Data Processing Agreement
Terms under which [LEGAL ENTITY NAME] processes guest personal data on behalf of the restaurant.
Version 1.0 · Last updated 2026-07-27
This Data Processing Agreement (DPA) forms part of the Terms of Service between [LEGAL ENTITY NAME] (the "Processor") and the restaurant using Dinebase (the "Controller"). It applies whenever the Processor processes personal data on the Controller's behalf under Regulation (EU) 2016/679 (GDPR).
1. Roles
The Controller determines the purposes and means of processing guest personal data. The Processor processes that data only on the Controller's documented instructions, which include the Terms of Service, this DPA and the Controller's use of the service's features.
2. Processor obligations
- Process personal data only on documented instructions, including for transfers to third countries, unless required by EU or member-state law.
- Ensure that persons authorised to process the data are bound by confidentiality.
- Implement the technical and organisational measures in Annex II.
- Respect the conditions in section 4 for engaging sub-processors.
- Assist the Controller, to the extent reasonably possible, in responding to data subject requests.
- Assist the Controller with security, breach notification and data protection impact assessments, taking into account the nature of processing and information available.
- On termination, delete or return personal data as set out in section 7.
- Make available information necessary to demonstrate compliance and allow for audits as set out in section 6.
3. Controller obligations
The Controller warrants that it has a lawful basis for the processing it instructs, that it provides the required privacy information to guests, and that its instructions do not breach data protection law. The Controller is responsible for the content it enters, including notes about guests.
4. Sub-processors
The Controller gives general authorisation for the Processor to engage the sub-processors listed on the Sub-processor page. The Processor will give at least 30 days' notice before adding or replacing a sub-processor, and the Controller may object on reasonable data protection grounds. If the objection cannot be resolved, the Controller may terminate the affected part of the service.
The Processor imposes data protection obligations on each sub-processor that are no less protective than those in this DPA and remains fully liable for their performance.
5. International transfers
Where personal data is transferred outside the EU/EEA, the Processor relies on the European Commission's Standard Contractual Clauses or another valid transfer mechanism, together with any supplementary measures required by the transfer assessment.
6. Audits
The Processor will respond to reasonable written information requests about its processing. On request, and no more than once per year unless required by a supervisory authority, the Controller may audit compliance with this DPA at its own cost, with at least 30 days' notice, during business hours and without disrupting the Processor's operations or the confidentiality of other customers' data.
7. Deletion and return
On termination the Controller may export its data through the service for 30 days. After that period the Processor deletes the personal data within 90 days, unless storage is required by EU or member-state law. Backups are deleted on their normal rotation cycle.
8. Personal data breach
The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, and provides the information reasonably available to support the Controller's own notification duties.
Annex I — Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the reservation and restaurant operations service |
| Duration | For the term of the subscription plus the deletion period in section 7 |
| Nature and purpose | Storing, organising, retrieving, transmitting and deleting reservation data; sending confirmation, reminder and notification messages |
| Categories of data subjects | Guests who make reservations or join a waitlist; the Controller's staff users |
| Categories of personal data | Name, phone number, email address, party size, date and time, notes entered by the restaurant, booking history, tags, and where card holds are enabled, payment method reference and card metadata held by the payment provider |
| Special categories | None requested by the service. The Controller should avoid entering health or other sensitive data in free-text notes |
| Frequency | Continuous, as the Controller uses the service |
Annex II — Technical and organisational measures
- Encryption of data in transit using TLS.
- Encryption at rest for the managed database and file storage.
- Row-level access control in the database so each workspace can only reach its own records.
- Role-based permissions (owner, manager, staff) inside each workspace.
- Authenticated server-side endpoints; privileged operations verify the caller's role before running.
- Audit logging of access and role changes and of sensitive reservation actions.
- Email verification for account and email changes; restricted Host View for shared devices.
- Managed hosting with provider-operated backups and restore procedures.
- Access to production data limited to personnel who need it for support and operations.
- Vulnerability reports handled through the contact address on the Trust page.