Data Processing Agreement
Last updated 30 June 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the restaurant) and TableTango Ltd, a company registered in England & Wales (company no. 17287615) whose registered office is 71–75 Shelton Street, Covent Garden, London WC2H 9JQ ("TableTango"). It sets out how we handle your guests' personal data on your behalf, as required by UK data protection law (UK GDPR Article 28). You accept it when you connect your restaurant. Plain English, as ever — questions to hello@tabletango.co.uk.
1. Who's who
Your guests' personal data is yours. You decide what's collected and why, so you are the data controller. We process it only to run the service for you, so we are your data processor. (Separately, for our own data — your account details and email enquiries to us, and our staff — we're the controller; that's covered in our privacy notice.)
2. What we process, and why
| Subject matter | Providing the TableTango booking service to your restaurant. |
|---|---|
| Duration | For as long as you use the service, then deletion/return as in section 7. As a standing retention measure, personal data on individual bookings is automatically anonymised 24 months after the booking, and text/email logs and unused waitlist/feedback records are deleted after 24 months. |
| Nature & purpose | Taking, storing and managing bookings; sending confirmation and reminder messages; and the optional features you switch on (waitlist, post-visit reviews, AI booking chat). |
| Types of personal data | Guest name, mobile number, email, booking details (date, time, party, table), and any notes or dietary/standing-requirement information the guest chooses to provide. |
| Categories of data subject | Your guests / diners (and people who join your waitlist). |
3. Our promises as your processor
- Only on your instructions. We process your guests' data only to provide the service and on your documented instructions (these terms + how you configure the service). We'll tell you if we think an instruction breaks the law.
- Confidentiality. Anyone who can access the data is bound to keep it confidential.
- Security. We keep appropriate technical and organisational measures (UK GDPR Article 32): data hosted in the UK (London); access controls and row-level security so each restaurant only sees its own data; encryption in transit and at rest; secret keys held in a secrets vault, never in the website code; daily encrypted backups with restoration; and monitoring for security issues.
- Helping with guest rights. We help you respond to your guests' data requests — the admin console can export or erase a guest's data by phone or email.
- Breaches. We'll tell you without undue delay if we become aware of a personal-data breach affecting your data, with the detail you need to meet your own obligations, and help you assess and report it.
- Help with assessments. We'll reasonably assist with data protection impact assessments and any prior consultation with the ICO.
- Deletion / return. When you leave, or ask us to, we delete or return your guests' data — and delete existing copies — within 30 days; this takes priority over the standing 24-month retention above, so we don't wait for the 24-month point. The only exception is data the law requires us to keep.
4. Sub-processors
We use a small set of trusted providers to run the service. This list covers the sub-processors that handle your guests' data; providers we use only for our own data — such as email-deliverability checks for our outreach to restaurants — are listed in our privacy notice instead. By accepting this DPA you give general authorisation to those below. We'll give you at least 30 days' notice before we add or replace one; if you have a reasonable data-protection objection, tell us and we'll try to resolve it, and if we can't you can stop using the affected feature or cancel without penalty. We put data-protection obligations on each sub-processor that are equivalent to those in this DPA, and we remain responsible to you for what they do with your guests' data.
| Provider | What they do |
|---|---|
| Supabase | Database & hosting (London, UK) |
| The SMS Works | Sends the SMS confirmations & reminders (UK-based; Twilio is a backup sender) |
| Zoho / ZeptoMail | Email — ZeptoMail (Zoho's transactional service) sends booking & account emails; Zoho Mail is our mailbox |
| Anthropic | Powers the AI booking chat |
| Netlify | Hosts the website |
| Stripe | Payment processing for the optional money features a restaurant switches on — holding a card for No-show Shield, and collecting and settling Deposits/prepayment and Booking add-ons; the restaurant is the merchant of record on its own Stripe account |
5. Where the data lives
Your guests' data is stored in the UK (London). Where a sub-processor necessarily processes some data outside the UK, it's done under the safeguards the law requires (an adequacy decision, or standard contractual clauses / the UK IDTA).
6. Your side
You confirm you have a lawful basis for collecting your guests' data, that you give your guests the privacy information they're entitled to, and that your instructions to us comply with data-protection law.
7. Audits & information
We'll give you the information you reasonably need to show you're meeting your Article 28 obligations, and allow audits or inspections to the extent the law requires (on reasonable notice and at reasonable cost).
8. Liability, term & law
This DPA lasts as long as we process your guests' data. Liability under it is governed by the limits in the Terms of Service, and nothing here limits anything that can't legally be limited. This DPA is governed by the law of England and Wales.
Contact
TableTango Ltd — hello@tabletango.co.uk · tabletango.co.uk · Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ