TermsPrivacyDPACookiesRefundsSecurityView pricingBack to login

Data Processing Agreement (DPA)

Last updated: 2026-05-21

This translation is provided for convenience only; the legally binding version is the Spanish original.

This Data Processing Agreement ("DPA") forms an integral part of Kitchen Stocker's Terms of Service and governs the processing of personal data carried out by Kitchen Stocker on behalf of its customers, in accordance with Article 28 of Regulation (EU) 2016/679 — the General Data Protection Regulation (GDPR, "RGPD") — and Ley Orgánica 3/2018 (LOPDGDD) (the Spanish Data Protection and Digital Rights Act).

1. Definitions

  • "Controller": the Kitchen Stocker customer who determines the purposes and means of the processing of personal data of its employees, suppliers or other third parties entered into the platform.
  • "Processor": Aura Media Consulting S.L. (NIF B8866789), owner of the Kitchen Stocker brand, with registered office at Calle Sagunto 1, Valencia (Valencia), 46009, which processes personal data on behalf of the Controller in order to provide the service.
  • "Service Personal Data": any personal data that the Controller enters into or uploads to the Kitchen Stocker platform in the context of using the service.

2. Subject Matter and Duration

Kitchen Stocker shall process Service Personal Data exclusively to provide the contracted functionality and in accordance with the Controller's documented instructions. This DPA shall remain in force for as long as the Controller maintains an active subscription to Kitchen Stocker.

3. Instructions from the Controller

Kitchen Stocker shall act only on the documented instructions of the Controller. Use of the platform's functionality constitutes the principal documented instruction. If Kitchen Stocker considers that any instruction infringes the GDPR or other applicable law, it shall notify the Controller immediately.

4. Technical and Organisational Measures

Kitchen Stocker implements and maintains appropriate technical and organisational measures to protect Service Personal Data against destruction, loss, alteration or unauthorised access, including:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest
  • Per-customer data isolation by means of a tenant identifier
  • Role-based access control with secure authentication
  • Multi-factor authentication (MFA) for administrator roles
  • Continuous error monitoring and security alerts
  • Backup policy and disaster recovery procedure

5. Sub-processors

The Controller authorises Kitchen Stocker to engage sub-processors for the provision of the service. Kitchen Stocker shall ensure that sub-processors provide sufficient data protection guarantees and shall impose on them obligations equivalent to those of this DPA.

The current sub-processors are: cloud infrastructure providers (hosting and database in the EU or under equivalent safeguards), a payment processor and an error monitoring tool. You may request the current list at privacy@kitchenstocker.com.

Kitchen Stocker shall notify the Controller of any addition or replacement of sub-processors at least 14 days in advance, giving the Controller the opportunity to object.

6. Confidentiality

Kitchen Stocker warrants that the persons authorised to process Service Personal Data are bound by confidentiality obligations, whether by contract or by statutory provision.

7. Assistance to the Controller

Kitchen Stocker shall assist the Controller, insofar as possible, in:

  • Responding to requests from data subjects exercising their rights (access, rectification, erasure, portability)
  • Complying with obligations arising from personal data security breaches
  • Carrying out data protection impact assessments (DPIAs) where necessary
  • Conducting prior consultations with the supervisory authority

8. Notification of Security Breaches

Kitchen Stocker shall notify the Controller, without undue delay and within a maximum of 72 hours of becoming aware of it, of any security breach affecting Service Personal Data, providing sufficient information to enable the Controller to comply with its notification obligations to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) and to the affected data subjects.

9. International Transfers

Kitchen Stocker shall not transfer Service Personal Data outside the European Economic Area (EEA) unless adequate safeguards exist under the GDPR (an adequacy decision, standard contractual clauses or other appropriate safeguards). In such a case, the Controller shall be informed.

10. Return and Deletion of Data

Upon termination of the contract, Kitchen Stocker shall make Service Personal Data available to the Controller for export for 30 days. After that period, Kitchen Stocker shall securely delete such data, unless applicable law requires its retention for an additional period.

11. Audits

Kitchen Stocker shall provide the Controller with all information necessary to demonstrate compliance with this DPA and, where applicable, shall allow for and contribute to audits or inspections, subject to reasonable prior notice and with costs borne by the Controller.

12. Contact

For any enquiry relating to this DPA: privacy@kitchenstocker.com