Ellich legal
Data Processing Addendum
This Addendum describes Ellich’s processing of personal data on behalf of a merchant or business customer and forms part of the Terms of Service.
Effective and last updated: July 25, 2026
1. Roles and instructions
Customer is the controller/business and Ellich is the processor/service provider for Customer Personal Data, except where Ellich independently determines a purpose described in the Privacy Notice. Ellich will process Customer Personal Data only to provide, secure, support, and improve the contracted service; follow documented Customer instructions; or comply with law.
2. Processing details
- Subject matter: hosted restaurant and retail operations, communications, integrations, and support.
- Duration: the service term plus the documented retention and deletion period.
- People: Customer personnel, guests, customers, loyalty members, vendors, applicants, and other contacts submitted by Customer.
- Data: identity, contact, employment, order, transaction, preference, consent, device, support, and operational records.
3. Confidentiality and security
Ellich will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and will maintain reasonable technical and organizational safeguards, including access control, tenant scoping, logging, vulnerability management, incident response, and encryption appropriate to risk.
4. Subprocessors
Customer authorizes Ellich to use subprocessors needed for hosting, security, support, payment connectivity, email/SMS, analytics, and enabled integrations. Ellich remains responsible for imposing data-protection obligations appropriate to each subprocessor’s work. Material new subprocessors will be notified through a reasonable account or service channel where required.
The current provider categories, purposes, and feature dependencies are described on the Subprocessor List. Optional providers apply only when the corresponding feature is enabled.
5. Assistance and incidents
Taking into account the nature of processing, Ellich will reasonably assist Customer with verified rights requests, security obligations, impact assessments, and regulator inquiries. Ellich will notify Customer without undue delay after confirming a breach of Customer Personal Data and provide available information needed for Customer’s legal assessment.
6. Return, deletion, and audits
At termination, Customer may export supported data during the applicable retrieval period. Ellich will delete or return Customer Personal Data as required by the agreement, except where law or legitimate security, billing, fraud, or backup requirements permit retention. On reasonable request, Ellich will provide available security and compliance information; on-site audits require advance agreement regarding scope, confidentiality, timing, and cost.
7. Transfers and precedence
Where legally required for international transfers, the parties will use an applicable recognized transfer mechanism. This Addendum controls over conflicting general Terms solely for its subject matter. Requests about this Addendum may be sent to privacy@ellich.com.