FoodTab

Legal

Data Processing Addendum

Version 1.0Effective 29 August 2026Forms part of the Merchant Terms of Service

In short

  1. Parties and scope
  2. Definitions
  3. Roles
  4. FoodTab's obligations as processor
  5. Your obligations as controller
  6. Sub-processors
  7. International transfers
  8. Security
  9. Personal data breaches
  10. Assistance and data subject requests
  11. Audit
  12. Return and deletion
  13. Liability and general
  14. Annex 1: Processing details
  15. Annex 2: Sub-processors
  16. Annex 3: Security measures

1. Parties and scope

1.1 This Addendum is between FOODTAB TECHNOLOGIES LTD ("FoodTab", "Processor") and the Business named on the store account ("you", "Controller"). It forms part of, and is accepted together with, the Merchant Terms of Service.

1.2 It applies to all personal data that FoodTab processes on your behalf in providing the Service ("Customer Data"), as described in Annex 1.

2. Definitions

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and any law that replaces or supplements them. "Controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Data Protection Law. "Sub-processor" means a third party engaged by FoodTab to process Customer Data. Other capitalised terms have the meanings in the Merchant Terms.

3. Roles

Processing activityControllerProcessor
Recording, fulfilling, delivering and refunding your Customers' Orders; your Customer records and order history at your shop; caller-ID matching; marketing you sendYouFoodTab
The FoodTab customer account layer (login, saved addresses, cross-shop order history, global opt-outs), platform security and fraud prevention, billing you, aggregate service analytics, legal complianceFoodTab is an independent controller. These activities are described in the Privacy Notice.
Card paymentsStripe is an independent controller for payment data. You are Stripe's customer under the Stripe Connected Account Agreement.
Your staff accounts and audit trailYou (employment relationship)FoodTab, and independent controller for account security

3.2 Where FoodTab is an independent controller, it complies with Data Protection Law on its own account and this Addendum does not apply to that processing.

4. FoodTab's obligations as processor

FoodTab will:

  1. process Customer Data only on your documented instructions, which are: the Merchant Terms, this Addendum, your configuration of the Service, and the actions you and your staff take in it. If we believe an instruction breaks Data Protection Law we will tell you. If the law requires us to process otherwise we will tell you before doing so unless the law forbids it;
  2. ensure that people authorised to process Customer Data are bound by confidentiality;
  3. implement the technical and organisational measures in Annex 3 and keep them under review;
  4. engage sub-processors only as set out in section 6;
  5. help you respond to data subject requests (section 10);
  6. help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us;
  7. delete or return Customer Data at the end of the Service (section 12);
  8. make available the information needed to demonstrate compliance and allow audits (section 11);
  9. not sell Customer Data, use it for its own marketing, or combine it with data from other shops except in aggregated form that does not identify individuals or you, and except for the independent-controller purposes in section 3.

5. Your obligations as controller

You will: have a lawful basis for the Customer Data you collect through the Service; give your Customers a privacy notice; only give us instructions that comply with Data Protection Law; configure staff permissions appropriately; not upload special category data unless necessary (allergy notes typed by a Customer for their own order are accepted); be responsible for your marketing consents and content; and respond to data subject requests that come to you.

6. Sub-processors

6.1 You authorise the sub-processors in Annex 2. We will impose written data protection obligations on each sub-processor that are no less protective than this Addendum, and we remain liable to you for their performance.

6.2 We will give at least 30 days' notice, by email to the owner and in the dashboard, before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period and we cannot resolve it, you may terminate the affected Service on written notice without penalty for the remaining subscription period.

7. International transfers

7.1 Customer Data is stored and processed in the United Kingdom (AWS London). Transfers to sub-processors outside the UK occur only as listed in Annex 2.

7.2 For such transfers we rely on UK adequacy regulations where they apply (including the UK Extension to the EU-US Data Privacy Framework for certified recipients), and otherwise on the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, plus supplementary measures where needed. You appoint FoodTab to enter into those instruments on your behalf as your processor.

8. Security

FoodTab will implement and maintain the measures in Annex 3, appropriate to the risk, and will not reduce the overall level of protection during the term. You are responsible for the security of your own devices, network, staff credentials and printed material.

9. Personal data breaches

9.1 FoodTab will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data, by email to the owner's registered address. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed, and a contact point, updating as information becomes available.

9.2 FoodTab will help you meet your obligations to notify the ICO and affected individuals. FoodTab will not notify your Customers or the ICO on your behalf about a breach of Customer Data unless you ask it to or the law requires it.

10. Assistance and data subject requests

10.1 The Service provides tools to look up, export, correct, merge and delete Customer records. Where a request cannot be met with those tools, FoodTab will assist within 10 working days of your request.

10.2 If a data subject contacts FoodTab directly about Customer Data you control, FoodTab will pass the request to you within 5 working days and will not respond substantively except to confirm that it has done so, unless the request also concerns data FoodTab controls.

10.3 FoodTab may charge reasonable costs for assistance that is excessive or repetitive, and will tell you before incurring them.

11. Audit

11.1 On written request no more than once in any 12 months, FoodTab will provide information reasonably necessary to demonstrate compliance with this Addendum, including summaries of security testing and sub-processor terms.

11.2 If that information is insufficient to meet a legal requirement or a supervisory authority's demand, you (or an independent auditor bound by confidentiality) may audit FoodTab's relevant records and systems on 30 days' notice, during business hours, without disrupting operations, at your cost unless the audit reveals a material breach by FoodTab.

12. Return and deletion

12.1 You may export Customer Data at any time through the dashboard.

12.2 On termination of the Merchant Terms, FoodTab will keep Customer Data available for export for 30 days, then delete it from live systems within a further 60 days and from backups within 90 days after that, except: data FoodTab must retain by law (order and payment records, for 6 years); data FoodTab holds as independent controller (section 3); and marketing opt-out records, which are kept so the choice continues to be honoured. FoodTab will confirm deletion in writing on request.

13. Liability and general

13.1 Each party's liability under this Addendum is subject to the limitations and exclusions in the Merchant Terms, except that nothing limits a party's liability for fines or compensation that Data Protection Law makes that party solely responsible for.

13.2 If this Addendum conflicts with the Merchant Terms on a data protection matter, this Addendum prevails. It is governed by the law of England and Wales.

13.3 FoodTab may update Annexes 2 and 3 as described in sections 6 and 8. Other changes follow section 19 of the Merchant Terms.

Annex 1: Processing details

Subject matter
Provision of the FoodTab till, online ordering, dashboard, messaging and assistant services to the Controller.
Duration
The term of the Merchant Terms plus the return and deletion period in section 12.
Nature and purpose
Collecting, storing, displaying, transmitting, matching and deleting personal data to take, prepare, deliver and account for orders; to send transactional and (where instructed) marketing messages; to identify returning customers; and to support the Controller's staff.
Categories of data subjects
The Controller's customers (including phone and walk-in customers), the Controller's staff and drivers, and people who contact the Controller through the Service.
Categories of personal data
Names; phone numbers; email addresses; delivery addresses and location; order contents, notes and history; payment method, status and Stripe references (no card numbers); marketing preferences; caller-ID numbers and call times; staff names, contact details, roles and activity; device and diagnostic logs; messages exchanged with the assistant.
Special category data
Not intended. Customers may type allergy or dietary information into order notes; it is processed only to prepare that order.

Annex 2: Sub-processors

Sub-processorPurposeLocationTransfer basis
Amazon Web Services EMEA SARLCompute, database, storage, authentication, email and SMS deliveryUK (eu-west-2, London)Not applicable (UK)
Cloudflare, Inc.Content delivery, DNS, storefront and dashboard hosting, real-time messaging, securityGlobal edge; EU/USUK adequacy (EU) and IDTA/UK Addendum; DPF certified
Stripe Payments Europe Ltd / Stripe, Inc.Card payments, payouts, refunds, disputes, payment linksIreland; USIndependent controller; DPF certified; Stripe's own transfer terms
Meta Platforms Ireland Ltd (WhatsApp Business Platform)Delivering WhatsApp messages to owners and, where the Controller instructs, to customersIreland; USUK adequacy (EU) and Meta's transfer terms; DPF certified
OpenAI, L.L.C.Language model behind the staff assistant; receives staff questions and the order, menu and settings data needed to answer them; API data is not used for model trainingUSIDTA/UK Addendum; DPF certified
Ideal Postcodes (Ideal Postcodes Ltd) and postcodes.ioAddress lookup from postcodeUKNot applicable (UK)
Mapbox, Inc.Map tiles in the till app's delivery viewUSIDTA/UK Addendum; DPF certified

Current as of the effective date. Changes are notified under section 6.2.

Annex 3: Security measures