01The jurisdiction this service is built for
Dohos's target service is a restaurant-ordering voice channel scoped to an explicit jurisdiction allowlist — country, state, and locality combinations that have been specifically reviewed, not a blanket "worldwide" or even "United States" claim. No European Union member state, the United Kingdom, or Switzerland is on that allowlist today. A Restaurant, a Caller, or a Payer outside the approved list produces a safe limitation message, not a best-effort attempt to serve them anyway — the policy's own framing is that an unreviewed jurisdiction fails closed by design, not by omission.
This is a narrower claim than "Dohos has no international footprint," and it is worth being precise about the difference. Provider infrastructure, routing, telemetry, subprocessors, backups, or personnel supporting a U.S.-focused product can still create incidental international access — a support engineer working from outside the country, a cloud region with a redundant node abroad. That is a materially different fact from offering the service to, or targeting, people located in the European Union, which is the trigger that brings GDPR's extraterritorial reach into play. Dohos does not do the latter today.
02What the data processing agreement says
The data processing agreement every Restaurant signs states its cross-border position directly rather than leaving it implied: no EU, UK, Swiss, Canadian, or other international transfer mechanism is incorporated into the current draft. That is not an oversight to be corrected later — it is an accurate reflection of a service that is not, today, processing personal data that would require one.
If that scope changes — a Restaurant with EU-resident customers, a caller physically located in a covered jurisdiction, a provider relationship that shifts data flows — the same agreement already names what has to happen before that processing begins: the parties execute an approved transfer addendum, complete the required transfer impact assessment and any supplementary safeguards it calls for, update the relevant notices and provider configuration, and only then activate the jurisdiction. Nothing about GDPR applicability is left to be discovered after the fact.
03Roles, if and when they attach
- Controller. Under GDPR's vocabulary, the party that decides why and how personal data is processed. For a Restaurant's own customer relationship, that is the Restaurant.
- Processor. The party that processes personal data on the controller's documented instructions, without deciding its own separate purpose for that data. That is Dohos's role for Restaurant-directed processing.
Dohos's internal privacy and data-governance policy assigns this same controller/processor role split as one line item in a broader role matrix that also covers CCPA's parallel vocabulary — business and service provider — because the underlying discipline doesn't change with the statute's name. Every processing activity gets an assigned role, a documented instruction, and a boundary on what Dohos may do independently of that instruction, regardless of which law is asking the question.
04The privacy design underneath, regardless of which statute applies
GDPR not currently applying is not the same as "no privacy discipline until it does." The same policy that assigns controller/processor roles also requires a specific, documented purpose before any data is collected, the minimum amount of data reasonably sufficient for that purpose, and a default-off posture for sensitive categories — health information, precise location, biometric identifiers — unless a specific, approved gate says otherwise. None of that is GDPR-specific machinery bolted on for European readiness; it is the standing rule for every Restaurant, Caller, and Payer regardless of location.
- a specific, documented purpose is required before data is collected, received, derived, or retained — a generic "business" or "analytics" purpose is not sufficient on its own
- data use for one purpose is not repurposed for another — marketing, profiling, or model training — without separate authority and notice
- an unknown source, purpose, or jurisdiction keeps the affected data path off rather than allowing it by default
- sensitive categories of data remain off unless a specific, approved, documented gate says otherwise