This DPA applies to OrderAI’s processing of personal data under GDPR or similar laws, effective for EU/UK users.
Roles
- Controller: OrderAI (determines data use).
- Processors: Microsoft Azure (hosting), OpenAI (GPT/DALL-E 3), Blockchain network (loyalty points).
Processing Details
- Purpose: Order processing, image generation, menu extraction, loyalty points management.
- Data: Guest orders, voice inputs, PDF menus, device info, loyalty transactions (e.g., wallet addresses).
- Duration: As needed for service or legal retention; Blockchain data is permanent.
Security
- Azure encryption for storage/transmission.
- OpenAI processes data per their terms, not retained beyond use.
- Blockchain uses cryptographic security (pseudonymized data).
Subprocessors
- Azure (global regions).
- OpenAI (GPT/DALL-E 3).
- Blockchain network (decentralized ledger).
- App stores (distribution).
Rights and Obligations
- OrderAI ensures compliance; processors follow instructions.
- EU users: Data subject rights honored, except Blockchain data cannot be deleted.
Contact Us
Email support@theorder.ai for DPA inquiries.