Version 1.3 · Last updated: September 2, 2026
Sub-processors and Technical Providers
The table distinguishes data verified in the provider's public documentation from configurations that depend on the MenuXS account. DPAs and referenced terms are incorporated into the relevant online agreement unless different negotiated terms apply.
Infrastructure, Communications, and Payments
| Provider and Purpose | Declared Location and Transfers | MenuXS Retention/Configuration |
|---|---|---|
| DigitalOcean Infrastructure, Spaces, and CDN | Primary storage configured in FRA1, Frankfurt. DPA with DPF and SCC as a fallback mechanism; sub-processors published by the provider. | Private AI import prefix with a maximum expiry of 24 hours. Other objects remain for the duration of the service or until deletion. |
| Vercel Frontend and Website | Primary processing declared in the United States; DPA and SCC for applicable transfers. | Runtime logs depend on the plan (from 1 hour to 30 days). No Log Drain should receive personal content without updating this page. |
| Stripe Subscriptions, Billing, and Payments | Global processing; DPA incorporated into the Stripe Services Agreement, DPF, and SCC. Stripe may act as a processor or controller depending on the purpose. | MenuXS retains identifiers and transaction status, not full card details. Stripe retention according to financial, anti-fraud, and legal obligations. |
| OpenAI (optional, with prior consent) ChatGPT Ads measurement and attribution | Processing and possible international transfers under the terms and safeguards applicable to OpenAI advertising services. | Active only with Marketing consent in the merchant funnel. MenuXS sends conversion events, pseudonymous advertising references, and technical data; restaurant-customer data is not sent through this pixel. |
| MailerLite Waitlist and Newsletter | For EEA customers served by the European entity, subscriber data declared in the EU (Netherlands; Germany for legacy). DPA and SCC; DPF where applicable. | Until revocation or expiry of MenuXS policy; deletion/suppression via provider account. |
| MailerSend Transactional Emails | DPA with SCC and list of sub-processors; infrastructure declared at Google Cloud EMEA. | Messages and logs according to plan and account settings; deletion upon request and within provider obligations. |
| Twilio (Optional) SMS | Global processing; DPA, SCC, and group Binding Corporate Rules. | Not active if credentials are not configured. Retention specific to product and deletion via Twilio functions/APIs. |
| Google / Apple (Optional) Social Login | Processing according to chosen provider terms and declared international transfers. | MenuXS retains provider identifier and verified email; local linkage is removed in the account deletion workflow. |
AI Import
| Provider | Declared Use and Processing | MenuXS Control |
|---|---|---|
| OpenRouter | Intermediary with global processing and potential transfer to the USA. DPA incorporated into commercial terms. By default, does not retain prompts/completions unless opted-in to logging. | Each request sets provider.zdr=true. Input/output logging and response caching must not be enabled on the account. Provider, model, and region are logged per job. |
| Google Gemini | Default downstream provider. For paid services, Google declares no training on prompts/responses; limited logs for abuse prevention and in-memory cache up to 24 hours may exist. | OpenRouter may only use declared ZDR endpoints. The actual model is logged. |
| Cloudflare Workers AI | Default PDF parser, configurable. Cloudflare declares not to use Customer Content for training or improvement without consent; storage only if separate storage services are used. | The actual parser is logged; MenuXS does not configure Cloudflare storage for this function. |
| Mistral AI | Alternative OCR parser. Opt-out training and ZDR are organizational controls; Labs models may have different terms. | Not used unless explicitly configured as mistral-ocr; before activation, ZDR, disabled training, and account DPA verification are required. |
If ZDR routing fails to find a compatible endpoint, the import must fail without sending data to a less protected endpoint. Uploaded files must be minimized and not contain unnecessary personal data.
Changes and Objections
The introduction of a new sub-processor will be communicated to merchants with at least 30 days' prior notice, except for urgent replacements necessary for security or continuity. Merchants may submit a reasoned objection by writing to privacy@menuxs.io or via PEC to 3sigma@pec.it.
Data Controller and Contacts
3Sigma s.r.l.s. a socio unico, Via Antonio Viri 16, 00124 Rome (RM), Italy; VAT ID 12847171001; REA RM-1404631. Privacy Office: privacy@menuxs.io; PEC 3sigma@pec.it.