Between
The Customer, a restaurant or food service venue holding an ARDOIZA account, identified by the information in its customer area, hereinafter “the Controller”,
and
ARDOIZA, the trading name under which the Service is operated by Mr Hamar Azzi, sole trader (entrepreneur individuel, EI), SIREN 511 435 885, SIRET 511 435 885 00021, registered with the Registre national des entreprises (French National Business Register), 4 place Victor Basch, 30400 Villeneuve-lès-Avignon, France, hereinafter “the Processor”.
This agreement is accepted by the Customer at the same time as the Terms of Sale, when its account is created. This acceptance is timestamped.
Article 1. Purpose
This agreement sets out the conditions under which the Processor processes, on behalf of and on the instructions of the Controller, the personal data of the Controller's end customers (people who visit its website, view its menu, order, book a table, or buy, receive or use a gift card through the Service), hereinafter “the Data”.
It applies when the Processor itself hosts the Data, that is to say for the Plans that include a Hosted Website, served at an address on the my-ardoiza.fr domain or, in the Pro Plan, at a domain name of the Controller connected to that website: the Processor then hosts the Controller's website, its database of orders, bookings and end customers, and the technical logs of its visitors. It also applies, whatever the Plan, to the booking requests received through the Controller's Menu Page (My menu section of the customer area, address on the carte.ardoiza.fr domain), which the Processor stores on its infrastructure on behalf of the Controller. It further applies, in the Basic, Essential and Pro Plans, to the Gift Cards that the Controller sells through the Gift Cards Module (article 23 of the Terms of Sale), whose data the Processor stores on its infrastructure on behalf of the Controller, including during the continued access provided for in article 23.8 of the Terms of Sale. It likewise applies, in the Basic, Essential and Pro Plans, to the data processed by the Reviews Module when the Controller has switched it on (article 24 of the Terms of Sale). When the Customer uses the Plugins on its own WordPress website, with its own hosting provider, the Data stays on that website: the Processor has no access to it, and this agreement only applies to support interventions that the Customer requests in writing and that require the Processor to access it.
It does not apply to data relating to the Customer itself (account, billing, support), for which ARDOIZA is the controller and which is covered by the Privacy Policy.
Article 2. Description of the processing
The description of the processing (nature, purposes, categories of data and of data subjects, duration) is set out in Annex 1.
Article 3. Obligations of the Processor
The Processor undertakes to:
3.1. Process the Data solely for the purposes described in Annex 1 and in accordance with the documented instructions of the Controller. The Terms of Sale, this agreement, the Customer's configuration of the Service (services switched on, consent texts) and the Customer's written requests constitute these instructions. If the Processor considers that an instruction infringes the GDPR or the applicable law, it informs the Controller immediately.
3.2. Not use the Data for its own purposes, and not transfer it, rent it out or exploit it for commercial purposes, identifying statistics, profiling or model training. The statistics made available to the Customer in its area (turnover, number of orders, best-selling products) are produced for the Customer alone.
3.3. Guarantee the confidentiality of the Data: only the Processor's authorised staff, bound by a contractual obligation of confidentiality, have access to it, to the extent strictly necessary for the operation, support and security of the Service.
3.4. Implement the technical and organisational measures described in Annex 2 in order to ensure a level of security appropriate to the risk (Article 32 of the GDPR), and develop them in line with the state of the art without reducing their overall level.
3.5. Taking into account the nature of the processing, assist the Controller in responding to requests from data subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection). To this end, the Service provides the Customer, in its website dashboard, with: searching for an end customer by name, email address or telephone number, viewing their orders and bookings, exporting their record and bookings, rectifying their contact details, erasing or anonymising their record and history, and the status of their consents; with the Ardoiza Clients plugin, importing a customer list from a file, with a preview before the import and the cancellation of the last import, and the immediate erasure of the imported line of a person, found by their email address or phone number. For Gift Cards, the Gift cards section of the customer area allows the Customer to view a card's record and history, to correct the Recipient's email address and to export the data; early erasure of a Buyer's or a Recipient's data, which is not offered on a self-service basis, is carried out by the Processor on written request from the Controller, within thirty (30) days. Exports that are not yet available on a self-service basis are provided by the Processor on written request, under the conditions of article 13.2 of the Terms of Sale. If a data subject contacts the Processor directly, the Processor forwards the request to the Controller within five (5) working days and does not reply in its place, unless instructed otherwise.
3.6. Assist the Controller in complying with its obligations relating to security, notification of breaches and, where applicable, data protection impact assessments and prior consultation of the CNIL (Commission nationale de l'informatique et des libertés, the French data protection authority), by providing the information available to it.
3.7. Notify the Controller of any Data breach (destruction, loss, alteration, disclosure or unauthorised access) as soon as possible and at the latest forty-eight (48) hours after becoming aware of it, by email to the account address, stating, as far as possible: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. The information may be provided in stages. The Processor does not inform the CNIL or the data subjects in place of the Controller, unless the Controller agrees or the law requires it.
3.8. Keep a record of the categories of processing activities carried out on behalf of its customers (Article 30.2 of the GDPR).
3.9. Process the Data only on servers located in the European Union, in France, subject to the sub-processors listed in Annex 3 and the safeguards stated there.
Article 4. Sub-processors
4.1. The Controller gives the Processor general authorisation to use the sub-processors listed in Annex 3 for the operations described there.
4.2. The Processor informs the Controller of any intended addition or replacement of a sub-processor, by a message in the customer area and by email, at least thirty (30) days before it takes effect. The Controller may object in writing to [email protected] within that period, on legitimate grounds. In the event of an objection and failing an acceptable solution, either party may terminate the contract free of charge before the change takes effect.
4.3. The Processor imposes on each sub-processor, by contract, data protection obligations equivalent to those of this agreement and remains fully liable to the Controller for the performance of their obligations.
Article 5. Transfers outside the European Union
The Processor does not transfer the Data outside the European Union, except in the cases described in Annex 3: relaying of network traffic by Cloudflare and, where the Turnstile anti-bot check is switched on for the Menu Page's booking request form or gift card purchase form, or for the Reviews Module feedback form, verification by Cloudflare of the end customer's token, IP address and browser signals; online payment by Stripe, where the Customer has switched on online payment or the Gift Cards Module; delivery of the Mobile App's notifications by Expo and then by Apple or by Google (Firebase Cloud Messaging). These transfers are governed by the safeguards stated in Annex 3 for each provider (the European Commission's standard contractual clauses, Commission Implementing Decision (EU) 2021/914, or, for Expo, the EU-U.S. Data Privacy Framework), supplemented by encryption in transit and data minimisation. Any new transfer is subject to the procedure in article 4.2.
Article 6. Obligations of the Controller
The Controller undertakes to:
6.1. Provide data subjects with the information required by Articles 13 and 14 of the GDPR, by means of the texts displayed in the ordering and booking process, which it can customise in its area, and of the terms of sale of Gift Cards, and of its own privacy policy. When it imports into the Service a customer list compiled outside it, it makes sure it may lawfully use it for the purposes of the Service and informs the data subjects of it, at the latest when it first communicates with them.
6.2. Have a legal basis for each processing operation, and obtain separate, freely given and revocable consent for any direct marketing to its end customers (Article L34-5 of the Code des postes et des communications électroniques, French Postal and Electronic Communications Code). For this purpose, the Service offers a separate, unticked marketing consent box. An indication of agreement contained in an imported file is never recorded as consent by the Service: if the Controller intends to rely on it, it keeps the evidence itself.
6.3. Collect through the Service only the data needed for bookings, orders, Gift Cards and the Reviews Module, and not enter any sensitive data within the meaning of Article 9 of the GDPR (end customers' free-text comments, for example about allergies, are handled by the Customer under its own responsibility and must not be kept longer than necessary).
6.4. Define and apply its retention periods, using the anonymisation and record erasure available in its website dashboard and, from its version 0.10.2, the retention setting of the Ardoiza Clients plugin (a period of one (1) to five (5) years without a booking or order, never longer on a Hosted Website than the period stated in its legal notice; automatic anonymisation or deletion, or a proposal only), and respond to requests to exercise rights.
6.5. Keep its record of processing activities (Article 30.1 of the GDPR), into which this agreement and Annex 1 may be transferred.
6.6. Secure its own access (strong password, two-factor authentication, updating its WordPress website, protection of the devices used in the dining room and in the kitchen).
Article 7. Audit and documentation
7.1. The Processor makes available to the Controller the information needed to demonstrate compliance with this agreement: this agreement and its annexes, the description of the security measures, the list of sub-processors, proof of hosting and, on written request, answers to a reasonable security questionnaire, within thirty (30) days.
7.2. The Controller may, no more than once a year and with thirty (30) days' notice, have an audit carried out at its own expense, by itself or by an independent third party bound by confidentiality, covering compliance with this agreement. The audit takes place during business hours, without disrupting the Service or compromising the security and confidentiality of the data of the Processor's other customers. Audit reports are confidential. If a breach is found, the Processor remedies it within a reasonable time.
Article 8. Return and deletion of the Data at the end of the contract
8.1. Throughout the term of the contract and for thirty (30) days after it ends, whatever the reason, the Controller can obtain all the Data in a structured, commonly used and machine-readable format, through the exports in its website dashboard and the full copy of its Hosted Website (Copies of my website page of its customer area) or, for what cannot yet be exported on a self-service basis, on written request to the Processor, in accordance with article 13 of the Terms of Sale.
8.2. At the end of that period, or on earlier written request from the Controller, the Processor deletes the Data from its production systems, then from the backups by rotation within a maximum of ninety (90) days, and destroys existing copies, unless there is a legal obligation to retain them. On request, the Processor confirms the deletion in writing.
8.3. Before deleting a Hosted Website, the Processor makes a full copy of the website, which the Controller downloads from its customer area (Copies of my website page) for thirty (30) days after deletion, under the conditions of article 13.6 of the Terms of Sale. If the export cannot be made, the website is not deleted until the export has succeeded. This export is deleted thirty (30) days after the website is deleted, then from the backups when they are rotated.
8.4. For Gift Card data, the periods in articles 8.1 and 8.2 run from the end of the continued access provided for in article 23.8 of the Terms of Sale, which lasts until the latest of the expiry dates of the Gift Cards sold; during this access, this data remains stored and only the Gift cards section remains open to the Controller. Where this access cannot be maintained, the Processor hands over to the Controller, before deleting the Data, the export provided for in that article, codes included.
Article 9. Liability
Each party is liable for damage caused by processing carried out in breach of the GDPR, under the conditions of Article 82 of the GDPR. The Processor's liability to the Controller under this agreement is subject to the limitations in article 16 of the Terms of Sale, except with regard to administrative fines imposed on the Controller solely as a result of a breach by the Processor of its own obligations.
Article 10. Term and order of precedence
This agreement applies throughout the term of the contract and for as long as the Processor holds Data. In the event of a conflict between the Terms of Sale and this agreement, this agreement prevails as regards the processing of the Data. This agreement is governed by French law; article 21 of the Terms of Sale applies to disputes.
Contact for any question about this agreement: [email protected].
Annex 1. Description of the processing
| Item | Description |
|---|---|
| Subject matter | Hosting of the Controller's website (Hosted Website) and provision of an online menu, table booking and online ordering (Click & Collect) service, including the Menu Page (My menu section of the customer area, carte.ardoiza.fr address) and its booking requests, whatever the Plan; sale, sending and redemption of the Controller's Gift Cards (Gift Cards Module, Basic, Essential and Pro Plans); sending, on behalf of the Controller, of a feedback request email after a confirmed booking request of the Menu Page, receipt and storage of the feedback (Reviews Module, Basic, Essential and Pro Plans) |
| Nature of the operations | Hosting of the website and its database, technical logging of visits, collection through the Service's forms, recording, transmission to the Controller (customer area, plugins, notifications), sending confirmation, reminder and cancellation emails to data subjects, issue, sending, redemption, refund and expiry of Gift Cards, keeping of their history, consultation, export, erasure, anonymisation, backup, import of customer files provided by the Controller (Ardoiza Clients plugin), keeping of a list of fingerprints of erased end customers so that a new import does not recreate them, sending of the Reviews Module feedback requests, recording of feedback, reply of the Controller by email, keeping of the objection list as a fingerprint |
| Purposes | Receiving and following up bookings and orders, communicating with end customers about their booking or order, history and statistics for the Controller, management of promotions and promo codes, management of the marketing consents obtained by the Controller; sale and redemption of Gift Cards, informing the Buyer and the Recipient (receipt, sending of the card, balance after each use, reminder before the expiry date), handling withdrawals and refunds, keeping the history for the Controller's accounts; collecting end customers' satisfaction after a booking, for the Controller only (no publication) |
| Categories of data subjects | Visitors to the Hosted Website; the Controller's end customers: people who book or order, including through a booking request sent from the Menu Page, and, where applicable, people designated to collect the order; Buyers and Recipients of Gift Cards; end customers whose contact details the Controller imports from a file; for the Reviews Module, end customers who sent a booking request confirmed through the Menu Page |
| Categories of data | Identity (surname, first name), contact details (email address, telephone number), content of the order (products, options, amounts, collection time, chosen payment method), booking (date, time, number of guests, preferred seating indoors or on the terrace, optional, comments), consents and their timestamps, IP address and timestamp of the order (security and proof), technical data on visits to the Hosted Website in the server logs (IP address, date and time, page requested, browser); Menu Page booking request (name, telephone number, email address, date, time, number of guests, preferred seating (indoors or terrace, optional), message; no IP address recorded with the request); where the Controller has switched on online payment for orders or the booking deposit, technical payment identifiers sent by Stripe (session, payment and refund identifiers, amounts, status; never the card number or the cardholder's name); Gift Cards: name and email address of the Buyer, name and email address of the Recipient, message (three hundred (300) characters at most), sending date chosen, language, amount, balance, expiry date, code kept in encrypted form and in the form of a fingerprint, history of movements (amount, date, author, venue, note from the Controller), technical payment and refund identifiers sent by Stripe; no IP address recorded with the card; imported customers: name, email address, phone number, answer contained in the file about agreeing to receive marketing (displayed, never recorded as consent), date and batch of the import; erased customers: fingerprint of the email address or, failing that, of the phone number, protected by a key specific to the website, which does not allow the address to be retrieved, and date of erasure; Reviews Module: end customer's name and email address (received with the booking request), date of the meal, language, rating from one (1) to five (5), optional comment (one thousand (1,000) characters at most), reply of the Controller, fingerprint of the email address (sending cap and objection list); no IP address recorded with the feedback |
| Sensitive data | None by design. Free-text comments may contain information about allergies: the Controller is responsible for managing it. The Reviews Module feedback form asks not to write any health information in it |
| Duration of the processing | Term of the contract, then thirty (30) days for export, then deletion in accordance with article 8 |
| Retention periods for the Data | Set by the Controller. The Service keeps the history of bookings and orders for the term of the contract, unless the Controller sets otherwise. With the Ardoiza Clients plugin, from its version 0.10.2, records of customers with no booking or order for the period the Controller chooses (from one (1) to five (5) years, three (3) years by default; on a Hosted Website, the period stated in its legal notice by default and at most) are anonymised every day, or deleted, or only proposed, according to its setting; until the Controller has saved an automatic setting, they are only proposed, and processed at its request. On deletion, only monthly totals without personal data are kept, and a record linked to a payment dispute is anonymised rather than deleted. Record-by-record anonymisation and erasure remain available at any time. Booking requests received through the Menu Page are deleted automatically ninety (90) days after the requested date. Gift Cards, according to the instruction that the Controller gives by switching on the Gift Cards Module: purchase abandoned before the payment is confirmed deleted thirty (30) days later; message deleted on the card's expiry date, or as soon as the card is refunded or cancelled; names and email addresses of the Buyer and the Recipient deleted three (3) years after the expiry date, or after the card is refunded or cancelled; history of movements, without any name or address, kept for as long as the account exists, for ten (10) years at most, then handed over to the Controller under the conditions of article 8.4. Imported customers: same rules as the records, the import date standing for the last activity of a customer with no booking or order; fingerprints of erased customers: deleted three (3) years after the record was erased, and at the latest when the Ardoiza Clients plugin is deleted from the Hosted Website, unless its administrator chose to keep its data, ten thousand (10,000) at most. Reviews Module, as instructed by the Controller when switching the module on: link valid for thirty (30) days; without feedback, name and email address erased when it expires; email address of a customer who answered erased ninety (90) days after the feedback; feedback and name erased thirteen (13) months after sending; objection list, as a fingerprint, kept as long as the account exists |
| Place of processing | France (OVH SAS production server, Gravelines data centre), subject to Annex 3 |
| Mobile app | The Controller's ARDOIZA Pro app receives its orders and bookings. The notification announcing an event on its device contains no end customer identification Data: only the type of event (new order, booking request, item already handled), the order or booking number assigned by the website, its technical identifier, the date and time of collection or of the table, the number of items or guests, the number of items pending and the website address. The details of the order or booking are only read by the app, on the Controller's website, after login (see Annex 3). After login, the app also allows a Gift Card to be looked up and redeemed, showing its balance, its expiry date, the Recipient's name and the Buyer's name; the sale of a Gift Card is announced to the Controller by email, never by an app notification |
Annex 2. Technical and organisational security measures
This annex describes the measures in place as at the date of this version, then the commitments not yet fulfilled, each with its deadline. The Service has been open to the public since 29 September 2026 on a production server hosted in France by OVH SAS (Gravelines data centre); the payment provider has been connected in live mode since 23 September 2026, for subscriptions as well as for online payment of orders and booking deposits (Stripe Connect). This annex is republished, with its date, whenever these measures change, and at the latest when a commitment listed at the end of this annex is fulfilled. The measures are reviewed at least once a year.
Measures in place as at the date of this version
Hosting and access to the infrastructure
- Production server hosted in France by OVH SAS, in its Gravelines data centre, since 29 September 2026; the physical security of that data centre (access control, power, cooling) is the hosting provider's responsibility. No more customer data on the development server, which is reserved for the team's internal tests. Proof of hosting (operator, data centre) provided to customers on simple request.
- Administrative access to the server reserved for the founders, by individual SSH key, without password, from the team's IP addresses only; direct login as administrator refused, attempts limited, logins and administration commands logged.
- Host firewall closed to all incoming traffic other than the administrative access above; the web services only accept traffic relayed by the delivery network (address ranges published by Cloudflare) and, for the team's checks, its own addresses; these rules are applied before the services start, at every reboot. The server presents to the delivery network an origin certificate issued by it.
- The administration console is a service separate from the customer area, permanently filtered by address.
- Hosted Websites: the WordPress cluster that serves them is isolated from the other services on separate internal networks; the service that creates, suspends and deletes websites can only be reached on an internal network, through signed and timestamped requests.
- Hosted Websites: the code of WordPress, the theme and the plugins is read-only; the media folder is not executable (checked on 21 September 2026); installing plugins or themes, editing code and command execution functions are disabled; the types of files uploaded are restricted.
- Hosted Websites: the WordPress login page is closed to the public. The restaurant owner has no WordPress password: they log in through a signed, single-use link, valid for two (2) minutes, issued from their customer area after a recent verification code, with a role limited to managing their content, orders, bookings and customers. A website cannot see the data of other websites.
Encryption
- Encrypted communications (TLS) between the visitor and the delivery network, then between the network and the server; HSTS header.
- Passwords hashed with Argon2id; security tokens stored as SHA-256 hashes; assistant IP addresses hashed with a secret.
- Licence keys and two-factor authentication secrets encrypted at rest (AES-256-GCM), with keys kept outside the database; licence interface responses signed.
- Backups encrypted with a public key (OpenPGP) whose private key is not on the server: the server cannot read back its own backups (checked on 20 September 2026).
Access control and authentication
- Authentication by email address and password (at least 12 characters, common passwords and passwords known from data leaks refused), one-time code by email for an unusual login without two-factor authentication, TOTP two-factor authentication with backup codes, trusted devices limited to thirty (30) days.
- Revocable server-side sessions of thirty (30) days at most, HttpOnly, Secure and SameSite cookies with the “__Host-” prefix; all sessions closed when the password is changed, and closure by the Customer, from the Security section, of any session open on another browser.
- A single Manager role per customer account; the ARDOIZA administration console is reserved for the founders, with mandatory two-factor authentication, time-limited invitations, IP address restriction and an audit log of every action.
- No viewing of passwords by the team; no secrets in the code, logs or documentation.
Separation and integrity of the application
- Strict isolation of data between accounts: every resource is loaded by identifier and by account; automated separation tests, run by the team before each release.
- Parameterised queries, systematic output escaping, security headers (strict CSP on the customer area; on Hosted Websites, a baseline CSP, with the strict policy for their public pages first applied in report-only mode; X-Content-Type-Options, Referrer-Policy, frame-ancestors 'none', or 'self' for pages shown as a preview within a page of the same origin: customisation of Hosted Websites, menu preview in the customer area), CSRF protection.
- Rate limiting on authentication, sign-up, password reset, licence checking, order creation and the assistant.
- Cloudflare Turnstile anti-bot check on the sign-up form, on the “Get some help” form, on the booking request form and gift card purchase form of the Menu Pages and, when the Reviews Module is switched on, on its feedback form (Annex 3); it has been switched on since 1 October 2026.
- Prices and content of orders fixed at confirmation; timestamped log of status changes.
- Gift Cards, since 1 October 2026: sixteen (16) character code drawn at random (80 bits), kept in the form of an HMAC-SHA-256 fingerprint, for lookups, and encrypted with AES-256-GCM, for resending the email and for the printable page, using two keys specific to these uses, derived from server keys kept outside the database; code never written in clear text in a log, a logged address or an event; constant-time comparison; searches limited to ten (10) per minute per device or session, and an account's searches blocked for fifteen (15) minutes after twenty (20) unknown codes in one hour, with an alert to the team; append-only history of movements, the database refusing any change to or deletion of a movement; idempotency key for each redemption; no name or email address in the logs.
- Import of customer files (Ardoiza Clients plugin): restricted to the website administrators, file of two (2) MB and five thousand (5,000) lines at most, preview kept thirty (30) minutes at most in a temporary storage specific to the administrator, then deleted, cancellation of the last import; erased customers: only a fingerprint of the email address or phone number, protected by a secret key specific to the website (HMAC-SHA-256), which does not allow the address to be retrieved, is kept, never the address in clear text, and it is deleted three (3) years after the erasure.
- Reviews Module: link signed by HMAC with a key derived from the Service lookup key, compared in constant time, valid for thirty (30) days; rate limits, honeypot field and delay token on the public form; no IP address recorded with the feedback; objection list as a fingerprint computed with a secret key; logs without address, rating or comment.
- WordPress plugins: pairing by a revocable licence key with limited scope, no password ever stored in WordPress; security review (escaping, nonces, capabilities) carried out by the team before each release.
Payment data
- No bank card data entered, sent or stored by ARDOIZA; the payment provider's forms and portal (PCI DSS compliance ensured by the provider). Since 23 September 2026, this provider has been connected in live mode, for subscriptions and for online payment of orders and booking deposits.
- Online payment for orders and booking deposit, open since 23 September 2026, and payment for Gift Cards, open since 1 October 2026: payment pages created on the Customer's Stripe account with ARDOIZA's restricted platform key, kept on its own servers only (customer area and administration console); no key to the Customer's account stored by ARDOIZA or by the Plugins.
Backup, updates and continuity
- Encrypted nightly backup of the databases (customer area, console, Hosted Websites database) and files (Hosted Websites' media, exports made before a website is deleted), kept on the server for fourteen (14) days for the databases and seven (7) days for the files.
- Copy of the backups off the server, every night since 25 September 2026, encrypted before leaving it, on OVH object storage located in France (Roubaix), databases, files and Hosted Websites' media included; versioned storage, locked against any deletion for fourteen (14) days, with a lifecycle rule that deletes each copy no later than ninety (90) days after it is written, checked and recorded on 24 and 28 September 2026; presence of the day's copy checked every morning from a host outside the server.
- Restore test carried out on 20 September 2026, with a written report: archive decrypted off the server, integrity of the databases checked; full restoration of the databases and files from the encrypted backups repeated on 24 September 2026 on the production server, then blank, and recorded.
- Security updates of the Hosted Websites handled by ARDOIZA, WordPress automatic updates being disabled, following a written procedure. Two instances serve the websites and are replaced one after the other: a real update was carried out in this way on 21 September 2026 on the development server, with no interruption observed (70 check requests during the operation, 70 normal responses), and a WordPress security release was applied in the same way on the production server on 29 September 2026, with no interruption observed. Automatic rollback to the previous version was deliberately tried on the production server on 24 September 2026: induced failure detected, previous instance put back into service in seventy-four (74) seconds, test recorded. Updating the database and restarting the server cause a brief interruption, carried out at night.
- Operating system security updates applied automatically every day; nightly watch on security releases (WordPress, software images, operating system) with email alerts to the team; written update policy: WordPress security release applied within forty-eight (48) hours, other critical security fix within seven (7) days.
- Menu stored in the database of the WordPress website that runs the plugins: its display depends neither on the customer area nor on the licence interface.
- Alert to the team on the server's disk space; technical log of errors, payments and outgoing calls reviewed by the team; maintenance outside service times as far as possible.
Logging and detection
- Access logs and audit log of sensitive actions, with no password, token, login link or key.
- Retention of the audit log (logins included) for twelve (12) months at most, then automatic deletion, except for entries kept as evidence for the period set by the Privacy Policy (article 4); the Hosted Websites' access logs are rotated every night and deleted no later than twelve (12) months after they are written, with a daily check; the customer area's technical logs (access and errors) are rotated by volume, their deletion by age being among the commitments listed at the end of this annex.
- Availability probe installed on 24 September 2026 outside the production server's data centre, which checks every five (5) minutes the customer area, the ardoiza.fr website, a Menu Page and a Hosted Website, alerts by email after two consecutive failures and monitors certificate expiry; heartbeat of the scheduled tasks and of the firewall sent to a third-party monitoring service, outside the hosting provider, which alerts when it falls silent; status of the services checked every five (5) minutes in the administration console.
- Authentication of the Service's emails by SPF, DKIM and DMARC, DKIM having been active since 22 September 2026.
- Vulnerability reporting address: [email protected], published in the file https://ardoiza.fr/.well-known/security.txt.
Organisation
- Team limited to the founders, each bound by confidentiality; awareness of good practice in security and data protection.
- Written procedure for incident management and breach notification (article 3.7), kept since 20 September 2026.
- Record of the categories of processing carried out on behalf of customers, kept since 20 September 2026.
- Deletion and anonymisation tools in the website dashboard, record by record; end-of-contract procedure (article 8).
Commitments not fulfilled as at the date of this version
The following measures are not in place, or not yet checked and recorded, as at the date of this version. Each is a commitment by ARDOIZA, with the deadline stated; this annex is republished, with its date, when a measure is fulfilled.
- Penetration test carried out by a third party, with vulnerabilities fixed: before 31 December 2026, then at least once a year and after any major change to the architecture.
- Professional liability insurance (article 18 of the Terms of Sale): as soon as it is taken out, announced by a new version of this annex.
- Strict verification, by the delivery network, of the origin certificate presented by the server, on all of the Service's domain names, recorded: before 31 December 2026.
- Filtering of outgoing connections from the Hosted Websites cluster at server level (licence interface, email, delivery network and, for the import of a menu at the Customer's request, reading of its former GloriaFood menu; nothing else): before 31 December 2026.
- Restoration of a single Hosted Website tried on a blank machine, with a written report, then restore tested at least once a quarter, with a written report, including a full restoration on a blank machine: first test before 31 December 2026.
- Check of the security advisories of software dependencies at each release: before 31 December 2026.
- Deletion by age (twelve (12) months at most) of the customer area's technical logs (access and errors): before 31 December 2026.
- Strict content security policy (CSP) enforced, and no longer only reported, on the public pages of the Hosted Websites: before 31 December 2026.
Annex 3. Authorised sub-processors
| Sub-processor | Operations concerning the Data | Location | Safeguards |
|---|---|---|---|
| JOUCLA CYBERDÉFENSE, Mr Hugo Joucla, sole trader, SIREN 938 064 714, 84 chemin du Rabet et du Ramplan, 13670 Saint-Andiol, France | Development, technical operation and maintenance of the platform: administrative access to the servers, databases and backups that contain the Data, on the Processor's instructions and only to the extent of these operations; no other use | France | Provider established in the European Union; processing contract that complies with Article 28 of the GDPR, obligations equivalent to this agreement (article 4.3) |
| OVH SAS, 2 rue Kellermann, 59100 Roubaix, France | Hosting of the servers, Hosted Websites, Menu Pages, databases, files and backups; for Hosted Websites and Menu Page booking requests, sending of confirmation, reply and reminder emails; for Gift Cards, sending of receipts, cards, balance notices and reminders; for the Reviews Module, sending of feedback requests and of the Controller's replies | France (Gravelines data centre) | Provider established in the European Union; OVHcloud data processing terms |
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States | Relaying and protection of network traffic (CDN, DNS for the ardoiza.fr and my-ardoiza.fr domains, issuing and presenting the security certificate for Customers' domain names connected to their Hosted Website, anti-DDoS): IP addresses, connection metadata, content of requests. Cloudflare decrypts traffic at its edge to filter it, then re-encrypts it towards the origin server: it can therefore technically access the content of requests, without storing it. Turnstile anti-bot check, switched on since 1 October 2026 for the Menu Page's booking request form and gift card purchase form and, when the Reviews Module is switched on, for its feedback form: verification token, IP address and browser signals of the end customer, for which Cloudflare is the controller, the Processor keeping nothing from it | Global network, processing possible outside the European Union | Cloudflare's data processing agreement with standard contractual clauses (Decision 2021/914), including for the Turnstile check |
| Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland, and affiliated companies | Only if the Customer switches on online payment for orders, the booking deposit or the Gift Cards Module: processing of the payment between the end customer and the Customer, on the Customer's Stripe account opened under the contract entered into directly between them; transmission to Stripe of the end customer's email address (receipt, fraud prevention), the amount and a description with no name or telephone number; transmission to ARDOIZA of the payment and refund identifiers and status | European Union, transfers to the United States possible | Standard contractual clauses; Stripe also acts as a controller for its own regulatory obligations, under the contract entered into directly between the Customer and Stripe. Feature open since 23 September 2026, and since 1 October 2026 for Gift Cards, active only for Customers who have switched it on |
| 650 Industries, Inc. (Expo), United States | Mobile app: delivery to the Customer's device of the notification announcing an order or a booking request; receives the device's notification token and the notification content described in Annex 1, with no end customer identification Data | United States | EU-U.S. Data Privacy Framework, in which Expo participates |
| Apple Inc., United States | Mobile app: delivery of the same notification on the Customer's iPhone or iPad (Apple's notification service), with the same data | United States | European Commission standard contractual clauses (Decision 2021/914) |
| Google LLC, United States | Only where the Customer uses the Mobile App on an Android device: delivery of the same notification on that device (Firebase Cloud Messaging, Google's notification service), with the same data | United States | European Commission standard contractual clauses (Decision 2021/914) |
No other sub-processor processes the Data. In particular, the automated assistant and the language model provider (Anthropic) receive no end customer data. No text message (SMS) service is used to date; should one be introduced, it would be added to this annex following the procedure in article 4.
Mobile App on Android. Google LLC is added to this annex by version 1.14 of 5 October 2026, the day the Mobile App was published on Google Play. No Data is passed to Google until the Customer has itself connected an Android device to its Account, and the Customer ends this at any time by disconnecting the device from the customer area. The information provided for in article 4.2 did not precede this publication by thirty (30) days. Customers whose Account was opened before 5 October 2026 are informed of it by a message in the customer area and by email; they may object to this addition in writing to [email protected], on legitimate grounds, during the thirty (30) days following that information, and either party may then terminate the contract free of charge under the conditions of article 4.2.