Data processing agreement
Last updated: August 2026
Draft: not yet binding. This document has not been reviewed by a solicitor and is not in force. It is published so that it can be read and reviewed. Passages in double square brackets are points that have not been settled yet.
This agreement sets out the terms on which Tekeats processes personal data on behalf of a restaurant using the platform. UK GDPR Article 28 requires a written contract of this kind, and it protects the restaurant as much as us: without it, a restaurant using any processor is itself non-compliant. It forms part of the terms of service.
1. Roles
You, the restaurant, are the controller of your customers’ personal data. Tekeats is your processor for it.
Where we process personal data for our own purposes (your staff’s accounts, our billing records, our security logs), we are a controller in our own right and this agreement does not apply to that processing. Our privacy policy does.
If we ever step outside your instructions and determine the purpose of processing your customers’ data ourselves, we would become a controller for that processing and would take on the responsibility that goes with it. We do not intend to, and we do not use your customers’ data to market to them.
2. What is being processed (Article 28(3) particulars)
Subject matter: provision of the Tekeats ordering platform to you.
Duration: for as long as the terms of service are in force, plus any retention period stated in section 9.
Nature and purpose: hosting, storing, transmitting, displaying and organising order and customer data so that you can take and fulfil orders, communicate with your customers about them, and see records of them.
Categories of personal data: names, email addresses, telephone numbers, delivery addresses and their coordinates, order contents and history, order notes including any allergy information a customer volunteers, account credentials in hashed form, saved addresses and favourites, profile images, notification device tokens, payment outcomes and references. Not card numbers: those never reach us.
Categories of data subject: your customers, including guests who order without an account.
Special category data: none is requested by the platform. A customer may volunteer health-related information in an allergy note. [[CONFIRM the position on free-text allergy notes with a solicitor: it is a well-known wrinkle in food-ordering platforms, since the field is necessary for safety but may attract Article 9.]]
3. Our obligations
We will process your customers’ personal data only on your documented instructions, which include your use of the platform’s features and settings, and this agreement. If we believe an instruction breaches data protection law, we will tell you.
If the law requires us to process data otherwise than on your instructions, we will tell you before doing so unless the law prohibits that.
We will ensure our personnel who access the data are subject to confidentiality obligations and are given access only where they need it for their role.
We will not sell your customers’ data, and we will not use it to build or improve a product for anyone other than you, beyond aggregated statistics that cannot identify your business or any individual.
4. Security (Article 32)
Each tenant’s data is held in a separate database. Isolation is a property of the architecture rather than of every query being written correctly, which is a meaningfully stronger position than shared tables with a filter.
Data is encrypted in transit. Passwords and guest order tokens are stored only as cryptographic hashes. Payment credentials held on your behalf stay server-side; only the public identifiers a payment form requires are exposed to a browser.
Access by our staff is role-limited, and access into your dashboard is recorded against the individual who performed it, with the period of access.
[[TO COMPLETE before this is signed with a merchant: state backup frequency and retention, restore testing, patching cadence, whether multi-factor authentication is enforced for staff access, and the penetration-testing position. A processor security schedule that is vague is the first thing a competent counterparty will push back on.]]
5. Sub-processors
You give general authorisation for us to engage sub-processors. The current list, with the function of each, is in our privacy policy under “Who else is involved”. It covers hosting and object storage, address search and geocoding, push notification delivery, the payment provider you connect, and email delivery.
We will impose data protection obligations on each sub-processor that are no less protective than those in this agreement, and we remain responsible to you for their performance.
We will give you 30 days’ notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds; if we cannot resolve your objection, you may terminate the affected part of the service without penalty for the unexpired term.
6. Helping you meet your own obligations
If one of your customers exercises a right (access, correction, deletion, portability, objection), we will help you respond. Much of it you can do yourself in the dashboard; where you cannot, ask us.
If a request comes to us directly, we will not answer it on your behalf. We will pass it to you and act on your instruction, and we will tell the individual we have done so, so that nobody is left without a reply.
We will provide the information you reasonably need for a data protection impact assessment or a consultation with the ICO, so far as it concerns our processing.
7. Personal data breaches
If we become aware of a personal data breach affecting your customers’ data, we will notify you without undue delay, and in any event within 24 hours of becoming aware of it.
The notification will describe what we know: the nature of the breach, the categories and approximate number of records involved, the likely consequences, and what we are doing about it. Where we do not yet know something, we will say so and follow up rather than delay the first notification.
You are the party that decides whether to notify the ICO and affected individuals, because you are the controller. We will help you do it.
8. Audit and information
We will make available the information reasonably necessary to demonstrate our compliance with this agreement, and allow for audits, on reasonable notice and no more than once a year unless a breach or a regulator requires otherwise.
Audits must be at your cost, during business hours, subject to confidentiality, and conducted so as not to disrupt the service or compromise another tenant’s data. Where an independent report or certification would answer your question, we may offer that instead.
9. Deletion and return
On termination, and at your choice, we will delete or return your customers’ personal data. Ask us before you close the account and we will help you export it.
We may keep data where UK law requires it (order and payment records for tax and VAT purposes in particular, for the current financial year plus six years) and we will keep it only for that purpose and protected by this agreement.
Backups expire on their own cycle, so data may persist in a backup for a period after deletion. It is not restored into service except as part of a full recovery.
10. International transfers
Where a sub-processor processes data outside the UK, we will ensure a lawful transfer mechanism is in place (the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses), together with any additional measures required.
The principal transfers today arise from Google’s address, mapping and notification services. See our privacy policy for the current position.
11. Liability and precedence
The liability provisions in the terms of service apply to this agreement. [[CONFIRM with a solicitor whether data protection liability should sit inside or outside the general cap. Counterparties often ask for it to sit outside, and insurers often have a view.]]
If this agreement conflicts with the terms of service on the processing of your customers’ personal data, this agreement prevails.
Questions about this document? Contact us.