Effective Date: July 29, 2026
This Data Processing Addendum (“DPA”) supplements and forms part of the Fried Terms of Service (the “Agreement”) between The Fmly Group, LLC, doing business as “Fried”(“Fried,” “we,” “us,” or “our”), and the business that uses the Service (“Customer,” “you,” or “your”). It governs our processing of Personal Information on your behalf in connection with the Fried restaurant-intelligence service (the “Service”). If there is a conflict between this DPA and the rest of the Agreement regarding the processing of Personal Information, this DPA controls.
The Service is offered in the United States only and is intended for business use. This DPA is drafted around U.S. state privacy laws (including the CCPA/CPRA) and does not incorporate the EU/UK GDPR or Standard Contractual Clauses, because the Service does not target or knowingly process data subject to those regimes.
1. Definitions
Capitalized terms not defined here have the meanings given in the Agreement or the Privacy Policy.
- Personal Information means information processed through the Service that identifies, relates to, or could reasonably be linked to an identified or identifiable individual, as further described in the Privacy Policy.
- Business / Controller means the Customer, who determines the purposes and means of processing the Personal Information it submits or connects to the Service.
- Service Provider / Processormeans Fried, which processes Personal Information on the Customer's behalf.
- Sub-processor means a third party engaged by Fried to process Personal Information in order to provide the Service, as listed on the Sub-processor List.
- Applicable Privacy Lawmeans U.S. federal and state privacy and data protection laws applicable to the processing, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).
- The terms “sell,” “share,” “business purpose,” and “commercial purpose” have the meanings given under the CCPA/CPRA.
2. Roles of the Parties and Scope of Processing
As between the parties, the Customer is the Business / Controller of the Personal Information it submits or connects to the Service, and Fried is the Service Provider / Processoracting on the Customer's behalf. Fried processes Personal Information only to provide, secure, support, and improve the Service under the Agreement and this DPA.
The details of processing are as follows:
- Subject matter:Fried's provision of the restaurant-intelligence Service.
- Duration: the term of the Agreement, plus any period required for deletion or de-identification under Section 8.
- Nature and purpose:connecting to the Customer's point-of-sale system, computing analytics from business data, and generating and delivering insights via email and dashboard.
- Categories of data subjects:the Customer's operators, staff members, and other authorized users of the Service.
- Categories of Personal Information: account and profile information (name, email, authentication identifiers); and, within POS-derived Business Data, employee identity, labor, and wage data as provided by the connected POS system.
3. Fried's Processing Obligations
Fried will:
- Process on instructions.Process Personal Information only on the Customer's documented instructions, including as set out in the Agreement, this DPA, and the Customer's use of the Service, except where required by law (in which case Fried will inform the Customer unless legally prohibited).
- Confidentiality. Ensure that personnel authorized to process Personal Information are bound by appropriate confidentiality obligations.
- Security. Implement and maintain reasonable administrative, technical, and organizational measures designed to protect Personal Information, as described in the Privacy Policy (including encryption in transit, access controls, and use of reputable infrastructure providers).
- Assist the Customer.Provide reasonable assistance to help the Customer respond to verified individual rights requests and to meet the Customer's own security and breach-response obligations, taking into account the nature of the processing and the information available to Fried.
- Incident notification.Notify the Customer without undue delay after becoming aware of a confirmed breach of security leading to the unauthorized access, disclosure, or loss of Personal Information processed on the Customer's behalf, and provide information reasonably available to Fried to help the Customer meet its obligations.
4. Sub-processors
The Customer provides a general authorization for Fried to engage the Sub-processors listed on the Sub-processor List, which is incorporated into this DPA by reference. Fried imposes data-protection obligations on its Sub-processors that are substantially consistent with those in this DPA, and remains responsible for their performance of those obligations.
Changes. Fried will provide notice before adding or replacing a Sub-processor that processes Personal Information (by updating the Sub-processor List with a dated change and/or emailing your account contact). If you reasonably object on data-protection grounds, you may terminate the affected Service as your exclusive remedy.
5. CCPA/CPRA Service Provider Terms
To the extent Fried processes Personal Information that is subject to the CCPA/CPRA, Fried acts as a Service Provider and agrees that it:
- will not sell or share Personal Information, as those terms are defined under the CCPA/CPRA;
- will not retain, use, or disclose Personal Information for any purpose other than the business purposes specified in the Agreement and this DPA, or as otherwise permitted by the CCPA/CPRA, and not outside the direct business relationship with the Customer;
- will not combine Personal Information received from the Customer with personal information from other sources, except as permitted by the CCPA/CPRA;
- certifies that it understands and will comply with these restrictions.
The Customer may take reasonable and appropriate steps to help ensure that Fried uses Personal Information in a manner consistent with the Customer's obligations under the CCPA/CPRA, and to stop and remediate unauthorized use.
6. Individual Rights Requests
If Fried receives a request from an individual to exercise rights under Applicable Privacy Law with respect to Personal Information processed on the Customer's behalf, Fried will, where legally permitted, direct the individual to the Customer and reasonably assist the Customer in responding.
7. Return and Deletion
On expiration or termination of the Agreement, or on the Customer's written request, Fried will delete or de-identify Personal Information processed on the Customer's behalf in accordance with the retention practices described in the Privacy Policy, except where retention is required by law or for legitimate business purposes such as security, dispute resolution, and legal compliance.
8. Records and Demonstrating Compliance
Fried will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. Any audit right is satisfied, where available, by Fried providing relevant documentation about its security and privacy practices; on-site audits are not contemplated for the Service at this stage.
9. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
10. Order of Precedence and Changes
This DPA is incorporated into and forms part of the Agreement. In the event of a conflict between this DPA and the remainder of the Agreement regarding the processing of Personal Information, this DPA governs. We may update this DPA from time to time consistent with Applicable Privacy Law; when we make material changes, we will update the Effective Date and provide notice through the Service or by email where appropriate.