Skip to content

Data processing agreement

The terms under which Restro processes your diners’ personal data on your instructions.

Last updated 29 July 2026

01Scope

This agreement applies whenever Restro processes personal data about your diners or your staff on your behalf. It forms part of the terms of service, and where the two disagree on data protection, this document wins.

02What is processed

Subject matter: providing the Restro service. Duration: for as long as your account is open, plus the retention periods set out in the privacy policy.

  • Categories of people: your diners, your staff, and the people you invite
  • Categories of data: names, contact details, addresses, order history, payment references, reviews, marketing preferences, staff hours and pay records
  • Special category data: none is required by the service, and none should be entered into free-text fields

03Our obligations

As processor we will:

  • Process personal data only on your documented instructions, including any transfer outside your region
  • Ensure everyone with access is bound by confidentiality
  • Apply appropriate technical and organizational security measures
  • Assist you in responding to requests from the people whose data it is
  • Assist you with impact assessments and consultations where the law requires them
  • Delete or return the data at the end of the agreement, unless the law requires us to keep it
  • Make available the information needed to demonstrate compliance, and allow audits

04Sub-processors

You give general authorization for us to use sub-processors for hosting, email delivery, text messaging, error monitoring and payments. A current list is available on request.

We will give you at least thirty days’ notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative, and if none exists you may terminate the affected part of the service.

05Security

Access is limited by role and by location, encrypted in transit and at rest, with every change written to a record nobody can edit. Card numbers never enter our systems.

06Personal data breaches

If we become aware of a breach affecting your data, we will notify you without undue delay and in any event within seventy-two hours of becoming aware, with what we know, what we are doing, and what we recommend you do.

07International transfers

Where personal data moves outside the region agreed with you, we rely on an adequacy decision where one exists and on standard contractual clauses where one does not.

08Deletion and return

On termination you may export your data for thirty days. After that we begin deletion, except where law requires retention, in which case the data remains protected by this agreement until it is deleted.