Data processing agreement entered into under art. 28 of Regulation (EU) 2016/679.
1.1. The controller is the restaurant subscribing to AurelTable, which determines the purposes and means of processing the personal data of its guests.
1.2. The processor is NB Studio di Nico Boccia, VAT number IT03154820645, with registered office in Montella (AV), Italy; certified email nico.boccia@pec.it.
1.3. Data subjects are the guests of the restaurant.
1.4. The expressions “personal data”, “processing”, “sub-processor” and “personal data breach” bear the meanings given to them in Regulation (EU) 2016/679.
2.1. The processor processes the personal data of data subjects for the sole purpose of providing the controller with the AurelTable features, namely the management of bookings and orders, the transmission of the related electronic mail and the production of statistics in aggregate form.
2.2. This agreement runs for the term of the service contract and terminates with it.
3.1. The processing concerns, in respect of guests making a booking, name, telephone number, WhatsApp number, email address, party size and any notes; and, in respect of guests placing a takeaway or delivery order, name, telephone number, email address, delivery address and items ordered.
3.2. No special categories of data within the meaning of art. 9 of the Regulation are envisaged. The controller undertakes not to enter data of that nature in free-text fields.
4.1. The processor processes personal data only on the documented instructions of the controller and ensures that persons authorised to process the data have undertaken a duty of confidentiality or are under an appropriate statutory obligation of secrecy.
4.2. The processor implements the security measures required by art. 32 of the Regulation, as particularised in article 7, and complies with the conditions for engaging a sub-processor set out in article 6.
4.3. The processor assists the controller in responding to requests by data subjects and in discharging its obligations as to security, breach notification and impact assessment, as particularised in article 8.
4.4. At the controller’s election the processor deletes or returns the data on termination, as particularised in article 10, and makes available the information necessary to demonstrate compliance with art. 28, permitting the audits provided for in article 11.
5.1. The controller’s documented instructions consist of this agreement, the service contract and the settings adopted by the controller in the management panel.
5.2. Where the processor considers that an instruction infringes the Regulation or other data protection provisions, it shall immediately inform the controller.
6.1. The controller authorises the processor to engage the sub-processors listed below, which are necessary for the provision of the service. The processor imposes upon them, by contract, data protection obligations equivalent to those contained in this agreement and remains liable to the controller for their performance.
| Sub-processor | Activity | Location | Safeguard |
|---|---|---|---|
| Supabase, Inc. | Database and authentication; data hosted on Amazon Web Services infrastructure, London region (eu-west-2) | Data: United Kingdom. Entity: Singapore | UK adequacy and Standard Contractual Clauses |
| Amazon Web Services | Cloud infrastructure on which Supabase operates | Entity: United States. Data: United Kingdom | Standard Contractual Clauses and UK adequacy |
| Cloudflare | Hosting, content delivery, bot protection and image storage | United States | Standard Contractual Clauses |
| Stripe | Payments and booking card holds | United States and Ireland | Standard Contractual Clauses |
| Resend | Transactional email | United States | Standard Contractual Clauses |
| OpenAI | Menu optical character recognition, assistant, translations | United States | Standard Contractual Clauses |
6.2. The processor informs the controller of any intended addition or replacement of a sub-processor, affording the controller the opportunity to object on legitimate grounds.
7.1. The processor implements the following technical and organisational measures: encryption of communications by means of HTTPS/TLS; access control and isolation of each restaurant’s data from that of every other, enforced at database level; storage of passwords by means of a strong hashing algorithm; rate limiting and protection against automated access; backups managed by the database provider; and data minimisation, only the data required by the booking and ordering features being processed.
8.1. The processor assists the controller, so far as technically possible, in responding to requests for the exercise of data subject rights and in discharging its obligations as to the security of processing.
8.2. In the event of a personal data breach the processor informs the controller without undue delay after becoming aware of it, providing the information necessary to enable the controller to make the notifications required to its supervisory authority and to data subjects.
9.1. Transfers to third countries are made solely to the sub-processors listed in article 6 and rest upon an adequacy decision, as regards the United Kingdom, or upon the Standard Contractual Clauses adopted by the European Commission, as regards the United States providers.
10.1. On termination, at the controller’s election, the processor deletes or returns all personal data of data subjects and deletes existing copies, save where retention is required by law.
10.2. Unless otherwise instructed, account data is deleted within 30 days of termination; bookings and orders are in any event deleted within 12 months of their respective dates.
10.3. The controller may at any time obtain a copy of the data independently, by means of the export function in the management panel.
11.1. The processor makes available to the controller the information necessary to demonstrate compliance with the obligations arising under this agreement and permits reasonable audits, including by documentation, on reasonable notice and subject to the confidentiality of other customers.
12.1. Where the Regulation does not apply, the allocation of responsibilities under this agreement is unchanged: the controller determines the purposes of the processing and the processor acts upon its instructions, which corresponds to the role of service provider under United States state privacy laws. The personal data of data subjects is not used for the processor’s own purposes, is not sold and is not shared; reference is made to Your Privacy Choices. The security measures, the list of sub-processors and the retention periods set out above apply without modification.
13.1. This agreement is taken to be executed and accepted by the controller upon activation and use of the AurelTable service and forms an integral part of the Terms of Service. The Italian version prevails in the event of discrepancy.