This Data Processing Addendum ("DPA") supplements and is incorporated into the MEP Terms of Service between MEP Suite LLC ("MEP," "Processor") and the customer ("Customer"). It applies where MEP processes Personal Information in Customer Data on Customer's behalf and Customer is subject to an Applicable Privacy Law that requires these terms. On the subject of personal-information processing, this DPA controls over any conflicting term of the Terms of Service.
1. Definitions
Capitalized terms not defined here have the meaning in the Terms of Service. "Applicable Privacy Law" means U.S. state privacy and data-protection laws applicable to Customer's use of the Service, including the California Consumer Privacy Act as amended ("CCPA") and the comprehensive privacy laws of Virginia, Colorado, Connecticut, and Texas, and other states with substantially similar processor-contract requirements. "Personal Information" (or "Personal Data") means information within Customer Data that identifies or is reasonably linkable to an individual and is protected by Applicable Privacy Law. "Business," "Controller," "Service Provider," "Processor," "Sale," "Share," "Consumer," and "Business Purpose" have the meanings given by Applicable Privacy Law. "Subprocessor" means a third party engaged by MEP to process Personal Information to provide the Service; it excludes MEP's own personnel and mere transmission conduits. "Security Incident" means a breach of security leading to the unauthorized acquisition of Personal Information.
2. Roles of the Parties
As between the parties and with respect to Personal Information in Customer Data, Customer is the Business/Controller and MEP is the Service Provider/Processor acting on Customer's behalf. Customer is responsible for the lawfulness of the Personal Information it submits and of its own collection, notice, and consent obligations to the individuals concerned. MEP processes Personal Information only as a Service Provider/Processor and not as a Third Party, Business, or Controller.
3. Scope and Instructions
MEP will process Personal Information only (a) on Customer's documented instructions, which comprise the Terms of Service, this DPA, the configuration and use of the Service by Customer's Authorized Users, and any subsequent written instructions Customer gives; and (b) for the Business Purposes of providing, securing, supporting, and maintaining the Service as described in Annex 1. MEP will inform Customer if it believes an instruction violates Applicable Privacy Law (MEP is not obligated to perform legal analysis on Customer's behalf).
4. Service Provider / Processor Obligations
MEP will: (a) not Sell or Share Personal Information; (b) not retain, use, or disclose Personal Information for any purpose other than the Business Purposes specified in this DPA, or outside the direct business relationship with Customer, except as permitted by Applicable Privacy Law; (c) not combine Personal Information received from Customer with personal information from another source, except as permitted by Applicable Privacy Law; (d) comply with the applicable obligations of a Service Provider/Processor and provide the same level of privacy protection as required of Customer; (e) notify Customer if it determines it can no longer meet its obligations under Applicable Privacy Law; and (f) grant Customer the rights in Sections 8, 9, and 11 to help ensure MEP's processing is consistent with Applicable Privacy Law. MEP certifies that it understands and will comply with the restrictions in this Section. This Section states the mandatory Service-Provider commitments and may not be narrowed.
5. Confidentiality of Personnel
MEP ensures that each person authorized to process Personal Information is subject to a duty of confidentiality and processes Personal Information only as instructed.
6. Security
MEP will implement and maintain the technical and organizational measures described in Annex 2 and in Section 9.3 of the Terms of Service, designed to protect Personal Information. The specific configurations, architecture, tooling, key management, and implementation of those measures are MEP's Confidential Information and trade secrets, are not required to be disclosed, and will not be disclosed. Customer is responsible for its own configuration choices, role assignments, and credential handling within the Service.
7. Subprocessors
7.1 General authorization. Customer generally authorizes MEP to engage Subprocessors, including MEP's affiliates, to process Personal Information, provided MEP engages each Subprocessor under a written contract requiring it to meet MEP's applicable obligations under this DPA. MEP remains responsible for its Subprocessors' performance of MEP's obligations under this DPA.
7.2 Disclosure. MEP maintains a current list of the categories of Subprocessors and their functions (Annex 3). The identities of specific Subprocessors are MEP's Confidential Information and will be made available to Customer upon written request, subject to the confidentiality obligations of the Agreement, and only to the extent Customer's processing is subject to a Law requiring such disclosure. MEP is not required to, and will not, publish a public list of Subprocessor identities.
7.3 Notice of changes. Where Applicable Privacy Law requires notice of a Subprocessor engagement, MEP will notify Customer of the addition of a new Subprocessor (by updating the list and providing notice by email or through the Service) at least thirty (30) days before that Subprocessor begins processing Personal Information, except that MEP may engage a replacement or emergency Subprocessor on shorter notice where necessary for security or service continuity.
7.4 Objection. Solely for Customers whose processing is subject to a Law that grants an opportunity to object to Subprocessors, Customer may, within thirty (30) days after notice of a new Subprocessor, object on reasonable, documented data-protection grounds by written notice, and the parties will discuss the objection in good faith. If the parties do not resolve the objection, Customer's sole and exclusive remedy is to terminate the Order for the affected Service and receive a refund of prepaid, unused fees for the terminated portion of the term.
8. Consumer / Data-Subject Requests
Taking into account the nature of the processing, MEP will provide reasonable assistance (including through the Service's self-service export and deletion features and, where needed, other reasonable technical measures) to enable Customer to respond to verifiable Consumer requests to access, delete, correct, or limit the processing of Personal Information. If MEP receives a Consumer request directed to Customer's data, MEP will, unless legally prohibited, promptly inform Customer and not respond except on Customer's instruction or as required by law.
9. Return and Deletion of Personal Information
9.1 Return or deletion. Customer may export Customer Data throughout the term using the Service's standard export functionality. Following expiration or termination of the Services, Customer may, by written request delivered within thirty (30) days, elect that MEP return Customer's Personal Information using MEP's then-standard export functionality and format. Absent a timely written election, MEP will delete Customer's Personal Information in the ordinary course. MEP's obligation to return is satisfied by making data available through its standard self-service export tools; any custom format, extract, or migration assistance is chargeable at MEP's then-current professional-services rates.
9.2 Retention carve-outs. Notwithstanding Section 9.1, MEP may retain Personal Information (a) to the extent required by applicable law or subject to a legal hold; (b) in routine backup or archival media, which will be overwritten or deleted in the ordinary course of MEP's backup rotation and which will remain logically isolated and not used for any purpose pending such deletion; and (c) in aggregated or de-identified form, provided MEP maintains and commits to the measures in Cal. Civ. Code 1798.140(m) and does not attempt to re-identify it. Retention under (a) is limited to purposes permitted by Cal. Civ. Code 1798.105(d).
9.3 Deletion standard; certification. Deletion is effected by commercially reasonable means with respect to MEP's production systems. Upon Customer's written request, an officer of MEP will provide a written certification that the required deletion has occurred; that certification satisfies Customer's right to documentation verifying non-retention. Certification is a written attestation and is not subject to third-party or independent verification.
9.4 Preservation at Customer's cost. If Customer notifies MEP in writing of a legal preservation obligation before the scheduled deletion date, MEP will suspend deletion of the identified data; such customer-directed retention is at Customer's cost, and Customer indemnifies MEP for data so retained. Customer, as employer and data owner, is solely responsible for its own statutory record-retention obligations and must export required records before deletion occurs.
10. Security Incidents
MEP will notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming a Security Incident affecting Personal Information. The notice will describe, to the extent then known, the nature of the incident, the categories and approximate volume of affected data, measures taken or proposed, and a contact point, and MEP will provide updates as information becomes available. As between the parties, Customer is responsible for determining whether the Security Incident triggers notification obligations to individuals or regulators and for making any such notifications; MEP will reasonably cooperate at Customer's request. MEP's notice is not an acknowledgment of fault. Nothing in this Section limits MEP's obligations under applicable breach-notification laws or requires MEP to provide access to systems, logs, or architecture beyond a summary reasonably necessary for Customer's own notification obligations.
11. Verification; Assessments; No Customer Audits
11.1 Sole verification method. The parties agree that MEP's obligations to take reasonable and appropriate steps sufficient for Customer to ensure MEP's compliance and to stop and remediate unauthorized use under the CCPA, and to make available information necessary to demonstrate compliance and to allow reasonable assessments under Applicable Privacy Law, are satisfied by the mechanisms in this Section, and by no other means. Upon Customer's reasonable written request, no more than once per twelve (12) months, MEP will make available, under the confidentiality terms of this DPA, its then-current independent third-party audit report (for example, SOC 2 Type II or ISO 27001) or, until such a report is available, a comparable independent security assessment or MEP's written compliance attestation responsive to a reasonable request. MEP may arrange for a qualified and independent assessor to conduct any assessment using an accepted control standard and provide a report to Customer upon request; such report is deemed to satisfy MEP's assessment and information-availability obligations.
11.2 No customer audits. Customer has no right to conduct or direct on-site audits, penetration testing, or any access to MEP's systems, networks, source code, security architecture, models, facilities, personnel, or other customers' data. Any assessment is remote and document-based. If, and only if, a supervisory authority compels a direct assessment, or the report under Section 11.1 is demonstrably insufficient to satisfy a mandatory legal requirement, Customer may submit one (1) written security questionnaire per twelve (12) months, on at least thirty (30) days' prior written notice, under NDA, at Customer's sole expense, scoped strictly to that Customer's own Personal Information and conducted by an independent assessor (not a competitor of MEP) bound by confidentiality.
11.3 Carve-outs. No verification activity extends to MEP's source code, trade secrets, security architecture, encryption or key-management implementations, multi-tenant infrastructure detail, other customers' data, or anything that would breach law or third-party confidentiality.
11.4 Preserved rights. Nothing in this Section removes MEP's obligation to notify Customer if it can no longer meet its obligations under Applicable Privacy Law, or Customer's right, upon such notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information; those steps are exercised through the mechanisms in this Section.
11.5 Colorado. For Customers subject to the Colorado Privacy Act, Customer consents that MEP may satisfy its assessment obligation through an independent auditor's report, provided at MEP's expense at least annually, in lieu of a Customer-conducted audit; the prohibitions in Section 11.2 on system, code, architecture, and premises access otherwise apply.
12. Confidentiality of Disclosures; Trade Secrets; Reservation of Rights
12.1 The parties' mutual confidentiality obligations under the Agreement are incorporated into this DPA. All information MEP discloses in connection with this DPA - including its security descriptions, Subprocessor identities and lists, audit, assessment, and certification reports, and deletion attestations - is MEP's Confidential Information. Customer will use such information solely to verify MEP's compliance with this DPA, will disclose it only to those of its personnel and advisors with a need to know who are bound by confidentiality, and will not disclose it to any third party or any competitor of MEP, or use it for any competitive or benchmarking purpose.
12.2 Customer will not reverse engineer, decompile, benchmark, or attempt to derive the structure, methods, models, or know-how of the Service. Nothing in this DPA grants Customer any license or right of access to MEP's systems, source code, networks, proprietary models, methods, know-how, or intellectual property, all of which remain MEP's exclusive property and trade secrets. MEP may satisfy any disclosure obligation in this DPA at a summary, control-category level and is not required to reveal specific configurations, vendors, or implementations.
13. Liability; Order of Precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. This DPA does not create separate or additional liability caps except to the extent required by Applicable Privacy Law.
14. Term
This DPA takes effect when incorporated into the Terms of Service and continues until MEP has deleted or returned all Personal Information under Section 9. Provisions that by their nature should survive termination will survive.
Annex 1 - Details of Processing
Subject matter and duration: processing of Personal Information within Customer Data for the term of the Service and the deletion period in Section 9.
Nature and purpose: providing, operating, securing, supporting, and improving the MEP restaurant-operations Service on Customer's behalf, including report ingestion, deterministic detection, AI-assisted drafting and decision support, task and record management, and reporting.
Categories of data subjects: Customer's owners and Authorized Users; Customer's employees, contractors, and job candidates (in employment records Customer creates); and restaurant guests whose information appears in reservation, review, or delivery data Customer imports.
Categories of Personal Information: identifiers (names, business email addresses, user account identifiers); employment-related information Customer enters; guest information within imported reservation/review/delivery data; and limited operational data associated with the foregoing. Customer controls what it submits.
Annex 2 - Security Measures (control-category level)
MEP maintains an information-security program consistent with a recognized control framework (for example, the NIST Cybersecurity Framework, ISO/IEC 27001, or the SOC 2 Trust Services Criteria), including controls in the following categories:
- Encryption of data in transit and at rest;
- Additional application-layer encryption of stored third-party integration credentials;
- Logical tenant isolation of customer data;
- Role-based access controls on a least-privilege basis;
- Authentication controls for user access;
- Restricted storage for sensitive documents with time-limited access;
- Logging and monitoring of material actions;
- Vulnerability management and change control;
- Incident detection and response.
The specific configurations, architecture, tooling, key management, vendors, and implementation of these controls are MEP's Confidential Information and trade secrets and are not, and will not be, disclosed. MEP may update this Annex at any time provided the level of protection is not materially diminished.
Annex 3 - Subprocessor Categories
MEP engages Subprocessors in the following functional categories, all processing data in the United States. Specific identities are MEP Confidential Information, available on written request under Section 7.2; they are not listed here and are not published.
| Category | Function |
|---|---|
| Cloud infrastructure and hosting | Application hosting, compute, and content delivery |
| Database, authentication, and storage | Data storage, user authentication, and file storage |
| AI model and speech providers | Language-model processing and text-to-speech for AI features |
| Email delivery and intake | Transactional email and inbound report intake |
| Supporting data services | Ancillary operational data used to provide the Service |