Command palette

Search pages, tools, and records.

Spensa - Data Processing Agreement

Effective date: 11.06.2026

This Data Processing Agreement forms part of the contract between Spensa Ges.m.b.H. and the customer when Spensa processes personal data on behalf of the customer.

It is intended to meet the requirements of Art. 28 GDPR for controller-processor relationships.

1. Subject matter and duration

Spensa processes customer personal data to provide, secure, support, maintain, and improve the contracted service. The processing lasts for the term of the customer contract and any legally or contractually required wind-down, deletion, backup, or dispute period.

2. Roles and instructions

The customer is the controller for customer personal data. Spensa is the processor and processes customer personal data only on documented instructions from the customer, including instructions in the contract, product configuration, user actions, support requests, and this DPA.

Spensa will inform the customer if, in Spensa's opinion, an instruction infringes applicable data protection law, unless the law prohibits such notice.

3. Data subjects and data categories

Data subjects may include customer users, organization members, establishment staff, supplier contacts, customer representatives, and people named in business documents handled by the customer.

Data categories may include account identifiers, roles, contact details, staff and scheduling data, supplier and order data, invoice and delivery data, POS and inventory data, menu and recipe data, document contents, attachments, notes, support data, logs, and metadata.

4. Confidentiality and security

Spensa ensures that persons authorized to process customer personal data are bound by confidentiality obligations or appropriate statutory confidentiality duties.

Spensa maintains technical and organizational measures appropriate to the risk, including access controls, tenant separation, encryption in transit, controlled storage access, logging, monitoring, backup and recovery measures, least-privilege access, and internal security procedures.

5. Subprocessors

The customer gives Spensa general authorization to use subprocessors needed to provide the service. The current list is published at /subprocessors.

Spensa will impose data protection obligations on subprocessors that are consistent with this DPA. Spensa remains responsible to the customer for subprocessor performance of those obligations.

6. International transfers

Where customer personal data is transferred outside the EU or EEA, Spensa will use a lawful transfer mechanism such as an adequacy decision, standard contractual clauses, or another safeguard permitted under GDPR Chapter V.

7. Assistance

Taking into account the nature of the processing and the information available to Spensa, Spensa will reasonably assist the customer with data subject requests, data security obligations, data protection impact assessments, prior consultations, and personal data breach obligations.

8. Personal data breaches

Spensa will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data. The notice will include available information needed by the customer to meet its legal obligations.

9. Deletion and return

After the end of the service, Spensa will delete or return customer personal data according to the contract, product functionality, and customer instructions, unless EU or Member State law requires continued retention.

Backups and logs may remain for limited periods until overwritten or deleted according to Spensa's normal retention and security processes.

10. Information and audits

Spensa will make available information reasonably necessary to demonstrate compliance with this DPA. Audits must be reasonable, proportionate, protect other customers and Spensa security, and may be satisfied through documentation, security summaries, third-party reports, or written answers where appropriate.

11. Customer obligations

The customer is responsible for lawfully collecting and using customer personal data, giving required notices, obtaining consents where needed, configuring user access, and ensuring that its instructions to Spensa comply with applicable law.