dohosGet started
PLATE Nº 078 · DOCUMENT

CCPA

TARGET-STATE DRAFT — NOT APPROVED OR EFFECTIVE
STATUSTarget-state draft
LAST REVIEWEDNone yet — no review has run
CONTACTvia /contact/security
DRAFT NOTICEThis page describes the role split, restrictions, and rights the California Consumer Privacy Act (as amended by the California Privacy Rights Act) calls for, and Dohos's current, honest activation status against it. It is not a claim that CCPA compliance has been verified, tested, or certified. The mechanism described below — a California schedule inside the data processing agreement — exists in drafted form and is not yet activated for California or any other state.

01Roles under the CCPA

  • Business. The party that determines the purpose and means of processing a California resident's personal information. For a Restaurant's own customer relationship, that is the Restaurant.
  • Service Provider. The party that processes personal information on the business's behalf, under a written contract, for the business's own specific business purposes only. That is Dohos's role for Restaurant-directed processing.

This is the same underlying role split GDPR calls controller and processor — the CCPA just names it differently. The data processing agreement carries a California-specific schedule that applies once activated for a Restaurant and only for the specific, listed business purposes named in that schedule. A generic reference to "the services" is not treated as sufficient — the schedule requires the actual purposes to be spelled out.

02No sale or sharing of personal information

Dohos's internal privacy and data-governance policy prohibits selling personal data, sharing it for cross-context behavioral advertising, or using it for targeted advertising, without exception carved out for California specifically — the prohibition is categorical, not state-gated. The same policy prohibits combining a caller's data with data from another Restaurant, another third party, or Dohos's own separate interactions with that person, except where a narrow, specifically approved and documented combination applies.

Practically, this means the CCPA's "opt out of sale or sharing" mechanism — the "Do Not Sell or Share My Personal Information" link many sites carry — answers a question that doesn't arise here: there is nothing being sold or shared to opt out of in the first place.

03Rights a California resident can exercise

The CCPA's own list of consumer rights and the privacy rights request process already built to receive them are the same list — this page doesn't repeat the mechanism, only maps the CCPA's specific names onto it:

CCPA RIGHTWHERE IT'S EXERCISED
Right to know / accessThe privacy rights request process — access and confirmation
Right to correctSame process — correction
Right to deleteSame process — deletion, including provider and backup propagation
Right to opt out of sale/sharingNot applicable in practice — nothing is sold or shared to opt out of, above
Right to limit use of sensitive personal informationSame process — opt-out and consent withdrawal
Right to non-discrimination for exercising a rightA standing rule, not a request type
Right to appeal a denialSame process — an independent reviewer not responsible for the original decision

No denial or appeal decision on a privacy request is made by an automated system alone under Dohos's rights procedure — a documented design choice worth stating plainly here, since it is exactly the kind of automated-decision question a CCPA-literate reviewer asks.

04Verifying who's asking

The CCPA doesn't require a business to hand data to whoever asks — it requires reasonable verification proportionate to the risk of getting it wrong. Dohos's rights procedure matches verification strength to what's being requested: a low-risk request can be verified against information already tied to the interaction, while a request touching sensitive data, payment history, or account access gets stronger verification and a security review. Neither end of that range asks for a full government identifier, a password, or a new voice biometric sample just to process an ordinary request.

An authorized agent may submit a request on a California resident's behalf where the CCPA permits it. Dohos's procedure verifies the agent's own identity and authority, and may still confirm directly with the individual for a higher-risk action — but it does not treat mere possession of an order number or phone number as proof of authority to act for someone else. A power of attorney or comparable legal authority goes to a human reviewer, not an automated check.

05Sensitive personal information

The CCPA defines its own sensitive-information category — precise geolocation, government identifiers, account credentials, and more. The categories most likely to appear in a restaurant-ordering call are payment credentials and allergy or dietary instructions. Payment credentials never enter a system this policy's data-governance rules apply to in the first place — see the PCI position for why. Allergy and dietary instructions are minimized, treated as sensitive where applicable, and are never used for health inference or marketing, and never represented as medical advice.

06Activation status

ATTENTIONThe data processing agreement's California schedule exists in drafted form today and is not activated for California or any other state. Every claim above describes what the schedule is built to do once activated, not a live, in-force contractual commitment. This is a deliberately conservative statement: the alternative — implying an unactivated schedule is already in effect — is exactly the kind of overclaim this library's sourcing was built to catch.