Legal
Data processing agreement
The Article 28 GDPR agreement between the restaurant, controller of its guests' data, and us, who process that data on its behalf.
Last updated:
Contents
1.Parties and effect
The controller is the business that holds a table2book account ("the restaurant"). The processor is Xolo Go OÜ - Avel Papalapas (Estonian registry code 14717109, EU VAT number EE102156920), Paju tn 1a, 50603 Tartu, Estonia ("we").
This agreement forms part of the Terms of use. It applies from the creation of the account and for as long as we process data on the restaurant's behalf.
2.Subject matter and duration
We process the restaurant's guest data only to run the service: storing and showing bookings, the guest book, the waitlist, orders and table payments, sending booking emails, and, with the add-on, handling phone calls through the booking assistant.
Processing lasts for as long as the account exists and until the data is deleted after it ends (see «Termination»).
3.Data and data subjects
| Data subjects | Data |
|---|---|
| The restaurant's guests | Name, phone, email, company and address (if filled in), booking date and time, party size, guest and staff notes, visit history, orders, table payment amounts (no card details), recordings and transcripts of calls with the assistant. |
| The restaurant's staff | Name, email, role, actions in the console (activity log), devices for push notifications. |
We do not ask for special categories of data. If the restaurant writes health information in notes (for example allergies), it does so on its own responsibility and only as far as needed to serve the guest.
4.The restaurant's instructions
We process the data only on the restaurant's instructions: the Terms of use, this agreement, and its settings and actions in the console. We do not use the data for our own purposes, do not sell it and do not use it for advertising. If an instruction appears to breach the law, we tell you.
5.Confidentiality
Only people who need access to run and support the service have it, and they are bound by confidentiality.
6.Security measures
- Encryption in transit (HTTPS with HSTS) across the site.
- Separation by restaurant: every read and write is limited to the signed-in user's restaurant.
- User sign-in through a specialised provider, and roles (owner, manager, staff) with different permissions.
- Rate limits on public endpoints (bookings, payments) and validation of the data that arrives from the browser.
- A Content Security Policy (CSP) that limits where scripts load from and where data is sent.
- Signed webhooks from the payment and telephony providers.
- Hosting in a data centre in the EU, and error monitoring.
7.Sub-processors
The restaurant authorises us to use the following sub-processors for its guests' data:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application and database | EU |
| Resend | Sending booking confirmation emails | USA |
| Retell AI (and its voice and language-model providers) | Phone booking assistant, only with the add-on: call, recording, transcript | USA |
| Twilio Inc. | The assistant's phone number and call routing, only with the add-on | USA |
| Functional Software, Inc. (Sentry) | Application error logging | EU (Germany) |
We notify you by email at least 30 days before adding a new sub-processor. You may object on reasonable grounds; if no solution is found, you may cancel your subscription. Each sub-processor is bound by a contract with the same data protection obligations.
8.Transfers outside the EU
Where a sub-processor processes data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework, where the provider is certified, or on the European Commission's Standard Contractual Clauses.
9.Assistance to the restaurant
- Guest requests: access and correction are handled in the console. The console's «Διαγραφή πελάτη» (delete guest) removes the guest's card, not the details stored in their bookings; for a complete deletion of a guest, send us a request and we carry it out.
- If a guest request reaches us, we forward it to the restaurant without answering it on the merits ourselves.
- Data breach: we notify you without undue delay and at the latest within 48 hours of becoming aware of it, with what we know about its scope and the measures taken.
- We give you the information you need for a data protection impact assessment or a consultation with the authority.
10.Termination
When you ask for the account to be deleted, we delete your guests' data within 30 days, unless the law requires us to keep some of it. Before deletion you can get a copy: as CSV from the console on paid plans, or on request on any plan.
11.Audits
We give you the information needed to demonstrate our compliance with this agreement and allow audits by you or an auditor you appoint, with reasonable notice and without access to other restaurants' data. Contact: esites.gr@gmail.com.