This document describes the roles and responsibilities regarding the processing of personal data within the GustaLocal service, in accordance with EU Regulation 2016/679 (GDPR).
1. Definitions
- Data Controller: the business that uses GustaLocal to manage its orders and customers.
- Data Processor: GustaLocal, which processes data on behalf of the Controller.
- Data Subject: the end customer who places an order through the platform.
- Personal data: any information that directly or indirectly identifies a natural person.
2. Data Processing Roles
In the context of using GustaLocal:
- The Merchant (business) is the Data Controller for their end customers' data.
- GustaLocal acts solely as a Data Processor, providing the technological infrastructure.
- GustaLocal processes end customer data only according to the Controller's instructions and to deliver the agreed service.
- Customer data remains the property of the business and is not used by GustaLocal for its own purposes.
🔒 Customer data always remains the property of the business. GustaLocal does not acquire any rights over customer data and processes it solely to provide the service.
3. Scope of Processing
GustaLocal processes the following categories of data on behalf of the Merchant:
- Identification data: name, phone number
- Contact data: email address (if provided)
- Logistical data: delivery address
- Transactional data: order content and amount
- Order history and preferences
4. GustaLocal's Obligations as Processor
- Process data only on documented instructions from the Controller
- Ensure confidentiality through staff bound by confidentiality obligations
- Implement appropriate technical and organisational security measures
- Assist the Controller in fulfilling GDPR obligations (e.g. data subject requests)
- Not sub-contract processing without informing the Controller
- Delete or return data at the end of the contract
- Provide all information necessary to demonstrate GDPR compliance
5. Sub-Processors
GustaLocal uses the following approved sub-processors, all bound by GDPR-compliant data processing agreements:
- Supabase — database and authentication (USA/EU)
- Stripe — payment processing (USA/EU)
- Twilio — WhatsApp notifications (USA)
- Brevo — transactional emails (EU)
- Mapbox — geolocation (USA)
- Google Maps Platform — geolocation and mapping services (USA)
- Mercado Pago — payments for Brazil
If new sub-processors are added, GustaLocal will inform Controllers with at least 30 days' notice.
6. Security Measures
- Data encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access control (RBAC)
- Two-factor authentication for system access
- Continuous monitoring and access logging
- Automatic daily backups with geographic redundancy
- Incident response procedures and breach notification within 72 hours
7. International Data Transfers
Some sub-processors (e.g. Supabase, Stripe, Twilio, Mapbox, Google Maps Platform) may process data in the United States or other non-EEA countries. Such transfers are made via:
- Standard Contractual Clauses (SCC) approved by the European Commission
- Equivalent certifications (e.g. EU-US Data Privacy Framework)
8. Data Subject Rights
The Controller (Merchant) is responsible for handling data subject requests. GustaLocal assists the Controller in:
- Providing access to a specific customer's personal data
- Rectifying or deleting data upon request
- Exporting data in structured format (portability)
- Blocking processing upon the data subject's request
9. Duration and Terms
- This DPA is valid for the entire duration of the GustaLocal service contract.
- Upon contract termination, data is deleted within 30 days, unless fiscal, accounting or legal obligations require longer retention.
- The Controller may request data export before account closure.