This Data Processing Addendum ("DPA") supplements the Terms of Service between you ("Customer") and Meat Now (operated by Fintech Data Solutions). It describes how we process Customer Data on your behalf.
1. Roles
For Customer Data, the Customer is the controller and Meat Now is the processor, processing data only on the Customer's documented instructions (i.e., to provide the Service).
2. Scope & purpose of processing
- Categories of data: account details (company, email), distributor names, uploaded price-sheet contents (products, prices, units, dates), and usage metadata.
- Purpose: extraction, AI-assisted product classification, best-price comparison, billing, security, and support.
- Duration: for the term of the subscription plus the retention period in the Privacy Policy.
3. Subprocessors
We use the following subprocessors, each under contractual data-protection obligations:
- Anthropic — AI product-name classification. Only text needed for classification is sent; not used to train models for this use.
- Square — payment processing.
- Hosting/infrastructure provider — application and database hosting.
- Plaid — only if the Customer connects a bank for the optional read-only finance view.
We will give notice of new subprocessors and remain responsible for their performance.
4. Security measures
- Tenant isolation enforced at the database level (row-level security; the application connects as a non-superuser role that cannot bypass it).
- Encryption in transit (HTTPS/TLS); passwords stored only as bcrypt hashes; payment card data handled by Square, not stored by us.
- Rate limiting, security headers, single-use tokenized password reset, and append-only audit trails.
- Least-privilege access and fail-closed defaults on sensitive operations.
5. Confidentiality & no individual disclosure
We keep Customer Data confidential. We do not sell or disclose your individual Customer Data to other customers or third parties as a product. Any benchmark or insight products are derived from aggregated, anonymized data that cannot be linked to you.
6. International processing
Data may be processed in the United States. We rely on appropriate safeguards where required.
7. Data subject requests
We will assist the Customer, as reasonably required, in responding to requests from individuals to access, correct, or delete personal data contained in Customer Data.
8. Return & deletion
On termination, the Customer may request export of Customer Data in a usable format and/or deletion. We will delete or return Customer Data within a reasonable period, subject to legal retention requirements for billing and security logs.
9. Incident notification
We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, with information reasonably available to us.
10. Contact
For data-protection matters, contact us.