Introduction & Parties
This Data Processing Addendum ("DPA") governs the processing of personal data by TableGreet LLC (the "Processor") on behalf of the customer subscribing to the TableGreet SaaS services (the "Controller"). This DPA is incorporated into and forms an integral part of the TableGreet Terms of Service.
For the purposes of European Union data protection laws (including the GDPR), UK data protection laws, and Moroccan data protection laws (Law No. 09-08), this DPA defines the security, privacy, and compliance commitments of TableGreet when handling Customer Personal Data.
Scope & Details of Processing
The details of the processing operations conducted under this DPA are as follows:
- Subject Matter: The provision of TableGreet digital menu SaaS platforms, analytics, tableside guest ordering, and QR code generator systems.
- Duration: The term of the main Agreement plus the period from the expiry of the Agreement until deletion of all Customer Personal Data.
- Nature and Purpose: To provide, support, maintain, secure, and improve the Services as requested by the Controller.
- Categories of Data Subjects: Controller's employees, staff, contractors, and hospitality guests (diners/end-users scanning QR codes).
- Categories of Personal Data: Name, contact details, account settings, roles, tableside orders, payment processing metadata, IP addresses, browser user-agents, and event logs.
Controller & Processor Obligations
A. Instructions: The Processor will process Customer Personal Data only on documented instructions from the Controller, including with respect to transfers of personal data to a third country, unless required to do so by applicable law.
B. Confidentiality: The Processor ensures that persons authorized to process the Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
C. Security Measures: The Processor will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risks of processing, as detailed in our Security Overview page.
D. Subprocessors: The Controller provides a general written authorization to the Processor to engage subprocessors. The current list of authorized subprocessors is available on our Subprocessors page.
Data Subject Rights & Assistance
Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the data subject's rights.
In addition, the Processor will assist the Controller in ensuring compliance with the obligations of security of processing, breach notification, data protection impact assessments, and prior consultations with supervisory authorities.
Deletion or Return of Personal Data
Upon termination of the Agreement or at the Controller's choice, the Processor will delete or return all Customer Personal Data to the Controller and delete existing copies unless applicable law requires storage of the personal data.
Account deletions triggered from the TableGreet platform dashboard will lead to the deletion of associated personal data within 30 calendar days, except for standard system backups which are securely overwritten in cycles of 30 days.
Audits and Inspections
The Processor will make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
Any audit must be scheduled at least 30 business days in advance, conducted during normal working hours, and restricted to once per calendar year, except following a confirmed security incident.
Contact & DPO
For any queries related to this Data Processing Addendum or TableGreet compliance operations, please contact us: