This Data Processing Agreement (“DPA”) forms part of the Terms of Use between the customer that accepts the Terms of Use (“Customer”) and Swanson International, Inc. DBA Linkasoarus, 400 Gilead Rd #86, Huntersville, NC 28078 (“Linkasoarus”). It applies whenever Linkasoarus processes Personal Data on Customer’s behalf through the Services, including Personal Data contained in Platform Data retrieved from Delivery Platforms.
Effective Date: October 2, 2026. Replaces the version dated April 20, 2026.
Capitalized terms not defined here have the meaning given in the Terms of Use.
“Controller”, “Processor”, “Sub-processor”, “Personal Data”, “Processing” and “Data Subject” have the meanings given in Data Protection Laws. Where a law uses different words (for example “business”, “service provider” and “personal information” under the CCPA), those words are read as the matching terms here.
“Data Protection Laws” means all laws that apply to the Processing of Personal Data under this DPA, including the EU General Data Protection Regulation (GDPR), the Polish Personal Data Protection Act (RODO), the California Consumer Privacy Act as amended by the CPRA (CCPA) and other U.S. state privacy laws, and Canada’s PIPEDA and Quebec’s Law 25.
“Customer Data” means Personal Data that Linkasoarus Processes on Customer’s behalf through the Services, including Platform Data and data from any other Third-Party Account Customer connects. Customer Data does not include Account Data.
“Account Data” means the Personal Data of Customer’s own representatives that Linkasoarus collects to open and run Customer’s account and bill for the Services (for example names, email addresses and billing details). Linkasoarus is an independent controller of Account Data under its Privacy Policy, and this DPA does not apply to it.
“Delivery Platform” means a third-party online ordering or delivery marketplace supported by the Services: currently Uber Eats, with DoorDash, Grubhub and SkipTheDishes to be added as each integration becomes available.
“Platform Account” means Customer’s merchant or business account with a Delivery Platform, and “Platform Data” means the data Linkasoarus retrieves from a Platform Account, which may include order records, item and menu data, refunds, adjustments and chargebacks, payout and settlement records, ratings and comments, and limited customer information such as a customer’s name, delivery address and phone number as the Delivery Platform makes it available.
“Services” means the Linkasoarus platform, applications, APIs and Integrations described in the Terms of Use, including Dispute Services.
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data.
For Customer Data, Customer is the Controller and Linkasoarus is the Processor. Where Customer itself acts as a processor for another party (for example a franchisor or a management company), Customer warrants that it has the authority to appoint Linkasoarus as a sub-processor on these terms, and Linkasoarus acts as Customer’s sub-processor.
Linkasoarus Processes Customer Data only to provide the Services and only as described in this DPA. Linkasoarus does not decide the purposes or means of Processing Customer Data.
If this DPA conflicts with the Terms of Use on a data-protection matter, this DPA controls. Where Standard Contractual Clauses apply under Section 10, they control over this DPA to the extent of any conflict.
Subject matter: provision of the Services to Customer. Duration: the term of Customer’s account plus the deletion period in Section 14. Frequency: continuous while an Integration is connected.
Nature and purpose of the Processing:
Account and team management for Customer’s locations and users.
Social media content sharing, scheduling and publishing, and review management (including AI-assisted drafting of replies to customer reviews, see Annex III), through Third-Party Accounts Customer connects (currently Facebook Pages and Google Business Profile; Instagram business accounts once supported).
Delivery Platform Integrations: retrieval and storage of Platform Data; sales, payout and reconciliation reporting; menu, item and ratings insights.
Dispute Services: presenting refund, adjustment and chargeback requests to Customer, routing them to the team members Customer chooses, recommending a response based on statistical analysis of comparable requests and outcomes, drafting the text of a dispute with the AI service listed in Annex III when a user asks, and submitting a dispute to the Delivery Platform only on the specific instruction of Customer or a team member Customer has authorized.
Analytics, service improvement and security, including the creation of aggregated or de-identified statistics that do not identify Customer, its locations or its customers.
Categories of Data Subjects:
Customer’s owners, managers, employees and team members.
Customer’s end customers: consumers who place orders through a Delivery Platform or interact with Customer’s connected social media accounts.
Delivery couriers and Delivery Platform support staff, to the limited extent they appear in order and dispute records.
Categories of Personal Data:
Team members: name, email address, role, time zone, account activity.
End customers (as the Delivery Platform makes them available): name, delivery address, phone number (often masked by the platform), order contents, order value, timestamps, refund, adjustment and chargeback details, ratings and comments.
Uber Eats, the only Delivery Platform connected today, does not provide customer names, addresses or telephone numbers in the reports Linkasoarus receives.
Platform Account credentials or access tokens supplied by Customer, stored in encrypted form.
Social media profile data and public interactions on Customer’s connected accounts.
Special categories of Personal Data: none are intended or required. Customer agrees not to submit special-category data, payment card data or government identifiers through the Services.
Customer’s documented instructions are: this DPA, the Terms of Use, the feature settings Customer selects in the Services (including the team members Customer designates for Dispute Services and each instruction to submit a dispute), and any further written instructions Customer gives that Linkasoarus accepts. Linkasoarus will tell Customer if, in its opinion, an instruction infringes Data Protection Laws.
Customer is responsible for: (a) the lawful basis for the Processing, including under GDPR and RODO; (b) giving any notices to, and obtaining any consents from, its team members and its end customers that Data Protection Laws require; (c) having the authority to connect each Platform Account and to permit Linkasoarus to access Platform Data under the Delivery Platform’s terms; and (d) the accuracy of the information it gives Linkasoarus for Dispute Services and each decision to submit a dispute.
Linkasoarus will:
Process Customer Data only on Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case Linkasoarus will tell Customer before Processing unless the law prohibits it.
Ensure that every person it authorizes to Process Customer Data is bound by a duty of confidentiality.
Implement and maintain the technical and organizational measures in Section 8 (Annex II).
Engage Sub-processors only under Section 9 (Annex III).
Assist Customer, taking into account the nature of the Processing, in responding to Data Subject requests (Section 11) and in meeting Customer’s obligations on security, Security Incident notification, data protection impact assessments and prior consultation with supervisory authorities.
Delete or return Customer Data at the end of the Services under Section 14.
Keep records of its Processing activities and make available the information reasonably needed to demonstrate compliance with this DPA, and allow audits under Section 13.
Tell Customer promptly if it can no longer meet its obligations under this DPA.
For Platform Data and any other Customer Data from a Third-Party Account, Linkasoarus further commits that it will:
Access the Third-Party Account through the provider’s official API or authorization process wherever one is available, and comply with the provider’s developer and data terms. Where a provider offers no API and Customer supplies login credentials, Linkasoarus will use them only for the features Customer enables.
Store credentials and access tokens encrypted at rest, restrict access to them to the systems and personnel that need them, never display a stored password, and revoke tokens and stop using credentials when the Integration is disconnected or the account closed.
Use Platform Data only to provide the Services to Customer, to maintain, secure and improve the Services, and to produce aggregated or de-identified statistics that do not identify Customer, its locations or its end customers.
Not sell Platform Data, and not share order-level or customer-level Platform Data with other Linkasoarus customers, other franchisees, a franchisor or brand network, advertisers or any other third party, other than Sub-processors acting on Linkasoarus’s instructions.
Keep each customer’s data logically separated from every other customer’s data, so that one customer cannot view another’s Platform Data.
Not combine Platform Data with Personal Data obtained from other sources except as needed to provide the Services to Customer.
Use only the AI service listed in Annex III, and only for the features listed there. It never receives Customer's account credentials or access tokens, and Linkasoarus never sends it a customer's name, address or telephone number from a Delivery Platform; a customer's comment is sent as the customer wrote it. The AI service does not use this data to train its models.
Submit a dispute under Dispute Services only on the specific instruction of Customer or a team member Customer has authorized, never on Linkasoarus’s own initiative; keep a record of each instruction, each dispute submitted and the Delivery Platform’s response, and make that record available to Customer in the Services.
To the extent the CCPA or another U.S. state privacy law applies, Linkasoarus is Customer’s “service provider” or “processor”, and Customer discloses Customer Data to Linkasoarus only for the limited and specified business purpose of providing the Services. Linkasoarus will not: (a) sell or share Customer Data; (b) retain, use or disclose Customer Data for any purpose other than the business purposes specified in this DPA, or outside the direct business relationship between Customer and Linkasoarus; or (c) combine Customer Data with Personal Data it receives from other sources, except as permitted by law. Linkasoarus will comply with the applicable law and provide the same level of privacy protection the law requires of Customer, will notify Customer if it determines it can no longer meet these obligations, and grants Customer the right to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Data. Linkasoarus certifies that it understands these restrictions and will comply with them.
Linkasoarus maintains the following measures, which reflect what is in place in production as of the date of this DPA, and reviews them at least once a year. Linkasoarus may update these measures as the Services evolve, provided the overall level of protection is not reduced.
Encryption in transit: TLS on all connections between users, the Services and connected platforms.
Encryption at rest: files and uploads stored in Amazon S3 are encrypted at rest.
Database: the production database runs on Amazon RDS with automated backups retained for 35 days. Encryption at rest for the database itself is not yet enabled.
Credential protection: access tokens and credentials for connected Delivery Platform accounts are encrypted before they are stored and are reachable only by the integration code.
Hosting: Amazon Web Services, with network controls and firewalls in place.
Tenant separation: each customer’s data is separated inside the platform, enforced in the application on every customer-scoped query.
Change control: code review on every change, automated checks in continuous integration, and production kept separate from staging and local environments.
Personnel: the AKRA developers who work on Linkasoarus have signed confidentiality and privacy agreements covering all Linkasoarus data.
Incident response: a written security incident procedure that sets out who is called, what is rotated and switched off first, what is recorded, and who notifies customers, regulators and platforms within the time this DPA requires.
Vulnerability management: automated dependency scanning on every code repository, with alerts raised to the development team, and platform patching as part of regular maintenance. Continuous external security rating and scanning through SecurityScorecard (securityscorecard.com). Linkasoarus does not claim a penetration test or a SOC 2 or ISO certification.
Customer gives general authorization for Linkasoarus to use the Sub-processors below. Linkasoarus will give Customer at least 30 days’ notice (by email or by updating this page and notifying Customer in the Services) before adding or replacing a Sub-processor that Processes Customer Data. Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected Services. Linkasoarus imposes data-protection obligations on each Sub-processor that are no less protective than this DPA and remains responsible for their performance.
Amazon Web Services, Inc. (United States): cloud hosting, storage and backups for all Customer Data.
AKRA POLSKA Sp. z o.o., ul. Radzikowskiego 35, 31-315 Kraków, Poland: software development and technical support for the platform. AKRA’s lead developers assigned to Linkasoarus have access to the platform’s code and, for support and maintenance, to production systems, limited to what the work requires. They have signed confidentiality and privacy agreements through AKRA covering all Linkasoarus data.
Elavon, Inc. (United States): payment card processing for Customer’s subscription. Elavon receives Account Data only, never Platform Data.
OpenAI, L.L.C. (United States): AI assistance for four features. Drafting social media posts: the keywords the user enters. Drafting replies to customer reviews: the review text, its star rating and the store name, with the reviewer's name removed before sending. Drafting the text of a dispute: the order identifier, order time, reported issue, refunded items, the amount charged to the store, the customer's comment where the Delivery Platform provides one, and a small number of Customer's own past successful dispute texts with all figures removed. Explaining refund patterns: aggregated refund figures (counts, percentages and amounts by store, item and time of day). What is never sent: Customer's account credentials or access tokens, and any customer name, address or telephone number from a Delivery Platform; a customer's comment is sent as the customer wrote it. Safeguards: Linkasoarus connects through the OpenAI API, not a ChatGPT account, under OpenAI's Data Processing Addendum, which is incorporated into OpenAI's Services Agreement and applies to Linkasoarus's API use. Sharing of inputs, outputs, feedback and evaluation data with OpenAI for model training is disabled on Linkasoarus's OpenAI organization, so the text sent is not used to train OpenAI's models. OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring and then deletes them. OpenAI maintains a SOC 2 Type 2 report.
Twilio Inc., operating SendGrid (United States): delivery of all account and notification emails sent by the Services, such as review alerts, publishing confirmations and, when the feature is enabled, dispute results. SendGrid receives the recipient’s email address and the content of each message; for review alerts, that content includes the reviewer’s public display name and review text as shown on Google. Messages are processed under Twilio’s data processing addendum. SendGrid never receives Customer’s account credentials or access tokens, and it has no access to the platform or its databases.
Functional Software, Inc. (Sentry) (United States): error monitoring. When an error occurs, it receives the error details and the signed-in user's email address, IP address and the page requested.
Datadog, Inc. (United States): performance monitoring. It receives request and database timings and the signed-in user's identifier.
Delivery Platforms (Uber Eats, DoorDash, Grubhub, SkipTheDishes) and social media and review platforms (Meta and Google) are independent controllers chosen by Customer. They are not Sub-processors of Linkasoarus.
Customer Data is hosted in the United States. Where Customer Data protected by the GDPR or Swiss law is transferred to a country without an adequacy decision, the parties rely on the European Commission’s Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor, as applicable), which are incorporated into this DPA by reference. Customer is the data exporter and Linkasoarus the data importer; Annexes I to III of this DPA serve as the annexes to those clauses.
For Customer Data about individuals in Canada (including data from SkipTheDishes once that integration is available), Linkasoarus provides a comparable level of protection through this DPA and will assist Customer with any notice, assessment or consent that PIPEDA or Quebec’s Law 25 requires for the transfer.
Linkasoarus will tell Customer if it becomes subject to a legal requirement that prevents it from honoring these transfer safeguards.
Linkasoarus will forward to Customer, within five business days, any request it receives from a Data Subject concerning Customer Data, and will not respond to the Data Subject except to refer the request to Customer, unless Customer instructs otherwise or law requires. Taking into account the nature of the Processing, Linkasoarus will provide reasonable assistance, through the Services where possible, so that Customer can respond to requests for access, correction, deletion, restriction, objection and portability within the time Data Protection Laws allow.
Linkasoarus will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer Data. The notice will describe the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point, with information supplied in phases as it becomes available. Linkasoarus will cooperate with Customer’s investigation and with any notification Customer must make to a supervisory authority or to Data Subjects (including the 72-hour requirement under the GDPR), and will not identify Customer in any public statement about the incident without Customer’s consent unless law requires it.
On written request, no more than once in any 12-month period unless a Security Incident has occurred or a supervisory authority requires it, Linkasoarus will make available the information reasonably necessary to demonstrate compliance with this DPA: its security documentation, summaries of any third-party assessments or certifications it holds, and written answers to a reasonable security questionnaire. If that information is not sufficient, Customer or an independent auditor bound by confidentiality may conduct an audit, on at least 30 days’ notice, during business hours, in a manner that does not disrupt Linkasoarus’s operations or expose other customers’ data, at Customer’s cost. The parties will agree to the scope in advance.
Linkasoarus keeps Customer Data only for as long as needed to provide the Services. When a Customer disconnects an Integration, Linkasoarus stops collecting data from it and will delete the Platform Data from that Integration within 30 days of Customer’s request. When Customer’s account ends, Linkasoarus will, at Customer’s choice made within 30 days, return Customer Data in a commonly used electronic format or delete it, and will delete it in any case within 30 days after that period, unless law requires longer retention or the data is needed to resolve a dispute already in progress. Copies in routine backups are retained for 35 days and then overwritten, and are not restored except for disaster recovery. On request, Linkasoarus will confirm deletion in writing.
Each party is responsible for its own compliance with Data Protection Laws. Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Use, except that nothing limits a party’s liability to the extent that applicable law prohibits such limitation, including liability that cannot be limited under the Standard Contractual Clauses.
This DPA takes effect when Customer accepts the Terms of Use or first connects a Third-Party Account, whichever is earlier, and continues for as long as Linkasoarus Processes Customer Data. Linkasoarus may update this DPA to reflect changes in law or in the Services by posting the revised version at www.linkasoarus.com/dpa and notifying Customer; changes that reduce Customer’s protections take effect no earlier than 30 days after notice. This DPA is governed by the laws of the State of North Carolina, subject to mandatory Data Protection Laws that apply to the Processing.
Swanson International, Inc. DBA Linkasoarus
400 Gilead Rd #86, Huntersville, NC 28078
Data protection contact: developer@Linkasoarus.com
704-666-2158