Parties, scope and precedence
This Data Processing Agreement (DPA) forms part of the written or electronic service agreement that incorporates it between Zadok Enterprise, operating in the Netherlands as Tembrel (Processor), and the business customer identified in that agreement (Customer). It takes effect with that incorporation, not merely because someone views this page.
It applies to personal data Tembrel processes on the Customer's behalf in providing the agreed service (Customer Personal Data). The Customer is the controller or, where it acts for another controller, an authorized processor. Tembrel is a processor or subprocessor respectively. Each party retains responsibilities imposed directly on it by applicable data-protection law, including Regulation (EU) 2016/679 (GDPR).
Processing for Tembrel's own business-contact, relationship-administration or independent security purposes is described in the Privacy Policy. Customer Personal Data is not reclassified as Tembrel's own data simply because it appears in a log. The purpose and instructions for the specific operation determine the role.
This DPA controls a conflict about Customer Personal Data with general service terms. Applicable standard contractual clauses control where they require it. A separately agreed data-processing agreement may replace or supplement this DPA expressly; no agreement may reduce mandatory protections. The schedules below form part of this DPA.
Documented instructions and responsibilities
The service agreement, this DPA, agreed configuration and the Customer's lawful written directions constitute documented instructions. Processing is limited to delivering, supporting and securing the Customer's agreed menu experience, not unrelated advertising, data resale or developing a general-purpose model for Tembrel's own use.
The Customer determines the purpose of its guest experience, the data it supplies, enabled features and authorized users. It must have the necessary rights and lawful bases, provide required notices and satisfy any additional conditions for sensitive data. If the Customer is itself a processor, it must have its controller's authority for these instructions and appointments.
Tembrel will process only on documented instructions, including instructions concerning transfers, unless EU or Member State law requires otherwise. In that case Tembrel will notify the Customer of the legal requirement before processing unless that law prohibits notice on important public-interest grounds. Tembrel will immediately inform the Customer if it considers an instruction to infringe applicable data-protection law and may suspend the affected operation while the parties resolve it.
Instructions that change the agreed service require a written operational arrangement. No such arrangement or fee condition excuses compliance with mandatory duties.
Confidentiality and security
Tembrel will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty. Access must be limited to what is needed for the authorized work.
Tembrel will implement and maintain technical and organizational measures appropriate to the risk under GDPR Article 32, considering the nature, scope, context and purpose of processing, the state of the art and implementation costs. Schedule B records the implemented technical baseline and the operational duties assumed under this DPA. It does not claim certification or absolute security.
Measures may evolve, but Tembrel will not materially reduce the overall protection of Customer Personal Data during the service. The Customer remains responsible for its own systems, account permissions, content and lawful configuration.
Subprocessors and changes
The Customer gives general written authorization for the providers identified for its agreed service in Schedule C, subject to the conditions here. Authorization covers only the services and processing scope actually recorded for that Customer. A provider's presence in source code or in a staging environment is not an instruction to activate it for a live Customer.
Tembrel will bind each appointed subprocessor to written data-protection obligations that provide the protection required by Article 28 for the work it performs. Tembrel remains responsible to the Customer for the subprocessor's performance of those obligations.
Tembrel will give the Customer at least 30 days' advance written notice of an intended addition or replacement, including its function and relevant processing location. Notice will use the service contact recorded in the agreement; a silent webpage edit is not sufficient notice. The Customer may object within that period on reasonable data-protection grounds.
The parties will work in good faith on an alternative or safeguards. If an objection cannot be resolved before the proposed processing begins, the affected processing will not be transferred to the disputed provider. Either party may end the affected service without a termination penalty, with a proportionate refund of prepaid unused fees for that service. If an urgent risk makes continued operation unsafe before a notice period can run, Tembrel may pause the affected feature rather than bypass authorization.
Data-subject requests
Taking account of the processing, Tembrel will assist the Customer through appropriate technical and organizational measures, insofar as possible, with requests to exercise data-subject rights. This includes identifying relevant records and supporting access, correction, restriction, portability or deletion where applicable.
If Tembrel receives a request relating to Customer Personal Data, it will pass it to the Customer without undue delay and will not decide or answer on the Customer's behalf unless authorized or required by law. Identity checks and data disclosure must be proportionate and secure. The Customer remains responsible for its response and deadlines; Tembrel's assistance must be timely enough to support them.
Personal-data breaches
Tembrel will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. A breach includes accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to that data.
As available, the notice will describe the nature of the breach, affected categories and approximate numbers of people and records, likely consequences, measures taken or proposed and a contact for further information. Tembrel will provide information in phases if necessary without delaying the initial notice, and will take reasonable steps to contain, investigate and remedy the breach.
Tembrel will assist the Customer with its regulatory and individual notification obligations. The Customer decides its notifications unless law requires Tembrel to act directly. No contractual allocation removes either party's statutory duties.
Risk assessments and regulatory assistance
Considering the processing and information available, Tembrel will assist with the Customer's obligations concerning security, breach assessment and notification, data-protection impact assessments and prior consultation with a supervisory authority under GDPR Articles 32 to 36.
The Customer must tell Tembrel about material risks or special processing requirements that are not evident from the agreed service. Tembrel will provide relevant information about its processing and safeguards, and cooperate with a competent authority as required. This DPA does not state that a particular Customer's impact assessment has already been completed.
Return and deletion
After the service ends, Tembrel will, at the Customer's choice, return or delete Customer Personal Data and delete existing copies, unless EU or Member State law requires storage. Tembrel will explain any such legal retention, protect the retained data and limit further use to the required purpose.
The parties will arrange a secure return format and prompt completion schedule appropriate to the volume, systems and Customer instructions. Tembrel will confirm completion when requested. Data awaiting return or deletion remains subject to this DPA and must not be used for another purpose.
Offboarding and routine retention jobs do not by themselves fulfill this obligation. Tembrel must address data outside those jobs, including orders, history and provider-held copies. Any backup that cannot practicably be selectively erased must be isolated from ordinary use, removed through the applicable rotation process and covered by the documented completion schedule; if restored, deletion instructions must be reapplied. This is a deletion duty, not a claim that automated full erasure or a fixed backup lifetime exists today.
Information and audit rights
Tembrel will make available information necessary to demonstrate compliance with this DPA and Article 28, and allow and contribute to audits, including inspections, by the Customer or an independent auditor it mandates.
The parties will normally begin with relevant documentation and agree reasonable notice, scope, confidentiality and safeguards for other customers' information. These arrangements must not prevent an effective audit, urgent investigation or regulator-required inspection. No certificate or report is promised where one does not exist.
Each party bears its ordinary internal compliance costs. Any charge for exceptional assistance must be agreed in advance, reasonable, and must not obstruct statutory rights or charge the Customer to remedy Tembrel's own breach.
International transfers
Tembrel will make restricted international transfers only on documented instructions and with a valid mechanism under applicable law. The Customer's approval of a provider does not by itself establish a transfer safeguard.
For an EEA transfer without an applicable adequacy decision, the parties must establish suitable safeguards before the transfer, such as the European Commission's clauses in Decision (EU) 2021/914 where applicable. Select the correct module and complete the parties, transfer description, competent authority, security measures and permitted options. Processor-to-processor onward transfers ordinarily require the corresponding module; this must be assessed for the actual relationship.
Where necessary, the parties will assess destination-country risks and implement supplementary measures. Applicable UK or Swiss adaptations must be agreed when those laws apply. Tembrel will inform the Customer if it cannot maintain the required safeguards and stop the affected transfer until a lawful arrangement is available.
This webpage does not claim to execute SCCs with an unidentified recipient. Schedule D states the current evidence and the information that must be recorded for each applicable transfer. Validly incorporated SCCs prevail over a conflicting term of this DPA.
Duration, liability and communications
This DPA continues for as long as Tembrel holds Customer Personal Data under the service, including any protected period needed for return, deletion or required storage. The service agreement identifies the Customer, authorized contacts, service scope and effective date.
Liability between the parties follows the applicable customer agreement and mandatory law. Nothing here removes data subjects' rights, restricts a supervisory authority or overrides liability required by the GDPR or applicable SCCs.
Privacy, incident, instruction and subprocessor notices use the written contact channels recorded by both parties in the service agreement. Those channels must be kept current. Tembrel's operator is Zadok Enterprise, Netherlands.
Zadok Enterprise (eenmanszaak), Netherlands. Trading as Tembrel.
KVK: 42135196
VAT: NL005523644B68
Privacy contact: [email protected]
Legal contact: [email protected]
Schedule A: processing details
- Subject matter
- The customer's configured Tembrel menu-knowledge, recommendation and guest-question service.
- Nature and purpose
- Collecting, transmitting, organizing, storing and retrieving supplied content and guest interactions; generating recommendations and enabled AI answers; transactional account messages and service notifications; business review, reporting, support, security and deletion under instructions.
- Duration and frequency
- For the agreed service period and necessary protected return/deletion period. Processing occurs as staff configure the service, guests interact, data is ingested, transactional messages are requested and maintenance operates.
- Data subjects
- Guests, customer staff and representatives, message recipients, and people whose information is included in customer content or connected source records.
- Personal data
- Guest text, recent conversation context, answers, feedback, language and menu references; random session IDs and interaction timestamps/actions; source order identifiers and item evidence; customer-supplied staff/contact information; recipient addresses, message content and delivery metadata; relevant configuration, revision and audit attribution. Categories depend on the features enabled.
- Sensitive data
- Not a requested input category. Free text, especially allergy or dietary questions, may reveal health, belief or other sensitive information. Customers must minimize such data and establish any required additional legal condition and safeguards before directing that processing. The service is not a medical record or emergency system.
- Customer instructions
- Agreed features, locations, integrations, access permissions and content, plus written instructions under this DPA. The customer must identify any special retention, transfer or deletion requirement before processing begins.
Live dictation uses browser speech recognition, not Tembrel audio storage. A submitted transcript enters the same text flow as a typed question. Browser-vendor audio processing is separate. Marketing examples are local simulations, not customer processing.
The current documented staging cleanup threshold for guest events, menu adds and questions is 400 days, applied in daily bounded batches. It is not a retention instruction for every Customer or data category. An agreed shorter requirement must be supported operationally before the affected data is processed. No automatic deletion of all records at offboarding is represented.
Schedule B: security measures
The implemented baseline includes:
- Staff authentication with hashed passwords, native MFA support, protected session cookies and server-side expiry/revocation checks.
- Role and location permissions, tenant-scoped store access and PostgreSQL row-level access controls using restricted runtime roles.
- HTTPS on documented staging endpoints, allowed-origin checks, rate limits and validation of public/integration requests.
- Hashing of order-ingest keys and AES-GCM protection for stored POS connection credentials under separately configured secrets.
- Operational and audit records, request correlation and query-string redaction in documented staging Worker logs.
- Bounded retention jobs with documented tenant isolation, failure/retry checks, and an isolated historical-point staging recovery test.
- Automated type, unit, build and browser checks for implemented behavior.
Operational obligations under this DPA include limiting authorized personnel, maintaining confidentiality, handling incidents and requests, reviewing changes for risk, and carrying out return/deletion instructions. These are contractual duties; this schedule does not claim a completed external audit, certification, penetration test, production recovery objective, staffed monitoring service or automatic erasure system.
Before a live customer environment is used, Tembrel and the Customer must confirm that its configuration and operational arrangements support these measures and any agreed additional requirements. Changes must preserve the protection required by the security section.
Schedule C: subprocessor authorization
The Subprocessor List identifies the evidenced service providers, their functions, current environment and location/transfer information. The agreement must record the version and providers applicable to the Customer's enabled service. A provider limited to staging is not represented as an active production processor.
- Resend: Transactional email delivery and delivery webhooks. Configured and verified in staging; controlled transactional delivery accepted. Production is not active..
- Cloudflare: Workers, Pages, Hyperdrive and Worker logs. Configured and verified in staging.
- Neon: Hosted PostgreSQL through Cloudflare Hyperdrive. Configured and verified in staging.
- Anthropic: API for enabled menu questions and dish explanations. Enabled in staging; a real response and quota enforcement are documented.
See the Subprocessor List for purpose, location, evidence scope and transfer information. These records do not establish live production appointments.
Customer-chosen till services, webhook recipients and a guest's browser voice vendor are not automatically appointed under this schedule. If Tembrel engages another party to process Customer Personal Data on its behalf, the appointment must follow the authorization and written-obligation requirements above.
Schedule D: transfer record
For each transfer requiring a safeguard, record with the service agreement: exporter and importer legal identity and contacts; controller/processor roles; data categories and subjects; purpose, frequency and duration; destination and access locations; applicable mechanism; SCC module/options/annexes where used; relevant security measures; and the assessment and supplementary measures supporting it.
The Subprocessor List distinguishes a verified database location from unknown ancillary processing locations and links the providers' published terms. Those public terms show available contractual structures, not proof of Tembrel's account-specific execution or a completed transfer assessment.
No restricted customer transfer should begin until the applicable record and mechanism are established. This schedule supports a completed customer-specific annex without inventing a recipient, signature or exclusive-EU promise.