. Zero Setup Fees 31-Day Free Trial Delivery + Pickup + Reservations Real-Time Dashboard All in one
Skip to main content

MealApp

This Data Processing Agreement (“DPA”) governs the processing of personal data carried out by MealApp on behalf of its Partner Restaurants (“Merchants”) when the Merchant uses the MealApp platform, including the ordering interface on mealapp.app and the merchant dashboard on mealappmanager.com.

This DPA is issued under Article 28 of Regulation (EU) 2016/679 (the “GDPR”) and forms an integral part of the commercial agreement between MealApp and each Merchant. By onboarding to the platform and processing diner orders through MealApp, the Merchant accepts and is bound by the terms of this DPA in full.

MealApp is the trading name of the company registered at Sint-Paulusplaats 11, 2000 Antwerp, Belgium, under Enterprise Number BE1034.892.802.

1. Definitions and Roles

For the purposes of this DPA, the following terms carry the meanings set out below.

  • Data Controller. The Merchant is the Data Controller. The Merchant determines the purposes and means of processing the personal data of the diners who place orders with it through MealApp.
  • Data Processor. MealApp is the Data Processor. MealApp processes personal data solely on behalf of, and on the documented instructions of, the Merchant.
  • Data Subject. The diner who places an order with the Merchant through the MealApp platform.
  • Personal Data. Any information relating to an identified or identifiable diner processed under this DPA, including the diner’s name, telephone number, delivery address, email address, order history, and related order details.
  • Applicable Law. The GDPR, the Belgian Data Protection Act of 30 July 2018, and any binding guidance issued by the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données).

2. Scope and Purpose of Processing

MealApp shall process Personal Data only for the following defined purposes:

  • Facilitating the placement, confirmation, preparation, and delivery of food orders between the diner and the Merchant.
  • Operating and maintaining the Merchant dashboard on mealappmanager.com, including order management, menu management, and reporting functions.
  • Processing payments and settlements in connection with orders placed through the platform.
  • Providing technical support to the Merchant and, where required, to the diner in relation to a specific order.

MealApp shall not sell, rent, license, or otherwise commercialise diner Personal Data. MealApp shall not process Personal Data for its own independent marketing purposes without a separate legal basis obtained directly from the Data Subject.

3. MealApp’s Obligations as Processor

MealApp undertakes the following obligations under Article 28 GDPR:

  • Documented instructions. MealApp shall process Personal Data only on the documented instructions of the Merchant. The Merchant’s use of the platform, and the standard order flow embedded in it, constitute such documented instructions unless the parties agree otherwise in writing.
  • Confidentiality. MealApp shall ensure that all personnel authorised to process Personal Data are bound by written confidentiality obligations or an equivalent statutory duty of confidence.
  • Security of processing. MealApp shall implement appropriate technical and organisational measures under Article 32 GDPR, including but not limited to encryption of data in transit and at rest, restricted access controls, secure hosting infrastructure within the European Economic Area, and regular security testing.
  • Assistance to the Controller. MealApp shall assist the Merchant, insofar as reasonably possible, in fulfilling its obligations to respond to Data Subject requests concerning access, rectification, erasure, restriction, portability, and objection.
  • Records of processing. MealApp shall maintain records of its processing activities carried out on behalf of the Merchant, in accordance with Article 30(2) GDPR.
  • Audit rights. MealApp shall make available to the Merchant, on reasonable written request, the information necessary to demonstrate compliance with this DPA.

4. Sub-Processors

The Merchant grants MealApp general written authorisation to engage third-party sub-processors for the purpose of delivering the platform, including but not limited to cloud hosting providers, payment service providers, communication and notification providers, and business analytics providers.

MealApp shall:

  • Engage only sub-processors that provide sufficient guarantees of GDPR-compliant technical and organisational measures.
  • Impose on each sub-processor, by written contract, data protection obligations no less protective than those set out in this DPA.
  • Remain fully liable to the Merchant for the performance of each sub-processor’s obligations.
  • Maintain an up-to-date list of sub-processors, available on request to partner@mealapp.net, and inform the Merchant of any intended additions or replacements, giving the Merchant a reasonable opportunity to object.

5. Data Breach Notification

In the event of a Personal Data Breach affecting Personal Data processed on behalf of the Merchant, MealApp shall notify the Merchant without undue delay after becoming aware of the breach, and in any event within a timeframe that permits the Merchant to comply with its own 72-hour notification duty to the Belgian Data Protection Authority under Article 33 GDPR.

The notification shall include, to the extent then known:

  • The nature of the breach, including the categories and approximate number of Data Subjects and records concerned.
  • The likely consequences of the breach.
  • The measures taken or proposed to address the breach and mitigate its adverse effects.
  • The contact point at MealApp for further information.

6. Deletion of Data

Upon termination of the commercial agreement between MealApp and the Merchant, or upon the Merchant’s departure from the platform for any reason, MealApp shall, at the Merchant’s written choice, delete or return all Personal Data processed on behalf of the Merchant, and delete existing copies.

MealApp is entitled to retain Personal Data where, and to the extent that, retention is required by Union law or Belgian law, including but not limited to fiscal, accounting, anti-money-laundering, or statutory record-keeping obligations. Any data retained under this paragraph shall continue to be protected in accordance with the terms of this DPA.

7. International Data Transfers

MealApp shall not transfer Personal Data outside the European Economic Area unless such transfer is subject to appropriate safeguards under Chapter V of the GDPR, including the European Commission’s Standard Contractual Clauses or an adequacy decision.

8. Liability and Governing Law

The liability of the parties under this DPA is governed by the commercial agreement between them and by the GDPR. This DPA is governed by Belgian law. Any dispute arising from or in connection with this DPA shall be submitted to the exclusive jurisdiction of the competent courts of Antwerp, Belgium.

9. Contact for Data Protection

All notices, requests, and communications concerning this DPA, including sub-processor lists, breach notifications, and Data Subject assistance requests, shall be addressed in writing to:

MealApp — Data Protection
Sint-Paulusplaats 11, 2000 Antwerp, Belgium
Enterprise Number: BE1034.892.802
Email: partner@mealapp.net