FoodTab

Legal

Data Processing Addendum

Version 1.2Effective 30 August 2026Forms part of the Merchant Terms of Service

In short

  1. Parties and scope
  2. Definitions
  3. Roles
  4. FoodTab's obligations as processor
  5. Your obligations as controller
  6. Sub-processors
  7. International transfers
  8. Security
  9. Personal data breaches
  10. Assistance and data subject requests
  11. Audit
  12. Return and deletion
  13. Liability and general
  14. Annex 1: Processing details
  15. Annex 2: Sub-processors
  16. Annex 3: Security measures

1. Parties and scope

1.1 This Addendum is between FOODTAB TECHNOLOGIES LTD ("FoodTab", "Processor") and the Business named on the store account ("you", "Controller"). It forms part of, and is accepted together with, the Merchant Terms of Service.

1.2 It applies to all personal data that FoodTab processes on your behalf in providing the Service ("Customer Data"), as described in Annex 1.

2. Definitions

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and any law that replaces or supplements them. "Controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Data Protection Law. "Sub-processor" means a third party engaged by FoodTab to process Customer Data. Other capitalised terms have the meanings in the Merchant Terms.

3. Roles

Processing activityControllerProcessor
Recording, fulfilling, delivering and refunding your Customers' Orders; your Customer records and order history at your shop; caller-ID matching; marketing you sendYouFoodTab
The FoodTab customer account layer (login, saved addresses, cross-shop order history, global opt-outs), platform security and fraud prevention, billing you, aggregate service analytics, legal complianceFoodTab is an independent controller. These activities are described in the Privacy Notice.
Card paymentsStripe is an independent controller for payment data. You are Stripe's customer under the Stripe Connected Account Agreement.
Your staff accounts and audit trailYou (employment relationship)FoodTab, and independent controller for account security

3.2 Where FoodTab is an independent controller, it complies with Data Protection Law on its own account and this Addendum does not apply to that processing.

4. FoodTab's obligations as processor

FoodTab will:

  1. process Customer Data only on your documented instructions, which are: the Merchant Terms, this Addendum, your configuration of the Service, and the actions you and your staff take in it. If we believe an instruction breaks Data Protection Law we will tell you. If the law requires us to process otherwise we will tell you before doing so unless the law forbids it;
  2. ensure that people authorised to process Customer Data are bound by confidentiality;
  3. implement the technical and organisational measures in Annex 3 and keep them under review;
  4. engage sub-processors only as set out in section 6, and impose on each of them the same data protection obligations as this Addendum imposes on FoodTab;
  5. help you respond to data subject requests (section 10);
  6. help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us;
  7. delete or return Customer Data at the end of the Service (section 12);
  8. make available the information needed to demonstrate compliance and allow audits (section 11);
  9. not sell Customer Data, use it for its own marketing, or combine it with data from other shops except in aggregated form that does not identify individuals or you, and except for the independent-controller purposes in section 3.

5. Your obligations as controller

You will: have a lawful basis for the Customer Data you collect through the Service; give your Customers a privacy notice (the storefront links to FoodTab's, which describes the shared processing, but you remain responsible for transparency to your own customers, staff and callers); only give us instructions that comply with Data Protection Law; configure staff permissions appropriately; be responsible for your marketing consents and content; and respond to data subject requests that come to you.

5.2 Allergy and health information. Allergy, intolerance and similar details that Customers type into order notes are health data (special category data). The Service collects them only with the Customer's explicit consent, stated at the point of entry, for the purpose of preparing and delivering that order safely. You must use them for nothing else, must not add them to marketing or profiling, and must handle them within your kitchen in line with food safety law. FoodTab keeps them out of the AI assistant and out of analytics.

6. Sub-processors

6.1 You authorise the sub-processors in Annex 2. We will impose on each sub-processor, by written contract, the same data protection obligations as are set out in this Addendum (Article 28(4)), and we remain fully liable to you for their performance.

6.2 We will give at least 30 days' notice, by email to the owner and in the dashboard, before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period and we cannot resolve it, you may terminate the affected Service on written notice without penalty for the remaining subscription period.

7. International transfers

7.1 Customer Data is stored and processed in the United Kingdom (AWS London). Transfers to sub-processors outside the UK occur only as listed in Annex 2.

7.2 For each such transfer FoodTab relies on the instrument shown in Annex 2: UK adequacy regulations for recipients in the European Economic Area; the UK Addendum to the EU Standard Contractual Clauses (or the ICO's International Data Transfer Agreement) contained in the sub-processor's data processing agreement for recipients elsewhere; and, in addition, the UK-US data bridge where the recipient holds a current UK Extension certification. FoodTab carries out and keeps under review the transfer risk assessment that Article 46 requires, on the basis that protection after transfer must not be materially lower than in the UK, and will provide a summary on request. You authorise FoodTab to enter into those instruments on your behalf as your processor.

8. Security

FoodTab will implement and maintain the measures in Annex 3, appropriate to the risk, and will not reduce the overall level of protection during the term. You are responsible for the security of your own devices, network, staff credentials and printed material.

9. Personal data breaches

9.1 FoodTab will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data, by email to the owner's registered address. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed, and a contact point, updating as information becomes available.

9.2 FoodTab will help you meet your obligations to notify the ICO and affected individuals. FoodTab will not notify your Customers or the ICO on your behalf about a breach of Customer Data unless you ask it to or the law requires it.

10. Assistance and data subject requests

10.1 The Service provides tools to look up, export, correct, merge and delete Customer records. Where a request cannot be met with those tools, FoodTab will assist within 10 working days of your request.

10.2 If a data subject contacts FoodTab directly about Customer Data you control, FoodTab will pass the request to you within 5 working days and will not respond substantively except to confirm that it has done so, unless the request also concerns data FoodTab controls.

10.3 FoodTab may charge reasonable costs for assistance that is excessive or repetitive, and will tell you before incurring them.

11. Audit

11.1 On written request no more than once in any 12 months, FoodTab will provide information reasonably necessary to demonstrate compliance with this Addendum, including summaries of security testing and sub-processor terms.

11.2 If that information is insufficient to meet a legal requirement or a supervisory authority's demand, you (or an independent auditor bound by confidentiality) may audit FoodTab's relevant records and systems on 30 days' notice, during business hours, without disrupting operations, at your cost unless the audit reveals a material breach by FoodTab.

12. Return and deletion

12.1 You may export Customer Data at any time through the dashboard.

12.2 On termination of the Merchant Terms you may choose, by written notice within 30 days, whether FoodTab returns Customer Data to you (as an export in a common machine-readable format) or deletes it. If you make no choice, FoodTab keeps it available for export for 30 days and then deletes it. Deletion from live systems happens within 60 days of the choice or the end of the 30-day period, and from backups within 90 days after that. FoodTab will confirm deletion in writing on request.

12.3 The following are excepted from return or deletion: (a) the transaction record FoodTab must keep for its own accounting and tax obligations as an independent controller, limited to order numbers, dates, amounts, fees, payment references and refund records, from which the Customer's name, contact details, address and notes are removed; (b) other data FoodTab holds as independent controller under section 3, such as FoodTab customer accounts; and (c) marketing opt-out records, kept so that the Customer's choice continues to be honoured.

13. Liability and general

13.1 Each party's liability under this Addendum is subject to the limitations and exclusions in the Merchant Terms, except that nothing limits a party's liability for fines or compensation that Data Protection Law makes that party solely responsible for.

13.2 If this Addendum conflicts with the Merchant Terms on a data protection matter, this Addendum prevails. It is governed by the law of England and Wales.

13.3 FoodTab may update Annexes 2 and 3 as described in sections 6 and 8. Other changes follow section 19 of the Merchant Terms.

Annex 1: Processing details

Subject matter
Provision of the FoodTab till, online ordering, dashboard, messaging and assistant services to the Controller.
Duration
The term of the Merchant Terms plus the return and deletion period in section 12.
Nature and purpose
Collecting, storing, displaying, transmitting, matching and deleting personal data to take, prepare, deliver and account for orders; to send transactional and (where instructed) marketing messages; to identify returning customers; to count scans of the Controller's printed QR codes and the orders they lead to (an anonymous device id, linked to a customer only once that customer orders; the Controller sees counts, not identities); and to support the Controller's staff.
Categories of data subjects
The Controller's customers (including phone and walk-in customers), the Controller's staff and drivers, and people who contact the Controller through the Service.
Categories of personal data
Names; phone numbers; email addresses; delivery addresses and location; order contents, notes and history; payment method, status and Stripe references (no card numbers); marketing preferences; caller-ID numbers and call times; staff names, contact details, roles and activity; device and diagnostic logs; messages exchanged with the assistant.
Special category data
Health data, where a Customer chooses to type an allergy, intolerance or similar detail into an order note. Collected with the Customer's explicit consent at the point of entry; processed only to prepare and deliver that order; excluded from the AI assistant and from analytics; retained with the order record.

Annex 2: Sub-processors

Sub-processorPurposeLocationTransfer basis
Amazon Web Services EMEA SARLCompute, database, storage, authentication, email and SMS deliveryUK (eu-west-2, London)Not applicable (UK)
Cloudflare, Inc.Content delivery, DNS, storefront and dashboard hosting, real-time messaging, securityGlobal edge; EU/USUK adequacy (EU) and UK Addendum in Cloudflare's DPA; DPF certified (UK Extension)
Stripe Payments Europe Ltd, Stripe Payments UK Ltd, Stripe, Inc.Card payments, payouts, refunds, disputes, payment links. Note: Stripe acts as an independent controller for payment data under your own agreement with Stripe; it is listed here for completeness because FoodTab sends it order identifiers and amounts to create charges on your accountIreland; UK; USYour Stripe agreement and Stripe's DPA; UK Addendum; DPF certified
Meta Platforms Ireland Ltd (WhatsApp Business Platform)Delivering WhatsApp messages to owners and, where the Controller instructs, to customersIreland; USUK adequacy (EU); UK Addendum in Meta's WhatsApp Business data transfer terms; DPF certified (UK Extension)
OpenAI, L.L.C. (OpenAI OpCo, LLC)Language model behind the staff assistant; receives staff questions and the order, menu and settings data needed to answer them (order numbers, items, totals, times, and customer names on orders; never order notes, addresses, phone numbers or payment data); API data is not used for model training; abuse-monitoring logs up to 30 daysUSUK Addendum in OpenAI's DPA; DPF certified (UK Extension)
Ideal Postcodes (Ideal Postcodes Ltd) and postcodes.ioAddress lookup from postcodeUKNot applicable (UK)
Mapbox, Inc.Map tiles in the till app's delivery viewUSUK Addendum in Mapbox's DPA; DPF certified (UK Extension)

Current as of the effective date. Changes are notified under section 6.2.

Annex 3: Security measures