Data Processing Agreement
The Article 28 contract that governs personal data you send through the Foodashi API.
1. What this is and when it applies
This Data Processing Agreement ("DPA") forms part of the Terms of Service and API License Agreement between you ("Customer", the controller) and Foodashi (the processor). It applies whenever you submit personal data to the Foodashi API. It takes effect automatically when you accept the Terms, and no signature is required — though we will sign a countersigned copy on request.
Where this DPA conflicts with the Terms of Service or API License Agreement on a data protection matter, this DPA prevails. In all other respects those agreements continue unchanged.
Most customers send us no personal data at all. A typical request is a dish name or a list of ingredients. This DPA exists for the cases where your request text, or data you choose to include, does contain personal data — and so that your own compliance review has something to point at.
2. Subject-matter, duration, nature and purposeArt. 28(3)
| Subject-matter | Processing of personal data contained in API requests you submit, solely to return the food, recipe and nutrition data you requested. |
|---|---|
| Duration | For as long as your account is active, plus the retention periods set out in our Privacy Policy. API request logs are retained for up to 90 days. |
| Nature & purpose | Receiving, transmitting, temporarily processing and logging request payloads in order to generate and return API responses, and to secure the service against abuse. |
| Types of personal data | Any personal data you choose to include in a request payload (for example a name or dietary note embedded in free text). Account and billing data you give us directly is processed by us as a controller, not under this DPA. |
| Categories of data subjects | Your end users, staff, or any individual whose data you include in a request. |
| Special categories | Not permitted. Do not submit health data, or any Article 9 special-category data, through the API. Dietary and allergen preferences relating to an identifiable person can constitute health data — send ingredients, not patients. |
3. Our obligations as processor
- Documented instructions only.Art. 28(3)(a) We process personal data only on your documented instructions, which for standard use are constituted by your API requests and these agreements. We will tell you if we believe an instruction infringes the GDPR.
- No transfer without a legal basis. We will not transfer personal data outside the EEA except under a valid transfer mechanism, as described in Section 6.
- Confidentiality.Art. 28(3)(b) Any person authorised to process the data is bound by confidentiality. Foodashi is currently operated by a single individual; access is limited to that person and the sub-processors listed below.
- Security.Art. 28(3)(c) · Art. 32 We maintain the technical and organisational measures described in Section 4.
- Sub-processors.Art. 28(3)(d) · 28(2) Engaged only under the terms in Section 5.
- Assisting with data subject rights.Art. 28(3)(e) Taking account of the nature of the processing, we will assist you by appropriate measures in responding to requests to exercise data subject rights. Because we hold request payloads only transiently and in short-lived logs, in practice this usually means confirming what was logged and deleting it.
- Assisting with security, breaches and DPIAs.Art. 28(3)(f) · Arts. 32–36 We will assist you in ensuring compliance with security obligations, breach notification, and data protection impact assessments, taking into account the information available to us.
- Deletion or return on termination.Art. 28(3)(g) On termination we delete personal data processed under this DPA within 30 days, except where EU or Member State law requires retention (for example Hungarian accounting law for billing records). You may request deletion sooner in writing.
- Information and audits.Art. 28(3)(h) We will make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. See Section 7 for how this works in practice.
4. Security measuresArt. 32
- Encryption in transit (TLS 1.2+) for all API traffic and all sub-processor connections.
- Encryption at rest for the database holding account and usage data.
- API keys stored as hashes, never in plaintext; keys are revocable and rotatable by you at any time.
- Row-level security on all customer and billing tables, with database access restricted to the service role used by the API worker.
- Rate limiting, abuse detection, WAF and DDoS protection at the network edge.
- Least-privilege access; administrative operations require a second authentication factor.
- Request logs limited to what is needed for security and diagnostics, retained no longer than 90 days.
These measures are reviewed periodically and may be updated, provided the level of security is not reduced.
5. Sub-processorsArt. 28(2), 28(4)
You give general written authorisation for us to engage the sub-processors listed below. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain fully liable to you for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare | API edge, DDoS protection, WAF | Global edge / US |
| Supabase | Database hosting (accounts, keys, usage metadata) | EU region |
| Google (Gemini) | Text generation from request payloads | US |
| DeepInfra / Black Forest Labs | Image generation — receives machine-generated food descriptions only, no personal data | US |
| Stripe | Payment processing (billing data; controller-to-controller) | US / EU |
| Brevo | Transactional email | EU (France) |
Changes. We will give at least 30 days' notice before adding or replacing a sub-processor, by email to your account address. If you object on reasonable data protection grounds within that period, you may terminate the affected services without penalty and receive a pro-rata refund of prepaid fees.
6. International transfersArts. 44–46
Where personal data is transferred outside the EEA, the transfer is covered by an adequacy decision, by the EU Standard Contractual Clauses, or by the EU–US Data Privacy Framework where the recipient is certified. The current position for each sub-processor is stated in our Privacy Policy, and you may request the applicable safeguard documentation at any time.
7. Breach notification & audits
Breach notification.Art. 33(2) We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting data processed on your behalf, with the information available to us at that time and updates as the investigation progresses. That timeframe is set to leave you room inside your own 72-hour obligation to your supervisory authority.
Audits. You may request the information necessary to demonstrate Article 28 compliance by writing to [email protected]. We will respond within 30 days. An on-site or third-party audit may be requested no more than once in any 12-month period, on 30 days' notice, at your cost, subject to reasonable confidentiality undertakings — or sooner where a supervisory authority requires it or following a confirmed breach.
8. Your obligations as controller
- You are responsible for having a lawful basis for the personal data you send us, and for giving your own data subjects the information they are entitled to.
- You must not submit Article 9 special-category data, criminal offence data, or the personal data of children, through the API.
- You must keep your API keys confidential and revoke them promptly if compromised.
- Your instructions must comply with data protection law; we may suspend processing of an instruction we reasonably believe is unlawful.
9. Liability, law and contact
Liability under this DPA is subject to the limitations in the Terms of Service, except where those limitations are not permitted by the GDPR or by mandatory law — in particular Article 82, which cannot be contracted around.
This DPA is governed by the laws of Hungary and, to the extent applicable, by the GDPR and Hungarian Act CXII of 2011 on informational self-determination.
Need a countersigned copy, or have your own DPA template? Email [email protected] with your entity details and we will return a signed PDF. If your organisation processes special-category data or requires bespoke terms, contact us before integrating rather than relying on this self-serve version.
Provider Details (Impresszum)
Business registration in progress. Foodashi is operated from Budapest,
Hungary and is in the process of being registered as an egyéni vállalkozó
(Hungarian sole proprietorship). Full statutory provider details — registered name,
seat address, registration number and tax number — will be published here as soon
as registration completes, and before any paid service is offered.
Until then you can reach us at
[email protected]
for any legal, contractual or data protection matter.