This Data Processing Addendum (“DPA”) forms part of the Merchant SaaS Terms between TECHSTRIDE S.A. de C.V. (Striq) and the Merchant. For personal data that the Merchant determines to submit through the service, the Merchant is the controller (or equivalent responsible party) and Striq is the processor or service provider. For data Striq controls for its own account, security, support, billing, and website purposes, Striq acts as controller under the Privacy Notice.
Striq will process Merchant-controlled personal data only to provide, secure, maintain, and support the contracted service, follow the Merchant’s documented instructions, and comply with applicable law. Service improvement that uses Merchant-controlled personal data will occur only under documented instructions or after the information has been aggregated or de-identified so it is no longer personal data. The Merchant must ensure that its instructions are lawful and that it has provided required notices and obtained required permissions. Striq will tell the Merchant if it reasonably believes an instruction violates applicable data-protection law.
Striq will require personnel and contractors with access to Merchant-controlled personal data to maintain confidentiality. Striq will maintain reasonable technical and organizational measures appropriate to the risk, including access controls, least-privilege practices, encrypted transport, logging, backup and recovery measures, vulnerability and incident processes, and appropriate staff training.
The Merchant authorizes Striq to use subprocessors needed for the service, including hosting, database, authentication, billing, email, monitoring, and support providers. Striq remains responsible for its subprocessors’ processing under this DPA, will impose materially protective obligations, and will provide information about relevant subprocessors upon reasonable request. Processing may take place internationally with safeguards required by applicable law.
Considering the nature of the service, Striq will provide reasonable assistance for the Merchant to respond to access, rectification, cancellation, opposition, deletion, portability, or similar requests. The Merchant is responsible for receiving and deciding requests as controller. If a request reaches Striq directly, Striq may identify and refer it to the Merchant, verify identity where appropriate, and assist without making an independent promise about the outcome or a fixed deadline.
Striq will notify the Merchant without undue delay after confirming a security incident involving Merchant-controlled personal data, subject to legal and security constraints. The notice will include reasonably available information about the incident and response. The parties will cooperate on investigation, containment, remediation, legally required notices, and reasonable evidence preservation.
During the service, Striq will provide the export or access functions included in the plan or reasonably needed for the Merchant to retrieve its data. On termination, Striq will follow the Merchant’s documented instruction to return or delete Merchant-controlled personal data, subject to legal retention, security backups, dispute preservation, and technical cycles. Data in backups may remain protected until the normal backup rotation.
On reasonable written request and no more than once per year unless an incident or regulator requires otherwise, Striq will provide information reasonably needed to demonstrate compliance with this DPA, such as security summaries or available audit materials. An audit must protect confidentiality, avoid disruption, and not expose another customer’s data or security-sensitive details.
The Merchant must use role-based access, protect credentials, give lawful instructions, minimize data, avoid placing sensitive personal information in free-text fields, maintain accurate menus and notices, and respond to guest requests and complaints about the restaurant’s food and services. The Merchant is responsible for its own controller duties and for the legality and accuracy of data it submits.
Subject matter: providing restaurant ordering, menu, pickup, receipt, staff, analytics, and account-support software. Duration: the term of the Merchant service plus limited retention and backup periods described in the Privacy Notice and this DPA.
If this DPA conflicts with the Merchant SaaS Terms about processing of Merchant-controlled personal data, this DPA controls. This DPA is version 1.0 and effective from August 16, 2026. Questions can be sent to contact@striq.net.
TECHSTRIDE S.A. de C.V. ("Striq").