Data Processing Agreement (DPA)
Last updated: September 2026 · Agreement under Art. 28 GDPR between the customer (controller) and Jannik Thieme, Simpli (processor)
1. Subject matter and duration
This agreement governs the processing of personal data that the processor carries out on behalf of the customer when providing the Simpli platform. It forms part of the Terms and Conditions and applies for the term of the service contract and beyond, for as long as the processor processes the customer's data.
It does not cover processing for which the processor is itself the controller, in particular the management of the customer account, billing, and the processing of data of visitors to menu pages described in the privacy policy.
2. Nature, purpose and scope of processing
Purpose: storing, preparing, translating and publicly providing the content entered by the customer as a digital menu, and the additional services ordered by the customer (AI features, AI menu import, setup service).
Type of data: personal data contained in the content provided by the customer, in particular names and contact details in the legal notice (Impressum) details, names of persons in menu or restaurant texts, and persons shown or named in uploaded images or documents.
Categories of data subjects: owners, managing directors, employees and contact persons of the customer, and other persons named or shown in the content.
Special categories of personal data (Art. 9 GDPR) are not to be processed; the customer does not provide such data.
3. Instructions
The processor processes the data only on documented instructions from the customer, unless required to do otherwise by law; in that case it informs the customer of that legal requirement before processing, unless the law prohibits this. The instructions follow from this agreement, the Terms and Conditions and the customer's use of the platform; the customer gives further instructions by email to info@simpli.menu.
If the processor considers an instruction to be unlawful, it informs the customer without delay.
4. Confidentiality
The processor ensures that all persons with access to the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
5. Technical and organisational measures (Art. 32 GDPR)
– Encrypted transmission of all data (TLS)
– Encrypted storage of data in Google Cloud (Firebase), with the database located in the EU
– Access to the dashboard only after sign-in; passwords are only stored hashed
– Server-side access rules: each customer can only change their own data; non-public data can only be read by the customer and authorised administrators
– Protection of interfaces against automated access (Firebase App Check) and rate limiting
– Administrative access only for the processor via separately authorised accounts
– Logging of errors and security-relevant events
– Deletion of data, including uploaded files, when an account is deleted
The processor may develop these measures further provided the level of protection is not reduced.
6. Sub-processors
The customer grants general authorisation for the use of sub-processors. Currently used:
– Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland: Firebase (authentication, database, file storage, Cloud Functions) and Google Vertex AI (AI features); processing in the EU (Frankfurt), transfers to the USA based on the EU-US Data Privacy Framework or the Standard Contractual Clauses
– Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA: hosting and delivery of the website and menu pages; EU-US Data Privacy Framework
– Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA: error monitoring in the dashboard; EU-US Data Privacy Framework
The processor informs the customer of intended changes at least four weeks in advance by email. The customer may object to the change for an important data protection reason; if no agreement can be reached, the customer may terminate the contract with effect from the date of the change. The processor imposes the same data protection obligations on every sub-processor by contract.
7. Assistance to the customer
The processor assists the customer with appropriate measures in fulfilling data subjects' rights (Arts. 12–23 GDPR), in particular by making it possible to change, delete and export content in the dashboard at any time. It also assists the customer with the obligations under Arts. 32–36 GDPR, taking into account the information available to it. If a data subject contacts the processor directly, it forwards the request to the customer.
8. Personal data breaches
The processor notifies the customer of a personal data breach without undue delay after becoming aware of it and provides the information the customer needs for its notification under Arts. 33 and 34 GDPR.
9. Deletion and return
The customer can download their content at any time via the export function and delete it in the dashboard. When the account is deleted, the processor deletes all data processed on the customer's behalf, including uploaded files, unless there is a legal obligation to retain it. Otherwise, the provisions of the Terms and Conditions on the end of the contract apply.
10. Evidence and audits
On request, the processor provides the customer with all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows audits by the customer or an auditor appointed by it who is bound to confidentiality. Audits must be announced with reasonable notice and carried out during normal business hours; evidence may primarily be provided through information and existing certifications of the sub-processors.
11. Final provisions
Liability is governed by Art. 82 GDPR; otherwise the liability provisions of the Terms and Conditions apply. In the event of conflicts between this agreement and the Terms and Conditions, the provisions of this agreement prevail in matters of data protection. The law of the Federal Republic of Germany applies.