Data Processing Agreement

CORTABLE LIMITED

Data Processing Agreement

Article 28 DPJL 2018 / UK GDPR — Customer (Controller) and Cortable (Processor)

Company

Cortable Limited (incorporated in Jersey, Channel Islands)

Platform

cortable.ai

Document

Data Processing Agreement

Version

1.0

Date

30 August 2026

Classification

Confidential — Privileged

Contents

Parties

Background

1. Definitions and Interpretation

2. Roles and Scope of Processing

3. Processor Obligations

4. Security Measures (Article 32)

5. Sub-Processing

6. International Transfers

7. Assistance with Data Subject Rights

8. Personal Data Breach

9. Audit and Records

10. Return and Deletion of Personal Data

11. Liability

12. Term, Precedence and Governing Law

Annex 1 — Details of the Processing

Annex 2 — Approved Sub-Processors

Annex 3 — Technical and Organisational Measures (Article 32)

Acceptance

Parties

(1) The Customer identified in the SaaS Subscription Agreement (the “Controller”); and

(2) Cortable Limited, incorporated in Jersey (Channel Islands) with registered number 165752 and registered office at 4th Floor, St Paul’s Gate, 22-24 New Street, St. Helier, JE1 4TR, Jersey (the “Processor”).

Background

This Data Processing Agreement (“DPA”) forms part of, and is subject to, the SaaS Subscription Agreement between the Parties (the “Principal Agreement”).

The Controller wishes to use the Processor’s Platform, which involves the Processor processing Personal Data on the Controller’s behalf.

This DPA sets out the terms required by Article 28 of the DPJL 2018 and, where applicable to Personal Data of UK-resident Data Subjects, the UK GDPR, and applies to all such processing.

1. Definitions and Interpretation

“Controller” , “Processor”, “Data Subject”, “Personal Data”, “Special Category Data”, “processing”, “Supervisory Authority” and “Personal Data Breach” have the meanings given in the Data Protection Laws.

“Data Protection Laws” the UK GDPR and the Data Protection Act 2018 to the extent applicable, and all other applicable data protection and privacy laws.

“Processing Details” the description of the processing set out in Annex 1.

“Restricted Transfer” a transfer of Personal Data to a country or territory that does not benefit from an adequacy decision or equivalent recognition under the applicable Data Protection Laws.

“Standard Contractual Clauses” the standard data protection clauses approved for international transfers under the applicable Data Protection Laws (including the EU SCCs and/or the UK International Data Transfer Agreement or Addendum, as appropriate).

“Sub-Processor” any third party engaged by the Processor (or by another Sub-Processor) to process Personal Data under this DPA.

Terms not defined here have the meaning given in the Principal Agreement. This DPA prevails over the rest of the Principal Agreement on data protection matters.

2. Roles and Scope of Processing

The Controller determines the purposes and means of processing the Personal Data described in Annex 1, and is responsible for the lawfulness of its collection and the instructions it gives. The Controller is responsible for establishing an appropriate Article 9 condition for processing Special Category Data and instructing the Processor accordingly

The Processor processes the Personal Data only as a processor, on the Controller’s behalf, to provide the Platform under the Principal Agreement and as further set out in Annex 1.

Annex 1 sets out the subject matter and duration of the processing, its nature and purpose, the types of Personal Data, the categories of Data Subjects, and the Special Category Data involved (Guest and staff allergen/dietary data).

Where the Processor processes its own customer-account, billing and usage data, it does so as a controller under the Cortable Privacy Policy; that processing is outside the scope of this DPA.

3. Processor Obligations

The Processor shall:

process the Personal Data only on the Controller’s documented instructions (including this DPA, the Principal Agreement, and the Controller’s use of the Platform’s configuration and features), including with regard to Restricted Transfers, unless required to process by law to which the Processor is subject, in which case it shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest;

immediately inform the Controller if, in its opinion, an instruction infringes the Data Protection Laws (without obligation to monitor the Controller’s compliance);

ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and are subject to appropriate training;

implement and maintain the technical and organisational measures set out in Annex 3, in accordance with Article 32 (clause 4);

respect the conditions in clause 5 for engaging Sub-Processors;

taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, and at the reasonable cost of the Controller, insofar as possible, to fulfil the Controller’s obligation to respond to requests by Data Subjects to exercise their rights (clause 7);

assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 (security, breach notification, data protection impact assessment and prior consultation), taking into account the nature of processing and the information available to the Processor (clauses 6, 8)The Processor shall be entitled to charge a reasonable fee for assisting with data protection impact assessments;

at the Controller’s choice, delete or return all Personal Data after the end of the provision of the services, and delete existing copies, unless storage is required by law (clause 10); and

make available to the Controller all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections (clause 9).

4. Security Measures (Article 32)

The Processor shall implement and maintain the technical and organisational measures set out in Annex 3, appropriate to the risk presented by the processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.

The Processor shall not materially reduce the overall level of protection of the Personal Data during the term. The Processor may update specific measures provided the protection is not materially diminished.

In assessing the appropriate level of security, the Parties shall have regard in particular to the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data, and to the heightened sensitivity of the Special Category (allergen/health) Data.

5. Sub-Processing

The Controller grants the Processor general written authorisation to engage the Sub-Processors listed in Annex 2 for the processing described against each.

The Processor shall notify the Controller of any intended addition or replacement of a Sub-Processor at least thirty (30) days in advance (via email, in-app notice or the Cortable sub-processor page), giving the Controller the opportunity to object.

The Controller may object on reasonable data-protection grounds within fourteen (14) days of notice. The Parties shall discuss the objection in good faith. If it cannot be resolved and the Processor proceeds, the Controller may terminate the affected services under the Principal Agreement as its sole remedy.

The Processor shall impose on each Sub-Processor, by written contract, data-protection obligations that are equivalent in substance to those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.

The Processor remains fully liable to the Controller for the performance of each Sub-Processor’s obligations.

6. International Transfers

The Processor shall not make a Restricted Transfer of Personal Data except as set out in Annex 2, on the Controller’s instructions, or as otherwise agreed, and in each case only where an appropriate transfer mechanism is in place.

Where a Restricted Transfer occurs (for example to US-based Sub-Processors such as Stripe, OpenAI and Anthropic), the Processor shall ensure it is covered by an applicable adequacy framework (such as the EU–US Data Privacy Framework where the recipient is certified) and/or the Standard Contractual Clauses with appropriate supplementary measures.

The Processor shall, on request, assist the Controller in carrying out a Transfer Impact Assessment for relevant transfers and provide reasonable information about the safeguards in place..

7. Assistance with Data Subject Rights

Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights of access, rectification, erasure, restriction of processing, data portability and objection, and rights relating to automated decision-making. The Processor shall be entitled to charge a reasonable fee for this assistance.

If the Processor receives a request directly from a Data Subject, it shall not respond substantively (other than to acknowledge or direct the Data Subject to the Controller) and shall promptly notify the Controller, unless legally required to respond.

8. Personal Data Breach

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller’s Personal Data.

The notification shall, to the extent known and as it becomes available, describe: (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address it and mitigate adverse effects; and (d) a contact point for further information.

The Processor shall take reasonable steps to contain and remediate the breach, preserve evidence (including via its audit-event records), and cooperate with the Controller so the Controller can meet its own obligations to notify the JOIC and/or UK ICO (within 72 hours where required) and affected Data Subjects.

The Processor shall not make any public statement attributing a breach to the Controller, or notify Data Subjects on the Controller’s behalf, without the Controller’s prior written agreement, except where required by law.

9. Audit and Records

The Processor shall maintain records of its processing activities carried out on behalf of the Controller, as required by Article 30(2).

The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and Article 28, which may include up-to-date certifications, audit reports or summaries (such as SOC 2 / ISO 27001, where held) and completed security questionnaires.

Where such information is insufficient, the Processor shall allow for and contribute to audits, including on-site inspections, by the Controller or an independent auditor it mandates (not a competitor of the Processor), subject to: (a) reasonable prior notice of at least thirty (30) days (or immediately following a Personal Data Breach); (b) no more than once in any twelve (12) month period unless required by a Supervisory Authority or following a breach; (c) confidentiality undertakings; and (d) audits being conducted during business hours so as to minimise disruption. Each Party bears its own costs unless the audit reveals material non-compliance by the Processor.

10. Return and Deletion of Personal Data

On termination of the provision of services, the Processor shall, at the Controller’s choice notified within thirty (30) days, return the Personal Data in a structured, machine-readable format and/or delete it, and delete existing copies, within ninety (90) days, unless storage is required by law.

Erasure within the live system is effected by soft-deletion and PII redaction (name redacted; email/phone nulled; lookup hashes cleared; free-text notes anonymised). The Processor shall ensure deletion propagates to file storage (S3), cache (Redis) and backups within their ordinary cycles, and that any Personal Data retained in backups is isolated from active processing and deleted on rotation.

The Processor may retain Personal Data to the extent, and for the period, required by law (for example financial records for six (6) years), and may retain Anonymised Data and usage data. Any retained Personal Data remains subject to this DPA.

11. Liability

Each Party’s liability under this DPA is subject to the limitations and exclusions of liability in the Principal Agreement, except to the extent the Data Protection Laws provide otherwise or such limitation is not permitted by law.

12. Term, Precedence and Governing Law

This DPA takes effect on the Effective Date and continues for as long as the Processor processes Personal Data on the Controller’s behalf, and any provisions intended to survive (including clauses 10 and 11) survive termination.

In the event of conflict between this DPA and the rest of the Principal Agreement on the protection of Personal Data, this DPA prevails.

This DPA is governed by the law and subject to the jurisdiction stated in the Principal Agreement,.

Annex 1 — Details of the Processing

Element

Detail

Subject matter

The provision of the Cortable restaurant operations Platform under the Principal Agreement.

Duration of processing

For the term of the Principal Agreement and any post-termination retrieval and deletion period.

Nature of processing

Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, encryption, anonymisation, erasure and destruction by automated means via the Platform.

Purpose of processing

Reservation and guest management; allergen and food-safety management; staff scheduling and time/attendance; point-of-sale and transaction processing; analytics and reporting; and related operational functions.

Types of Personal Data

Identity and contact data (name, email, phone); booking and reservation data; guest profile and behavioural data; Special Category Data (allergies, dietary requirements, severity); employment data (role, skills, schedules, attendance, compensation); financial/transaction data (tokens, amounts, invoices); audit and usage data (actions, IP, user agent).

Special Category Data

Guest allergies and dietary requirements; staff allergen records. Processed for food-safety/occupational-health purposes under Article 9(2)(b) and/or, where applicable, explicit consent under Article 9(2)(a).

Categories of Data Subjects

Restaurant guests; restaurant employees and workers; restaurant management and owners.

Frequency of processing

Continuous, for the duration of the Principal Agreement.

Controller

The Customer.

Processor

Cortable Limited.

Annex 2 — Approved Sub-Processors

Sub-Processor

Service

Data processed

Location

Transfer mechanism

Amazon Web Services

Infrastructure: RDS (database), S3 (file storage), Textract (OCR)

All platform data

UK (eu-west-2)

Jersey–UK adequacy

Stripe

Payment processing and subscription billing

Billing data, payment tokens, subscription status

US / EU

EU–US Data Privacy Framework + SCCs as fallback

Brevo (Sendinblue)

Transactional email

Email addresses, booking confirmations

EU (France)

Jersey EU adequacy

OpenAI

AI/ML services (primary)

Anonymised / aggregated operational data

US

SCCs + supplementary measures; TIA

Anthropic

AI/ML services (fallback)

Anonymised / aggregated operational data

US

SCCs + supplementary measures; TIA

The Processor maintains the current sub-processor list and notifies the Controller of changes under clause 5.

Annex 3 — Technical and Organisational Measures (Article 32)

3.1 Encryption and key management

Encryption in transit: TLS 1.2+ for all client–server and server–database communications.

Encryption at rest: AWS RDS AES-256 volume encryption across the PostgreSQL cluster.

Field-level encryption: Fernet symmetric encryption applied to guest name, email and phone.

Deterministic lookup hashing (HMAC-SHA256) to enable search of contact fields without decryption.

3.2 Access control and authentication

Passwords hashed with bcrypt at an appropriate work factor; never stored or logged in plaintext.

Session security: HMAC-signed cookies with httpOnly, secure and sameSite flags, and configurable expiry.

Role-based access control (RBAC).

Rate limiting on sensitive endpoints (e.g. login, GDPR export and erase).

3.3 Tenant isolation and integrity

Multi-tenant isolation enforced by PostgreSQL Row-Level Security, scoped per tenant on every database connection.

Erasure by soft-delete and PII redaction preserving referential integrity, with propagation to file storage, cache and backups.

3.4 Logging, monitoring and resilience

Audit logging: an AuditEvent record of entity, action, actor, IP address, user agent, before/after state and timestamp.

Automated monitoring and anomaly detection feeding the incident-response process.

Encrypted, regularly tested backups; defined restoration procedures.

3.5 Payments and third parties

No raw card data stored; all card processing delegated to Stripe (PCI DSS Level 1).

Allergen label images uploaded to S3 are processed by OCR and deleted immediately after extraction.

3.6 Organisational measures

Confidentiality obligations and data-protection training for personnel with access to Personal Data.

Sub-processor due diligence and contractual flow-down of data-protection obligations.

Incident-response procedures including breach assessment, notification workflow and a breach register.

Acceptance

This DPA forms part of the Principal Agreement and is accepted online together with it during sign-up at cortable.ai. By accepting the SaaS Subscription Agreement, the Customer (as Controller) accepts this DPA. No separate signature is required.

Enterprise customers who require a counter-signed copy of this DPA may request one; the online terms otherwise govern.