Data processing agreement
Whenever guests use a venue's digital menu, Kymiro processes personal data on that venue's behalf. This agreement forms part of the contract between NT Investments UG (haftungsbeschrรคnkt), operating Kymiro ("processor"), and the venue operating the digital menu ("controller"), and satisfies Article 28(3) GDPR.
Version 1.0 โ in force since 21 August 2026
1. Subject matter, duration and termination
Kymiro processes personal data exclusively to provide the contractually agreed services: a digital menu, transmission of guest requests to the venue, table sessions, staff and partner accounts, and the reporting shown in the back office. The agreement starts when the venue is created and ends when the main contract ends. It can only be terminated together with the main contract.
2. Nature and purpose of the processing
Collection, storage, structuring, display, transmission to the venue, and deletion of data created while guests use the digital menu, plus the technical operation, security and support of the platform. No processing takes place for Kymiro's own purposes.
3. Categories of data and data subjects
The processing covers:
- Data subjects: guests of the venue, employees of the venue, and the venue's contact persons.
- Guest data: selected products, quantities, options and item notes, preliminary amounts, cover fees and minimum spend, service requests and waiter calls, session and spot identifiers, an optional self-chosen display name, language and appearance preference.
- Staff data: name, email address, role, station assignment, invitation and sign-in metadata.
- Technical data: IP address, timestamps, device and browser information, error logs.
- Guests are never asked for a name, address, phone number, email address or payment card. No special categories under Art. 9 GDPR are processed; venues must not enter such data into free-text fields.
4. Processing on documented instructions
Kymiro processes personal data only on the documented instructions of the venue (Art. 28(3)(a) GDPR). The instructions are given by this agreement, the main contract and the settings the venue makes in the back office. Additional instructions must be made in text form to info@kymiro.com. Kymiro informs the venue if, in its opinion, an instruction infringes data protection law and may suspend the instruction until it is confirmed. Where Union or Member State law requires processing beyond the instructions, Kymiro informs the venue before processing unless that law prohibits it.
5. Confidentiality
Every person authorised by Kymiro to process personal data is bound to confidentiality in writing or is under an appropriate statutory obligation of confidentiality, and is trained on data protection duties. The obligation survives the end of their engagement (Art. 28(3)(b) GDPR).
6. Technical and organisational measures (Art. 32 GDPR)
Kymiro maintains a level of security appropriate to the risk. The current measures are:
- Encryption in transit (TLS 1.2+ for every connection) and encryption at rest for the database and file storage.
- Row level security on every database table, so a venue can only ever read and write its own data; guests reach only the session belonging to their spot.
- Role-based access: owner, manager, waiter, station staff and setup partner each see only what their role requires; sales partners are technically blocked from day-to-day guest data.
- Authentication with hashed passwords, protection against known leaked passwords, rate limits on sign-in and password reset, and short-lived access tokens.
- Privileged operations run server-side with re-checked permissions; the browser never holds administrative credentials.
- Logging of security-relevant back-office actions (audit log) including actor and timestamp.
- Segregated environments for development and production, automated backups with point-in-time recovery, and restore tests.
- Data minimisation by design: guests order without an account, and no payment card data is processed by Kymiro.
- Availability and resilience through managed, redundant infrastructure inside the European Union.
- Regular review of the measures; Kymiro may change them as long as the level of protection is not reduced.
7. Sub-processors
The venue grants general written authorisation for the use of sub-processors (Art. 28(2) GDPR). The current list is published on the sub-processors page and is part of this agreement. Kymiro informs venues of any intended addition or replacement at least 30 days in advance by email; the venue may object on reasonable data protection grounds within that period, in which case either party may terminate the affected service. Every sub-processor is bound by data protection obligations equivalent to those in this agreement, and Kymiro remains fully liable for their performance.
8. International transfers
Personal data is stored and processed inside the European Union. Where a sub-processor exceptionally accesses data from a third country, the transfer is based on an adequacy decision or on the EU Standard Contractual Clauses together with supplementary measures. Kymiro does not transfer data to third countries on its own initiative without the venue's instruction.
9. Assistance with data subject rights
Guests and staff must address their requests to the venue as controller. Kymiro assists the venue with appropriate technical and organisational measures (Art. 28(3)(e) GDPR): the back office allows access to, correction of and deletion of session and request data, and account holders can export their own data and delete their account themselves. If a data subject contacts Kymiro directly, we forward the request to the venue without undue delay and do not answer it ourselves.
10. Support with Articles 32 to 36 GDPR
Kymiro supports the venue in ensuring security of processing, in notifying personal data breaches, and in data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available. Kymiro notifies the venue of a personal data breach affecting its data without undue delay, and at the latest within 24 hours of becoming aware, including the known facts, likely consequences and measures taken.
11. Deletion and return of data
At the end of the main contract the venue may export its data. Afterwards Kymiro deletes the personal data processed on the venue's behalf within 30 days, unless Union or Member State law requires further storage. During the contract, retention follows the deletion concept:
- Closed table sessions with their requests, item notes and guest display names: automatically deleted 30 days after the session is closed; only anonymous daily totals remain for up to 90 days.
- Support requests: deleted 24 months after they were submitted.
- Back-office audit log entries: deleted 12 months after the action.
- Staff invitations: deleted after they expire or are accepted.
- Account and contract data: kept for the duration of the contract, then deleted subject to statutory retention duties (10 years for accounting records under ยง 147 AO and ยง 257 HGB).
- After an account is erased we keep pseudonymised proof only โ the date and version of the agreements accepted, accounting records and the record of the erasure itself. It contains no name, email address or phone number (Art. 17(3)(b) and (e) GDPR).
- A pending legal matter (open invoice, dispute, request by an authority) suspends deletion for as long as the matter requires; the data is restricted, not used for anything else, and deleted once the matter ends.
12. Documentation and audits
Kymiro maintains a record of processing activities carried out on behalf of the venue and makes available all information necessary to demonstrate compliance with Art. 28 GDPR. The venue may verify compliance during business hours, with reasonable notice, without disrupting operations and no more than once a year unless there is a specific cause โ as a rule through documentation, self-disclosure or certificates, and only in exceptional cases through an on-site inspection.
13. Liability and precedence
Liability follows Art. 82 GDPR and the main contract. Where this agreement conflicts with other agreements between the parties, this agreement prevails for matters of data protection. Should individual provisions be invalid, the remainder stays in force. The agreement is governed by German law; the place of jurisdiction is Dรผsseldorf, unless mandatory law of the venue's Member State โ for example Greek consumer or supervisory law โ provides otherwise.
How this agreement is concluded
Venues accept this agreement when they create their venue in the back office and each time a new version is published. We record the acceptance with the date, version and venue; you can request a copy at any time via info@kymiro.com. A signed paper version is available on request.