Data Processing Addendum

Last updated: July 13, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Brands Downtown, operating OwnTable (“Processor”) and the Restaurant (“Controller”). It applies where OwnTable processes personal data of the Controller’s diners (“Diner Data”) on the Controller’s behalf.

1. Roles

The Controller determines the purposes and means of processing Diner Data. OwnTable processes it only on the Controller’s documented instructions, which include the configuration of the Service and these Terms.

2. Subject matter & scope

ItemDetail
Subject matterProvision of ordering, AI, delivery, and retention features
DurationThe term of the agreement, plus the retention period
Nature & purposeStoring, transmitting, and processing orders and diner communications
Categories of dataName, phone, delivery address, order history, reviews, chat transcripts
Data subjectsThe Controller’s diners and customers

3. Processor obligations

  • Process Diner Data only on documented instructions, including for international transfers, unless required by law (in which case we notify you where permitted).
  • Ensure personnel are bound by confidentiality.
  • Implement appropriate technical and organizational measures (Section 6).
  • Assist the Controller — taking into account the nature of processing — with data-subject requests, security, breach notification, and DPIAs.
  • At the Controller’s choice, delete or return Diner Data at the end of the agreement, subject to legal retention.
  • Make available information needed to demonstrate compliance and allow reasonable audits.

4. Subprocessors

The Controller provides general authorization for OwnTable to engage the subprocessors listed in our Privacy Policy. We impose data-protection obligations on each subprocessor no less protective than this DPA, and remain liable for their performance. We will give notice of new subprocessors and a reasonable window to object.

5. Data-subject requests

Where a diner contacts us directly, we will refer them to the Controller. The Service provides self-serve export and deletion tools so the Controller can fulfill access, erasure, and portability requests. We will assist with requests we cannot fulfill through those tools.

6. Security measures

  • Encryption in transit (TLS) and at rest.
  • Per-tenant isolation enforced by database row-level security.
  • Third-party credentials stored in an encrypted vault, never exposed to the browser.
  • Role-based access control and optional multi-factor authentication.
  • Rate-limiting and abuse protection on public endpoints.
  • Audit logging of sensitive actions; error monitoring; least-privilege service access.

7. Personal-data breaches

We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Diner Data, with the information reasonably available to help the Controller meet its own notification obligations.

8. International transfers

Where processing involves transfer outside the UK/EEA, the parties rely on Standard Contractual Clauses (or an equivalent approved mechanism), which are incorporated by reference.

9. Liability

Each party’s liability under this DPA is subject to the limitations in the Terms of Service.

10. Signing

This DPA is effective upon acceptance of the Terms. A countersigned copy for procurement is available on request from sales@owntable.io.

This document is provided for transparency and is not legal advice. We recommend review by qualified counsel before relying on it for your jurisdiction. Questions: sales@owntable.io.