← Home

Data Processing Agreement

This agreement governs our processing of the personal data that enters the platform from running your restaurant — your customers' and staff data. You are the controller of it and we are the processor. It forms part of the Terms of Service and applies automatically to every subscriber, with no separate signature required.

Effective · 1 September 2026Last updated · 12 September 2026

01Subject matter and parties

You (the "controller") determine the purpose and means of processing your customers' and staff data. We (the "processor") process it on your behalf and only on your documented instructions, for the purpose of providing the service agreed in the Terms of Service.

Subject matter

DetailOperating the Noqta platform for your restaurant

Duration

DetailThe life of your subscription, followed by deletion or anonymisation within ninety days

Nature of processing

DetailCollection, storage, organisation, analysis, generation, and making available to you

Categories of data

DetailPhone numbers, names, order history, loyalty balances, staff records and shifts

Categories of data subjects

DetailYour restaurant's customers, and its staff

02Our obligations as processor

  • We process data only on your documented instructions, unless required otherwise by law — in which case we will notify you before processing unless the law prohibits notification.
  • Everyone on our side with access to the data is bound by a written duty of confidentiality.
  • We apply the technical and organisational measures set out below.
  • We engage sub-processors only on the conditions set out in the dedicated section.
  • We assist you by reasonable means in responding to data subject requests.
  • We assist you in meeting your obligations regarding security of processing and incident notification.
  • We delete or return the data at the end of the service, at your election.
  • We make available the information necessary to demonstrate our compliance with this agreement.

03Sub-processors

You grant us general authorisation to engage sub-processors to operate the platform, on the following conditions.

  • We bind each sub-processor to obligations no less protective than those we owe you under this agreement.
  • We remain liable to you for a sub-processor's performance as if it were our own.
  • We give you thirty days' notice before adding a new sub-processor or replacing an existing one.
  • You may object on reasoned grounds within that period; if no reasonable alternative can be found, you may terminate without penalty and receive a refund of the unused portion of your term.

Hosting and infrastructure

PurposeRunning and serving the application
Processing locationInternational data centres

Database

PurposeStoring platform data
Processing locationInternational data centres

Authentication

PurposeManaging sign-in and identity
Processing locationInternational data centres

WhatsApp messaging

PurposeSending and receiving agent messages
Processing locationPer the provider

AI models

PurposeGenerating analysis and answers
Processing locationInternational data centres

Email

PurposeOperational messages
Processing locationInternational data centres

04Technical and organisational measures

  • Data encrypted in transit and at rest.
  • Each controller's data isolated from every other's, with that isolation enforced at the application layer on every read and write.
  • Role-based access control on a least-privilege basis.
  • An immutable audit trail over sensitive operations, particularly anything touching money.
  • Regular encrypted backups, with restoration tested periodically.
  • Periodic review of internal access rights, and withdrawal of anything no longer required.

05Personal data breach notification

On becoming aware of an incident affecting the security of personal data we process for you, we will notify you without undue delay and in any case within seventy-two hours of becoming aware of it, providing:

  • A description of the nature of the incident, the categories of data, and the approximate number of data subjects, so far as we can establish them.
  • The likely consequences we anticipate.
  • The measures we have taken or propose to take to limit the impact.
  • A contact point on our side for following up.

Notification to you is not an admission of liability. Notifying a supervisory authority or the data subjects themselves — where required — remains your responsibility as controller, and we will assist you with it.

06Assisting with data subject requests

The platform lets you handle most requests yourself: access, rectification, export and deletion. If we receive a request directed to you, we will refer it to you and will not respond on your behalf unless you ask us to in writing.

07Audit

Once a year, on thirty days' notice, we will make available the reasonable information necessary to demonstrate compliance with this agreement. If a supervisory authority requires an on-site audit, we will cooperate with you, at your cost, and without compromising the confidentiality of our other customers' data.

08Return and deletion of data

  • For thirty days after the service ends, your data remains available for you to export yourself.
  • After that we delete or anonymise it within ninety days of the end date.
  • Copies may persist in encrypted backup for a limited period before being cycled out, and remain subject to this agreement until deleted.
  • We will provide written confirmation of deletion on request.

09Precedence

Where this agreement conflicts with the Terms of Service in respect of the processing of personal data, this agreement prevails.

Data protection contact

For rights requests, incident notifications, or any matter arising under this agreement, write to the address below.

ehab@noqtaplatform.com