Data Processing Addendum (DPA)
GDPR Article 28 compliant data processing terms, security commitments, and standard contractual clauses.
- Effective
- September 4, 2026
- Entity
- Antigravity
- Jurisdiction
- India
- Applies to
- kafei.in
1. Scope, Purpose & Relationship of the Parties
This Data Processing Addendum ("DPA") supplements the Kafei Terms of Service and applies to the processing of Personal Data under European Data Protection Laws (including EU GDPR 2016/679, UK GDPR, and Swiss Data Protection Acts).
- Customer is the Data Controller: Determines the purposes and means of processing diner and restaurant employee Personal Data.
- Kafei is the Data Processor: Processes Personal Data strictly on behalf of and under the documented instructions of the Customer.
2. Subject Matter & Categories of Data
- Subject Matter: Provision of cloud restaurant POS, KDS, table QR ordering, inventory, and demand forecasting.
- Categories of Data Subjects: Restaurant diners, guests, staff, cashiers, managers, and administrators.
- Types of Personal Data: Names, emails, phone numbers, dining timestamps, table numbers, ordered items, billing references, and device IP logs.
3. Obligations of the Processor (Kafei)
3.1 Documented Instructions
Kafei shall process Personal Data exclusively in accordance with Customer’s documented instructions, unless required to do so by applicable law.
3.2 Technical and Organizational Measures (TOMs)
- TLS 1.3 / HTTPS encryption for all data in transit.
- AES-256 encryption for data at rest and database volumes.
- Multi-tenant logical isolation preventing cross-account access.
- Role-Based Access Control (RBAC) and least privilege principles.
4. Sub-processors
Customer grants general authorization for Kafei to engage sub-processors. The current list, including what each one processes and where, is published at kafei.in/subprocessors. Kafei imposes contractual data protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance.
Kafei will post any new or replacement sub-processor on that page at least 30 days before it begins processing Customer Personal Data. Customer may object on reasonable, documented data protection grounds within that period, in which case the parties will work in good faith toward an alternative; if none is available, Customer may terminate the affected subscription with a pro-rated refund of the unused prepaid term.
5. International Transfers
Where processing involves transferring Personal Data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (Controller to Processor), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this DPA by reference and prevail over any conflicting term. The technical measures in Section 3.2 and in our Security Policy constitute the supplementary measures accompanying those transfers.
6. Personal Data Breach Notification
In the event of a confirmed Personal Data Breach impacting Customer’s data, Kafei will notify Customer without undue delay (and in any event within 48 hours of becoming aware of the breach) and provide relevant details.
7. Data Subject Requests & Assistance
Kafei will promptly forward any request it receives directly from a Data Subject relating to Customer's data, without responding to it itself except to confirm the request was received. Taking account of the nature of the processing, Kafei will provide reasonable assistance to Customer in fulfilling requests to access, correct, delete, or port Personal Data, and in carrying out data protection impact assessments and prior consultations under Articles 35 and 36 of the GDPR.
8. Audit Rights
On reasonable written notice and no more than once per year (or following a confirmed breach), Kafei will make available the information necessary to demonstrate compliance with Article 28 and will contribute to an audit conducted by Customer or an independent auditor Customer mandates, subject to confidentiality obligations and to Customer bearing the auditor's costs.
9. Data Deletion and Return
Upon termination of the Services, Kafei shall, at Customer's election, delete or return all Personal Data within 30 days, unless statutory retention laws require continued storage. Encrypted backups are purged on their normal rotation within 90 days.
Questions about this policy?
Write to us for data subject requests, deletion requests, security reports, or compliance reviews. We respond within 5 business days.
Antigravity, Kolkata, West Bengal, India