ServeCounter

Legal

Data processing agreement

You are responsible for your customers' data. We process it for you, and only as set out here.

Version 1.8 · draft, not in force · Other versions: 1.0, 1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7

This is a courtesy translation. The Dutch version is the one that applies; where the two differ, the Dutch text is what was agreed.

What we process

Name, email, telephone and address of your customers, their orders, bookings and sales, and what they paid. For a delivery also the delivery address, the note for the driver, the times of each stop, and the position of your driver's phone while they carry an order. For an order from a delivery platform you connect, what the platform sends about it. Of your drivers: their login and their role. Nothing further.

What for

Only to make the product work: showing your orders, bookings and sales, sending your customers their confirmation, showing your driver where to go, and telling a customer when their order is on its way and where it is. We sell nothing on and use none of it to advertise. A driver's position is used for the map the customer sees and for nothing else: not for timekeeping, speed, rating or ranking.

Where it sits

In Europe: your data sits on a server in Germany and your mail goes through Frankfurt. Every business has a database of its own; yours cannot be read from another business. One exception: your payment provider. Stripe processes payment data outside Europe too, under the European Commission's standard contractual clauses.

Who else can reach it

Our sub-processors are on a list we maintain: our hosting party, our mail sender, and Stripe or Buckaroo for the payments. Where you deliver, also OpenFreeMap, which supplies the map tiles: your customer's browser asks it for them directly, not through our servers, and OpenFreeMap sees their IP address and which part of the map they look at, and nothing of the order. A delivery platform you connect is your own party, not our sub-processor: it sends you the order and we receive it for you. If a new one joins, we give thirty days' notice, and if you disagree you may cancel.

Who here may touch it

Only colleagues who need the data for their work, and they have signed a confidentiality undertaking.

Checking that we keep to it

You may have us audited once a year by an independent auditor, at your own cost, with notice beforehand. We answer questionnaires about our security at no charge.

If a customer of yours asks for their data

If somebody asks you for access, correction or deletion, we supply what you need for it. If such a request reaches us, we pass it on to you.

If something goes wrong

In the event of a data breach we tell you within 48 hours, with what happened and what we are doing about it. Reporting to the Dutch Data Protection Authority is your responsibility; we supply what you need for it.

If you stop

Then we delete the data, apart from the tax records we have to keep for seven years.

Your drivers and where they are

You are the controller of your drivers' data, and we hold it for you. The position of a driver's phone is sent to us only while the driver carries an order; we keep only the latest and delete it at the last delivery, when the run or the day is closed, and when it has not been updated for about two hours. You can switch the customer's live map off in the settings: the Driver app then never asks your drivers for their location. It is on unless you switch it off. Nobody at your business can see it: only the customer whose order is being carried can. Before you use delivery, tell your drivers what is collected and why: the Driver app shows them a notice, and you add the rest, such as your reason and any agreement with your works council. A data protection impact assessment for location data is your duty as controller; we provide one you can adopt, for the part only we can write.

Questions about this document go to [email protected].