01Roles under the CCPA
- Business. The party that determines the purpose and means of processing a California resident's personal information. For a Restaurant's own customer relationship, that is the Restaurant.
- Service Provider. The party that processes personal information on the business's behalf, under a written contract, for the business's own specific business purposes only. That is Dohos's role for Restaurant-directed processing.
This is the same underlying role split GDPR calls controller and processor — the CCPA just names it differently. The data processing agreement carries a California-specific schedule that applies once activated for a Restaurant and only for the specific, listed business purposes named in that schedule. A generic reference to "the services" is not treated as sufficient — the schedule requires the actual purposes to be spelled out.
02No sale or sharing of personal information
Dohos's internal privacy and data-governance policy prohibits selling personal data, sharing it for cross-context behavioral advertising, or using it for targeted advertising, without exception carved out for California specifically — the prohibition is categorical, not state-gated. The same policy prohibits combining a caller's data with data from another Restaurant, another third party, or Dohos's own separate interactions with that person, except where a narrow, specifically approved and documented combination applies.
Practically, this means the CCPA's "opt out of sale or sharing" mechanism — the "Do Not Sell or Share My Personal Information" link many sites carry — answers a question that doesn't arise here: there is nothing being sold or shared to opt out of in the first place.
03Rights a California resident can exercise
The CCPA's own list of consumer rights and the privacy rights request process already built to receive them are the same list — this page doesn't repeat the mechanism, only maps the CCPA's specific names onto it:
| CCPA RIGHT | WHERE IT'S EXERCISED |
|---|---|
| Right to know / access | The privacy rights request process — access and confirmation |
| Right to correct | Same process — correction |
| Right to delete | Same process — deletion, including provider and backup propagation |
| Right to opt out of sale/sharing | Not applicable in practice — nothing is sold or shared to opt out of, above |
| Right to limit use of sensitive personal information | Same process — opt-out and consent withdrawal |
| Right to non-discrimination for exercising a right | A standing rule, not a request type |
| Right to appeal a denial | Same process — an independent reviewer not responsible for the original decision |
No denial or appeal decision on a privacy request is made by an automated system alone under Dohos's rights procedure — a documented design choice worth stating plainly here, since it is exactly the kind of automated-decision question a CCPA-literate reviewer asks.
04Verifying who's asking
The CCPA doesn't require a business to hand data to whoever asks — it requires reasonable verification proportionate to the risk of getting it wrong. Dohos's rights procedure matches verification strength to what's being requested: a low-risk request can be verified against information already tied to the interaction, while a request touching sensitive data, payment history, or account access gets stronger verification and a security review. Neither end of that range asks for a full government identifier, a password, or a new voice biometric sample just to process an ordinary request.
An authorized agent may submit a request on a California resident's behalf where the CCPA permits it. Dohos's procedure verifies the agent's own identity and authority, and may still confirm directly with the individual for a higher-risk action — but it does not treat mere possession of an order number or phone number as proof of authority to act for someone else. A power of attorney or comparable legal authority goes to a human reviewer, not an automated check.
05Sensitive personal information
The CCPA defines its own sensitive-information category — precise geolocation, government identifiers, account credentials, and more. The categories most likely to appear in a restaurant-ordering call are payment credentials and allergy or dietary instructions. Payment credentials never enter a system this policy's data-governance rules apply to in the first place — see the PCI position for why. Allergy and dietary instructions are minimized, treated as sensitive where applicable, and are never used for health inference or marketing, and never represented as medical advice.