Data Processing Agreement (DPA)
Between the Restaurant ("Controller") and Madar ("Processor"), forming part of the Terms of Service.
1. Roles
The Restaurant is the controller of personal data it processes through Madar — its diners' order and delivery details, its reservations, and its employees' records. Madar is the processor, acting only on the Restaurant's documented instructions.
Madar is an independent controller only for its own account-holder and billing records, which fall outside this DPA.
2. Subject matter
| Duration | term of the Terms of Service |
| Nature | providing point-of-sale, ordering, delivery, reservation and workforce software |
| Purpose | operating the Restaurant's business |
| Data subjects | diners; the Restaurant's staff and employees |
| Categories | contact details (name, phone, delivery address); order and payment records; employee records including national ID, salary, and attendance location coordinates |
The Restaurant should note that employee location coordinates and national ID numbers are processed where it enables those features.
3. Madar's obligations
We will:
- process personal data only on the Restaurant's documented instructions, including for transfers out of Egypt, unless required otherwise by law (and will say so where permitted);
- ensure personnel with access are bound by confidentiality;
- apply appropriate technical and organisational security measures (clause 5);
- engage sub-processors only per clause 6;
- assist the Restaurant in responding to data-subject requests, insofar as our access allows;
- assist with security, breach notification and impact assessments, given the information available to us;
- on termination, delete or return personal data, except where law requires retention (clause 8);
- make available the information needed to demonstrate compliance and allow audits per clause 7.
4. The Restaurant's obligations
The Restaurant warrants that it has a lawful basis for the data it processes through Madar and has given the required notices — including to its employees before enabling attendance location checking, and to its diners.
Where the Restaurant instructs Madar to disclose data to a third-party system it uses (for example a shopping-mall reporting integration), the Restaurant is responsible for the lawfulness of that disclosure and warrants it is entitled to direct it.
Location checking in the staff app is optional and off unless the Restaurant enables it. Enabling it is the Restaurant's decision and its responsibility as employer.
5. Security measures
Current measures include: role- and branch-scoped access enforced at the database level (row-level security); encryption in transit; key-based administrative access with protocol-restricted automation credentials; segregated, access-controlled backups whose restorability is verified by automated weekly test restores; and self-hosted error monitoring configured to exclude personal data, retained 30 days.
Backups are encrypted at rest and held on infrastructure separate from the production server. Security measures are described in full at Security.
6. Sub-processors
The Restaurant provides general authorisation for the sub-processors listed at Sub-processors. We will give 30 days' notice before adding one; the Restaurant may object on reasonable data-protection grounds, and if we cannot resolve the objection it may terminate the affected service.
We remain liable for our sub-processors' acts and omissions.
7. Audit
We will provide information reasonably necessary to demonstrate compliance. Audits are on reasonable notice, no more than once a year unless required by a regulator or following a breach, during business hours, without disrupting operations, and subject to confidentiality.
8. Deletion and return
On termination, we delete or return personal data at the Restaurant's choice, except where retention is required by law. Backups are the exception: data persists in backups until they age out on the normal cycle — we do not surgically edit backups, as that would destroy their integrity as recovery points. See the retention schedule.
9. Breach
We will notify the Restaurant without undue delay after becoming aware of a personal data breach affecting its data, with the information needed for the Restaurant to meet its own notification duties. In any event within 48 hours of becoming aware.
10. Transfers
Some sub-processors process personal data outside Egypt, as identified at Sub-processors. Such transfers are made with the safeguards required by Egyptian data protection law, and the Restaurant authorises them by entering into this DPA.
11. Liability
Each party's aggregate liability under this DPA is subject to the limitation of liability in the Terms of Service. Nothing limits liability that cannot be limited by law.