Draft for legal review. Not legal advice; not yet approved by counsel.

Data Processing Agreement

Between the restaurant business that uses Tablenote (the Controller) and [Tablenote legal entity, address, to be completed by Tablenote] (the Processor), under Article 28 GDPR.

1. Parties and roles

The Controller decides to collect guest feedback for its restaurant and is the controller for that feedback. The Processor runs the Tablenote service and processes the feedback only on the Controller's behalf. For the Controller's own account data (names and email addresses of the people who sign in), Tablenote acts as a controller under its own privacy policy.

2. Subject matter and duration

The Processor provides anonymous guest feedback by QR code: a rating page, aggregated dashboards and weekly or monthly summaries. This agreement applies for as long as the Controller has a Tablenote account, and its deletion duties continue after that (section 9).

3. Nature and purpose of the processing

Collecting, storing, aggregating and deleting guest ratings so the Controller can see combined feedback about its restaurant. The Controller sees only figures that combine at least 5 ratings, never a single guest's rating, and never a time of day. The processing is not used to evaluate individual employees.

4. Types of personal data

5. Categories of data subjects

Guests of the Controller who choose to leave feedback. Indirectly, staff may be mentioned in comment text; the automatic name removal is designed to remove such mentions before storage.

6. Obligations of the processor

  1. Process the data only on the Controller's documented instructions, which are this agreement and the Controller's settings in the service.
  2. Ensure that everyone with access is bound to confidentiality.
  3. Take the security measures in section 10 (Article 32 GDPR).
  4. Engage sub-processors only as set out in section 7.
  5. Help the Controller answer data-subject requests, as far as the data allows: ratings are not linked to a guest's identity.
  6. Help the Controller with security, breach notification, impact assessments and prior consultation (Articles 32 to 36 GDPR), and report a personal-data breach without undue delay.
  7. Delete the data at the end of the service (section 9) unless law requires storage.
  8. Make available the information needed to show compliance, and allow and contribute to audits (section 12 sets the terms).

7. Sub-processors

The Processor informs the Controller of any intended change of sub-processors in advance, so the Controller can object.

8. International transfers

Data may be processed in the USA as well as in the EU (owner decision 2026-10-05). Resend, Inc. and Anthropic, PBC are located in the USA. Transfers to a country outside the EU or EEA follow Articles 44 to 49 GDPR. Transfer mechanism per sub-processor (for example the EU-US Data Privacy Framework or the EU standard contractual clauses): [to be confirmed by counsel].

9. Retention and deletion

10. Technical and organisational measures

11. California service-provider terms

Where the CCPA applies, the Processor acts as a service provider. It does not sell or share the personal information, does not retain, use or disclose it outside the direct business relationship or for any purpose other than providing the service, and does not combine it with personal information from other sources, except as the law allows.

12. Liability and governing law

[Liability, audit terms, governing law and place of jurisdiction, to be completed by counsel.]