Data Processing Agreement
This TablesReady Data Processing Agreement ("DPA") reflects the parties' agreement with respect to the terms governing the Processing of Personal Data under the TablesReady Terms of Service with respect to Customers (the "Agreement"). Where Personal Data is transferred outside the European Economic Area, the United Kingdom, or Switzerland, this DPA incorporates the applicable cross-border transfer mechanisms — the EU Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, the United Kingdom International Data Transfer Addendum, and the Swiss adaptations described in Exhibit 1. This DPA is an amendment to the Agreement and is effective upon its incorporation into the Agreement. Upon its incorporation into the Agreement, the DPA will form a part of the Agreement.
The term of this DPA will follow the term of the Agreement. Terms not otherwise defined herein will have the meaning as set forth in the Agreement.
THIS DPA INCLUDES:
- Cross-Border Data Transfer Mechanisms (the EU Standard Contractual Clauses, the UK Addendum, and Swiss adaptations), attached as EXHIBIT 1.
- Annex I — details of the Personal Data and parties to the transfer.
- Annex II — description of the technical and organizational security measures implemented by the data importer.
- Annex III — list of Sub-Processors.
1. Definitions
"Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
"Customer" has the meaning given in the Agreement and means the business or other organization that creates a TablesReady account or uses the Services to manage its waitlist, reservations, bookings, guests, or guest communications. Depending on the circumstances, Customer may act as a Controller or as a Processor on behalf of a third-party Controller.
"Data Protection Law" means all applicable legislation relating to data protection and privacy, including the GDPR, the UK GDPR, the Swiss FADP, and all other applicable national, state, or local laws and regulations, together with any implementing or successor laws, in each case as amended, consolidated, or replaced from time to time. The terms "process", "processes" and "processed" will be construed accordingly.
"Data Subject" means the individual to whom Personal Data relates.
"EU SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to the GDPR, adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as completed and as further described in Exhibit 1.
"GDPR" means the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"Swiss FADP" means the Swiss Federal Act on Data Protection of 25 September 2020, as amended, and its implementing ordinance.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018 and in force from 21 March 2022, as completed and as further described in Exhibit 1.
"UK GDPR" means the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018.
"Instruction" means the written, documented instruction, issued by Controller to Processor, and directing the same to perform a specific action with regard to Personal Data (including, but not limited to, depersonalizing, blocking, deletion, making available).
"Personal Data" means any information relating to an identified or identifiable individual where such information is contained within Customer Data and is protected similarly as personal data or personally identifiable information under applicable Data Protection Law.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
"Processing" means any operation or set of operations which is performed on Personal Data, encompassing the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction or erasure of Personal Data.
"Processor" means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
"Standard Contractual Clauses" or "SCCs" means, collectively, the EU SCCs, the UK Addendum, and the Swiss adaptations, in each case as set out and completed in Exhibit 1, and as applicable to a given transfer.
2. Details of the Processing
- Categories of Data Subjects. Customer's customers, guests, employees, contractors, and Authorized Users. Data Subjects also include individuals attempting to communicate with or transfer Personal Data to the Customer's end users.
- Types of Personal Data. Contact information such as name, phone number, and email, the extent of which is determined and controlled by the Customer in its sole discretion, and other Personal Data such as customer preferences, service usage data, and other electronic data submitted, stored, sent, or received by end users via the Services.
- Subject-Matter and Nature of the Processing. The subject-matter of Processing of Personal Data by Processor is the provision of the Services to the Customer that involves the Processing of Personal Data. Personal Data will be subject to those Processing activities as may be specified in the Agreement.
- Purpose of the Processing. Personal Data will be Processed for purposes of providing the Services set out and otherwise agreed to in the Agreement.
- Duration of the Processing. Personal Data will be Processed for the duration of the Agreement, subject to Section 4 of this DPA.
3. Customer Responsibility
Within the scope of the Agreement and in its use of the Services, Customer will be solely responsible for complying with the statutory requirements relating to data protection and privacy, in particular regarding the disclosure and transfer of Personal Data to the Processor and the Processing of Personal Data. For the avoidance of doubt, Customer's instructions for the Processing of Personal Data will comply with the Data Protection Law. This DPA is Customer's complete and final instruction to TablesReady in relation to Personal Data, and additional instructions outside the scope of this DPA require prior written agreement between the parties. Instructions will initially be specified in the Agreement and may, from time to time thereafter, be amended, amplified, or replaced by Customer in separate written instructions.
Customer will inform Processor without undue delay and comprehensively about any errors or irregularities related to statutory provisions on the Processing of Personal Data.
4. Obligations of Processor
- Compliance with Instructions. The parties acknowledge and agree that Customer is the Controller of Personal Data, or acts as a Processor on behalf of a third-party Controller, and TablesReady is the Processor or Sub-Processor of that data. Processor will collect, process, and use Personal Data only within the scope of Customer's instructions. If the Processor believes that an instruction of the Customer infringes the Data Protection Law, it will immediately inform the Customer without delay. If Processor cannot process Personal Data in accordance with the instructions due to a legal requirement under applicable Data Protection Law, Processor will (i) promptly notify the Customer of that legal requirement before the relevant Processing to the extent permitted by the Data Protection Law; and (ii) cease all Processing (other than merely storing and maintaining the security of the affected Personal Data) until such time as the Customer issues new instructions with which Processor is able to comply. If this provision is invoked, Processor will not be liable to the Customer under the Agreement for any failure to perform the applicable services until such time as the Customer issues new instructions in regard to the Processing.
- Security. Processor will take the appropriate technical and organizational measures to adequately protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, described under Annex II.
- Confidentiality. Processor will ensure that any personnel whom Processor authorizes to process Personal Data on its behalf is subject to confidentiality obligations with respect to that Personal Data. The undertaking to confidentiality will continue after the termination of the above-entitled activities.
- Personal Data Breaches. Processor will notify the Customer without undue delay after it becomes aware of any Personal Data Breach affecting Personal Data. At the Customer's request, Processor will promptly provide the Customer with all reasonable assistance necessary to enable the Customer to notify relevant Personal Data Breaches to competent authorities and/or affected Data Subjects, if Customer is required to do so under the Data Protection Law.
- Data Subject Requests. Processor will provide reasonable assistance, including by appropriate technical and organizational measures and taking into account the nature of the Processing, to enable Customer to respond to any request from Data Subjects seeking to exercise their rights under the Data Protection Law with respect to Personal Data (including access, rectification, restriction, deletion, or portability of Personal Data, as applicable), to the extent permitted by law. If such request is made directly to Processor, Processor will promptly inform Customer and will advise Data Subjects to submit their request to the Customer. Customer will be solely responsible for responding to any Data Subjects' requests. Customer will reimburse Processor for the costs arising from this assistance.
- Compliance Assistance and Audit Requests. Taking into account the nature of the Processing and the information available to Processor, Processor will provide reasonable assistance necessary for Customer to comply with Customer's obligations under Data Protection Law relating to security of Processing, Personal Data Breach notification, Data Protection Impact Assessments, and consultations with supervisory authorities. Processor may satisfy such assistance by providing existing documentation, written responses, and reasonable support. Customers on an Enterprise plan may request security questionnaires and reasonable audits related to Processor's Processing of Personal Data under this DPA. Audits must be subject to reasonable prior notice, confidentiality, scope limitations, and security requirements, and may not unreasonably disrupt Processor's business or compromise the security, privacy, or confidentiality of Processor's systems or another customer. Customer will reimburse Processor for costs arising from assistance, questionnaires, audits, or other non-routine requests, except to the extent otherwise agreed in writing.
- Sub-Processors. Customer agrees that Processor may disclose Personal Data to its subcontractors for purposes of providing the Services ("Sub-Processors"), provided that Processor (i) shall enter into an agreement with its Sub-Processors that imposes on the Sub-Processors obligations regarding the Processing of Personal Data that are at least as protective of Personal Data as those that apply to Processor hereunder, including requiring the Sub-Processors to only process Personal Data to the extent required to perform the obligations sub-contracted to them, and (ii) shall remain fully liable for all obligations subcontracted to, and all acts and omissions of, the Sub-Processors. Processor's current list of Sub-Processors is set out in Annex III and maintained at www.tablesready.com/dpa. The Processor will inform Customer of any intended changes concerning the addition or replacement of Sub-Processors and Customer will have an opportunity to object to such changes on reasonable grounds within ten (10) business days after being notified of the engagement of the Sub-Processor. If Customer objects to a new Sub-Processor, as permitted in the preceding sentence, Processor will use reasonable efforts to make available to Customer a change in the Services or recommend a commercially reasonable change to Customer's configuration or use of the Services to avoid Processing of Personal Data by the objected-to new Sub-Processor without unreasonably burdening Customer. If Processor is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) days, either party may terminate the component of the Services which cannot be provided by Processor without the use of the objected-to new Sub-Processor by providing written notice to the other party. Processor will refund Customer any prepaid fees covering the remainder of the term of Customer's subscription following the effective date of termination with respect to such terminated component of the Services, without imposing a penalty for such termination on Customer.
- Data Transfers. Customer acknowledges and agrees that, in connection with the performance of the Services under the Agreement, Personal Data will be transferred to TablesReady, LLC in the United States. To the extent Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland is transferred to TablesReady (or onward to a Sub-Processor) in a country that has not received an adequacy decision under applicable Data Protection Law, the Standard Contractual Clauses set out in Exhibit 1 apply and are incorporated by reference: the EU SCCs (Module Two, controller to processor; and Module Three, processor to processor, where Customer itself acts as a processor) for EEA transfers; the UK Addendum for United Kingdom transfers; and the Swiss adaptations for Switzerland. The Annexes to those clauses are completed by Annexes I through III of this DPA.
- Deletion or Retrieval of Personal Data. During the term of the Agreement, Customer may retrieve or delete Personal Data using Service features available for Customer's plan and Customer's data-retention settings. Following termination or expiry of the Agreement, Processor will delete Personal Data in accordance with the Agreement, Customer's applicable retention settings, Processor's standard deletion and backup lifecycle, and Data Protection Law, except to the extent retention is required or permitted by Data Protection Law. If Customer requests return or export of Personal Data, Processor will provide reasonable assistance to the extent available under Customer's plan and the Services; Customers on Free and Starter plans may not be able to export all Customer Data. Processor does not provide deletion certifications unless separately agreed in writing. Any additional cost arising in connection with the return or deletion of Personal Data after the termination or expiration of the Agreement will be borne by Customer.
5. General Provisions
With respect to updates and changes to this DPA, the terms that apply in the "Amendment; No Waiver" section of "Miscellaneous" in the Agreement will apply.
In case of any conflict, this DPA will take precedence over the regulations of the Agreement. Where individual provisions of this DPA are invalid or unenforceable, the validity and enforceability of the other provisions of this DPA will not be affected.
Upon the incorporation of this DPA into the Agreement, the parties indicated in Section 6 below (Parties to this DPA) are agreeing to the Standard Contractual Clauses (where and as applicable) and all Annexes attached thereto. In the event of any conflict or inconsistency between this DPA and the Standard Contractual Clauses in Exhibit 1, the Standard Contractual Clauses will prevail.
TablesReady processes Personal Data in accordance with the Data Protection Law requirements contained herein that are applicable to TablesReady's provision of the Services.
6. Parties to this DPA
This DPA is an amendment to and forms part of the Agreement. Customer and TablesReady are each a party to this DPA. The legal entity agreeing to this DPA as Customer represents that it is authorized to agree to and enter into this DPA for, and is agreeing to this DPA solely on behalf of, the Customer.
EXHIBIT 1 — Cross-Border Data Transfer Mechanisms
This Exhibit sets out the mechanisms that apply to the transfers of Personal Data described in Section 4 ("Data Transfers"). It does not reproduce the full text of the clauses it incorporates; the official texts are incorporated by reference and apply as completed below.
Part A — EU Standard Contractual Clauses (EEA transfers)
For transfers of Personal Data subject to the GDPR, the EU SCCs are incorporated into this DPA by reference. The official text is published by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 and is available at eur-lex.europa.eu. The EU SCCs are completed as follows:
- Modules. Module Two (Controller to Processor) applies where Customer is a controller of the Personal Data. Module Three (Processor to Processor) applies where Customer acts as a processor on behalf of a third-party controller.
- Clause 7 (Docking clause). Applies.
- Clause 9 (Use of Sub-Processors). Option 2 (general written authorization) applies. The Processor will inform the Customer of any intended addition or replacement of Sub-Processors as set out in Section 4 ("Sub-Processors"), giving at least ten (10) business days' prior notice.
- Clause 11 (Redress). The optional language providing for an independent dispute-resolution body does not apply.
- Clause 17 (Governing law). The EU SCCs are governed by the law of Ireland.
- Clause 18 (Choice of forum and jurisdiction). Disputes will be resolved before the courts of Ireland.
- Annexes. Annex I, Annex II, and Annex III of this DPA serve as Annexes I, II, and III to the EU SCCs respectively.
- Data exporter / data importer. Customer is the data exporter; TablesReady, LLC is the data importer.
In the event of any conflict between this DPA and the EU SCCs, the EU SCCs prevail with respect to transfers to which they apply.
Part B — UK International Data Transfer Addendum (UK transfers)
For transfers of Personal Data subject to the UK GDPR, the UK Addendum is incorporated into this DPA by reference. The official text issued by the UK Information Commissioner is available at ico.org.uk. The UK Addendum's tables are completed as follows:
- Table 1 (Parties). The Parties and their details are as set out in Annex I.A.
- Table 2 (Approved EU SCCs). The version of the Approved EU SCCs to which the UK Addendum appends is the EU SCCs set out in Part A above, including the Modules and elections specified there.
- Table 3 (Appendix Information). The Appendix Information is set out in Annex I, Annex II, and Annex III of this DPA.
- Table 4 (Ending the Addendum when the Approved Addendum changes). Neither Party may end the UK Addendum as set out in Section 19 of the UK Addendum, except as otherwise provided in the UK Addendum.
For transfers subject to the UK GDPR, references in the EU SCCs are read as adjusted by the UK Addendum, and the Information Commissioner is the competent supervisory authority.
Part C — Switzerland (Swiss FADP)
For transfers of Personal Data subject to the Swiss FADP, the EU SCCs apply with the following adaptations:
- The Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority for transfers governed by the Swiss FADP.
- References in the EU SCCs to the "GDPR" are read to include the Swiss FADP, and references to "Member State" are read to include Switzerland, in each case to the extent the transfer is subject to the Swiss FADP.
- The EU SCCs also protect the Personal Data of Swiss-resident Data Subjects, who may enforce their third-party-beneficiary rights in Switzerland, until the entry into force of any equivalent provisions under Swiss law.
Annex I
A. List of Parties
Data exporter. Customer, as defined in the Agreement, acting as Controller (or, under Module Three of the EU SCCs, as a processor on behalf of a third-party controller). The data exporter's contact details, role, and signature are as set out in the Agreement and the Customer's account. The data exporter's activities relevant to the transfer are its use of the Services to manage waitlists, reservations, check-ins, and guest communications.
Data importer. TablesReady, LLC, a New Hampshire limited liability company, 11 Forest Green Rd, Rye, NH 03870, USA, acting as Processor. Contact: support@tablesready.com. The data importer's activities relevant to the transfer are the provision of the Services to the Customer as described in the Agreement.
B. Description of Transfer
- Categories of Data Subjects. As set out in Section 2 — the Customer's customers, guests, employees, contractors, and Authorized Users, and individuals who communicate with or transfer Personal Data to the Customer's end users.
- Categories of Personal Data. As set out in Section 2 — contact information (such as name, phone number, and email) and other Personal Data such as customer preferences, service-usage data, and other electronic data submitted, stored, sent, or received via the Services.
- Sensitive data. The parties do not anticipate the transfer of special categories of data.
- Frequency of the transfer. Continuous, for the duration of the Agreement.
- Nature and purpose of the Processing. Provision of the Services to the Customer, as set out in Sections 2 and 4.
- Duration of the Processing / retention. For the duration of the Agreement, subject to Section 4 ("Deletion or Retrieval of Personal Data").
- Sub-Processors. Transfers to Sub-Processors are for the purposes and the duration set out in Annex III and the Agreement.
C. Competent Supervisory Authority
Where the EU SCCs apply and are governed by Irish law, the competent supervisory authority is the Irish Data Protection Commission, except where Clause 13 of the EU SCCs requires the supervisory authority of the Member State in which the data exporter is established or, as relevant, in which affected Data Subjects are located. For transfers subject to the UK GDPR, the competent authority is the UK Information Commissioner; for transfers subject to the Swiss FADP, the FDPIC.
Annex II — Technical and Organizational Measures
The data importer implements and maintains the following technical and organizational measures to protect Personal Data, taking into account the nature, scope, and purposes of the Processing:
- Access control. Access to servers, source code, and third-party tools is secured with two-factor authentication. Personnel and contractors are granted the lowest level of access that allows them to perform their work, and access to production systems or production data is limited to personnel with a need to know.
- Personnel confidentiality. Personnel and contractors sign confidentiality agreements before gaining access to sensitive information.
- Remote-work safeguards. The data importer operates as a remote organization and uses a Zero Trust access model requiring authentication to access TablesReady resources. Personnel are required to use a secure VPN when working from public networks.
- Credential protection. Customer account passwords are hashed using bcrypt and are not retrievable after hashing. Email-based password resets can only be sent to the account's pre-registered email address. Invited account users receive personalized invite links that expire after 30 days.
- Session controls. After login, users receive a JSON web token for API access. The token is invalidated after 24 hours of inactivity.
- Encryption in transit. Communications between the TablesReady frontend and backend are encrypted using TLS 1.2, or TLS 1.3 where supported. TablesReady uses Heroku Automated Certificate Management for backend certificates and Cloudflare end-to-end encryption for the domain.
- Encryption at rest. User data stored in Heroku Postgres is encrypted at rest.
- Production data handling. Production data is not copied to external devices such as personal laptops.
- Logging and retention. Logs are stored separately from backend infrastructure in Datadog and are retained for 30 days before permanent deletion.
- Application data retention. Customer application data is deleted 18 months after the last login by default. Customers may configure Data Retention settings to delete Customer application data as soon as 1 day after it is created.
- Software development controls. Code is reviewed by at least one other developer before committing and is tested in a staging environment against a QA checklist before production deployment.
- Vulnerability and threat detection. Client and backend dependencies are regularly scanned for known security vulnerabilities, and vulnerable dependencies are patched and redeployed rapidly. Datadog Application Security Monitoring is used to detect and protect against threats targeting production systems in real time.
- Availability and backups. Database backups are performed daily, retained for 7 days, and can be restored within hours. For messaging outages, the data importer can fail over between Telnyx and Twilio to support message deliverability.
- Infrastructure providers. The data importer relies on established cloud-infrastructure providers, including Heroku and Amazon Web Services, that maintain measures designed to support the confidentiality, integrity, availability, and resilience of processing systems.
- Sub-Processor measures. The data importer imposes data-protection obligations on its Sub-Processors that are at least as protective as those in this DPA, as set out in Section 4 ("Sub-Processors").
Notwithstanding any provision to the contrary otherwise agreed by the data exporter, TablesReady may modify or update these measures at its discretion, provided that such modification or update does not result in a material degradation in the protection offered by these measures. Capitalized terms not otherwise defined in this Annex have the meanings set out in the DPA or the Agreement.
Annex III — List of Sub-Processors
This Annex sets out the Sub-Processors authorized under the general written authorization in Section 4 and EU SCCs Clause 9 (Option 2). Each Sub-Processor is engaged under a written agreement imposing data-protection obligations at least as protective as those in this DPA, and only a minimum relevant set of data is shared with each:
- Heroku — used for processing requests and funneling data to database
- Amazon Web Services (AWS) — used for cloud infrastructure and storage
- Google Cloud / Firebase — used for hosting and infrastructure
- Redis Labs — used for application data caching and temporary storage of user data
- Cloudflare — used for DNS, content delivery, security, and bot protection (Turnstile)
- Telnyx — used for messaging (SMS) and voice
- Twilio — used for messaging (SMS) and voice
- Postmark — used for transactional emails
- Datadog — used for logging and monitoring and may contain limited user data
- Amplitude — used for product analytics and may contain limited user data
- Drip — used for marketing emails and may contain limited user data
- Help Scout — used for support and chat
- Recurly — used for subscription management
- Stripe — used for payment processing
- ProfitWell — used for subscription metrics and may contain limited billing data
- Informizely — used for surveys and may contain limited user data