GDPR Contractual Agreement

Data Processing Agreement

Agreement between the restaurant customer as controller and RestoFlow as processor for guest personal data.

Effective date: 2026-09-18
Last updated: 2026-09-18

1. Application and Roles

This Data Processing Agreement (“DPA”) forms part of the RestoFlow Terms accepted by the customer. For restaurant guest personal data processed through QR menus, orders, staff requests, reservations and reviews, the restaurant customer is the controller and RESTOFLOW S.R.L. is the processor.

For its own RestoFlow account, billing, security, support, platform administration and promoter data,RESTOFLOW S.R.L. acts independently as controller under the Privacy Policy.

2. Subject Matter, Duration and Data Categories

Processing covers the provision of restaurant SaaS and lasts for the customer account term, plus limited periods necessary for retention, backups, security or legal obligations.

Processing may cover guest identification and contact data entered by guests, reservation data, table orders and requests, feedback/reviews, QR session identifiers and limited technical data. Data subjects include restaurant guests, prospective customers, staff and other persons authorized by the restaurant. Processing supports menu display, service operations, staff communication, reservations, analytics and technical support, strictly on the customer's documented instructions.

3. Instructions, Confidentiality and Security

RestoFlow processes personal data only on the customer's documented instructions, including instructions expressed through configuration and actions in the platform, unless required otherwise by law. RestoFlow may seek clarification on, or decline, an instruction that appears unlawful.

RestoFlow ensures authorized personnel are bound by confidentiality obligations and applies proportionate technical and organizational measures, including role-based access, restaurant data separation/RLS, authentication, secret protection, security logs, limited administrative access and reasonable security updates.

4. Assistance, Incidents and Data Subject Requests

Taking account of processing nature, RestoFlow reasonably assists the customer with access, rectification, erasure, restriction, objection and portability requests. Guest requests may be redirected to the restaurant, which remains responsible for its controller response.

RestoFlow will notify the customer without undue delay of a personal data breach it becomes aware of and provide reasonably available information for the customer to assess and meet its legal obligations. The customer must promptly notify RestoFlow of relevant incidents or authority instructions.

5. Subprocessors and Transfers

The customer grants general written authorization for subprocessors required to provide the service. Current providers may include Vercel (hosting), Supabase (database, authentication, storage and functions; the production project is in EU Paris), Resend (email), Stripe and Stripe Connect (payments), SmartBill (fiscal documents), OpenAI (AI features), and Meta only where the customer enables that integration.

RestoFlow binds subprocessors to compatible data-protection obligations. For a material subprocessor change, RestoFlow will notify the customer via the primary account email or in-platform notice before implementation where reasonably possible. The customer may raise a reasoned objection within 30 days; the parties will seek a reasonable solution, including disabling the affected feature where necessary.

Where data is transferred outside the EEA, RestoFlow will use GDPR-permitted transfer mechanisms such as adequacy decisions, Standard Contractual Clauses or other applicable safeguards.

6. Return, Deletion and Audit

On service termination and customer instruction, RestoFlow deletes or returns personal data processed for the customer through its deletion process, except where retention is required by law or for legal claims. Operational guest data is subject to a 30-day operational retention period; backups expire under the applicable technical rotation.

On reasonable request no more than once per year, the customer may request information needed to demonstrate compliance with this DPA or conduct a proportionate audit with reasonable notice, without impairing security, confidentiality of other customers or service availability.