Legal · Article 28 UK GDPR
Data Processing Agreement (DPA)
Conformed standard version — UK GDPR compliant. This DPA forms part of the Master Software-as-a-Service (SaaS) Agreement between OrderWeb Ltd (Processor) and the restaurant entity subscribing to our multi-tenant platform (Controller).
Last updated: 9 August 2026
OrderWeb Ltd (incorporated in England and Wales) is the Processor. The Controller operates a restaurant or food service establishment and uses OrderWeb for online ordering, shops, gift cards and table reservations. In providing these services, the Processor hosts, stores and processes personal data belonging to the Controller’s end-customers and personnel.
1. Definitions and interpretation
Applicable Data Protection Law means the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and the Data (Use and Access) Act, alongside any successor legislation applicable in the United Kingdom.
Customer Data means any and all Personal Data processed by the Processor on behalf of the Controller through the provision of the OrderWeb platform.
Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data transmitted, stored, or otherwise processed.
The terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Supervisory Authority” have the meanings assigned under Applicable Data Protection Law.
2. Scope, roles, and particulars of processing
For restaurant administration, end-customer food orders and transactions, the restaurant client is the Data Controller and OrderWeb Ltd is the Data Processor.
Details of processing operations
- Subject matter & duration: Provision of the OrderWeb multi-tenant software system and administrative tools for the active duration of the commercial SaaS Agreement.
- Nature and purpose: Collecting, organising, validating, hosting, routing and transferring order payloads, physical delivery information and payment routing metadata to execute and fulfil consumer transactions.
- Categories of data subjects: End-consumers ordering from the Controller’s storefronts, and authorised administrative staff, managers or employees of the Controller.
- Types of personal data: Full customer names, physical delivery addresses, billing addresses, telephone numbers, email addresses, items ordered, booking timings, loyalty metrics, and unique transactional reference IDs (such as Stripe Payment Intent strings or Worldpay reference codes).
Exclusion of raw card data: The platform uses zero-knowledge hosted tokenisation. No raw payment card Primary Account Numbers (PANs), cardholder PINs or CVV security codes are handled, written or stored by the Processor’s infrastructure.
3. Obligations of the Processor
Pursuant to Article 28(3) UK GDPR, the Processor covenants and warrants the following:
3.1 Documented instructions
The Processor shall process Customer Data solely on the documented, written instructions of the Controller, including with respect to cross-border data transfers, unless required to do otherwise by domestic laws of the United Kingdom to which the Processor is subject.
3.2 Confidentiality and personnel
Personnel authorised to process Customer Data are bound by strict contractual or statutory non-disclosure obligations and receive adequate training on data handling principles.
3.3 Security measures (Article 32)
The Processor maintains technical and organisational measures appropriate to the risks, including but not limited to:
- Strict application-level and database-level multi-tenant separation via isolated database schemas or verified Row-Level Security (RLS).
- AES-256-GCM cryptography securing saved tenant credentials, webhook endpoints and API secret keys at rest.
- Enforced TLS (minimum TLS 1.2, targeted TLS 1.3) for customer-facing and backend data in transit.
- Rigid administrative access logs, mandatory multi-factor authentication (MFA) for production environments, and structured database backups.
3.4 Sub-processors
The Controller provides general written authorisation for the Processor to engage sub-processors for network, hosting, transactional messaging and security functions. Currently authorised partners are listed in Schedule 1 below.
The Processor shall notify the Controller of proposed changes or substitutions at least fourteen (14) days in advance, giving a reasonable opportunity to object on valid security grounds. The Processor remains fully liable to the Controller for the execution of duties by any sub-processor.
3.5 Assistance with data subject rights
Taking into account the native capabilities of the multi-tenant application, the Processor shall provide administrative tools or manual assistance so the Controller can honour Chapter III UK GDPR requests (access, rectification, restriction, portability or erasure).
3.6 Governance and impact assessments
The Processor shall render reasonable assistance with risk assessments, infrastructure logging, Data Protection Impact Assessments (DPIAs), and consultation with the Information Commissioner’s Office (ICO).
3.7 Deletion or return of data
Upon termination or expiration of the SaaS Agreement, the Processor shall, at the Controller’s formal choice, securely purge, overwrite or return all copies of Customer Data in live database instances, unless prolonged storage is mandated by UK statutory or tax laws.
3.8 Inspections and audits
The Processor shall make available information necessary to verify Article 28 compliance, and shall allow reasonable, pre-scheduled reviews or audits by the Controller or an independent auditor appointed by the Controller.
4. Personal data breach notification
The Processor shall notify the Controller without undue delay, and in all cases no later than seventy-two (72) hours, after becoming aware of an authenticated Personal Data Breach affecting Customer Data.
Notification shall identify the estimated scope of records compromised, potential consumer impacts, and the defensive remediation steps enacted by the platform’s security team.
5. Miscellaneous and governing law
If this DPA conflicts with the primary commercial SaaS Master Agreement, this DPA governs data protection topics.
This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the English courts.
Schedule 1: Pre-approved infrastructure sub-processors
The Controller authorises the following sub-processors to maintain core OrderWeb functionality:
| Sub-processor | Core processing activity | Geographic region & safeguards |
|---|---|---|
| Amazon Web Services (AWS) / Google Cloud Platform | Production cloud compute instances, multi-tenant database hosting, encrypted storage volumes, and log persistence. | United Kingdom Region (London / eu-west-2). Localised customer payloads remain inside UK sovereign boundaries. |
| Stripe, Inc. | Tokenised customer payment intent initialisation, token processing, webhook callbacks, and merchant dashboard management. | UK / United States. Secured via the official UK International Data Transfer Agreement (IDTA) / Standard Contractual Clauses. |
| Worldpay UK Limited / Global Payments Inc. | Acquiring bank card payment processing integration, authorisation queries, and merchant settlement endpoints. | United Kingdom / European Economic Area (EEA) sovereign zones. |
| Twilio, Inc. / SendGrid | Automated transactional notifications, SMS updates for order fulfilment tracking, and HTML email customer receipts. | United States / European Union. Protected via explicit operational security addenda and EU-UK approved cross-border transfer agreements. |
Execution and sign-off
IN WITNESS WHEREOF, the parties agree to this Data Processing Agreement through their duly authorised corporate representatives.
For the Processor
OrderWeb Ltd
Authorised signature: _______________________
Name: ____________________________________
Title: _____________________________________
Date: _____________________________________
For the Controller
[Restaurant name / entity]
Authorised signature: _______________________
Name: ____________________________________
Title: _____________________________________
Date: _____________________________________
Related: Privacy Policy · Terms & Conditions
Questions? Contact us or email mail@orderweb.co.uk.