Data Processing Addendum

Last updated: August 2, 2026

Please review before relying on this document

This Data Processing Addendum (“DPA”) forms part of the Agreement between Bake Boost FZE LLC (“BakeOnyx”) and its customers. It follows the standard GDPR Article 28 structure and is provided for transparency; it is not legal advice, and you should review it with qualified data-protection counsel for your specific circumstances. A counter-signable copy is available on request at privacy@bakeonyx.ai.

1. Parties and scope

This DPA is entered into between Bake Boost FZE LLC, of Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates (“BakeOnyx,” “Processor”), and the customer identified in the Agreement (the “Customer,” “Controller”). It is incorporated into and forms part of the Terms of Serviceand any order for the BakeOnyx service (together, the “Agreement”).

It applies to BakeOnyx’s Processing of Personal Data on the Customer’s behalf where the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR, or an equivalent data-protection law (“Data Protection Law”) applies. Where this DPA conflicts with the Agreement on the subject of data protection, this DPA prevails.

2. Roles of the parties

The Customer is the Controller of the Personal Data it, its staff, and its store and wholesale customers submit to the service. BakeOnyx is the Processor and Processes that Personal Data only to provide the service. Where the Customer is itself a processor for a third-party controller, BakeOnyx acts as a sub-processor and the Customer warrants it has the authority to engage BakeOnyx on those terms.

Capitalized terms not defined here (Personal Data, Processing, Data Subject, Personal Data Breach, Supervisory Authority, and similar) have the meanings given in Data Protection Law.

3. Processing on documented instructions

BakeOnyx will Process Personal Data only on the Customer’s documented instructions, including as set out in the Agreement, this DPA (see Annex 1), and the Customer’s configuration and use of the service, unless required to do otherwise by law — in which case BakeOnyx will inform the Customer beforehand unless the law prohibits it. BakeOnyx will promptly tell the Customer if, in its opinion, an instruction infringes Data Protection Law.

BakeOnyx does notsell Personal Data, use it for its own advertising, or use Customer Personal Data to train BakeOnyx’s own AI models. Personal Data sent to AI sub-processors is Processed solely to provide the relevant feature to the Customer.

4. Confidentiality

BakeOnyx ensures that persons authorized to Process the Personal Data are bound by confidentiality obligations and Process the Personal Data only as necessary to provide the service.

5. Security

BakeOnyx implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the Personal Data, as required by Article 32 GDPR. A summary of current measures is at Annex 2. The Customer is responsible for its own use of the service, including access management for its users and the configuration of features that transmit data to third-party integrations at its direction.

6. Sub-processing

The Customer provides general authorization for BakeOnyx to engage sub-processors to Process Personal Data. The current list is maintained at bakeonyx.ai/subprocessors and forms Annex 3. BakeOnyx imposes on each sub-processor data-protection obligations no less protective than those in this DPA and remains responsible for their performance.

BakeOnyx will give the Customer notice of any intended addition or replacement of a sub-processor (by updating the sub-processor page and, for subscribers, by email to the address on file — subscribe at privacy@bakeonyx.ai), giving the Customer the opportunity to object on reasonable data-protection grounds. If an objection cannot be resolved, the Customer’s remedy is to terminate the affected part of the service.

7. International transfers

BakeOnyx is established in the United Arab Emirates, outside the European Economic Area (EEA). Application data is primarily hosted within the EEA (see bakeonyx.ai/subprocessors), but to the extent BakeOnyx, as data importer, Processes EEA personal data from outside the EEA, that transfer is governed by the European Commission’s Standard Contractual Clauses (SCCs), module two (controller-to-processor), which are incorporated into this DPA by reference and completed with its Annexes, together with any supplementary measures required.

Some sub-processors also Process Personal Data outside the EEA. Where they do, BakeOnyx ensures an appropriate transfer mechanism under Chapter V GDPR is in place — SCCs and, where applicable, the EU–US Data Privacy Framework — with any supplementary measures required. The mechanism for each sub-processor is indicated at bakeonyx.ai/subprocessors.

8. Assistance to the Customer

Taking into account the nature of the Processing, BakeOnyx will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject requests to exercise their rights (access, rectification, erasure, restriction, portability, and objection). Where a Data Subject contacts BakeOnyx directly regarding Customer Personal Data, BakeOnyx will refer them to the Customer. BakeOnyx will also assist the Customer with data-protection impact assessments and prior consultations under Articles 35–36 GDPR, taking into account the information available to BakeOnyx.

9. Personal Data Breach

BakeOnyx will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide the Customer with information reasonably available to it to help the Customer meet its own notification obligations under Articles 33–34 GDPR.

10. Return and deletion

On termination of the service, and at the Customer’s choice, BakeOnyx will delete or return the Personal Data and delete existing copies, unless retention is required by law. Deletion follows BakeOnyx’s standard retention schedule described in the Privacy Policy (including any grace period for account recovery and routine backup rotation).

11. Audits and information

BakeOnyx will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits are subject to reasonable notice, confidentiality, frequency limits, and the security and continuity of the service; BakeOnyx may satisfy audit requests by providing relevant documentation and responding to a reasonable questionnaire.

12. Liability and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA remains in effect for as long as BakeOnyx Processes Personal Data on the Customer’s behalf.


Annex 1 — Details of Processing

  • Subject matter: provision of the BakeOnyx bakery-management service.
  • Duration: for the term of the Agreement plus the retention periods in the Privacy Policy.
  • Nature and purpose:hosting, storage, and Processing of Personal Data to operate the service’s features (orders, customers, invoicing, messaging, and AI-assisted insights, drafting, and forecasting) on the Customer’s instructions.
  • Categories of Data Subjects:the Customer’s staff and users; the Customer’s store, wholesale, and prospective customers; and the Customer’s business contacts.
  • Categories of Personal Data: identification and contact details (name, email, phone, address); order and transaction history; messages and inquiries; and, where the Customer provides them, preferences and event details. BakeOnyx does not require special categories of data; the Customer should avoid submitting them except where a feature is intended for it (e.g. allergen/dietary information the Customer chooses to record).
  • Special categories:none required; any submitted are at the Customer’s direction and responsibility.

Annex 2 — Technical and organizational measures

Current measures include, without limitation:

  • Encryption of data in transit (TLS) and encryption of sensitive tokens at rest.
  • Logical tenant isolation — every bakery is a separate tenant and all data access is scoped to the authenticated tenant.
  • Role-based access control for the Customer’s own users (owner, manager, staff).
  • Least-privilege administrative access and authentication controls for BakeOnyx personnel.
  • Encrypted, access-controlled backups with retention and off-site storage.
  • Application and error monitoring, and audit logging of security-relevant events.
  • Dependency vulnerability scanning in the deployment pipeline.

Measures evolve with the service and the state of the art; BakeOnyx may update them provided the level of security is not materially reduced.

Annex 3 — Sub-processors

The authorized sub-processors are those listed, and kept current, at bakeonyx.ai/subprocessors, including their purpose, location, and international-transfer safeguard. That page is incorporated into this DPA by reference.