Data Processing Addendum
Last updated: July 13, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Brands Downtown, operating OwnTable (“Processor”) and the Restaurant (“Controller”). It applies where OwnTable processes personal data of the Controller’s diners (“Diner Data”) on the Controller’s behalf.
1. Roles
The Controller determines the purposes and means of processing Diner Data. OwnTable processes it only on the Controller’s documented instructions, which include the configuration of the Service and these Terms.
2. Subject matter & scope
| Item | Detail |
|---|---|
| Subject matter | Provision of ordering, AI, delivery, and retention features |
| Duration | The term of the agreement, plus the retention period |
| Nature & purpose | Storing, transmitting, and processing orders and diner communications |
| Categories of data | Name, phone, delivery address, order history, reviews, chat transcripts |
| Data subjects | The Controller’s diners and customers |
3. Processor obligations
- Process Diner Data only on documented instructions, including for international transfers, unless required by law (in which case we notify you where permitted).
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organizational measures (Section 6).
- Assist the Controller — taking into account the nature of processing — with data-subject requests, security, breach notification, and DPIAs.
- At the Controller’s choice, delete or return Diner Data at the end of the agreement, subject to legal retention.
- Make available information needed to demonstrate compliance and allow reasonable audits.
4. Subprocessors
The Controller provides general authorization for OwnTable to engage the subprocessors listed in our Privacy Policy. We impose data-protection obligations on each subprocessor no less protective than this DPA, and remain liable for their performance. We will give notice of new subprocessors and a reasonable window to object.
5. Data-subject requests
Where a diner contacts us directly, we will refer them to the Controller. The Service provides self-serve export and deletion tools so the Controller can fulfill access, erasure, and portability requests. We will assist with requests we cannot fulfill through those tools.
6. Security measures
- Encryption in transit (TLS) and at rest.
- Per-tenant isolation enforced by database row-level security.
- Third-party credentials stored in an encrypted vault, never exposed to the browser.
- Role-based access control and optional multi-factor authentication.
- Rate-limiting and abuse protection on public endpoints.
- Audit logging of sensitive actions; error monitoring; least-privilege service access.
7. Personal-data breaches
We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Diner Data, with the information reasonably available to help the Controller meet its own notification obligations.
8. International transfers
Where processing involves transfer outside the UK/EEA, the parties rely on Standard Contractual Clauses (or an equivalent approved mechanism), which are incorporated by reference.
9. Liability
Each party’s liability under this DPA is subject to the limitations in the Terms of Service.
10. Signing
This DPA is effective upon acceptance of the Terms. A countersigned copy for procurement is available on request from sales@owntable.io.