Data Processing Agreement
CORTABLE LIMITED
Data Processing Agreement
Article 28 DPJL 2018 / UK GDPR — Customer (Controller) and Cortable (Processor)
Company
Cortable Limited (incorporated in Jersey, Channel Islands)
Platform
cortable.ai
Document
Data Processing Agreement
Version
1.0
Date
30 August 2026
Classification
Confidential — Privileged
Contents
Parties
Background
1. Definitions and Interpretation
2. Roles and Scope of Processing
3. Processor Obligations
4. Security Measures (Article 32)
5. Sub-Processing
6. International Transfers
7. Assistance with Data Subject Rights
8. Personal Data Breach
9. Audit and Records
10. Return and Deletion of Personal Data
11. Liability
12. Term, Precedence and Governing Law
Annex 1 — Details of the Processing
Annex 2 — Approved Sub-Processors
Annex 3 — Technical and Organisational Measures (Article 32)
Acceptance
Parties
(1) The Customer identified in the SaaS Subscription Agreement (the “Controller”); and
(2) Cortable Limited, incorporated in Jersey (Channel Islands) with registered number 165752 and registered office at 4th Floor, St Paul’s Gate, 22-24 New Street, St. Helier, JE1 4TR, Jersey (the “Processor”).
Background
This Data Processing Agreement (“DPA”) forms part of, and is subject to, the SaaS Subscription Agreement between the Parties (the “Principal Agreement”).
The Controller wishes to use the Processor’s Platform, which involves the Processor processing Personal Data on the Controller’s behalf.
This DPA sets out the terms required by Article 28 of the DPJL 2018 and, where applicable to Personal Data of UK-resident Data Subjects, the UK GDPR, and applies to all such processing.
1. Definitions and Interpretation
“Controller” , “Processor”, “Data Subject”, “Personal Data”, “Special Category Data”, “processing”, “Supervisory Authority” and “Personal Data Breach” have the meanings given in the Data Protection Laws.
“Data Protection Laws” the UK GDPR and the Data Protection Act 2018 to the extent applicable, and all other applicable data protection and privacy laws.
“Processing Details” the description of the processing set out in Annex 1.
“Restricted Transfer” a transfer of Personal Data to a country or territory that does not benefit from an adequacy decision or equivalent recognition under the applicable Data Protection Laws.
“Standard Contractual Clauses” the standard data protection clauses approved for international transfers under the applicable Data Protection Laws (including the EU SCCs and/or the UK International Data Transfer Agreement or Addendum, as appropriate).
“Sub-Processor” any third party engaged by the Processor (or by another Sub-Processor) to process Personal Data under this DPA.
Terms not defined here have the meaning given in the Principal Agreement. This DPA prevails over the rest of the Principal Agreement on data protection matters.
2. Roles and Scope of Processing
The Controller determines the purposes and means of processing the Personal Data described in Annex 1, and is responsible for the lawfulness of its collection and the instructions it gives. The Controller is responsible for establishing an appropriate Article 9 condition for processing Special Category Data and instructing the Processor accordingly
The Processor processes the Personal Data only as a processor, on the Controller’s behalf, to provide the Platform under the Principal Agreement and as further set out in Annex 1.
Annex 1 sets out the subject matter and duration of the processing, its nature and purpose, the types of Personal Data, the categories of Data Subjects, and the Special Category Data involved (Guest and staff allergen/dietary data).
Where the Processor processes its own customer-account, billing and usage data, it does so as a controller under the Cortable Privacy Policy; that processing is outside the scope of this DPA.
3. Processor Obligations
The Processor shall:
process the Personal Data only on the Controller’s documented instructions (including this DPA, the Principal Agreement, and the Controller’s use of the Platform’s configuration and features), including with regard to Restricted Transfers, unless required to process by law to which the Processor is subject, in which case it shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest;
immediately inform the Controller if, in its opinion, an instruction infringes the Data Protection Laws (without obligation to monitor the Controller’s compliance);
ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and are subject to appropriate training;
implement and maintain the technical and organisational measures set out in Annex 3, in accordance with Article 32 (clause 4);
respect the conditions in clause 5 for engaging Sub-Processors;
taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, and at the reasonable cost of the Controller, insofar as possible, to fulfil the Controller’s obligation to respond to requests by Data Subjects to exercise their rights (clause 7);
assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 (security, breach notification, data protection impact assessment and prior consultation), taking into account the nature of processing and the information available to the Processor (clauses 6, 8)The Processor shall be entitled to charge a reasonable fee for assisting with data protection impact assessments;
at the Controller’s choice, delete or return all Personal Data after the end of the provision of the services, and delete existing copies, unless storage is required by law (clause 10); and
make available to the Controller all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections (clause 9).
4. Security Measures (Article 32)
The Processor shall implement and maintain the technical and organisational measures set out in Annex 3, appropriate to the risk presented by the processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.
The Processor shall not materially reduce the overall level of protection of the Personal Data during the term. The Processor may update specific measures provided the protection is not materially diminished.
In assessing the appropriate level of security, the Parties shall have regard in particular to the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data, and to the heightened sensitivity of the Special Category (allergen/health) Data.
5. Sub-Processing
The Controller grants the Processor general written authorisation to engage the Sub-Processors listed in Annex 2 for the processing described against each.
The Processor shall notify the Controller of any intended addition or replacement of a Sub-Processor at least thirty (30) days in advance (via email, in-app notice or the Cortable sub-processor page), giving the Controller the opportunity to object.
The Controller may object on reasonable data-protection grounds within fourteen (14) days of notice. The Parties shall discuss the objection in good faith. If it cannot be resolved and the Processor proceeds, the Controller may terminate the affected services under the Principal Agreement as its sole remedy.
The Processor shall impose on each Sub-Processor, by written contract, data-protection obligations that are equivalent in substance to those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.
The Processor remains fully liable to the Controller for the performance of each Sub-Processor’s obligations.
6. International Transfers
The Processor shall not make a Restricted Transfer of Personal Data except as set out in Annex 2, on the Controller’s instructions, or as otherwise agreed, and in each case only where an appropriate transfer mechanism is in place.
Where a Restricted Transfer occurs (for example to US-based Sub-Processors such as Stripe, OpenAI and Anthropic), the Processor shall ensure it is covered by an applicable adequacy framework (such as the EU–US Data Privacy Framework where the recipient is certified) and/or the Standard Contractual Clauses with appropriate supplementary measures.
The Processor shall, on request, assist the Controller in carrying out a Transfer Impact Assessment for relevant transfers and provide reasonable information about the safeguards in place..
7. Assistance with Data Subject Rights
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights of access, rectification, erasure, restriction of processing, data portability and objection, and rights relating to automated decision-making. The Processor shall be entitled to charge a reasonable fee for this assistance.
If the Processor receives a request directly from a Data Subject, it shall not respond substantively (other than to acknowledge or direct the Data Subject to the Controller) and shall promptly notify the Controller, unless legally required to respond.
8. Personal Data Breach
The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller’s Personal Data.
The notification shall, to the extent known and as it becomes available, describe: (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address it and mitigate adverse effects; and (d) a contact point for further information.
The Processor shall take reasonable steps to contain and remediate the breach, preserve evidence (including via its audit-event records), and cooperate with the Controller so the Controller can meet its own obligations to notify the JOIC and/or UK ICO (within 72 hours where required) and affected Data Subjects.
The Processor shall not make any public statement attributing a breach to the Controller, or notify Data Subjects on the Controller’s behalf, without the Controller’s prior written agreement, except where required by law.
9. Audit and Records
The Processor shall maintain records of its processing activities carried out on behalf of the Controller, as required by Article 30(2).
The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and Article 28, which may include up-to-date certifications, audit reports or summaries (such as SOC 2 / ISO 27001, where held) and completed security questionnaires.
Where such information is insufficient, the Processor shall allow for and contribute to audits, including on-site inspections, by the Controller or an independent auditor it mandates (not a competitor of the Processor), subject to: (a) reasonable prior notice of at least thirty (30) days (or immediately following a Personal Data Breach); (b) no more than once in any twelve (12) month period unless required by a Supervisory Authority or following a breach; (c) confidentiality undertakings; and (d) audits being conducted during business hours so as to minimise disruption. Each Party bears its own costs unless the audit reveals material non-compliance by the Processor.
10. Return and Deletion of Personal Data
On termination of the provision of services, the Processor shall, at the Controller’s choice notified within thirty (30) days, return the Personal Data in a structured, machine-readable format and/or delete it, and delete existing copies, within ninety (90) days, unless storage is required by law.
Erasure within the live system is effected by soft-deletion and PII redaction (name redacted; email/phone nulled; lookup hashes cleared; free-text notes anonymised). The Processor shall ensure deletion propagates to file storage (S3), cache (Redis) and backups within their ordinary cycles, and that any Personal Data retained in backups is isolated from active processing and deleted on rotation.
The Processor may retain Personal Data to the extent, and for the period, required by law (for example financial records for six (6) years), and may retain Anonymised Data and usage data. Any retained Personal Data remains subject to this DPA.
11. Liability
Each Party’s liability under this DPA is subject to the limitations and exclusions of liability in the Principal Agreement, except to the extent the Data Protection Laws provide otherwise or such limitation is not permitted by law.
12. Term, Precedence and Governing Law
This DPA takes effect on the Effective Date and continues for as long as the Processor processes Personal Data on the Controller’s behalf, and any provisions intended to survive (including clauses 10 and 11) survive termination.
In the event of conflict between this DPA and the rest of the Principal Agreement on the protection of Personal Data, this DPA prevails.
This DPA is governed by the law and subject to the jurisdiction stated in the Principal Agreement,.
Annex 1 — Details of the Processing
Element
Detail
Subject matter
The provision of the Cortable restaurant operations Platform under the Principal Agreement.
Duration of processing
For the term of the Principal Agreement and any post-termination retrieval and deletion period.
Nature of processing
Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, encryption, anonymisation, erasure and destruction by automated means via the Platform.
Purpose of processing
Reservation and guest management; allergen and food-safety management; staff scheduling and time/attendance; point-of-sale and transaction processing; analytics and reporting; and related operational functions.
Types of Personal Data
Identity and contact data (name, email, phone); booking and reservation data; guest profile and behavioural data; Special Category Data (allergies, dietary requirements, severity); employment data (role, skills, schedules, attendance, compensation); financial/transaction data (tokens, amounts, invoices); audit and usage data (actions, IP, user agent).
Special Category Data
Guest allergies and dietary requirements; staff allergen records. Processed for food-safety/occupational-health purposes under Article 9(2)(b) and/or, where applicable, explicit consent under Article 9(2)(a).
Categories of Data Subjects
Restaurant guests; restaurant employees and workers; restaurant management and owners.
Frequency of processing
Continuous, for the duration of the Principal Agreement.
Controller
The Customer.
Processor
Cortable Limited.
Annex 2 — Approved Sub-Processors
Sub-Processor
Service
Data processed
Location
Transfer mechanism
Amazon Web Services
Infrastructure: RDS (database), S3 (file storage), Textract (OCR)
All platform data
UK (eu-west-2)
Jersey–UK adequacy
Stripe
Payment processing and subscription billing
Billing data, payment tokens, subscription status
US / EU
EU–US Data Privacy Framework + SCCs as fallback
Brevo (Sendinblue)
Transactional email
Email addresses, booking confirmations
EU (France)
Jersey EU adequacy
OpenAI
AI/ML services (primary)
Anonymised / aggregated operational data
US
SCCs + supplementary measures; TIA
Anthropic
AI/ML services (fallback)
Anonymised / aggregated operational data
US
SCCs + supplementary measures; TIA
The Processor maintains the current sub-processor list and notifies the Controller of changes under clause 5.
Annex 3 — Technical and Organisational Measures (Article 32)
3.1 Encryption and key management
Encryption in transit: TLS 1.2+ for all client–server and server–database communications.
Encryption at rest: AWS RDS AES-256 volume encryption across the PostgreSQL cluster.
Field-level encryption: Fernet symmetric encryption applied to guest name, email and phone.
Deterministic lookup hashing (HMAC-SHA256) to enable search of contact fields without decryption.
3.2 Access control and authentication
Passwords hashed with bcrypt at an appropriate work factor; never stored or logged in plaintext.
Session security: HMAC-signed cookies with httpOnly, secure and sameSite flags, and configurable expiry.
Role-based access control (RBAC).
Rate limiting on sensitive endpoints (e.g. login, GDPR export and erase).
3.3 Tenant isolation and integrity
Multi-tenant isolation enforced by PostgreSQL Row-Level Security, scoped per tenant on every database connection.
Erasure by soft-delete and PII redaction preserving referential integrity, with propagation to file storage, cache and backups.
3.4 Logging, monitoring and resilience
Audit logging: an AuditEvent record of entity, action, actor, IP address, user agent, before/after state and timestamp.
Automated monitoring and anomaly detection feeding the incident-response process.
Encrypted, regularly tested backups; defined restoration procedures.
3.5 Payments and third parties
No raw card data stored; all card processing delegated to Stripe (PCI DSS Level 1).
Allergen label images uploaded to S3 are processed by OCR and deleted immediately after extraction.
3.6 Organisational measures
Confidentiality obligations and data-protection training for personnel with access to Personal Data.
Sub-processor due diligence and contractual flow-down of data-protection obligations.
Incident-response procedures including breach assessment, notification workflow and a breach register.
Acceptance
This DPA forms part of the Principal Agreement and is accepted online together with it during sign-up at cortable.ai. By accepting the SaaS Subscription Agreement, the Customer (as Controller) accepts this DPA. No separate signature is required.
Enterprise customers who require a counter-signed copy of this DPA may request one; the online terms otherwise govern.