Data Processing Agreement
Ultimo aggiornamento: 10 ottobre 2026
Bozza — i dati aziendali sono provvisori fino alla registrazione della società.
Questo documento è disponibile in inglese. In caso di differenze tra le versioni linguistiche, prevale la versione inglese.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Terms”) between [COMPANY NAME], [LEGAL FORM], [REGISTERED ADDRESS], company number [COMPANY NUMBER] (the “Processor”), and the business that has accepted the Terms (the “Controller” or “Customer”). It sets out the parties’ obligations under Article 28 of Regulation (EU) 2016/679 (the “GDPR”). It is accepted together with the Terms and does not need to be signed separately.
1. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given in the GDPR. “Customer Personal Data” means personal data contained in the Customer Data (as defined in the Terms) that the Processor processes on behalf of the Controller. “Sub-processor” means any processor engaged by the Processor to process Customer Personal Data. Other capitalised terms have the meaning given in the Terms.
2. Subject matter, duration, nature and purpose
- Subject matter: the provision of the Total-It dashboard, which receives closed orders from the Controller’s tills and turns them into management reports and exports.
- Duration: for the term of the Terms and, after termination, until deletion of Customer Personal Data in accordance with section 12.
- Nature of processing: collection via the ingest API, storage, organisation, aggregation, computation of reports, display, export, backup, and deletion.
- Purpose: solely to provide, secure, maintain and support the Service for the Controller in accordance with the Terms and the Controller’s documented instructions.
3. Categories of data and data subjects
3.1 Categories of personal data
Customer Data consists mainly of transactional data. It may constitute personal data where it relates, directly or indirectly, to an identifiable individual. It may include:
- order data: product names, quantities, prices, VAT rates and amounts, table identifiers, number of covers;
- payment data: payment method identifiers, amounts and tips (no card numbers or other card data);
- timestamps and device identifiers of tills;
- venue names and any other information the Controller enters in free-text fields;
- for Users of the Controller: email address, role, and activity within the Controller’s account.
The Controller shall not send special categories of personal data (Art. 9 GDPR), data relating to criminal convictions, or guest names or other unnecessary personal data in free-text fields such as product names.
3.2 Categories of data subjects
- the Controller’s staff and Users (for example staff linked to a till, shift, table or tips);
- possibly the Controller’s guests, to the extent the Controller enters information relating to them (for example in product names, table identifiers or other free-text fields).
4. Instructions
- The Processor processes Customer Personal Data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by EU or Member State law; in that case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits this.
- The Terms, this DPA and the Controller’s configuration and use of the Service (including sending data from its tills, inviting Users, exporting and deleting data) constitute the Controller’s complete documented instructions. Additional instructions require the Processor’s written agreement and may be subject to reasonable fees.
- The Processor will promptly inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law; it may suspend performance of that instruction until it is confirmed or modified.
5. Controller obligations
The Controller warrants that:
- it has a valid legal basis for the processing and has given all necessary information to data subjects (including its staff) about the processing of their data through the Service;
- its instructions comply with applicable law;
- it is solely responsible for the accuracy, quality and legality of Customer Personal Data and the means by which it was obtained, and for the configuration of its tills, Users and Device Keys.
6. Confidentiality
The Processor ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it to provide, support or secure the Service.
7. Security (Art. 32 GDPR)
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing. These measures are described in Annex 2. The Processor may update these measures, provided the overall level of security is not materially reduced. The Controller acknowledges that the measures are appropriate for the Customer Personal Data concerned, and is responsible for the security of its own credentials, Device Keys, devices and networks.
8. Sub-processors
- The Controller gives the Processor a general written authorisation to engage Sub-processors. The Sub-processors in place at the date of this DPA are listed in Annex 1 and are deemed approved.
- The Processor will inform the Controller of any intended addition or replacement of a Sub-processor at least [SUB-PROCESSOR NOTICE PERIOD, e.g. 30] days in advance, by email to the account owner or through the Service.
- The Controller may object to the change on reasonable grounds relating to data protection by notifying [PRIVACY EMAIL] within that period. The parties will discuss the objection in good faith. If no solution is found, the Controller may, as its sole remedy, terminate the affected subscription before the change takes effect; the Processor will refund any Fees prepaid for the period after termination. If the Controller does not object within the notice period, the change is deemed accepted.
- The Processor imposes on each Sub-processor, by contract, data protection obligations that offer at least substantially the same level of protection as this DPA, and remains responsible to the Controller for the performance of the Sub-processor’s obligations in accordance with Art. 28(4) GDPR, subject to section 14.
- In an emergency (for example where a Sub-processor ceases to operate or poses a security risk), the Processor may replace it immediately and will inform the Controller as soon as possible afterwards.
9. International transfers
Customer Personal Data is primarily hosted in [HOSTING REGION]. The Processor will not transfer Customer Personal Data to a country outside the European Economic Area that does not benefit from an adequacy decision unless appropriate safeguards are in place under Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses (entered into with the relevant Sub-processor) or the Sub-processor’s certification under the EU-U.S. Data Privacy Framework, together with supplementary measures where necessary. The Controller authorises such transfers to the Sub-processors listed in Annex 1 on that basis.
10. Assistance
- Data subject requests. Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights. The Service’s export and deletion features are the primary means of assistance. If the Processor receives a request directly, it will forward it to the Controller without undue delay and will not respond itself except to direct the data subject to the Controller.
- DPIAs and consultation. Taking into account the nature of the processing and the information available to it, the Processor provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, primarily by making available the information in this DPA and its documentation.
- Costs. Assistance that goes beyond making available the Service’s self-service features and existing documentation may be charged at the Processor’s then-current reasonable rates, unless the request arises from the Processor’s breach of this DPA.
11. Personal data breaches
The Processor will notify the Controller without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will, to the extent available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available. The Processor will take reasonable steps to contain and remediate the breach and will assist the Controller in meeting its obligations under Articles 33 and 34 GDPR. Notification of a breach is not an acknowledgement of fault or liability.
12. Deletion or return of data
At the end of the provision of the Service, the Controller may export Customer Data using the export features for 30 days. After that period the Processor deletes Customer Personal Data from its live systems; copies in backups are deleted within a further [BACKUP RETENTION PERIOD, e.g. 30] days, unless EU or Member State law requires storage. The Controller instructs the Processor accordingly. Deletion is the default; return in a format other than the standard export is available on request at reasonable cost.
13. Information and audits
- The Processor makes available to the Controller the information reasonably necessary to demonstrate compliance with Art. 28 GDPR, primarily through documentation (such as this DPA, a description of security measures, and, where available, certifications or audit reports of the Processor or its Sub-processors).
- If the Controller reasonably considers that this information is insufficient, or where required by a supervisory authority, the Controller may conduct an audit, including an inspection, subject to the following: (a) no more than once per calendar year, unless following a personal data breach or a request from a supervisory authority; (b) at least 30 days’ prior written notice to [LEGAL EMAIL]; (c) conducted during normal business hours, without unreasonable disruption, and in a manner that does not compromise the security or confidentiality of other customers’ data; (d) by the Controller or an independent auditor bound by confidentiality who is not a competitor of the Processor; (e) at the Controller’s cost, including reasonable compensation for the Processor’s time.
- Audits of Sub-processors are carried out through the reports and documentation made available by those Sub-processors.
14. Liability
Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the Terms of Service, and the aggregate liability under the Terms and this DPA together is subject to the cap set out in the Terms, to the extent permitted by law. This does not limit either party’s liability towards data subjects under Article 82 GDPR, or any liability that cannot be limited under applicable law. The Controller indemnifies the Processor against claims and fines resulting from the Controller’s breach of this DPA or of data protection law, including unlawful instructions.
15. Miscellaneous
- In case of conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA prevails.
- The Processor may amend this DPA where required by changes in law, guidance of supervisory authorities, or changes to the Service, provided the amendment does not reduce the overall protection of Customer Personal Data. Material amendments will be notified in accordance with the Terms.
- This DPA is governed by the law of [COUNTRY OF GOVERNING LAW], and the courts of [COMPETENT COURTS] have exclusive jurisdiction, as provided in the Terms.
Annex 1 — Sub-processors
| Sub-processor | Service | Data concerned | Location / transfer safeguard |
|---|---|---|---|
| Supabase | Database, authentication, data hosting, backups | All Customer Data and User account data | [HOSTING REGION]; Standard Contractual Clauses for any access from outside the EEA |
| Stripe | Payments and subscription billing (card data collected by Stripe directly) | Billing contact details of the Customer; no Customer sales data | EU and United States; EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses |
| [WEB HOSTING PROVIDER] | Hosting and delivery of the web application | Customer Data in transit and as displayed; request logs | [WEB HOSTING REGION / TRANSFER SAFEGUARD] |
| [EMAIL PROVIDER] | Transactional emails (invitations, password resets, notices) | User and invitee email addresses, email content | [EMAIL PROVIDER REGION / TRANSFER SAFEGUARD] |
Annex 2 — Technical and organisational measures
Confidentiality and access control
- Tenant isolation enforced in the database with row-level security policies and explicit column-level grants.
- Role-based access within each customer account (owner, admin, viewer).
- Passwords hashed by the authentication provider; per-venue device keys stored only as hashes and revocable.
- Least-privilege access for the Processor’s personnel and systems; privileged (service-role) access used only by server-side code after the caller has been authorised.
- Secrets and keys kept out of source code and stored in the hosting providers’ secret management.
Integrity
- Encryption in transit using TLS for the dashboard, website and ingest API.
- Authenticated ingest API: each till must present a valid device key for its venue.
- Order records are insert-only; submitted data is validated for consistency before storage.
- No card data is received or stored.
Availability and resilience
- Managed cloud infrastructure with encryption at rest and regular automated backups.
- Tills keep data locally while offline and synchronise when connectivity returns.
Organisational measures
- Confidentiality commitments for all persons with access to personal data.
- Data minimisation: no guest names or card data collected by design.
- Incident response procedure, including breach notification as set out in section 11.
- Selection of Sub-processors with appropriate security guarantees and data processing agreements.
- Regular review of access rights, dependencies and security measures.