This document sets out the terms of personal data processing under Art. 28 GDPR between you (the controller) and SIA «IT Hospitality» (the processor), Katrīnas iela 5, LV-1045 Rīga, Latvia, registration number 40203196322. It applies together with the Terms of Service and is concluded with business customers.
Roles of the parties
You determine the purposes and means of processing the data contained in your documents and reference data - you are the controller. We process that data solely on your instructions - we are the processor. Your account data and correspondence with us we process as a controller; this agreement does not cover them and they are described in the Privacy Policy.
Subject matter, nature and duration
- Subject matter: providing the service of intake, recognition and audit of supplier documents.
- Nature of processing: intake, recognition, matching, storage, calculation, transfer into your back office, deletion.
- Purpose: solely the provision of the service to the extent you instructed.
- Duration: for the term of the service agreement and the retention period stated below.
Categories of data and data subjects
Personal data appears in supplier documents to a limited extent: names and contact details of supplier representatives, signatures and goods-receipt marks, data of sole traders. Categories of data subjects: employees and representatives of your suppliers, and your own staff working with documents. Special categories of data under Art. 9 GDPR are not processed; if they appear in a document, we do not use them.
Our obligations
- Process data only on your documented instructions, including for transfers to third countries.
- Ensure confidentiality: access is limited to staff who need it for their work and who are bound by confidentiality obligations.
- Apply the technical and organisational measures required by Art. 32 GDPR - see the section below.
- Assist you in responding to data subject requests: access, rectification, erasure, restriction, portability.
- Assist you with the obligations under Art. 32-36 GDPR to the extent available to us as processor.
- Notify you of a personal data breach without undue delay after becoming aware of it, describing the nature of the breach and the measures taken.
- Make available the information needed to demonstrate compliance with Art. 28 and contribute to audits.
Sub-processors
You give general authorisation for the engagement of sub-processors. The current list:
- Anthropic PBC (USA) - recognition of document content. European Commission Standard Contractual Clauses.
- Google (USA) - interpreting the wording of a question in the assistant; only the question text is transferred. Standard Contractual Clauses.
- Supabase (United Kingdom, London) - database and file storage.
- Contabo GmbH (EU, Nuremberg) - document processing server.
- Vercel (United Kingdom, London) - hosting for the website and the application.
- Telegram - delivery of alerts and intake of documents, if you use that channel.
- Cloudflare - protection of forms against automated submissions.
- Stripe Payments Europe (Ireland) - card payment processing. The billing contact and a card identifier are transferred; the card details themselves are held by Stripe, not by us. Transfers within the Stripe group to the US rely on the European Commission's standard contractual clauses.
- Resend (USA) - sending email: sign-in, confirmations, notifications. The recipient address and the message text are transferred. Transfers to a third country rely on standard contractual clauses.
- NEXX - only if you enabled the integration: the supplier list and product catalogue needed for orders are transferred. The transfer is made on your instruction and within the scope of the integration.
We give at least thirty days' notice of our intention to engage a new sub-processor or replace an existing one. Within that period you may object on reasonable data protection grounds; if the disagreement cannot be resolved, you may terminate the agreement without penalty.
Transfers outside the EEA
Three sub-processors are located in the USA. Transfers are made on the basis of the European Commission's Standard Contractual Clauses with supplementary measures: encryption in transit and minimisation of the data transferred. In the assistant, only the text of the question leaves our perimeter - no invoices, prices, suppliers or stock figures; the access key is separate from the one used for document recognition. The database and hosting are located in the United Kingdom: the European Commission has recognised it as providing an adequate level of protection, so such transfers require no separate contractual clauses.
Security measures
- Encryption of data in transit and at rest.
- Row-level access control in the database: a company sees only its own data.
- Staff access on a least-privilege basis, with action logging.
- Backups and restore testing.
- Separate access keys for different external services.
When the service ends
At your choice we delete or return all data processed under this agreement - on your request within 14 days. If you do not state a choice, the data is deleted three years after the service ends. The exception is information we are required by law to keep: our accounting records of the payments between us.
Your obligations
You confirm that you have a legal basis for providing us with the data contained in your documents and that your instructions do not infringe the GDPR. You are responsible for the content of the data you upload to the service.
Contact and requesting a copy
The text of the agreement is published on this page. If your compliance process needs a signed copy, request it at hello@restoaudit.ai.
SIA «IT Hospitality», Katrīnas iela 5, LV-1045 Rīga, Latvia