Data Processing Agreement
Last updated: 2026-07-04
This Data Processing Agreement (DPA) forms part of the agreement between Brewmargin ("Processor") and the customer business ("Controller") and governs the Processor's processing of personal data on the Controller's behalf under Article 28 GDPR. Where the Controller and Processor have signed a negotiated DPA, that signed version prevails over this page.
Signed and countersigned copies of this DPA, including negotiated terms, are executed as part of Enterprise agreements. If you need a signed DPA, contact us.
1. Subject matter and duration
The Processor processes personal data to provide invoice-based costing, margin and pricing analytics for the Controller's business. Processing lasts for the term of the service agreement and the retention periods in our Privacy Policy, after which data is deleted or returned.
2. Nature and purpose
Receiving and storing supplier invoices forwarded or uploaded by the Controller; extracting their line items (including via the AI sub-processor below); maintaining ingredient price history, recipes and margins; importing menu items and sales volumes from a point-of-sale account the Controller connects; and generating dashboards, reports and pricing suggestions for the Controller.
3. Categories of data and data subjects
Data subjects: the Controller's own users of the dashboard (owners and invited team members), and individuals whose details appear incidentally on supplier invoices (such as a supplier representative's name or business contact details). Data: names and email addresses of the Controller's users; one-way hashed IP addresses; business contact details appearing on invoice documents; menu and sales data from a connected till. No special-category data is expected — the Controller agrees not to submit documents containing it.
4. Controller and Processor obligations
The Processor processes personal data only on documented instructions from the Controller; ensures persons authorised to process are bound by confidentiality; implements the technical and organisational measures in Section 6; assists the Controller with data-subject requests and with its obligations under Articles 32–36; and, at the Controller's choice, deletes or returns the data at the end of processing.
5. Sub-processors
The Controller authorises the Processor to engage the sub-processors below. We give notice of intended changes so the Controller may object. Each is bound by data-protection terms no less protective than this DPA.
| Sub-processor | Purpose | Location / safeguard |
|---|---|---|
| Hetzner Online GmbH | Hosting & database infrastructure | Germany / Finland (EU) |
| Cloudflare, Inc. | DNS, CDN & network edge | Global edge; EU SCCs + Data Processing Addendum |
| Anthropic, PBC | AI extraction of invoice line items | USA; SCCs — API data is not used for model training |
| Stripe Payments Europe, Ltd. | Payment processing (paid plans) | Ireland (EU); engaged when card billing is enabled |
| Resend, Inc. | Outbound transactional email | USA; SCCs |
| ActiveCampaign, LLC (Postmark) | Inbound email receiving for forwarded invoices | USA; SCCs |
Square and SumUp are not sub-processors: the Controller connects them directly and they process till data as independent controllers under their own terms.
6. Security measures (Article 32)
Encryption of data in transit (TLS); connected-service credentials and two-factor secrets sealed at rest with authenticated encryption; passwords stored only as Argon2id hashes; raw IP addresses hashed, never stored; strict per-organisation tenant isolation so a customer only ever sees its own data; least-privilege team roles; an origin exposing no public web ports; encrypted off-site backups with keys held outside the infrastructure; and append-only audit logging. Full detail is on our security page.
7. International transfers
Personal data is stored in the EU. Where a sub-processor processes data outside the EEA, transfers rely on Standard Contractual Clauses or an adequacy decision.
8. Breach notification and audits
The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach (see our Privacy Policy) and makes available the information necessary to demonstrate compliance with Article 28.
To request a signed copy of this DPA, contact [email protected].