This Data Processing Addendum ("DPA") forms part of the Kitchn End User License Agreement and Terms of Service (the "Agreement") between Kitchn LLC, a Virginia limited liability company ("Kitchn"), and the Merchant identified in the Agreement ("Merchant"). It is incorporated into the Agreement by reference and applies automatically, without signature, to the extent Kitchn processes Merchant Personal Data on Merchant's behalf. Capitalized terms not defined here have the meanings given in the Agreement.
In the event of a conflict, this DPA governs over the Agreement with respect to the processing of Merchant Personal Data; the Agreement governs everything else. Nothing in this DPA modifies, limits, or overrides any agreement between Merchant and its POS Provider, Payment Processor, acquirer, or card networks, and where this DPA conflicts with a POS Provider's applicable terms with respect to that provider's data, the POS Provider's terms govern as to that data.
1. Definitions
- "Applicable Data Protection Law" — all privacy and data protection laws that apply to the processing of Merchant Personal Data under this DPA, including, where applicable, the California Consumer Privacy Act as amended (the "CCPA"), the Virginia Consumer Data Protection Act, and other U.S. state privacy laws.
- "Merchant Personal Data" — personal data or personal information (as defined by Applicable Data Protection Law) contained in Merchant Data that Kitchn processes on Merchant's behalf under the Agreement — including data relating to Merchant's Diners, customers, marketing subscribers, loyalty members, and staff.
- "Security Incident" — a confirmed breach of Kitchn's security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Merchant Personal Data. Unsuccessful attempts (such as blocked attacks, port scans, or failed login attempts) are not Security Incidents.
- "Subprocessor" — a third party engaged by Kitchn to process Merchant Personal Data on Kitchn's behalf in support of the Services.
- "Controller," "processor," "business," "service provider," "third party," "sell," "share," "data subject," and "consumer" have the meanings given by Applicable Data Protection Law.
2. Roles and Scope
2.1 Roles. For Merchant Personal Data processed to provide the Services, Merchant is the controller (or business) and Kitchn is the processor (or service provider). Kitchn acts as an independent controller only for the limited purposes described in Section 1 of the Kitchn Privacy Policy — managing Merchant's account and billing, platform security, fraud and abuse prevention, legal compliance, and Kitchn's own business communications with Merchant — and that independent processing is outside the scope of this DPA.
2.2 Details of processing. The subject matter, duration, nature, and purpose of processing, the categories of data subjects, and the types of Merchant Personal Data are set out in Annex I.
2.3 United States scope. Consistent with Section 2.5 of the Agreement, the Services are offered and directed solely to persons located in the United States, and the parties do not intend any processing under this DPA to be subject to the GDPR, UK GDPR, or Swiss FADP. If, notwithstanding that scoping, such a law is found to apply to specific processing, the parties will cooperate in good faith to promptly implement any additional measures that law requires for that processing.
3. Kitchn's Processing Obligations
Kitchn will:
(a) process Merchant Personal Data only on Merchant's documented instructions, which consist of: the Agreement and this DPA; Merchant's configuration and use of the Services (including the features, integrations, and campaigns Merchant enables); and any other written instructions Merchant gives that are consistent with the Agreement. Kitchn will inform Merchant if, in Kitchn's opinion, an instruction violates Applicable Data Protection Law, and may suspend the affected processing until the instruction is revised;
(b) not sell Merchant Personal Data, not share it for cross-context behavioral advertising, and not process it for targeted advertising;
(c) not retain, use, or disclose Merchant Personal Data for any purpose other than performing the Services and as permitted by Applicable Data Protection Law, including not retaining, using, or disclosing it outside the direct business relationship between Kitchn and Merchant;
(d) not combine Merchant Personal Data with personal information received from another merchant or from Kitchn's own interactions with a consumer, except as permitted by Applicable Data Protection Law for a permitted business purpose (such as security and fraud prevention) or to provide the Services Merchant has enabled;
(e) not use Merchant Personal Data to train third-party artificial intelligence models, and not use one merchant's data to benefit a competitor;
(f) ensure that persons authorized to process Merchant Personal Data are bound by confidentiality obligations;
(g) certify that it understands and will comply with the restrictions in this Section 3; and
(h) notify Merchant promptly if Kitchn determines that it can no longer meet its obligations under Applicable Data Protection Law, in which case Merchant may take the reasonable and appropriate steps permitted by that law to stop and remediate any unauthorized processing.
4. Security
4.1 Safeguards. Kitchn will maintain administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Merchant Personal Data, as described in Annex II. Kitchn may update its safeguards from time to time, provided the updates do not materially reduce the overall protection of Merchant Personal Data during the term of the Agreement.
4.2 Payment card data. Cardholder data is not transmitted to or stored on Kitchn systems. Card entry is performed through the Payment Processor's hosted fields, and card-present transactions on a POS device are processed by the POS Provider and its acquirer; Kitchn receives only tokens and non-sensitive descriptors, as described in Section 5 of the Privacy Policy.
4.3 Merchant responsibilities. Merchant is responsible for: configuring roles, permissions, and integrations appropriately; safeguarding its credentials and enabling multi-factor authentication where offered; the security of its own devices, networks, and staff practices; and the lawfulness of the Merchant Personal Data it submits, imports, or directs Kitchn to process.
5. Subprocessors
5.1 General authorization. Merchant provides general written authorization for Kitchn to engage the Subprocessors listed in Annex III, and to replace or add Subprocessors as provided below. Kitchn will impose on each Subprocessor written data protection obligations no less protective than those in this DPA, and remains responsible to Merchant for each Subprocessor's performance.
5.2 Changes. Kitchn will update Annex III on this page before adding or replacing a Subprocessor and will notify Merchant of material changes by email to the account owner or by notice in the Services at least 15 days before the new Subprocessor processes Merchant Personal Data (except in urgent replacement scenarios necessary for security or continuity, where notice will follow as soon as practicable). If Merchant reasonably objects on data protection grounds, the parties will discuss in good faith; if no resolution is reached, Merchant may terminate the affected subscription in accordance with the Agreement as its sole remedy.
5.3 Merchant-directed services. POS Providers, Delivery Providers, the Payment Processor, and other integrations that Merchant elects to connect act at Merchant's direction under Merchant's own agreements with them. They are recipients of Merchant Personal Data at Merchant's instruction, not Kitchn's Subprocessors, except to the extent they process Merchant Personal Data solely on Kitchn's behalf.
6. Assistance with Rights Requests
6.1 Tools. The Services provide Merchant with tools to access, review, and correct Diner and customer records, which Merchant should use as its primary means of responding to consumer and data subject requests. Where a self-service export or deletion capability is not available for a given record type, Kitchn will perform the export or deletion on Merchant's written request under Section 6.2.
6.2 Forwarding and assistance. If Kitchn receives a request directly from a consumer relating to Merchant Personal Data, Kitchn will forward it to Merchant promptly and inform the requester that it has done so. Taking into account the nature of the processing, Kitchn will provide reasonable assistance — through the tools above and, where those are insufficient, through commercially reasonable additional measures — to enable Merchant to respond to requests to exercise rights under Applicable Data Protection Law within the timelines that law imposes on Merchant.
6.3 Other assistance. Kitchn will provide reasonable assistance, at Merchant's cost for extraordinary requests, with data protection assessments and regulator consultations that Applicable Data Protection Law requires of Merchant, to the extent they concern processing under this DPA and the necessary information is available to Kitchn.
7. Security Incident Notification
Kitchn will notify Merchant without undue delay, and in any event within 72 hours, after confirming a Security Incident affecting Merchant Personal Data. The notice will describe, to the extent then known: the nature of the incident; the categories and approximate volume of affected data and data subjects; the measures taken or planned to address it; and a contact point. Kitchn will take reasonable steps to contain and remediate the incident and will keep Merchant reasonably informed. Kitchn's notification is not an acknowledgment of fault or liability. Merchant is responsible for any notification to consumers or regulators that Applicable Data Protection Law requires of Merchant as controller, and Kitchn will provide reasonable cooperation.
8. Deletion and Return
8.1 During the term. Merchant may access, review, and manage Merchant Personal Data through the Services throughout the Subscription Term, and may request a machine-readable export, or deletion of specific records, at any time under Section 6.
8.2 On termination. Following termination or expiration of the Agreement, the export window and deletion timeline in Section 27.4 of the Agreement apply: Merchant may request an export for 30 days, and Kitchn will thereafter delete or de-identify Merchant Personal Data within 90 days, except (a) records Kitchn must retain for tax, accounting, dispute-resolution, legal-hold, or compliance purposes, which remain protected by this DPA and are deleted when the retention obligation ends; (b) aggregated and de-identified data that no longer identifies Merchant or any individual; and (c) copies in routine backups, which are overwritten on Kitchn's normal cycle and are not restored into production in the ordinary course.
8.3 POS data. Data derived from a connected POS Provider is additionally subject to the deletion commitments in Section 7 of the Privacy Policy, including deletion or de-identification within 30 days of disconnection or uninstall.
9. Audits and Compliance Information
9.1 Information. On Merchant's reasonable written request (no more than once per 12-month period, unless required by a regulator or following a Security Incident affecting Merchant), Kitchn will make available information reasonably necessary to demonstrate compliance with this DPA — such as its security overview, completed security questionnaires, and summaries of third-party assessments where available.
9.2 Audits. Where Applicable Data Protection Law grants Merchant an audit right that the information in Section 9.1 does not satisfy, Merchant (or an independent auditor on its behalf that is not a Kitchn competitor, bound by confidentiality) may conduct an audit of Kitchn's processing of Merchant Personal Data, limited to that purpose, on at least 30 days' written notice, during business hours, no more than once per 12-month period, at Merchant's expense, and in a manner that does not compromise the security or confidentiality of other merchants' data. Kitchn may satisfy an audit request through a mutually agreed remote review. Findings are Kitchn's Confidential Information.
9.3 Cooperation. Each party will cooperate in good faith with the other's reasonable compliance requests concerning the processing of Merchant Personal Data.
10. Sensitive and Health-Related Preferences
The Services do not maintain a persistent dietary or allergen profile for Diners. Where a Diner voluntarily includes dietary, allergen, or religious-observance information in a free-text order note or catering inquiry, Kitchn processes that information solely to transmit the Diner's instructions to Merchant with that order, at the Diner's direction, as described in Sections 3.6 and 10.5 of the Privacy Policy. Kitchn does not use it for marketing, profiling, or inference, and does not sell it. Merchant must not use such information for any purpose other than fulfilling the Diner's orders and accommodating the Diner's stated needs, and must not disclose it except as necessary for that purpose or as required by law.
11. Legal Process
If Kitchn receives a subpoena, court order, or other legally binding demand for Merchant Personal Data, Kitchn will — unless legally prohibited — promptly notify Merchant and reasonably cooperate with lawful efforts by Merchant to limit or challenge the demand. Kitchn may disclose Merchant Personal Data where required by law, limited to what is legally required.
12. De-identified and Aggregated Data
Kitchn may create and use de-identified and aggregated data as described in Section 6.5 of the Privacy Policy. Where Kitchn receives or creates de-identified data, it will maintain and use it only in de-identified form, will not attempt to re-identify it except as permitted by Applicable Data Protection Law to test the effectiveness of de-identification, and will contractually require the same of recipients.
13. Liability and Order of Precedence
This DPA does not create remedies or liabilities beyond those in the Agreement. Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations in Section 29 of the Agreement, and all such liability counts toward — and does not stack on top of — the caps stated there. In case of conflict among documents, the order of precedence in Section 4 of the Agreement applies.
14. Term, Changes, and Contact
14.1 Term. This DPA is effective for as long as Kitchn processes Merchant Personal Data under the Agreement and, with respect to retained records, until deletion under Section 8.
14.2 Changes. Kitchn may update this DPA as reasonably necessary to reflect changes in law, the Services, or Subprocessors, following the change process in Section 36 of the Agreement. Updates will not materially reduce the protections of this DPA during a current Subscription Term without Merchant's consent.
14.3 Contact. Questions, objections, audit requests, and notices under this DPA: info@orderkitchn.com, subject line "Privacy Request" (or "Security" for Security Incident matters). A countersigned copy of this DPA is available on request.
Annex I: Details of Processing
| Item | Description |
|---|---|
| Subject matter | Kitchn's provision of the multi-tenant restaurant commerce platform described in the Agreement — branded online-ordering storefronts, the operator dashboard, order processing, payments orchestration, POS and delivery integrations, marketing dispatch, loyalty, gift cards, and reporting. |
| Duration | The Subscription Term, plus the export and deletion periods in Section 8 of this DPA. |
| Nature and purpose | Hosting, storage, transmission, display, organization, analysis, and deletion of Merchant Personal Data as needed to operate Merchant's storefront, receive and route Orders, process payments through the Payment Processor, synchronize with Merchant's connected POS, dispatch delivery, send Merchant-directed communications, operate loyalty/gift-card/promotion features Merchant enables, and produce Merchant's reports. |
| Categories of data subjects | Merchant's Diners, customers, and guests; Merchant's marketing subscribers and loyalty members; Merchant's staff and authorized users; participants in group orders and catering inquiries. |
| Types of personal data | Identity and contact data (name, email, phone, addresses); account credentials (hashed) and authentication records; order contents, transaction history, taxes, tips, and fulfillment details; delivery addresses and instructions; payment tokens and non-sensitive card descriptors (no card numbers or security codes); loyalty, gift card, referral, and promotion activity; marketing preferences, suppression records, and email engagement; reviews and other submissions; staff roles and order-attribution identifiers; device, log, and usage data. |
| Sensitive data | Only dietary, allergen, or religious-observance information a Diner voluntarily includes in order notes or catering inquiries, processed as described in Section 10 of this DPA. No government identifiers, precise geolocation, biometric, or payment card data. |
Annex II: Security Measures
Kitchn maintains the following measures, consistent with Section 12 of the Privacy Policy:
- Encryption — TLS for data in transit; encryption at rest for production data stores holding personal information.
- Access control — role-based and resource-based authorization enforced server-side; least-privilege identity and access management; multi-factor authentication available for supported account types; credentials and secrets in managed secret stores rather than source code.
- Tenant isolation — logical separation of each merchant's data enforced in the application layer and reinforced at the data layer; per-tenant identity pools and token audiences.
- Session security —
HttpOnly,Securecookies with same-site restrictions; short-lived access tokens; token revocation; login-attempt lockouts. - Network and edge protection — private subnets with no direct public database exposure; a web application firewall in front of the production API; rate limiting; bot and abuse protections.
- Payment isolation — no cardholder data on Kitchn systems; payment card entry through the Payment Processor's hosted fields (PCI DSS Level 1 processor).
- Monitoring and logging — structured logging, audit trails for privileged actions, alerting, and log archival.
- Resilience — automated backups; high-availability multi-availability-zone deployment for production databases; recovery procedures.
- Personnel and vendors — confidentiality obligations and role-appropriate security training; written data protection terms with Subprocessors.
- Incident response — a maintained incident response plan and the notification commitments in Section 7 of this DPA.
Annex III: Subprocessors
Kitchn engages the following Subprocessors to process Merchant Personal Data. Providers Merchant separately elects to connect (POS Providers, Delivery Providers, the Payment Processor acting under Merchant's Stripe agreements) act at Merchant's direction per Section 5.3.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, databases, storage, CDN, identity, email delivery (SES), queuing, serverless compute, logging | United States |
| Stripe, Inc. | Payment processing, billing, and payout infrastructure engaged by Kitchn as platform | United States |
| Google LLC | Sign-in with Google; Maps, Places, geocoding, and address validation | United States |
| Apple Inc. / Google LLC | Push notification delivery, where mobile applications are offered | United States |
Kitchn will update this Annex and provide notice as described in Section 5.2 before adding or replacing Subprocessors.