1 Parties effect and precedence
This Data Processing Agreement forms part of the accepted HungrySpots contract between Airus Energy LLC and the business customer identified in the order or account acceptance record. It applies only to personal information that HungrySpots processes on that customer's behalf to provide the contracted service. The customer is the controller, or a processor with authority from its controller, and Airus Energy LLC is the processor or subprocessor as appropriate.
The processing particulars in the schedules below, the accepted order, and lawful written instructions identify the service. This agreement does not authorise independent advertising or unrelated use of customer information. It does not govern processing for which we independently act as controller, which is described in our Privacy Policy.
Mandatory law and an applicable executed international-transfer instrument take priority over a conflicting clause. This agreement takes priority over the general Terms for the personal information it covers. Customer rights under this agreement cannot be reduced by an internal policy amendment.
2 Customer instructions and obligations
The customer instructs us to process personal information only to provide, maintain, secure, and support the contracted services, perform authorised publication or export, and carry out other documented lawful instructions. The accepted service configuration is an instruction only within those agreed purposes. International disclosures or access must have a separate lawful transfer basis where required.
We process covered information only on documented instructions, including instructions about international transfers, unless binding law requires otherwise. In that case we inform the customer before the processing unless the law prohibits notice. We promptly tell the customer if, in our opinion, an instruction infringes applicable data protection law and may suspend the affected processing while the issue is resolved.
The customer is responsible for the legality, accuracy, necessary notices and permissions, and authorised content of its instructions. It must not submit sensitive, children's, or regulated personal information outside the service's expressly agreed scope. This responsibility does not excuse our own obligations or an unauthorised use by us.
3 Confidentiality and security
People authorised to process the information must be subject to confidentiality commitments or an appropriate statutory duty. Access must be limited to what their work requires. We implement appropriate technical and organisational measures for the risk, including the agreed controls in the security schedule below.
Measures address confidentiality, integrity, availability, resilience, recovery, and regular testing as required by applicable law. We may improve measures as technology changes, but must not materially reduce the agreed protection. We give the customer information reasonably needed to assess security, subject to protection of other customers and confidential security details.
4 Subprocessors
The customer gives general written authorisation for subprocessors identified in the completed register made available before acceptance. We notify the customer at least 30 days before adding or replacing a subprocessor for covered processing, unless an urgent protective replacement requires shorter notice and applicable law allows it.
The customer can object on reasonable data protection grounds during the notice period. We work in good faith to address the objection, provide a reasonable alternative, or refrain from the disputed processing. If no reasonable solution is available, the customer may end the affected service before the new subprocessor processes its information and receive a refund of the unused prepaid part of that affected service, subject to mandatory law.
We impose data protection obligations on the subprocessor that provide the required equivalent protection for its work, including appropriate security, instructions, confidentiality, assistance, and deletion. We remain responsible to the customer for the subprocessor's performance of those obligations as required by applicable law.
5 Assistance with rights and compliance
Taking account of the nature of processing and the information available to us, we assist the customer with requests to access, correct, delete, restrict, object, or receive portable information. We forward a request about customer-controlled information without undue delay, with an operational target of two business days. We do not respond on the customer's behalf except on instructions or where the law independently requires us to act.
We also assist the customer with security obligations, breach notifications, data protection impact assessments, and required authority consultation. Ordinary assistance necessary to meet our own duties is included in the service. Any charge for substantial additional customer-requested work must be agreed in advance and must not prevent a mandatory duty from being fulfilled.
6 Personal data breaches
We notify the customer without undue delay after becoming aware of a personal data breach affecting covered information. Our target is an initial notice within 24 hours of awareness. This target does not permit avoidable delay. We provide known details about the nature and likely impact, affected information, mitigation, and a contact for further information. We supplement the notice as the investigation develops.
We cooperate with the customer's lawful response and notification duties. A notice is not by itself an admission of liability. We do not notify the customer's affected individuals on its behalf unless instructed or legally required, but this does not postpone a notification duty that applies independently to us.
7 Return deletion and retained copies
At the end of the service, the customer may choose return or deletion of covered information. We provide a reasonable export opportunity, normally for 30 days where continued restricted retention is lawful, unless the customer instructs earlier deletion. We delete the covered information and existing copies unless law requires specific retention. We identify and restrict any legally required retained records.
Active-system deletion is completed without undue delay after the applicable instruction or export period, within an expressly agreed period and any shorter mandatory deadline. A valid individual erasure request is not delayed merely because this contract offers the customer an export period. Protected backups expire under the applicable supplier schedule, which must be disclosed and assessed for the agreed scope; this policy does not certify a universal 90-day limit. They remain unavailable for ordinary use, and deletion instructions are reapplied after a disaster-recovery restoration.
We instruct subprocessors to return or delete corresponding information as required. On reasonable request, we provide confirmation of completed actions and disclose any lawful remaining retention and expiry. We do not treat removal from the customer interface as evidence of full deletion.
8 Information and audits
We make available information needed to demonstrate compliance and allow and contribute to audits and inspections by the customer or a qualified independent auditor acting for it. Ordinary audits use reasonable notice, scope, frequency, confidentiality, and measures to protect other customers and security. A regulator's rights, a significant incident, or a reasonable evidence-based concern are not blocked by an ordinary scheduling limit.
Relevant certifications or independent reports may help answer a request, but do not replace audit rights where further inspection is necessary under the law. Fees for exceptional additional work must be reasonable and agreed, and cannot be used to frustrate a required audit. We promptly inform the customer if we consider an audit instruction unlawful.
9 International transfers and government requests
We do not make a restricted international transfer of covered information without an applicable lawful mechanism and the customer's documented authorisation or another legal duty. Where Standard Contractual Clauses or another instrument is needed, the parties complete and accept the actual applicable instrument and annexes before the transfer. This agreement is not a substitute for it.
We assess binding requests for covered information, disclose only what is legally required, notify the customer where lawful, and seek appropriate clarification or challenge when a request is unlawful or disproportionate and a challenge is reasonably available. Transfer-agreement obligations continue to apply.
10 United States service-provider terms
Where the CCPA or another applicable US state law requires these restrictions, we process covered information as a service provider, contractor, or processor for the specified purposes. We do not sell or share it, retain or use it outside the stated business purposes or direct service relationship except as lawfully permitted, or combine it with information from other customers or our own interactions except where the law specifically permits the combination.
We comply with the obligations applicable to us under that law and provide the required level of privacy protection. We inform the customer if we can no longer meet those obligations. The customer may take reasonable steps to confirm compliant use and stop and remediate unauthorised use. We certify that we understand these restrictions and will comply with them. Further subcontracting requires the corresponding written restrictions and safeguards.
11 Term and changes
This agreement applies while covered processing continues, including lawful retained copies after service termination. Changes that reduce required protection need the agreement and notices required by law and the contract. A commercial liability clause does not limit a data subject's rights, a regulator's powers, or mandatory transfer-instrument rights.
Processing and subprocessor schedules
Schedule 1 Processing particulars
| Field | Agreed particulars |
|---|---|
| Subject matter | Provision of the HungrySpots restaurant website builder hosting and specifically enabled customer features |
| Duration | Contract term plus the limited return deletion and lawful retention periods in this agreement |
| Nature of operations | Receiving organising storing retrieving transmitting publishing on instruction exporting protecting and deleting information |
| Purposes | Supply and support the contracted restaurant service on documented instructions |
| Data subjects | Restaurant representatives and staff; identifiable people in supplied media; visitors or customers only where an agreed feature actually processes their information |
| Information | Supplied contact and role details restaurant content and identifiable media; guest name, email or phone, party size, requested date and time, optional notes, request status, and necessary visitor events where enabled |
| Restricted information | No intentional sensitive children's biometric payment-credential or identity-document processing without a specific lawful written scope and safeguards |
| Controller | Business customer identified in the accepted order or account record |
| Processor | Airus Energy LLC Apartment 17, Entrance 3, Building 15, Baga Toiruu, 4th Khoroo, Chingeltei District, Ulaanbaatar, Mongolia |
| Customer contact | Customer's recorded account privacy or authorised business contact |
| Processor contact | airusenergymn@gmail.com |
| Ordinary deletion | Without undue delay within the accepted processing schedule and applicable rights deadlines; residual protected backups follow the supplier schedule and are restricted from ordinary use |
| Transfers and locations | Actual recipients countries remote access and lawful mechanisms recorded in the accepted provider and transfer schedules |
Schedule 2 Security measures
The agreed measures include role-based account access; separation of restaurant records and public publication state; secure transport; appropriate protection for stored information and backups; confidential staff handling; controlled secrets; safe uploads; minimised logs; documented retention and deletion; breach response; provider oversight; and regular proportionate verification. We maintain internal procedures that implement these measures.
The service-specific evidence register records the implementation, owner, date, scope, and verification evidence for each measure. A technical measure is represented as present only after it has been verified for the actual service. Changes must preserve the agreed protection and remain suitable for the risk.
Schedule 3 Approved subprocessor register
Only the following infrastructure providers are identified for the described service. Authorization under an accepted customer agreement applies to the relevant service and scope. Provider contracting entities and any required transfer annexes must be confirmed against the actual supplier account before restricted processing. A public policy is not proof of an executed agreement.
| Service | Purpose and data | Known location | Agreement and transfer status | Deletion and change notice |
|---|---|---|---|---|
| Supabase | Authentication, database, legacy media, authentication delivery; account, restaurant, guest, and session records | Primary database South Korea; relevant supplier support and subprocessors can be international | Applicable supplier terms and DPA at https://supabase.com/legal/dpa. This policy does not certify execution or a separate Mongolia transfer mechanism; complete required instruments before restricted processing | Active erasure through the verified account workflow; backups and supplier logs follow their applicable schedules. Customer notices use the recorded account email |
| Vercel | Hosting, request delivery, operational logs, and enabled optional analytics | Current function region United States iad1; content delivery and relevant operations global | Applicable supplier terms and DPA at https://vercel.com/legal/dpa. Execution and required transfer assessment must be established separately | Supplier log and backup schedules; private account routes excluded from optional analytics. Customer notices use the recorded account email |
| Cloudflare R2 | Storage and signed delivery of new restaurant media where configured | Automatic placement or configured jurisdiction; no unverified EU-only or bucket-location commitment | Applicable supplier terms and DPA at https://www.cloudflare.com/cloudflare-customer-dpa/. Verify account, jurisdiction, execution, and any required transfer mechanism separately | Media deletion is physically verified; provider operational records follow supplier terms. Customer notices use the recorded account email |
Google and Meta act as independent identity providers for their own sign-in services. The company contact mailbox uses Google Gmail under its applicable service terms; no Google Workspace DPA execution is asserted. These services and their information flows are disclosed in the public provider register at https://hungryspots.com/data-protection#providers. A future payment or email integration must be identified and assessed before receiving covered information.
