For restaurants

Annex 1 — Data Processing Addendum

Effective Date: 18 August 2026 · Last Updated: 18 August 2026

This Data Processing Addendum (“DPA”) forms part of the Sizzle Restaurant/SaaS Agreement between Flowyn, operator of Sizzle (“Sizzle”, “we”, “us”, “our”), and the subscribing restaurant, café, QSR, cloud kitchen or other hospitality business (“Restaurant”, “you”, “your”).

This DPA governs the processing of personal data by Sizzle in connection with the Sizzle services provided to the Restaurant.

1.

Purpose

The purpose of this DPA is to establish the responsibilities of the parties regarding personal data processed through Sizzle.

The parties agree to cooperate in maintaining appropriate privacy, security and data-protection practices applicable to their respective roles.

This DPA should be read together with:

  • The Restaurant/SaaS Agreement
  • Sizzle Privacy Policy
  • Applicable Sizzle policies
  • Applicable data-protection law

If there is a conflict concerning personal-data processing, this DPA will govern that specific processing relationship to the extent required by applicable law.

2.

Definitions

For this DPA:

“Customer Data” means personal data relating to customers, members, guests, staff or other individuals that the Restaurant provides to Sizzle or that Sizzle processes in connection with the Restaurant's use of Sizzle.

“Personal Data” has the meaning given under applicable data-protection law.

“Processing” includes collecting, recording, organising, storing, accessing, using, transmitting, analysing, modifying, retrieving, disclosing, deleting or otherwise handling personal data.

“Services” means the Sizzle software and services provided to the Restaurant.

“Subprocessor” means a third-party service provider engaged by Sizzle to process personal data in connection with the Services.

3.

Roles of the Parties

The parties acknowledge that their roles may differ depending on the processing activity.

Restaurant

For Customer Data that the Restaurant independently collects, uploads or determines to use for its own business purposes, the Restaurant is responsible for determining the purposes for which that information is used and for ensuring that its collection and provision to Sizzle is lawful.

Sizzle

Sizzle processes Restaurant Customer Data to provide the contracted Services.

Sizzle may also independently process certain information for purposes described in the Sizzle Privacy Policy, including platform security, fraud prevention, service operation, product improvement, analytics and other permitted purposes.

The parties acknowledge that the precise legal classification of each party may depend on the particular processing activity and applicable law.

4.

Categories of Personal Data

Depending on the Services enabled, Customer Data may include:

  • Name
  • Mobile number
  • Account identifiers
  • Restaurant membership information
  • Order history
  • Items ordered
  • Table/session information
  • Reservation information
  • Loyalty activity
  • CoinZ
  • Rewards
  • Coupons and vouchers
  • Campaign interactions
  • Customer feedback
  • Reviews and ratings
  • Birthday month/day
  • Student verification status and related information where applicable
  • Technical and security information

The Restaurant should not provide Sizzle with information that is unnecessary for the Services.

5.

Categories of Data Subjects

Customer Data may relate to:

  • Restaurant customers
  • Guests
  • Members
  • Restaurant staff
  • Reservation guests
  • Individuals participating in restaurant events
  • Other individuals whose information the Restaurant lawfully provides to Sizzle
6.

Processing Purposes

Sizzle may process Customer Data to:

  • Platform operations
  • Operate the Sizzle platform
  • Authenticate users
  • Manage accounts
  • Manage restaurants
  • Process orders
  • Manage tables
  • Manage reservations
  • Operate kitchen and staff functionality
  • Customer engagement
  • Operate memberships
  • Manage loyalty programs
  • Calculate rewards
  • Manage CoinZ
  • Apply coupons
  • Deliver eligible offers
  • Support customer engagement
  • Restaurant services
  • Provide restaurant analytics
  • Generate reports
  • Provide customer-management functionality
  • Provide campaign tools
  • Provide customer-service functionality
  • Security
  • Detect fraud
  • Prevent abuse
  • Secure accounts
  • Investigate suspicious activity
  • Protect the platform
  • Maintain technical integrity
  • Service improvement

Where permitted by applicable law:

  • Improve Sizzle
  • Analyse platform usage
  • Improve performance
  • Develop new features
  • Generate aggregated or de-identified insights
  • Conduct product research
7.

Restaurant Instructions

Sizzle will process Restaurant Customer Data in accordance with:

  • The Restaurant/SaaS Agreement
  • This DPA
  • The enabled Services
  • Reasonable documented instructions from the Restaurant

Sizzle is not required to follow instructions that:

  • Conflict with applicable law
  • Would compromise the security of Sizzle
  • Are technically impossible
  • Would require substantial functionality outside the agreed Services without appropriate agreement

If an instruction appears to create a significant legal or security concern, Sizzle may request clarification before implementing it.

8.

Restaurant Responsibilities

The Restaurant is responsible for:

  • Providing accurate Customer Data
  • Having appropriate authority to provide Customer Data to Sizzle
  • Providing legally required notices
  • Obtaining required consent where applicable
  • Ensuring imported databases were obtained lawfully
  • Ensuring marketing campaigns comply with applicable requirements
  • Ensuring staff use Customer Data appropriately
  • Maintaining appropriate access controls within the Restaurant
  • Promptly removing former staff
  • Not uploading unnecessary sensitive information

The Restaurant must not use Sizzle to process data it is legally prohibited from providing.

9.

Data Minimisation

The parties agree that personal data should be limited to information reasonably necessary for the relevant Services and purposes.

Sizzle may implement technical limitations, retention controls or other safeguards designed to reduce unnecessary processing.

Restaurants should not upload sensitive or unrelated information merely because Sizzle technically permits an upload.

10.

Subprocessors

Sizzle may engage third-party providers to provide infrastructure and Services.

Subprocessors may provide:

  • Cloud hosting
  • Database infrastructure
  • Authentication
  • Messaging
  • WhatsApp services
  • Payment processing
  • Analytics
  • Security
  • Error monitoring
  • AI services
  • Customer support
  • Other technology infrastructure

Sizzle may authorise these providers to process relevant information to the extent necessary to provide their services.

Sizzle will seek to impose appropriate confidentiality and security obligations on relevant providers.

11.

Changes to Subprocessors

Sizzle may add or replace Subprocessors as its technology stack develops.

Where applicable law requires notification or other safeguards regarding Subprocessor changes, Sizzle will follow those requirements.

Sizzle may maintain an internal list of relevant Subprocessors and make appropriate information available to Restaurants.

12.

Security Measures

Sizzle will maintain reasonable technical and organisational safeguards appropriate to the nature of the information processed.

Measures may include:

  • Authentication controls
  • Role-based access
  • Tenant isolation
  • Database access controls
  • Encryption/security controls
  • Access logging
  • Security monitoring
  • Error monitoring
  • Backup procedures
  • Vulnerability management
  • Security testing
  • Incident-response procedures

The final security measures may evolve as the Sizzle infrastructure changes.

The DPDP Rules specifically contemplate reasonable security safeguards including measures such as encryption, access controls, monitoring, backups and contractual safeguards for Data Processors.

13.

Confidentiality

Sizzle will restrict access to Customer Data to persons and providers who require access for authorised purposes.

Persons authorised to process Customer Data should be subject to appropriate confidentiality obligations.

The Restaurant must similarly ensure that its personnel handle Customer Data confidentially and only for authorised purposes.

14.

Personal Data Breaches

If Sizzle becomes aware of a personal-data breach affecting Customer Data, Sizzle will respond according to its incident-response procedures and applicable law.

Where appropriate, Sizzle may:

  • Investigate the incident
  • Contain the incident
  • Assess affected information
  • Take corrective measures
  • Cooperate with the Restaurant
  • Provide information reasonably necessary for the Restaurant to meet its own legal obligations
  • Notify relevant authorities or affected individuals where required

The final notification process will follow the requirements applicable to the relevant party and processing activity.

The final DPDP Rules include specific breach-notification requirements, including notification obligations and detailed information to be provided to the Board in applicable circumstances.

15.

Assistance With Privacy Requests

Where a Restaurant receives a valid request from an individual concerning Customer Data processed through Sizzle, Sizzle will provide reasonable technical assistance where necessary and appropriate.

This may include assistance with:

  • Access requests
  • Correction
  • Deletion
  • Withdrawal of consent
  • Other applicable privacy rights

The Restaurant should not request Sizzle to disclose information where doing so would violate another person's privacy or applicable law.

16.

Verification of Requests

Sizzle may require reasonable verification before processing a privacy request.

This is intended to prevent:

  • Identity theft
  • Unauthorised account access
  • Fraudulent deletion
  • Unauthorised disclosure

Verification should be proportionate to the sensitivity of the requested information.

17.

Data Retention

Sizzle will retain Customer Data for periods reasonably necessary for:

  • Providing the Services
  • Maintaining accounts
  • Maintaining transaction records
  • Security
  • Fraud prevention
  • Dispute resolution
  • Legal obligations
  • Financial/accounting requirements
  • Other permitted purposes

Different categories of information may have different retention periods.

Where Customer Data is no longer required, Sizzle may delete, anonymise or securely isolate it.

18.

Termination

Following termination of the Restaurant's Sizzle subscription:

  • The Restaurant may request an applicable data export.
  • Sizzle will provide the export through available mechanisms where reasonably practicable.
  • The Restaurant will have the applicable export period specified by Sizzle.
  • Following the export period, Sizzle may delete or anonymise Customer Data it no longer needs.

Sizzle may retain information where necessary for:

  • Legal compliance
  • Security
  • Fraud prevention
  • Dispute resolution
  • Accounting
  • Enforcement of rights
  • Other lawful purposes
19.

Restaurant Data Export

Exports may contain information reasonably available within Sizzle's systems.

Depending on the data type and technical structure, exports may be provided in:

  • CSV
  • JSON
  • Other commonly usable formats

Sizzle does not guarantee that every derived internal system record, security log, proprietary algorithm or internal analytical model can be exported.

20.

International Processing

Sizzle may use Subprocessors that process information outside India.

Where applicable, Sizzle will implement the safeguards and comply with restrictions required by applicable Indian law.

The Restaurant acknowledges that modern cloud infrastructure may involve distributed processing and infrastructure across multiple jurisdictions.

21.

AI Providers

Where AI services are used:

  • Sizzle will determine the appropriate data required for the relevant feature.
  • Unnecessary personal data should not be provided to AI providers.
  • Where practical, information may be aggregated or de-identified.
  • AI providers may process information according to their contractual arrangements with Sizzle.

Sizzle will not intentionally provide unnecessary Customer Data to an AI provider merely because it is available within the platform.

22.

Aggregated and De-identified Information

Nothing in this DPA prevents Sizzle from creating and using information that is aggregated or appropriately de-identified so that it does not identify an individual or expose another Restaurant's identifiable Customer Data.

Sizzle may use such information for:

  • Analytics
  • Benchmarking
  • Research
  • Product development
  • Business intelligence
  • Platform optimisation
  • Industry insights

Sizzle retains rights in its proprietary analytical methodologies, models and platform-level insights, subject to applicable law.

23.

Restaurant-Specific Analytics

Sizzle may provide the Restaurant with analytics concerning its own customers and operations.

Such analytics may include:

  • Customer visits
  • Repeat visits
  • Order frequency
  • Popular products
  • Reward usage
  • Campaign performance
  • Retention
  • Membership activity
  • Other business metrics

The Restaurant does not receive another Restaurant's identifiable customer information.

24.

Marketing

Where Sizzle provides marketing tools, the Restaurant is responsible for ensuring that its campaigns comply with:

  • Applicable law
  • Consent requirements
  • Communication preferences
  • Platform rules
  • WhatsApp/provider policies
  • Other applicable messaging requirements

Sizzle may suspend campaigns that appear unlawful, abusive, fraudulent or harmful.

25.

Data Accuracy

The Restaurant is responsible for ensuring that Customer Data it provides is reasonably accurate and up to date where required for the relevant purpose.

Sizzle may provide mechanisms for correcting or updating information where technically supported.

26.

Security Cooperation

The parties will reasonably cooperate on security matters where necessary.

The Restaurant must promptly notify Sizzle of suspected:

  • Account compromise
  • Unauthorised access
  • Data leakage
  • Credential theft
  • Malicious activity
  • Other security incidents involving Sizzle
27.

Audit and Compliance Information

Subject to reasonable confidentiality and security restrictions, Sizzle may provide information reasonably necessary for the Restaurant to understand Sizzle's relevant data-processing and security practices.

Sizzle is not required to provide:

  • Source code
  • Security credentials
  • Internal security vulnerabilities
  • Information that would compromise another customer's confidentiality
  • Proprietary infrastructure details
  • Information that would materially compromise Sizzle's security
28.

Confidentiality of Compliance Information

Information exchanged under this DPA for security, privacy or compliance purposes must be treated as confidential unless disclosure is required by law.

29.

Changes to This DPA

Sizzle may update this DPA where reasonably necessary because of:

  • Changes in law
  • Changes in the Sizzle platform
  • Changes in Subprocessors
  • Changes in security practices
  • Changes in data-processing activities

Material changes will be communicated where required.

30.

Order of Precedence

If there is a conflict:

  • Mandatory applicable law takes precedence.
  • This DPA governs personal-data processing matters.
  • The Restaurant/SaaS Agreement governs commercial matters.
  • Feature-specific terms govern specific features where expressly stated.
31.

Survival

Provisions concerning:

  • Confidentiality
  • Data protection
  • Security
  • Data retention
  • Intellectual property
  • Liability
  • Dispute resolution

will survive termination to the extent necessary to give them effect.

32.

No Transfer of Ownership

This DPA does not transfer ownership of Customer Data to Sizzle.

The Restaurant retains its rights in Restaurant-provided business data subject to the licences and processing rights necessary to operate Sizzle.

Sizzle retains ownership of:

  • Sizzle software
  • Platform architecture
  • Proprietary technology
  • Analytics methodologies
  • Aggregated/de-identified platform insights
  • Sizzle intellectual property

subject to applicable law.

33.

Contact

  • Flowyn / Sizzle
  • Hyderabad, Telangana, India
  • General: flowyn.info@gmail.com
  • Privacy: privacy@sizzle.business

Questions about this document? Email privacy@sizzle.business.