Draft for legal review. Not legal advice; not yet approved by counsel.
Data Processing Agreement
Between the restaurant business that uses Tablenote (the Controller) and [Tablenote legal entity, address, to be completed by Tablenote] (the Processor), under Article 28 GDPR.
1. Parties and roles
The Controller decides to collect guest feedback for its restaurant and is the controller for that feedback. The Processor runs the Tablenote service and processes the feedback only on the Controller's behalf. For the Controller's own account data (names and email addresses of the people who sign in), Tablenote acts as a controller under its own privacy policy.
2. Subject matter and duration
The Processor provides anonymous guest feedback by QR code: a rating page, aggregated dashboards and weekly or monthly summaries. This agreement applies for as long as the Controller has a Tablenote account, and its deletion duties continue after that (section 9).
3. Nature and purpose of the processing
Collecting, storing, aggregating and deleting guest ratings so the Controller can see combined feedback about its restaurant. The Controller sees only figures that combine at least 5 ratings, never a single guest's rating, and never a time of day. The processing is not used to evaluate individual employees.
4. Types of personal data
- Ratings: stars, selected feedback chips, detail stars, the channel (dine-in or delivery), the code placement and the business day. No time of day is stored with a rating. A star a guest taps is saved even if the guest leaves the page before sending; feedback chips, detail stars and comments are sent only when the guest sends.
- Comment text, only in languages whose automatic name removal has met its quality target, and only after names and personal descriptors are removed. Comment text is not stored in other languages.
- Abuse protection: a salted, daily rotating hash of the IP address, a one-time page-load token and the time a rating was received, kept apart from the ratings.
- No names, email addresses or phone numbers of guests are requested.
5. Categories of data subjects
Guests of the Controller who choose to leave feedback. Indirectly, staff may be mentioned in comment text; the automatic name removal is designed to remove such mentions before storage.
6. Obligations of the processor
- Process the data only on the Controller's documented instructions, which are this agreement and the Controller's settings in the service.
- Ensure that everyone with access is bound to confidentiality.
- Take the security measures in section 10 (Article 32 GDPR).
- Engage sub-processors only as set out in section 7.
- Help the Controller answer data-subject requests, as far as the data allows: ratings are not linked to a guest's identity.
- Help the Controller with security, breach notification, impact assessments and prior consultation (Articles 32 to 36 GDPR), and report a personal-data breach without undue delay.
- Delete the data at the end of the service (section 9) unless law requires storage.
- Make available the information needed to show compliance, and allow and contribute to audits (section 12 sets the terms).
7. Sub-processors
- Hosting and database: [provider and location, to be completed by Tablenote].
- Email delivery for owner emails (sign-in links, summaries): Resend, Inc., USA. Guest feedback is sent only as combined figures.
- AI summaries and translation of comments after names and personal details have been removed (planned): Anthropic, PBC, USA. Data retention and use for training: [terms, to be confirmed by counsel]. It is listed here before it is used.
The Processor informs the Controller of any intended change of sub-processors in advance, so the Controller can object.
8. International transfers
Data may be processed in the USA as well as in the EU (owner decision 2026-10-05). Resend, Inc. and Anthropic, PBC are located in the USA. Transfers to a country outside the EU or EEA follow Articles 44 to 49 GDPR. Transfer mechanism per sub-processor (for example the EU-US Data Privacy Framework or the EU standard contractual clauses): [to be confirmed by counsel].
9. Retention and deletion
- Raw comment text: at most 24 hours, until the names are removed.
- IP hash and abuse records, including one-time tokens and receive times: at most 48 hours.
- Cleaned comment text: 90 days.
- Combined figures: for as long as the account exists. A paid pack that ends falls back to the free pack; older history is hidden, not deleted.
- After the Controller deletes its account, collection stops at once and all venue data is deleted within 30 days.
10. Technical and organisational measures
- Data minimisation: no guest names or contact details; ratings store the business day only.
- Aggregation: every figure shown to the Controller comes from a period and a cell with at least 5 ratings, and further figures are hidden where they would reveal a smaller count. [Whether shares such as "happy guests" need an additional floor is under review by Tablenote.]
- Name removal before storage of comment text, in several rule- and model-based layers.
- Encryption in transit (TLS); access to production systems limited to named Tablenote staff: [details, to be completed by Tablenote].
- No cookies, tracking or analytics on the guest rating page.
- Monitoring of the scheduled deletion jobs, with an alert when one does not run.
11. California service-provider terms
Where the CCPA applies, the Processor acts as a service provider. It does not sell or share the personal information, does not retain, use or disclose it outside the direct business relationship or for any purpose other than providing the service, and does not combine it with personal information from other sources, except as the law allows.
12. Liability and governing law
[Liability, audit terms, governing law and place of jurisdiction, to be completed by counsel.]