Legal
Data Processing Addendum
In short
- This is the written contract UK GDPR Article 28 requires between a business (the controller) and a company that processes personal data for it (the processor).
- For your customers' order data, you are the controller and FoodTab is your processor. We act only on your instructions, keep it secure, help you answer customer requests, tell you within 48 hours of a breach, and delete or return it when you leave.
- Our sub-processors (AWS, Cloudflare, Stripe, Meta, OpenAI and a few others) are listed in Annex 2. We give 30 days' notice before adding one.
- Data lives in the UK. Where a sub-processor is outside the UK, adequacy regulations or the UK transfer addendum apply.
- Parties and scope
- Definitions
- Roles
- FoodTab's obligations as processor
- Your obligations as controller
- Sub-processors
- International transfers
- Security
- Personal data breaches
- Assistance and data subject requests
- Audit
- Return and deletion
- Liability and general
- Annex 1: Processing details
- Annex 2: Sub-processors
- Annex 3: Security measures
1. Parties and scope
1.1 This Addendum is between FOODTAB TECHNOLOGIES LTD ("FoodTab", "Processor") and the Business named on the store account ("you", "Controller"). It forms part of, and is accepted together with, the Merchant Terms of Service.
1.2 It applies to all personal data that FoodTab processes on your behalf in providing the Service ("Customer Data"), as described in Annex 1.
2. Definitions
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and any law that replaces or supplements them. "Controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Data Protection Law. "Sub-processor" means a third party engaged by FoodTab to process Customer Data. Other capitalised terms have the meanings in the Merchant Terms.
3. Roles
| Processing activity | Controller | Processor |
|---|---|---|
| Recording, fulfilling, delivering and refunding your Customers' Orders; your Customer records and order history at your shop; caller-ID matching; marketing you send | You | FoodTab |
| The FoodTab customer account layer (login, saved addresses, cross-shop order history, global opt-outs), platform security and fraud prevention, billing you, aggregate service analytics, legal compliance | FoodTab is an independent controller. These activities are described in the Privacy Notice. | |
| Card payments | Stripe is an independent controller for payment data. You are Stripe's customer under the Stripe Connected Account Agreement. | |
| Your staff accounts and audit trail | You (employment relationship) | FoodTab, and independent controller for account security |
3.2 Where FoodTab is an independent controller, it complies with Data Protection Law on its own account and this Addendum does not apply to that processing.
4. FoodTab's obligations as processor
FoodTab will:
- process Customer Data only on your documented instructions, which are: the Merchant Terms, this Addendum, your configuration of the Service, and the actions you and your staff take in it. If we believe an instruction breaks Data Protection Law we will tell you. If the law requires us to process otherwise we will tell you before doing so unless the law forbids it;
- ensure that people authorised to process Customer Data are bound by confidentiality;
- implement the technical and organisational measures in Annex 3 and keep them under review;
- engage sub-processors only as set out in section 6;
- help you respond to data subject requests (section 10);
- help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us;
- delete or return Customer Data at the end of the Service (section 12);
- make available the information needed to demonstrate compliance and allow audits (section 11);
- not sell Customer Data, use it for its own marketing, or combine it with data from other shops except in aggregated form that does not identify individuals or you, and except for the independent-controller purposes in section 3.
5. Your obligations as controller
You will: have a lawful basis for the Customer Data you collect through the Service; give your Customers a privacy notice; only give us instructions that comply with Data Protection Law; configure staff permissions appropriately; not upload special category data unless necessary (allergy notes typed by a Customer for their own order are accepted); be responsible for your marketing consents and content; and respond to data subject requests that come to you.
6. Sub-processors
6.1 You authorise the sub-processors in Annex 2. We will impose written data protection obligations on each sub-processor that are no less protective than this Addendum, and we remain liable to you for their performance.
6.2 We will give at least 30 days' notice, by email to the owner and in the dashboard, before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period and we cannot resolve it, you may terminate the affected Service on written notice without penalty for the remaining subscription period.
7. International transfers
7.1 Customer Data is stored and processed in the United Kingdom (AWS London). Transfers to sub-processors outside the UK occur only as listed in Annex 2.
7.2 For such transfers we rely on UK adequacy regulations where they apply (including the UK Extension to the EU-US Data Privacy Framework for certified recipients), and otherwise on the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, plus supplementary measures where needed. You appoint FoodTab to enter into those instruments on your behalf as your processor.
8. Security
FoodTab will implement and maintain the measures in Annex 3, appropriate to the risk, and will not reduce the overall level of protection during the term. You are responsible for the security of your own devices, network, staff credentials and printed material.
9. Personal data breaches
9.1 FoodTab will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data, by email to the owner's registered address. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed, and a contact point, updating as information becomes available.
9.2 FoodTab will help you meet your obligations to notify the ICO and affected individuals. FoodTab will not notify your Customers or the ICO on your behalf about a breach of Customer Data unless you ask it to or the law requires it.
10. Assistance and data subject requests
10.1 The Service provides tools to look up, export, correct, merge and delete Customer records. Where a request cannot be met with those tools, FoodTab will assist within 10 working days of your request.
10.2 If a data subject contacts FoodTab directly about Customer Data you control, FoodTab will pass the request to you within 5 working days and will not respond substantively except to confirm that it has done so, unless the request also concerns data FoodTab controls.
10.3 FoodTab may charge reasonable costs for assistance that is excessive or repetitive, and will tell you before incurring them.
11. Audit
11.1 On written request no more than once in any 12 months, FoodTab will provide information reasonably necessary to demonstrate compliance with this Addendum, including summaries of security testing and sub-processor terms.
11.2 If that information is insufficient to meet a legal requirement or a supervisory authority's demand, you (or an independent auditor bound by confidentiality) may audit FoodTab's relevant records and systems on 30 days' notice, during business hours, without disrupting operations, at your cost unless the audit reveals a material breach by FoodTab.
12. Return and deletion
12.1 You may export Customer Data at any time through the dashboard.
12.2 On termination of the Merchant Terms, FoodTab will keep Customer Data available for export for 30 days, then delete it from live systems within a further 60 days and from backups within 90 days after that, except: data FoodTab must retain by law (order and payment records, for 6 years); data FoodTab holds as independent controller (section 3); and marketing opt-out records, which are kept so the choice continues to be honoured. FoodTab will confirm deletion in writing on request.
13. Liability and general
13.1 Each party's liability under this Addendum is subject to the limitations and exclusions in the Merchant Terms, except that nothing limits a party's liability for fines or compensation that Data Protection Law makes that party solely responsible for.
13.2 If this Addendum conflicts with the Merchant Terms on a data protection matter, this Addendum prevails. It is governed by the law of England and Wales.
13.3 FoodTab may update Annexes 2 and 3 as described in sections 6 and 8. Other changes follow section 19 of the Merchant Terms.
Annex 1: Processing details
- Subject matter
- Provision of the FoodTab till, online ordering, dashboard, messaging and assistant services to the Controller.
- Duration
- The term of the Merchant Terms plus the return and deletion period in section 12.
- Nature and purpose
- Collecting, storing, displaying, transmitting, matching and deleting personal data to take, prepare, deliver and account for orders; to send transactional and (where instructed) marketing messages; to identify returning customers; and to support the Controller's staff.
- Categories of data subjects
- The Controller's customers (including phone and walk-in customers), the Controller's staff and drivers, and people who contact the Controller through the Service.
- Categories of personal data
- Names; phone numbers; email addresses; delivery addresses and location; order contents, notes and history; payment method, status and Stripe references (no card numbers); marketing preferences; caller-ID numbers and call times; staff names, contact details, roles and activity; device and diagnostic logs; messages exchanged with the assistant.
- Special category data
- Not intended. Customers may type allergy or dietary information into order notes; it is processed only to prepare that order.
Annex 2: Sub-processors
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Compute, database, storage, authentication, email and SMS delivery | UK (eu-west-2, London) | Not applicable (UK) |
| Cloudflare, Inc. | Content delivery, DNS, storefront and dashboard hosting, real-time messaging, security | Global edge; EU/US | UK adequacy (EU) and IDTA/UK Addendum; DPF certified |
| Stripe Payments Europe Ltd / Stripe, Inc. | Card payments, payouts, refunds, disputes, payment links | Ireland; US | Independent controller; DPF certified; Stripe's own transfer terms |
| Meta Platforms Ireland Ltd (WhatsApp Business Platform) | Delivering WhatsApp messages to owners and, where the Controller instructs, to customers | Ireland; US | UK adequacy (EU) and Meta's transfer terms; DPF certified |
| OpenAI, L.L.C. | Language model behind the staff assistant; receives staff questions and the order, menu and settings data needed to answer them; API data is not used for model training | US | IDTA/UK Addendum; DPF certified |
| Ideal Postcodes (Ideal Postcodes Ltd) and postcodes.io | Address lookup from postcode | UK | Not applicable (UK) |
| Mapbox, Inc. | Map tiles in the till app's delivery view | US | IDTA/UK Addendum; DPF certified |
Current as of the effective date. Changes are notified under section 6.2.
Annex 3: Security measures
- Encryption: TLS 1.2 or higher for all traffic; encryption at rest for databases, storage and backups.
- Access control: role-based permissions for staff at each shop; capability-based permissions for FoodTab platform staff; per-store isolation enforced on every server request; short-lived signed tokens; per-device sign-in for tills; least-privilege service roles in the cloud environment.
- Card data: never enters FoodTab systems; collected on Stripe-hosted pages.
- Secrets: held in a managed secrets store, never in code or logs; rotated on compromise.
- Webhooks and integrations: signature verification on every inbound webhook; replay protection; allow-listed routes for the assistant's actions with the same permission checks as the user interface.
- Logging and monitoring: audit trail of administrative and staff actions; server logs retained 12 months; alerting on errors and abuse patterns; rate limiting.
- Data minimisation: masked identifiers in logs (for example last four digits of phone numbers); free-text notes excluded from unauthenticated responses; diagnostic logs expire after 7 days.
- Resilience: UK-region managed database with point-in-time recovery; multiple availability zones; tills operate offline and resynchronise.
- Development: separate development and production environments; code review; automated tests; dependency updates; production changes deployed through version-controlled configuration.
- People: confidentiality obligations for everyone with access; access removed promptly when no longer needed.
- Incident response: documented process for detection, containment, notification (section 9) and post-incident review.