Data Processing Agreement
Version 1.0 · Last updated 26 September 2026
1. Parties and status
This agreement is between you, the customer identified in your Amusebit account (the “Controller”), and it Kwaks OÜ, registry code 16835586, of Tornimäe tn 5, 10145 Tallinn, Estonia (the “Processor”).
It applies where we process personal data on your behalf, and it satisfies Article 28(3) of Regulation (EU) 2016/679 (the GDPR). It takes effect when you accept the Terms of Service and lasts as long as your account does.
Where we process data about the people who use your account (your email, your billing details, the sign-in accounts of the team members you invite, and how the app is used), we are the controller, not your processor, and our privacy policy governs that instead. This agreement is only about data you put into the platform, and about the people who read your published menus.
2. Subject matter of the processing
We process personal data only to provide the Amusebit service: storing what you enter, rendering and hosting your published menus, translating text when you ask, and supporting you when you need help.
Duration
For the term of your subscription, plus the 30-day deletion window described in clause 9.
Nature and purpose
Storage, organisation, retrieval, transformation into published pages, transmission to the people who view your menus, and deletion.
Types of personal data
Most menu content isn’t personal data at all. In practice the categories that can arise are:
- Names and job titles, if you credit staff on a menu.
- Images that include identifiable people, if you upload such photos.
- Contact details you publish for your venue, where these belong to an individual.
- The IP address and browser details of people who open your published menus, which every web request carries. We don’t log or analyse these; they’re used only to deliver the page.
Categories of data subjects
Your staff, any individual you choose to name or picture in your content, and the people who view your published menus.
Special categories
The service isn’t designed for special-category data under Article 9, and you must not put such data into it.
3. Our obligations
We will:
- Process only on your instructions. Your use of the service is your instruction. We won’t process the data for our own purposes. If EU or member-state law ever compels us to do something else, we’ll tell you first unless that law forbids it.
- Tell you if an instruction looks unlawful. If we think an instruction of yours breaks the GDPR or other EU or member-state data protection law, we’ll tell you straight away.
- Keep it confidential. Everyone with access is bound by confidentiality obligations.
- Secure it, as set out in clause 4.
- Help you answer data subjects. The app lets you edit and delete content yourself, which handles most requests directly. Where it doesn’t, we’ll help.
- Help you meet Articles 32 to 36 (security, breach notification, and impact assessments), taking into account what we know and the nature of the processing.
- Delete or return the data when the service ends, as clause 9 describes.
- Give you what you need to demonstrate compliance, and allow audits under clause 7.
4. Security measures
Our technical and organisational measures under Article 32 include:
- Encryption in transit (TLS) and at rest for all stored data.
- Tenant isolation: every request is authorised against your membership of a specific venue before it can read or write anything, and roles limit what each member can do.
- Authentication through a managed identity provider, with a password policy and email verification.
- Least-privilege access to production systems, restricted to the people who operate them.
- Automated, versioned infrastructure, so changes are reviewable and reproducible.
- Point-in-time backups of the primary datastore, kept for 35 days in the same EU region.
- Logging and monitoring of access and errors, retained for 90 days.
We’re a small company and we’d rather be honest about that than imply certifications we don’t hold: we aren’t currently ISO 27001 or SOC 2 certified. Our infrastructure sits on AWS, which is.
5. Sub-processors
You give general authorisation for us to use the sub-processors listed below. Each is bound by a written contract imposing the same protections as this agreement, and we remain fully liable to you for what they do.
Amazon Web Services EMEA SARL
Luxembourg, part of the Amazon group
- What it does
- Hosting, database, file storage, content delivery, sign-in and account email. Effectively the whole platform runs here.
- Data location
- eu-central-1 (Frankfurt, Germany). Stored data stays in the EU.
- Delivery
- Pages and images are delivered through a content delivery network, which caches copies briefly at edge locations near the reader. For a reader outside the EU, that edge location can be outside the EU too.
- Safeguards
- AWS Data Processing Addendum, incorporating the EU Standard Contractual Clauses.
Amazon Bedrock
An AWS service, listed separately because it's the only place your content meets a machine-learning model
- What it does
- Translates menu text when you use the AI translation feature. Only the text you ask to translate is sent.
- Data location
- EU regions only, via an EU inference profile. Requests don't leave the EU.
- Who sees it
- Nobody outside AWS. The model runs inside AWS infrastructure. Anthropic, whose model it is, receives nothing and has no contract with us.
- Training
- AWS doesn't use Bedrock inputs or outputs to train models, and doesn't share them with the model provider.
Microsoft Ireland Operations Limited
Dublin, Ireland
- What it does
- Hosts our email, including hello@amusebit.com, so it holds the support conversations you have with us.
- Data location
- Microsoft data centres, with possible transfer to Microsoft Corporation in the United States.
- Safeguards
- Microsoft's Data Protection Addendum with the EU Standard Contractual Clauses; Microsoft Corporation is certified under the EU–US Data Privacy Framework.
Font delivery. Published menus load their typefaces from Google Fonts. Google isn’t our sub-processor and receives no menu content, but it does receive the IP address and browser details of each reader, as any web request carries:
Google LLC (Google Fonts)
United States
- What it does
- Delivers the typefaces used on published menus and in the Amusebit app. This website serves its own fonts and doesn't use it.
- What it receives
- The reader's IP address and browser details, which any web request carries. Google Fonts sets no cookies, and Google says it collects only what it needs to serve the fonts.
- Why
- Our legitimate interest in showing menus in the typefaces a venue chose, quickly and consistently (Art. 6(1)(f) GDPR).
- Safeguards
- Google LLC is certified under the EU–US Data Privacy Framework.
Changes. We’ll give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you have a reasonable objection on data protection grounds, tell us within those 30 days and we’ll work with you to find an alternative. If we can’t, you may end the service by written notice. Fees already paid aren’t refunded.
6. International transfers
All personal data we store is stored in the EU, in eu-central-1 (Frankfurt, Germany). Data can leave the EEA in two ways: Microsoft, which hosts our email, may process support correspondence in the United States under the EU Standard Contractual Clauses; and Google receives menu readers’ IP addresses when it delivers fonts. Both Microsoft Corporation and Google LLC are certified under the EU–US Data Privacy Framework.
Published menus are delivered by a content delivery network, which caches copies briefly near each reader. For a reader outside the EEA, that cached copy can be outside the EEA too. The stored data doesn’t leave the EU.
7. Audits
On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we’ll provide the information you reasonably need to verify our compliance. That includes the certifications and audit reports of our sub-processors.
If that’s genuinely not enough, you may carry out or mandate an on-site audit, on 30 days’ notice, during business hours, without disrupting the service, and subject to confidentiality. You bear the cost unless the audit uncovers material non-compliance.
8. Personal data breaches
We’ll notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data. The notice will describe what happened, which categories and roughly how many records are affected, the likely consequences, and what we’re doing about it. Where we don’t have all of that at once, we’ll send what we have and follow up.
Notifying your supervisory authority and your data subjects is your call to make as controller. We’ll give you what you need to make it.
9. Deletion and return
At any time while your account is open, you can ask us for an export of your data in a machine-readable format, and we’ll send it within one month. When your subscription ends, or when you delete your account, we schedule all of your personal data for deletion 30 days later. That window exists so an accidental deletion or a billing dispute can be undone. After it passes, the data is deleted, and it leaves our rolling backups within a further 35 days.
We keep data beyond that point only where EU or member-state law requires it, principally invoices and accounting records, which Estonian law requires us to hold for seven years. Anything kept that way stays subject to this agreement.
10. Your obligations
As controller, you are responsible for:
- Having a lawful basis for the personal data you put into the service.
- Giving your own data subjects the information the GDPR requires.
- Not uploading special-category data.
- Making sure your instructions to us (that is, your use of the service) don’t put us in breach of the GDPR.
- Managing who you invite into your venue and what role you give them.
11. Liability and order of precedence
The limitation of liability in the Terms of Service applies to this agreement too, as part of the single overall cap set there, to the extent the GDPR allows.
Where this agreement conflicts with the Terms of Service on any other data protection matter, this agreement wins. It’s governed by Estonian law, as the Terms are.
12. Contact
Data protection questions, audit requests, and breach correspondence all go to hello@amusebit.com.