1. Scope and incorporation
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between Tech for Tabs, LLC (“Tech for Tabs”) and the customer that accepts it (“Customer”). It applies whenever Tech for Tabs processes Customer Personal Data on Customer's behalf in providing the Services, and takes effect when Customer accepts the Agreement.
If this DPA conflicts with the Agreement, this DPA controls as to the processing of Customer Personal Data. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control.
2. Definitions
- Data Protection Laws — all laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended (“CCPA”), and other US state privacy laws.
- Customer Personal Data — personal data contained in Customer Data that Tech for Tabs processes on behalf of Customer.
- Security Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Subprocessor — a third party engaged by Tech for Tabs to process Customer Personal Data.
- “Controller,” “processor,” “data subject,” “processing,” “business,” “service provider” and similar terms have the meanings given in Data Protection Laws.
3. Roles and instructions
Customer is the controller (or business) of Customer Personal Data and Tech for Tabs is its processor (or service provider). Tech for Tabs will process Customer Personal Data only on Customer's documented instructions, which are the Agreement, this DPA and Customer's configuration and use of the Services, unless required to do otherwise by law (in which case Tech for Tabs will inform Customer before processing, unless the law prohibits it). Tech for Tabs will tell Customer if it believes an instruction infringes Data Protection Laws.
Customer is responsible for the lawfulness of its instructions and of the Customer Personal Data it provides, including giving notices to and obtaining any consents from its staff and guests.
4. Details of processing
| Subject matter | Provision of the Tech for Tabs restaurant operating system to Customer. |
|---|---|
| Duration | The term of the Agreement plus the post-termination export and deletion periods described in it. |
| Nature and purpose | Hosting, storage, retrieval, organisation, computation, transmission and display of Customer Personal Data to provide the Services — including invoices and purchasing, costing, point of sale, reservations and waitlist, scheduling and time clock, reporting, AI invoice reading, support and security. |
| Categories of data subjects | Customer's Authorized Users; Customer's employees and contractors; Customer's guests; contacts at Customer's vendors. |
| Types of personal data | Identification and contact details (name, email, phone); job title, role and permissions; schedules, time punches, timesheets, pay rates and tip allocations; reservation, waitlist and visit details, preferences and notes (which may include allergies or dietary requirements provided by guests); order and check details; vendor contact details; usage and log data. |
| Sensitive data | Not intended. Guest notes may incidentally include health-related information such as allergies, which Customer provides at its discretion for the purpose of serving the guest safely. |
5. Confidentiality of personnel
Tech for Tabs will ensure that personnel authorized to process Customer Personal Data are bound by obligations of confidentiality and access it only as needed to provide the Services, support and security.
6. Security measures
Tech for Tabs will implement and maintain technical and organisational measures appropriate to the risk, including:
- logical tenant isolation enforced on every database query, with automated tests that verify it;
- encryption in transit (TLS) and encryption at rest by our database provider;
- AES-256-GCM encryption of stored third-party credentials and webhook secrets, with keys held outside the database;
- salted password hashing (scrypt), hashed API keys and single-use, expiring password-reset tokens;
- role-based access controls scoped by location, and re-validation of sessions on every request;
- audit logging of security-relevant and financial actions;
- managed database backups with point-in-time recovery;
- least-privilege access for Tech for Tabs personnel.
A current summary is published on our Security page. Tech for Tabs may update these measures provided the overall level of protection is not reduced.
7. Subprocessors
Customer gives general authorization for Tech for Tabs to engage Subprocessors. Our current Subprocessors are listed at techfortabs.com/legal/subprocessors. Tech for Tabs will impose data protection obligations on each Subprocessor that are no less protective than this DPA, and remains responsible for their performance.
Tech for Tabs will give at least 30 days' notice before adding or replacing a Subprocessor, by updating that page and notifying customers who have asked to receive notices. Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected Services and receive a refund of prepaid fees for the remainder of the term.
8. Data subject requests
Taking into account the nature of the processing, Tech for Tabs will assist Customer by appropriate technical and organisational measures in responding to requests from data subjects to exercise their rights. Most requests can be handled by Customer directly in the Services (for example, by editing, exporting or deleting records). If Tech for Tabs receives a request directly, it will forward it to Customer and will not respond except to direct the data subject to Customer, unless required by law.
9. Security incidents
Tech for Tabs will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the incident, the categories and approximate volume of data affected, likely consequences and the measures taken or proposed. Tech for Tabs will take reasonable steps to contain and remediate the incident and provide reasonable assistance with Customer's own notification obligations. Notification is not an acknowledgement of fault.
10. Impact assessments and consultation
Tech for Tabs will provide reasonable information to help Customer carry out data protection impact assessments and prior consultations with supervisory authorities, where required by Data Protection Laws and relating to Customer's use of the Services.
11. Audits
On written request no more than once a year, Tech for Tabs will provide information reasonably necessary to demonstrate compliance with this DPA, such as responses to security questionnaires and summaries of its security practices. Where Data Protection Laws require an on-site audit, it will be conducted by Customer or an independent auditor bound by confidentiality, on 30 days' notice, during business hours, at Customer's expense and without disrupting the Services.
12. International transfers
Tech for Tabs and its Subprocessors process Customer Personal Data in the United States. To the extent Customer Personal Data originating in the EEA, UK or Switzerland is transferred to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor, and Module Three, processor to processor, as applicable), together with the UK International Data Transfer Addendum and any Swiss amendments where relevant, are incorporated by reference, with the details of processing in Section 4 and the security measures in Section 6 completing their annexes, and with Florida, United States, replaced by the law and courts required by those clauses where necessary.
13. CCPA service provider terms
To the extent the CCPA applies, Tech for Tabs will not:
- sell or share Customer Personal Data;
- retain, use or disclose it for any purpose other than the business purposes of providing the Services under the Agreement, or outside the direct business relationship with Customer;
- combine it with personal information it receives from other sources, except as permitted by the CCPA.
Tech for Tabs will notify Customer if it can no longer meet its obligations under the CCPA.
14. Return and deletion
During the term Customer can export Customer Personal Data at any time. After termination, Tech for Tabs will make it available for export for 30 days and then delete it from active systems, with backup copies overwritten within 90 days, except where retention is required by law.
15. Liability
Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws do not permit such limitation.
16. Contact and countersignature
This DPA applies automatically when you accept the Terms of Service. If your organisation needs a countersigned copy or has questions, email legal@techfortabs.com. Privacy questions: privacy@techfortabs.com.
Data Processing Addendum · Tech for Tabs, LLC · Last updated October 8, 2026