Last updated: 2026-05-21
This Data Processing Agreement ("DPA") forms an integral part of Kitchen Stocker's Terms of Service and governs the processing of personal data carried out by Kitchen Stocker on behalf of its customers, in accordance with Article 28 of Regulation (EU) 2016/679 — the General Data Protection Regulation (GDPR, "RGPD") — and Ley Orgánica 3/2018 (LOPDGDD) (the Spanish Data Protection and Digital Rights Act).
Kitchen Stocker shall process Service Personal Data exclusively to provide the contracted functionality and in accordance with the Controller's documented instructions. This DPA shall remain in force for as long as the Controller maintains an active subscription to Kitchen Stocker.
Kitchen Stocker shall act only on the documented instructions of the Controller. Use of the platform's functionality constitutes the principal documented instruction. If Kitchen Stocker considers that any instruction infringes the GDPR or other applicable law, it shall notify the Controller immediately.
Kitchen Stocker implements and maintains appropriate technical and organisational measures to protect Service Personal Data against destruction, loss, alteration or unauthorised access, including:
The Controller authorises Kitchen Stocker to engage sub-processors for the provision of the service. Kitchen Stocker shall ensure that sub-processors provide sufficient data protection guarantees and shall impose on them obligations equivalent to those of this DPA.
The current sub-processors are: cloud infrastructure providers (hosting and database in the EU or under equivalent safeguards), a payment processor and an error monitoring tool. You may request the current list at privacy@kitchenstocker.com.
Kitchen Stocker shall notify the Controller of any addition or replacement of sub-processors at least 14 days in advance, giving the Controller the opportunity to object.
Kitchen Stocker warrants that the persons authorised to process Service Personal Data are bound by confidentiality obligations, whether by contract or by statutory provision.
Kitchen Stocker shall assist the Controller, insofar as possible, in:
Kitchen Stocker shall notify the Controller, without undue delay and within a maximum of 72 hours of becoming aware of it, of any security breach affecting Service Personal Data, providing sufficient information to enable the Controller to comply with its notification obligations to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) and to the affected data subjects.
Kitchen Stocker shall not transfer Service Personal Data outside the European Economic Area (EEA) unless adequate safeguards exist under the GDPR (an adequacy decision, standard contractual clauses or other appropriate safeguards). In such a case, the Controller shall be informed.
Upon termination of the contract, Kitchen Stocker shall make Service Personal Data available to the Controller for export for 30 days. After that period, Kitchen Stocker shall securely delete such data, unless applicable law requires its retention for an additional period.
Kitchen Stocker shall provide the Controller with all information necessary to demonstrate compliance with this DPA and, where applicable, shall allow for and contribute to audits or inspections, subject to reasonable prior notice and with costs borne by the Controller.
For any enquiry relating to this DPA: privacy@kitchenstocker.com