connection carrying the data;
  • encryption at rest wherever the data is stored;
  • access control that names a person — shared accounts do not satisfy this, for the same reason they do not satisfy the terms of service;
  • credentials issued to you are stored as secrets, never in a repository, a log, a client-side bundle or a ticket;
  • logging that lets you reconstruct who accessed what, without the log itself becoming a second copy of the data;
  • a documented procedure for restoring availability after an incident, and evidence that it has been tried.

7. Sub-processors

You may engage sub-processors — a hosting provider, a mail service — under a general authorisation, provided each is bound to obligations no weaker than these.

You keep a current list available to us on request, and you tell us before adding or replacing one. We may object on reasonable data protection grounds; if we do and the matter cannot be resolved, either side may terminate the affected processing.

8. Assistance and incidents

  • You assist us in answering a data subject's request. Where one reaches you directly, you pass it on rather than answering it yourself.
  • You assist with data protection impact assessments and with prior consultations, to the extent the information is yours to give.
  • A personal data breach is reported to us without undue delay and at the latest within 24 hours of becoming aware of it, with what you know at that point. The 72-hour clock in Art. 33 starts at awareness and not at certainty, so a first report that is incomplete is better than a late one that is not.

9. Return and deletion

When the processing ends you delete the data, or return it first if we ask within thirty days. Deletion covers backups on their ordinary rotation, and you confirm it in text form.

The exception is data you are required by law to keep. You tell us which, and why, and you stop processing it for any other purpose.

10. Evidence and audits

You demonstrate compliance with this agreement on request. A current certification or an auditor's report covering the relevant scope is sufficient evidence in the first instance.

Where that does not answer the question, we may audit — with reasonable notice, during business hours, no more than once a year unless there is a concrete reason, and in a way that does not disclose your other customers' data to us.