Terms and conditions of UpMenu website

These Terms and Conditions are effective as of October 1, 2026.

INTRODUCTION

  1. These Terms and Conditions govern the rights and obligations related to the use of the Service by Clients and Users and define the Services provided by the Service Provider through the Service.
  2. Certain Services may be subject to separate terms and conditions, price lists, product terms or other terms accepted by the Client.
  3. If specific terms and conditions applicable to a particular Service differ from these Terms and Conditions, the specific terms and conditions shall prevail with respect to that Service.
  4. These Terms and Conditions do not exclude the application of other terms adopted by the Service Provider, including in particular the UpMenu Payments Terms and Conditions, Affiliate Program Terms and Conditions, Reseller Program Terms and Conditions, or individual agreements concluded between the Client and the Service Provider.
  5. Where an individual agreement concluded between the Client and the Service Provider expressly differs from these Terms and Conditions, the individual agreement shall prevail to the extent of such difference.

ARTICLE 1. DEFINITIONS

The following terms shall have the meanings set out below:

  1. Service Provider – TASTYSOFT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office in Łódź, Poland, registered office and service address: Sienkiewicza 85/87/8 P. XI, 90-057 Łódź, entered in the Register of Entrepreneurs of the National Court Register under KRS No. 0000411725, NIP 7252058310, REGON 101374260. Contact e-mail: [email protected].
  2. Subscription – a configuration of Services within a selected paid variant of Service functionality. The scope and names of available variants are specified in the current Price List.
  3. Price List – the Service Provider's commercial offer specifying prices of Subscriptions, Additional Services and other paid functionalities. The Price List may be made available through the Service, Settings Panel, an individual offer or another document accepted by the Client.
  4. Client – an individual conducting business activity, a legal person or an organisational unit having legal capacity, using the Service in connection with its business activity.
  5. Restaurant Customer – a person or entity placing an order or making a purchase from a Restaurant operated by the Client.
  6. Client Account – an individual account enabling the Client to use the Service and manage the Restaurant.
  7. Managed Services – additional services offered by the Service Provider which may be ordered by the Client under the applicable Price List, product description or separate terms.
  8. Restaurant – a physically or organisationally separate location or locations where the Client conducts restaurant activity or another business activity supported by the Service.
  9. Protected Business Individual – an individual conducting business activity who, under mandatory applicable law, benefits in relation to the Agreement from protections which cannot lawfully be excluded or restricted.
  10. Subscription Period – the period during which the Client may use the Services for a fee under the selected Subscription.
  11. Subscription Fee – the Service Provider's remuneration for Services covered by the Subscription.
  12. Additional Fee – a fee arising from the use of an Additional Service.
  13. Trial Period – a period during which a new Client may use selected functionalities free of charge.
  14. UpMenu or Service – the website and IT system operated by the Service Provider under the UpMenu trade name, including upmenu.com.
  15. Services – services and functionalities made available to the Client by the Service Provider through the Service.
  16. Additional Services – paid or free Services available outside the basic scope of the Subscription or as an extension thereof.
  17. UpMenu Payments – an Additional Service enabling the Client to use services and functionalities related to accepting payments, provided under the UpMenu Payments Terms and Conditions.
  18. UpMenu Payments Terms and Conditions – separate terms and conditions governing the use of UpMenu Payments.
  19. Existing Online Payments – an online payment service provided to the Client under the payment model applicable before the Client accepts the UpMenu Payments Terms and Conditions.
  20. Agreement – the legal relationship established between the Service Provider and the Client under these Terms and Conditions.
  21. User – a person using the Services on behalf of or for the benefit of the Client.
  22. Settings Panel – functionality used to configure the Client Account and place Orders.
  23. Registration – creation of a Client Account through the Service.
  24. Terms and Conditions – these UpMenu Service Terms and Conditions.
  25. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council.
  26. Parties – the Service Provider and the Client.
  27. Order – an order placed by the Client for a Subscription, Additional Service or another paid functionality of the Service.

ARTICLE 2. GENERAL PROVISIONS

  1. These Terms and Conditions govern the use of the Service and the Services provided through it.
  2. Only an entity using the Service in connection with its business activity may be a Client.
  3. A User may act on behalf of or for the benefit of the Client.
  4. The Client may have more than one Client Account and may manage more than one Restaurant.
  5. These Terms and Conditions are made available free of charge in a form enabling them to be saved and reproduced.
  6. Registration is required to become a Client.
  7. Registration requires acceptance of these Terms and Conditions and results in conclusion of the Agreement between the Parties.
  8. Certain Additional Services may require separate activation, an Order or acceptance of specific terms and conditions.
  9. Use of UpMenu Payments requires acceptance of the UpMenu Payments Terms and Conditions and fulfilment of the conditions specified therein.
  10. The Client may participate in affiliate, reseller, partner or other programs under the applicable specific terms and conditions.

ARTICLE 3. SERVICES

  1. Services may include in particular:

a) access to the Service and its content;

b) Client Account;

c) online ordering system;

d) Restaurant websites;

e) mobile applications;

f) reservation system;

g) loyalty program;

h) marketing functionalities;

i) SMS, e-mail and push messaging;

j) reporting and analytics tools;

k) integrations with third parties;

l) UpMenu Payments;

m) Existing Online Payments in the cases specified in Articles 6 and 18;

n) Managed Services;

o) other functionalities specified in the current offer or Price List.

  1. The scope of functionalities available to the Client depends on the selected Subscription, Additional Services and configuration of the Client Account.
  2. Certain Services may be provided using services or infrastructure supplied by third parties.
  3. Detailed terms applicable to an Additional Service may be specified in specific terms and conditions, the Price List, product description or Order.
  4. By using the Services, the Client does not acquire any intellectual property rights in the Service or UpMenu software other than the right to use them within the scope resulting from the Agreement.
  5. Where individual designs or materials are supplied by the Client, the Client retains the rights it holds in such designs or materials.
  6. The Service Provider may develop, modify and update Service functionality, subject to the Client's acquired rights.
  7. The Service Provider may test new or modified functionalities, including through A/B testing, provided that this does not prevent the Client from using the basic functionalities covered by its Subscription.

ARTICLE 4. CLIENT ACCOUNT

  1. Registration takes place using a form or another method made available by the Service Provider.
  2. The Client shall provide the information required during Registration.
  3. Registration requires acceptance of these Terms and Conditions and acknowledgement of the Privacy Policy.
  4. A person registering on behalf of the Client represents that they are duly authorised to do so.
  5. The Client is responsible for the accuracy and currency of data provided during Registration and while using the Service.
  6. The Client is responsible for protecting its login credentials.
  7. The Client may grant Users permissions to use the Client Account.
  8. Actions performed by Users within the scope of their permissions shall be deemed actions of the Client.
  9. Granting administrator permissions authorises the User to act on behalf of the Client within the scope of such permissions.
  10. The Client shall promptly notify the Service Provider of any unauthorised access or suspected compromise of Client Account credentials.

ARTICLE 5. CONFIGURATION OF SERVICES AND SUBSCRIPTION

  1. The Client may select Subscriptions and Additional Services available in the Service Provider's current offer.
  2. Orders may be placed through the Settings Panel or another method made available by the Service Provider.
  3. Before placing an Order, the Client shall receive information concerning the subject matter of the Order and the applicable price.
  4. Orders may affect the configuration of the Services and applicable fees.
  5. A Subscription upgrade may take effect immediately and the applicable fee may be charged proportionally for the remaining part of the Subscription Period.
  6. A Subscription downgrade takes effect from the next Subscription Period unless otherwise agreed.
  7. The Client shall keep its billing and contact details up to date.
  8. Activation of an Additional Service may require additional technical, organisational, regulatory or legal conditions to be fulfilled.
  9. The applicable price shall be the Price List or offer in force when the Order is placed unless individual pricing has been agreed.

ARTICLE 6. ADDITIONAL SERVICES AND PAYMENTS

  1. The Client may order Additional Services available in the current offer.
  2. Additional Services may be charged in particular as:

a) a monthly fee;

b) a one-off fee;

c) a per-unit usage fee;

d) a percentage fee;

e) a per-transaction or per-event fee;

f) another charging mechanism specified in the Price List.

  1. Detailed billing rules applicable to an Additional Service may be specified in the Price List, specific terms and conditions, product description or Order.

UpMenu Payments

  1. UpMenu Payments are provided under the UpMenu Payments Terms and Conditions.
  2. The Client transitions to the UpMenu Payments model upon acceptance of the UpMenu Payments Terms and Conditions.
  3. From that time, the legal terms governing UpMenu Payments are set out in the UpMenu Payments Terms and Conditions.
  4. Technical activation or full availability of UpMenu Payments may additionally require fulfilment of technical, operational, regulatory or verification requirements specified in the UpMenu Payments Terms and Conditions.

Existing Online Payments

  1. A Client who has not accepted the UpMenu Payments Terms and Conditions may continue using Existing Online Payments under these Terms and Conditions and the applicable Price List.
  2. Existing Online Payments are charged as a commission calculated on the value of payments in accordance with the Price List applicable to the Client.
  3. Such commission may be settled against amounts intended for payout to the Client in accordance with the settlement mechanism applicable to Existing Online Payments.
  4. A due and payable Subscription Fee may also be settled in whole or in part through that mechanism where technically available.
  5. By using Existing Online Payments, the Client accepts the settlement mechanism described in paragraphs 9–11.
  6. Upon acceptance of the UpMenu Payments Terms and Conditions, paragraphs 8–12 cease to apply to new payments governed by UpMenu Payments.
  7. Provisions relating to Existing Online Payments may continue to apply after acceptance of the UpMenu Payments Terms and Conditions only to the extent necessary to complete settlements relating to payments or events that arose before the transition to UpMenu Payments.

ARTICLE 7. FEES, PRICE LIST AND TAXES

  1. The Client shall pay the remuneration resulting from the Subscription, Additional Services, Price List and Orders.
  2. All prices are net prices unless expressly stated otherwise.
  3. Prices may be specified in PLN, EUR, USD or another currency stated in the Price List, Order or individual offer.
  4. Taxes, duties, levies, charges or other governmental or public-law liabilities applicable to a Service shall be added to the Service Provider's remuneration where the Service Provider is required to charge or collect them under applicable law, including in particular VAT, GST, Sales Tax or equivalent taxes.
  5. Tax treatment may depend in particular on the Client's country of establishment, tax status, place of business, place of supply of the Services and other relevant circumstances.
  6. Where applicable law requires the Client to account for a tax, the Service Provider may issue the relevant billing document without charging that tax.
  7. The Client shall provide true, complete and current information necessary to determine the correct tax treatment.
  8. A change in tax treatment resulting from a change in law, the Service Provider exercising a legally available option regarding taxation, the Client's tax status, place of supply or another tax-relevant circumstance shall not constitute a change in the net price.
  9. This Article applies to both Existing Online Payments and UpMenu Payments, subject to the specific provisions of the UpMenu Payments Terms and Conditions.
  10. Subscription Fees are payable in advance for each Subscription Period unless the Price List, Order or individual arrangements provide otherwise.
  11. Available payment methods may include payment card, bank transfer or other methods made available by the Service Provider.
  12. For recurring payments, the Client authorises the Service Provider or relevant payment provider to collect subsequent amounts due in accordance with the selected payment method.
  13. Invoices and other billing documents may be issued and delivered electronically using the details provided by the Client.
  14. Payment shall be deemed made when the amount due has been successfully received by the Service Provider or otherwise settled through an agreed settlement mechanism.
  15. In the event of late payment, the Service Provider may charge interest in accordance with applicable law.
  16. Late payment may result in restriction or suspension of the Services.
  17. Changes to the Price List are governed by Article 17.

ARTICLE 8. CLIENT OBLIGATIONS

  1. The Client is responsible for the acts and omissions of Users as for its own acts and omissions.
  2. The Client shall in particular:

a) provide true, complete and current information;

b) correctly configure the Restaurant and its offer;

c) use the Service in accordance with its intended purpose, these Terms and Conditions and applicable law;

d) ensure that its sales, products and services comply with applicable law;

e) maintain any customer-facing terms and conditions, privacy notices and other documentation required in connection with its business;

f) have appropriate legal bases for processing personal data;

g) correctly determine prices and taxes applicable to its products and services;

h) use the Service in a manner which does not interfere with its operation or security;

i) adequately protect the Client Account against unauthorised access;

j) hold the necessary rights to materials uploaded to the Service;

k) pay all amounts due to the Service Provider on time.

  1. The Client uses the Service for the purposes of its own business activity.
  2. The Client is responsible for its offer, sales, fulfilment of orders and other obligations towards Restaurant Customers.
  3. The Client shall use appropriate security measures for devices and software used to access the Service.

ARTICLE 9. SERVICE PROVIDER OBLIGATIONS

  1. The Service Provider shall provide the Services with due care.
  2. The Service Provider shall take reasonable measures to maintain continuity and proper operation of the Service.
  3. The Service Provider shall not be liable for unavailability caused by circumstances outside its reasonable control, including in particular:

a) telecommunications network or Internet failures;

b) acts or omissions of third-party providers;

c) acts or omissions of the Client;

d) cyberattacks;

e) force majeure,

unless liability results from mandatory applicable law or from the Service Provider's failure to

perform or improper performance of its own obligations.

  1. The Service Provider provides the Service as a solution intended for the uses resulting from its described functionality and does not guarantee suitability for Client-specific purposes that have not been agreed with the Service Provider.
  2. Service levels are governed by Appendix No. 1.

ARTICLE 10. LIABILITY

  1. The Service Provider shall not be liable for consequences arising from:

a) content entered by the Client;

b) the Client's lack of a legal basis for processing personal data;

c) disclosure by the Client of login credentials to unauthorised persons;

d) configuration performed by the Client;

e) failure by the Client to comply with these Terms and Conditions;

f) acts or omissions of the Client towards Restaurant Customers.

  1. To the extent permitted by applicable law, the Service Provider's liability shall be limited to actual loss and shall exclude loss of profits.
  2. The Service Provider's total liability arising under the Agreement shall not exceed the total remuneration paid by the relevant Client to the Service Provider during the 12 months preceding the event giving rise to liability.
  3. The limitations set out in paragraphs 2 and 3 shall not apply to the extent that their exclusion or limitation is prohibited by mandatory applicable law.
  4. With respect to a Protected Business Individual, any limitation of liability shall apply only to the extent permitted under mandatory applicable law.
  5. The Client shall be responsible for reasonable and documented losses, costs, fees and claims incurred by the Service Provider to the extent that they result directly from an act or omission of the Client, breach of these Terms and Conditions or breach of applicable law.
  6. The Client shall not be liable for losses, costs, fees or claims to the extent caused by an act or omission of the Service Provider.
  7. Nothing in these Terms and Conditions shall exclude or limit liability that cannot lawfully be excluded or limited.

ARTICLE 11. PERSONAL DATA

  1. The Service Provider acts as controller where personal data is processed for its own purposes related to entering into and performing the Agreement.
  2. Such processing is governed by the Privacy Policy.
  3. Where the Service Provider processes personal data on behalf of the Client, such processing is governed by Appendix No. 2 – Data Processing Agreement (DPA).
  4. Certain Additional Services may involve processing or transfer of personal data by other entities acting under applicable law, their own terms and conditions, privacy notices or agreements.
  5. The Client is responsible for having a lawful basis for providing personal data to the Service Provider where such data is processed on behalf of the Client.

ARTICLE 12. TECHNICAL REQUIREMENTS AND MAINTENANCE

  1. Use of the Service requires:

a) a device with Internet access;

b) current system software;

c) a current web browser or relevant application;

d) technical functionality necessary for proper operation of the Service.

  1. The Client shall maintain appropriate technical and security measures.
  2. Disabling cookies, JavaScript or other required functions may limit Service functionality.
  3. Technical issues may be reported using support channels made available by the Service Provider.
  4. The Service Provider may perform scheduled and emergency maintenance.
  5. Service availability and incident handling are governed by Appendix No. 1 – Service Level Agreement (SLA).

ARTICLE 13. COMPLAINTS

  1. Complaints concerning operation of the Service or provision of Services may be submitted using contact channels made available by the Service Provider.
  2. A complaint should contain information enabling identification of the Client, contact details and a description of the issue.
  3. The Service Provider may request additional information reasonably necessary to investigate the complaint.
  4. Complaints shall be handled within the period required by applicable law or, where no period is prescribed, within 14 days of receipt of a complete complaint.
  5. Services governed by specific terms and conditions may be subject to additional complaint procedures set out in such terms and conditions.

ARTICLE 14. CONCLUSION, SUSPENSION AND TERMINATION OF THE AGREEMENT

  1. The Agreement is concluded upon Registration and acceptance of these Terms and Conditions.
  2. The Agreement is concluded for an indefinite period.
  3. The Client may terminate the Agreement using functionality made available through the Service or by contacting the Service Provider.
  4. Where a paid Subscription Period is in progress, termination generally takes effect at the end of that Subscription Period unless otherwise agreed or required by mandatory applicable law.
  5. The Service Provider may terminate the Agreement by giving one month's notice.
  6. The Service Provider may suspend the Services in particular in the event of:

a) breach of these Terms and Conditions;

b) overdue payments;

c) suspected abuse or unlawful use of the Service;

d) a security risk;

e) conduct exposing the Service Provider to legitimate third-party claims;

f) a legal or regulatory requirement or an order of a competent authority.

  1. The Service Provider may terminate the Agreement with immediate effect in the event of a material breach, including where the Client:

a) uses the Service unlawfully;

b) has provided materially false information;

c) is in material payment default;

d) acts to the detriment of the Service Provider;

e) fails to cease a material breach after notice.

  1. Termination does not release either Party from obligations arising before termination.
  2. Provisions which by their nature survive termination remain effective, including provisions concerning settlements, Refunds, Chargebacks, Reserves, liability and other obligations arising before termination.
  3. Refunds of unused Subscription Fees shall apply only where provided by these Terms and Conditions, individual arrangements or applicable law.

ARTICLE 15. OTHER PROVISIONS

  1. The Service Provider may verify the truthfulness, completeness and currency of information supplied by the Client.
  2. The Service Provider may require documents necessary for Client verification or use of particular Services.
  3. Relevant functionality may be restricted while material verification issues remain unresolved where justified by security, applicable law or the nature of the Service.
  4. Transfer by the Client of rights and obligations arising under the Agreement may require the Service Provider's prior consent.
  5. The Service Provider shall not be liable for failure to perform or improper performance caused by force majeure.
  6. Force majeure means an external event outside a Party's reasonable control which could not reasonably have been foreseen or avoided, including in particular natural disasters, war, riots, widespread infrastructure failures, epidemics or actions of public authorities.
  7. The Client may permit the Service Provider to use the Client's name, trade names, trademarks or materials showing use of the Service for reference or marketing purposes.
  8. Following a justified objection by the Client, the Service Provider shall cease such use within a reasonable period, taking into account materials already produced.

ARTICLE 16. MANDATORY STATUTORY RIGHTS

  1. These Terms and Conditions are intended exclusively for business Clients.
  2. Where mandatory applicable law grants a Client specific statutory rights which cannot lawfully be excluded or restricted, those rights shall apply in accordance with such law.
  3. Where mandatory applicable law grants a Client a statutory right of withdrawal, such right shall apply in accordance with that law.
  4. Nothing in these Terms and Conditions limits any statutory rights which cannot lawfully be excluded or restricted.

ARTICLE 17. AMENDMENTS TO THE TERMS AND CONDITIONS AND PRICE LIST

  1. The Service Provider may amend these Terms and Conditions or the Price List for valid reasons, including in particular:

a) changes in applicable law;

b) new obligations imposed by competent authorities;

c) changes in the scope of the Services;

d) introduction of new functionality or modification of existing functionality;

e) changes in the Service delivery model;

f) changes of suppliers, operators, partners or infrastructure used to provide the Services;

g) changes in the costs of providing the Services;

h) changes in the settlement model;

i) security requirements;

j) changes in taxation or other public-law obligations;

k) relevant changes in legal interpretation or case law;

l) correction of errors, inaccuracies or ambiguities.

  1. Clients shall be notified of amendments by e-mail, through the Client Account or by another durable means of communication.
  2. The notice shall specify at least the scope of the amendments and their effective date.
  3. Unless applicable law requires otherwise, amendments shall take effect no earlier than 14 days after notification.
  4. Amendments shall not prejudice rights already acquired by the Client in respect of Services already paid for, unless the amendment is required by mandatory applicable law or results from circumstances outside the Service Provider's reasonable control.
  5. A Client who does not accept an amendment may terminate the Agreement in accordance with these Terms and Conditions.
  6. A change in tax treatment resulting from a change in law, the Service Provider exercising a legally available option regarding taxation or another tax-relevant circumstance, which does not change the net price, shall not constitute a change in the net price of the Service.

ARTICLE 18. CHANGE OF PAYMENT MODEL

  1. A Client using Existing Online Payments may continue to use them until the Client accepts the UpMenu Payments Terms and Conditions.
  2. Acceptance by the Client of the UpMenu Payments Terms and Conditions is the contractual event determining the Client's transition from Existing Online Payments to the UpMenu Payments model.
  3. From the moment referred to in paragraph 2, the rules governing UpMenu Payments shall be set out in the UpMenu Payments Terms and Conditions.
  4. Technical activation of UpMenu Payments may require fulfilment of additional conditions specified in the UpMenu Payments Terms and Conditions, including Client verification and technical configuration.
  5. Provisions relating to Existing Online Payments may continue to apply after the Client has accepted the UpMenu Payments Terms and Conditions only to the extent necessary to complete settlements, refunds, complaints, disputes, chargebacks or other events relating to payments made before such acceptance.
  6. Transition to UpMenu Payments shall not affect any amounts due, obligations or liabilities arising before the transition.
  7. The tax treatment of Services is governed independently by Article 7 and does not depend on whether the Client uses Existing Online Payments or UpMenu Payments.

ARTICLE 19. FINAL PROVISIONS

  1. Matters not governed by these Terms and Conditions shall be governed by applicable law.
  2. These Terms and Conditions shall be governed by Polish law, subject to mandatory provisions of law applicable to a particular Client which cannot lawfully be excluded.
  3. For Clients other than Protected Business Individuals, disputes shall be subject to the courts having jurisdiction over the Service Provider's registered office to the extent legally permitted.
  4. Where mandatory applicable law provides a Protected Business Individual with different rules regarding jurisdiction, such mandatory rules shall apply.
  5. If any provision of these Terms and Conditions is held to be invalid, ineffective or unenforceable, this shall not affect the validity or enforceability of the remaining provisions unless applicable law provides otherwise.
  6. These Terms and Conditions may be made available in different language versions. In the event of any discrepancy between language versions, the English version shall prevail, unless mandatory applicable law requires otherwise.
  7. The following Appendices form an integral part of these Terms and Conditions:

a) Appendix No. 1 – Service Level Agreement (SLA);

b) Appendix No. 2 – Data Processing Agreement (DPA).

APPENDIX NO. 1

SERVICE LEVEL AGREEMENT (SLA)

1. SCOPE

  1. This Service Level Agreement applies to the paid core functionalities of the UpMenu Service provided directly by the Service Provider.
  2. This SLA does not apply to third-party services, websites, payment infrastructure, telecommunications networks or other infrastructure outside the Service Provider's reasonable control.
  3. Specific Services may be subject to separate service levels where expressly agreed.

2. BUSINESS HOURS

  1. For the purposes of this SLA, Business Hours means 08:00 to 16:00 Central European Time or Central European Summer Time, as applicable, on Business Days.
  2. Business Day means Monday to Friday excluding public holidays in Poland.

3. INCIDENT REPORTING

  1. Technical incidents may be reported 24 hours a day using the support channels made available by the Service Provider.
  2. Incidents are handled during Business Hours unless the Service Provider decides to provide additional support outside Business Hours.
  3. The Client shall provide information reasonably necessary to identify and diagnose the incident.

4. INCIDENT CLASSIFICATION

4.1 Critical Incident

A Critical Incident means a failure of systems controlled by the Service Provider causing

material unavailability of the core Service for the Client where no reasonable workaround is

available.

4.2 Error

An Error means an incident affecting the operation of the Service which does not qualify as a

Critical Incident.

5. INITIAL RESPONSE TARGETS

The Service Provider aims to provide an initial response within:

a) Critical Incident – 8 Business Hours;

b) Error – 24 Business Hours. The initial response may include acknowledgement of the incident, preliminary diagnosis, request for additional information or information concerning further handling.

6. RESOLUTION TARGETS

The Service Provider aims to:

a) resolve a Critical Incident within 1 Business Day;

b) resolve an Error which prevents normal use of the Service and for which no reasonable workaround exists within 3 Business Days;

c) resolve other Errors within 7 Business Days. These periods are operational targets and may be extended where resolution depends on third parties, Client cooperation, external infrastructure or circumstances outside the Service Provider's reasonable control.

7. SERVICE AVAILABILITY

  1. The Service Provider commits to monthly availability of the core Service of at least 98%.
  2. Availability shall be calculated as follows:

Availability = (Total Time – Excluded Time – Unavailable Time) / (Total Time – Excluded

Time) × 100%

  1. Availability shall be measured primarily using monitoring systems operated or designated by the Service Provider.
  2. Unavailable Time means periods during which the core Service is materially unavailable due to circumstances attributable to the Service Provider.

8. EXCLUDED TIME

The following periods shall not be included as Unavailable Time:

a) scheduled maintenance;

b) emergency maintenance reasonably required to protect security, integrity or continuity;

c) force majeure;

d) failures or configuration issues attributable to the Client;

e) failures of telecommunications networks or Internet connectivity outside the Service Provider's reasonable control;

f) failures of third-party services or integrations outside the Service Provider's reasonable control;

g) malicious attacks, including DDoS attacks, where the Service Provider has implemented reasonable protective measures;

h) suspension or restriction resulting from the Client's breach, overdue payments or security issues attributable to the Client;

i) unavailability resulting from changes, configurations or integrations introduced by the Client or a third party acting on the Client's behalf.

9. SERVICE CREDITS

  1. If monthly Availability falls below 98%, the Client may request a service credit.
  2. The service credit shall correspond proportionally to the Subscription Fee attributable to the period during which the core Service was unavailable due to circumstances attributable to the Service Provider.
  3. A request for a service credit should be submitted within 30 days following the month in which the relevant unavailability occurred.
  4. The Client shall provide information reasonably necessary to identify the relevant incident.
  5. Except where mandatory applicable law provides otherwise, a service credit constitutes the Client's contractual remedy specifically for failure to meet the Availability commitment.

10. THIRD-PARTY SERVICES

  1. Availability and performance of third-party services are outside the scope of the Availability commitment unless expressly agreed otherwise.
  2. This includes in particular:

a) payment operators;

b) acquiring banks;

c) issuing banks;

d) card schemes;

e) banking networks;

f) SMS and e-mail providers;

g) external delivery services;

h) third-party integrations;

i) Internet and telecommunications providers.

  1. The Service Provider shall nevertheless use reasonable efforts to cooperate with relevant third parties where necessary to diagnose incidents affecting integrated Services.

APPENDIX NO. 2

DATA PROCESSING AGREEMENT (DPA)

This Data Processing Agreement forms an integral part of the UpMenu Service Terms and

Conditions.

1. DEFINITIONS

For the purposes of this DPA:

  1. Controller, Processor, Processing, Personal Data, Data Subject, Personal Data Breach, Supervisory Authority and other data-protection terms shall have the meanings given to them under the GDPR where applicable.
  2. Client Data means Personal Data processed by the Service Provider on behalf of the Client in connection with the Services.
  3. Subprocessor means a third party engaged by the Service Provider to process Client Data on behalf of the Client.
  4. Applicable Data Protection Law means the GDPR and any other data protection or privacy law applicable to the relevant Processing.

2. ROLES OF THE PARTIES

  1. To the extent that the Service Provider processes Client Data solely on behalf of the Client, the Client acts as Controller and the Service Provider acts as Processor.
  2. Where the Client itself acts as a Processor on behalf of another Controller, the Service Provider acts as a further processor.
  3. This DPA applies only to Processing for which the Service Provider acts as Processor or further processor.
  4. The Service Provider may separately act as Controller with respect to Personal Data processed for its own purposes, including account administration, billing, security, fraud prevention, legal compliance and protection of legal claims. Such Processing is governed by the Service Provider's Privacy Policy and applicable law.
  5. Where a payment operator, financial institution or another third party independently determines the purposes and means of Processing, including where required for KYC, AML, fraud prevention, regulated payment services or regulatory compliance, that entity may act as an independent Controller. Processing performed by such independent Controller is not governed by this DPA.

3. SUBJECT MATTER AND DURATION OF PROCESSING

  1. The subject matter of Processing is the Processing of Client Data necessary to provide, operate, maintain, support and secure the Services.
  2. Processing shall continue for the duration of the Agreement and for such limited period thereafter as is necessary to return, export, secure or delete Client Data or comply with applicable law.

4. NATURE AND PURPOSE OF PROCESSING

Processing may include in particular:

a) collection;

b) recording;

c) organisation;

d) structuring;

e) storage;

f) retrieval;

g) consultation;

h) use;

i) transmission;

j) disclosure to authorised recipients;

k) modification;

l) restriction;

m) deletion;

n) other operations necessary to provide the Services. The purpose of Processing is to provide, operate, maintain, secure and support the Services on behalf of the Client.

5. CATEGORIES OF DATA SUBJECTS

Client Data may relate in particular to:

a) Restaurant Customers;

b) Users;

c) employees and other personnel of the Client;

d) persons making reservations;

e) members of loyalty programs;

f) recipients of Client marketing communications where lawfully processed;

g) individuals communicating with the Client through the Service;

h) other persons whose Personal Data the Client lawfully enters into or processes through the Service.

6. CATEGORIES OF PERSONAL DATA

Client Data may include in particular:

a) first and last name;

b) e-mail address;

c) telephone number;

d) delivery or contact address;

e) company information;

f) order information;

g) order history;

h) order values and discounts;

i) loyalty-program information;

j) reservation information;

k) User account information;

l) communications and comments;

m) technical and device information;

n) payment-related identifiers and transaction metadata;

o) other Personal Data entered into the Service by or on behalf of the Client. The Service is not intended for storage by the Service Provider of full payment card credentials unless expressly agreed otherwise.

7. SPECIAL CATEGORIES OF PERSONAL DATA

  1. The Services are not intended for systematic Processing of special categories of Personal Data.
  2. The Client shall not intentionally provide such data unless Processing is necessary, lawful and appropriate for use of the relevant Service.
  3. The Client remains responsible for determining whether it has a lawful basis for such Processing.

8. DOCUMENTED INSTRUCTIONS

  1. The Service Provider shall process Client Data only on documented instructions from the Client unless Processing is required by applicable law.
  2. Instructions include:

a) this DPA;

b) the Agreement;

c) configuration and use of the Service by or on behalf of the Client;

d) other documented instructions accepted by the Service Provider.

  1. If applicable law requires the Service Provider to process Client Data other than on the Client's instructions, the Service Provider shall inform the Client before Processing unless prohibited by law.
  2. If the Service Provider reasonably believes that an instruction infringes Applicable Data Protection Law, it shall inform the Client unless prohibited by law.

9. CLIENT RESPONSIBILITIES

The Client is responsible for:

a) the lawfulness of Client Data;

b) having an appropriate legal basis for Processing;

c) providing legally required information and notices to Data Subjects;

d) ensuring that its instructions comply with Applicable Data Protection Law;

e) accuracy and appropriateness of data entered into the Service;

f) determining whether the Service is suitable for the Client's intended Processing.

10. CONFIDENTIALITY

  1. Persons authorised by the Service Provider to process Client Data shall be subject to confidentiality obligations.
  2. Access to Client Data shall be limited to persons who require such access for legitimate purposes related to the Services.
  3. Confidentiality obligations shall continue after the relevant person's access to Client Data has ended.

11. SECURITY

  1. The Service Provider shall implement appropriate technical and organisational measures taking into account:

a) the state of the art;

b) implementation costs;

c) the nature, scope, context and purposes of Processing;

d) risks to the rights and freedoms of Data Subjects.

  1. Measures may include, as appropriate:

a) access controls;

b) authentication and authorisation mechanisms;

c) encryption of data in transit;

d) logical separation of customer environments;

e) backup procedures;

f) logging and monitoring;

g) vulnerability management;

h) incident-response procedures;

i) employee security and confidentiality measures;

j) business continuity and recovery procedures.

  1. Security measures may evolve over time, provided that the overall level of protection is not materially reduced.

12. PERSONAL DATA BREACHES

  1. The Service Provider shall notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Data.
  2. The notification shall include, to the extent reasonably available:

a) the nature of the Personal Data Breach;

b) categories of affected Data Subjects;

c) categories of affected Personal Data;

d) likely consequences;

e) measures taken or proposed to address the breach.

  1. Where all relevant information is not immediately available, information may be provided in phases.
  2. Notification of a Personal Data Breach shall not constitute an admission of fault or liability.

13. DATA SUBJECT REQUESTS

  1. Taking into account the nature of Processing, the Service Provider shall provide reasonable assistance to enable the Client to respond to lawful Data Subject requests.
  2. Where the Service Provider receives a request directly relating to Client Data, it shall normally forward or redirect that request to the Client unless applicable law requires otherwise.
  3. The Client remains responsible for responding to Data Subject requests where the Client acts as Controller.

14. ASSISTANCE WITH DATA PROTECTION OBLIGATIONS

Taking into account the nature of Processing and information available to it, the Service Provider

shall provide reasonable assistance concerning:

a) security obligations;

b) Personal Data Breach assessment and notification;

c) data protection impact assessments;

d) prior consultations with Supervisory Authorities;

e) other obligations under Article 28 GDPR where applicable.

15. SUBPROCESSORS

  1. The Client grants the Service Provider general authorisation to engage Subprocessors.
  2. The Service Provider shall maintain an up-to-date list of material Subprocessors used in connection with the Services.
  3. The list may be made available:

a) through the Service or Client Account;

b) on the Service Provider's website; or

c) upon request.

  1. Where reasonably practicable, the Service Provider shall notify the Client in advance of material additions or replacements of Subprocessors.
  2. The Client may object to a new Subprocessor on reasonable grounds relating specifically to the protection of Personal Data.
  3. The Parties shall cooperate in good faith to address a justified objection.
  4. Where the objection cannot reasonably be resolved and use of the relevant Subprocessor is necessary to provide the affected Service, either Party may terminate the affected Service.
  5. The Service Provider shall impose appropriate contractual data protection obligations on Subprocessors.
  6. The Service Provider remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.

16. INTERNATIONAL DATA TRANSFERS

  1. Client Data may be processed in countries other than the Client's country.
  2. Where Applicable Data Protection Law restricts international transfers, the Service Provider shall use an appropriate lawful transfer mechanism.
  3. Such mechanisms may include:

a) an adequacy decision;

b) Standard Contractual Clauses approved by the European Commission;

c) recognised certification or contractual mechanisms;

d) another legally permitted safeguard.

  1. Where required, the Service Provider shall implement supplementary measures appropriate to the relevant transfer.

17. AUDITS AND INFORMATION

  1. The Service Provider shall make available information reasonably necessary to demonstrate compliance with this DPA.
  2. The Client should first use available:

a) compliance documentation;

b) security documentation;

c) certifications;

d) audit reports;

e) written responses supplied by the Service Provider.

  1. Where further verification is reasonably necessary, the Client may request an audit no more than once per calendar year unless:

a) required by a Supervisory Authority;

b) required following a material Personal Data Breach;

c) otherwise required by Applicable Data Protection Law.

  1. An audit shall:

a) be subject to reasonable prior notice;

b) take place during normal business hours;

c) avoid unreasonable disruption to the Service Provider;

d) protect confidential information of the Service Provider and other clients;

e) not include access to Personal Data relating to other clients;

f) not include penetration testing or security testing without the Service Provider's prior written consent.

  1. The Client shall bear its own costs of an audit unless the audit demonstrates a material breach by the Service Provider.

18. RETURN AND DELETION OF CLIENT DATA

  1. During the Agreement, the Client may export Client Data using functionality made available through the Service.
  2. Following termination of the Agreement, the Client may request export of available Client Data within 30 days unless otherwise agreed.
  3. Following expiry of the applicable retention period, the Service Provider shall delete or anonymise Client Data unless retention is required by applicable law.
  4. Client Data may remain temporarily in backups in accordance with the Service Provider's standard backup-retention cycles.
  5. Data retained in backups shall remain protected and shall not be actively processed except where reasonably necessary for continuity, recovery, security or compliance.

19. PUBLIC AUTHORITY REQUESTS

  1. Where legally permitted, the Service Provider shall inform the Client of a legally binding request by a public authority for access to Client Data.
  2. The Service Provider may disclose Client Data where required by applicable law or a binding decision of a competent authority.

20. LIABILITY

  1. Liability arising under this DPA shall be subject to the liability provisions of the main Terms and Conditions.
  2. This limitation shall not apply to the extent that Applicable Data Protection Law prohibits such limitation.

21. PRECEDENCE

  1. In the event of a conflict between this DPA and the main Terms and Conditions concerning Processing of Client Data, this DPA shall prevail.
  2. In all other matters, the main Terms and Conditions shall continue to apply.

PREVIOUS VERSIONS OF THE TERMS AND CONDITIONS