Data Processing Agreement

Version 1.0  ·  Compliant with GDPR Art. 28, UK GDPR, and Swiss nFADP

How this DPA applies: By using Blaze Labels to process staff personal data, you agree to this standard DPA. If your organisation requires a countersigned version, contact legal@blazeiq.io.

Between:

EGS Enggist and Grandjean Software SA
Rue des Usines 17, 2000 Neuchâtel, Switzerland (CHE-112.254.588)
("Processor" / "EGS")

and

The Customer identified in the Blaze Labels account ("Controller")


Recitals

A. The Controller has subscribed to the Blaze Labels kitchen label printing service operated by EGS ("Service").

B. In providing the Service, EGS processes personal data on behalf of the Controller, as described in this Agreement.

C. This Agreement is entered into pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR"), Article 28 of the UK GDPR, and Article 9 of the Swiss Federal Act on Data Protection (nFADP, effective 1 September 2023).

D. This Agreement forms part of, and is incorporated into, the Terms of Service between the Parties.


1. Definitions

1.1 "Data Protection Law" means: the GDPR and national implementing legislation; the UK GDPR and Data Protection Act 2018; the nFADP and implementing ordinances; and any other applicable data protection legislation, as amended.

1.2 "Controller" means the hotel, restaurant or food service operator that has subscribed to the Service and determines the purposes and means of processing staff personal data.

1.3 "Processor" means EGS, which processes personal data on behalf of the Controller.

1.4 "Data Subject" means the kitchen and food preparation staff employed by or working for the Controller, whose names appear in Blaze Labels.

1.5 "Personal Data" has the meaning given in Article 4(1) GDPR or equivalent applicable definition.

1.6 "Sub-processor" means any third party engaged by EGS to process Personal Data in connection with the Service.

1.7 "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this Agreement.


2. Subject Matter and Nature of Processing

2.1 Subject matter. EGS processes Personal Data solely to provide the Service. The core processing activity is recording print events in the Blaze Labels audit log: each time a kitchen staff member selects their name and a food preparation label is printed, the system stores a log entry associating the staff member's name with the printed item, timestamp, and printer identifier.

2.2 No secondary use. EGS shall not process Personal Data for any purpose other than those set out in this Agreement. EGS shall not sell, rent, or commercialise Personal Data, nor use it to build or improve any product other than the Service.


3. Categories of Personal Data

CategoryDescriptionExamples
Staff nameDisplay name of the kitchen staff member as entered in Blaze Labels"Maria Santos"
Food item nameName of the food item for which the label was printed"Chicken Stock"
TimestampDate and time of the print event2025-04-01 07:42 UTC
Printer identifierInternal identifier of the printer usedMAC address or network IP

No special categories of personal data (Article 9 GDPR) are processed — no health, biometric, genetic, racial, or political data.


4. Categories of Data Subjects

Kitchen and food preparation staff employed by, contracted to, or working under the direction of the Controller, whose names appear in the Blaze Labels system as authorised users.


5. Purpose and Duration

5.1 Purpose. Processing is for: (a) generating printed food preparation labels for food safety and traceability; (b) maintaining a print audit log to demonstrate compliance with food safety regulations; (c) enabling authorised supervisors to review print history and investigate food safety incidents.

5.2 Duration. Processing continues for the duration of the subscription. Print log records are retained for two (2) years from the date of the print event, then automatically and permanently deleted.

5.3 Termination. Upon termination, EGS shall delete or return all Personal Data within 30 days at the Controller's election, except where retention is required by law.


6. Processor Obligations

6.1 Processing on documented instructions

EGS shall process Personal Data only on documented instructions from the Controller. EGS shall inform the Controller if an instruction would infringe Data Protection Law.

6.2 Confidentiality

EGS shall ensure that persons authorised to process Personal Data are subject to a binding duty of confidentiality. Access is limited to personnel who need it to carry out their obligations.

6.3 Technical and organisational security measures

EGS shall implement and maintain the measures set out in Schedule 1. These are reviewed at least annually.

6.4 Sub-processors

EGS shall not engage a new Sub-processor without providing the Controller with 30 days' prior written notice. The Controller hereby grants prior general authorisation for the Sub-processors listed in Schedule 2. EGS shall impose equivalent data protection obligations on all Sub-processors and shall remain fully liable for their performance.

6.5 Data subject rights

EGS shall assist the Controller in fulfilling Data Subject rights requests (access, correction, erasure, restriction, portability, objection). EGS shall forward any direct requests from Data Subjects to the Controller promptly and without responding directly.

6.6 Assistance with controller obligations

EGS shall assist with: security of processing (Art. 32); data protection impact assessments (Art. 35); prior consultation (Art. 36); and Security Incident notification. EGS shall notify the Controller without undue delay and within 72 hours of becoming aware of a Security Incident affecting their Personal Data, providing: nature of the incident, approximate numbers of Data Subjects and records affected, likely consequences, and measures taken or proposed.

6.7 Deletion and return

Print log records are automatically deleted after the 2-year retention period. The Controller may request earlier deletion at any time — EGS shall action within 30 days and confirm in writing. On-request deletion is a hard delete (non-recoverable).

6.8 Audit rights

EGS shall make available all information necessary to demonstrate compliance and permit audits by the Controller or their mandated auditor, subject to: 30 days' written notice; normal business hours; Controller bearing audit costs; auditor bound by confidentiality. EGS may satisfy the audit obligation by providing current ISO 27001 or SOC 2 certification reports in lieu of on-site inspection.


7. Controller Obligations

7.1 Lawful basis. The Controller warrants it has, and will maintain, an appropriate lawful basis for processing staff personal data, including where required obtaining consent from or providing notices to Data Subjects.

7.2 Staff notification. The Controller shall ensure that Data Subjects are informed of the processing described in this Agreement in accordance with Articles 13–14 GDPR (or equivalent). This includes making available or posting a staff privacy notice — a template is available from EGS on request or at blaze.calcmenu.io/privacy.

7.3 Accuracy. The Controller is responsible for the accuracy of Personal Data entered into the Service. EGS has no liability for errors in data provided by the Controller.


8. Sub-processors

EGS shall notify the Controller in writing at least 30 days before adding, replacing, or removing a Sub-processor. The Controller may object on reasonable data protection grounds within 20 days. If the parties cannot resolve the objection and the change materially impairs the Controller's compliance obligations, the Controller may terminate the affected service on 30 days' notice without penalty.


9. International Transfers

9.1 Storage location. All Personal Data processed under this Agreement is stored on Supabase infrastructure in Zurich, Switzerland (AWS eu-central-2). EGS is likewise established in Switzerland. Processing therefore takes place entirely within Switzerland under ordinary operation.

9.2 Adequacy — EEA transfers. Switzerland benefits from a European Commission adequacy decision (Commission Decision 2000/518/EC of 26 July 2000, most recently reaffirmed following the Commission's periodic review of 15 January 2024). Transfers from the EEA to the Service do not require Standard Contractual Clauses or other transfer safeguards.

9.3 Adequacy — UK transfers. The United Kingdom continues to recognise Switzerland as providing adequate protection, carrying forward the pre-Brexit EU adequacy decision as retained law under the Data Protection Act 2018. Transfers from the UK to the Service do not require the IDTA or the UK Addendum.

9.4 Sub-processor safeguards. Supabase, Inc. is a US-headquartered entity whose support personnel may access the Swiss-hosted environment on a need-to-know basis. EGS has accepted Supabase's Data Processing Agreement, which incorporates the EU Standard Contractual Clauses (Commission Decision 2021/914) and the UK Addendum for any such access, together with Supabase's Transfer Impact Assessment.

9.5 Future transfers. If any further transfer outside Switzerland, the EEA, or the UK becomes necessary, EGS shall implement an appropriate transfer mechanism (adequacy decision, SCCs with transfer impact assessment, Binding Corporate Rules, or equivalent) before the transfer occurs and shall notify the Controller.


10. Liability

Each Party is liable for losses arising from their breach of this Agreement or Data Protection Law. EGS's total aggregate liability is subject to any cap in the Main Agreement, except that neither Party excludes liability prohibited by applicable law (including fraud or wilful misconduct). Where both Parties are liable to a Data Subject for the same damage, liability is apportioned by the degree of each Party's responsibility.


11. Governing Law

This Agreement is governed by Swiss law (Canton of Neuchâtel), without prejudice to any mandatory provisions of GDPR or UK GDPR. The courts of Neuchâtel, Canton of Neuchâtel have exclusive jurisdiction, subject to any mandatory jurisdiction provisions of Data Protection Law (including Data Subjects' right to bring claims before the supervisory authority of their habitual residence).


12. General

This Agreement prevails over the Main Agreement to the extent of any conflict regarding processing of Personal Data. EGS may amend this Agreement to reflect changes in Data Protection Law with 30 days' written notice of material changes; continued use constitutes acceptance. In case of conflict between English and any translation, the English version prevails.


13. Acceptance

This DPA is self-executing.

By creating a Blaze Labels account and processing staff Personal Data through the Service, the Controller accepts this Data Processing Agreement in its entirety. No countersignature is required for this version to be legally binding between the Parties under Article 28(9) GDPR, which permits DPAs in electronic form.

A countersigned PDF version of this DPA, including a completed cover page identifying the Controller legal entity, is available on request from legal@blazeiq.io. EGS will return a signed copy within 10 business days.

Effective date: The date on which the Controller first uses the Service, or the effective date of the countersigned version, whichever is earlier.

Schedule 1 — Technical and Organisational Measures
Schedule 2 — Approved Sub-processors
Sub-processorEntityData locationData processedSafeguards
Supabase Supabase, Inc. Zurich, Switzerland — AWS eu-central-2 All Personal Data in clause 3 (staff names, food items, timestamps, printer IDs) Supabase standard DPA (EU SCCs + UK Addendum); SOC 2 Type II; ISO 27001 via AWS; data hosted exclusively within Switzerland (EU/UK adequacy)

EGS has accepted Supabase's Data Processing Agreement incorporating Standard Contractual Clauses for any processing by Supabase personnel outside the EU/EEA. A copy is available on request (subject to redaction of commercially confidential information).