Terms of ServicePrivacy PolicyData Processing Agreement
Data Processing Agreement
Last updated 5 October 2026.
This Data Processing Agreement (“DPA”) forms part of the agreement between the restaurant using Tafels (“Controller”, “you”) and Memocom Solutions B.V. (“Processor”, “Tafels”), and applies whenever Tafels processes personal data of your guests on your behalf. It’s written to reflect Article 28 of the GDPR. It’s incorporated into, and accepted alongside, the Terms of Service — by using Tafels to process guest data, you and Tafels agree to it. If your organisation needs a separately countersigned copy, contact us at legal@tafels.app.
1. Subject matter and duration
Tafels processes personal data on your instructions for as long as you have a Tafels account, in order to provide the reservation, payment, review and related features you use.
2. Nature and purpose of processing
Storing and managing reservations; matching bookings to tables; sending confirmation, change, cancellation and reminder emails; processing online deposits, prepayments and gift card sales through your own connected Stripe account; collecting and showing review feedback; producing reports and exports for you; and anything else reasonably needed to provide the modules you’ve switched on.
3. Types of personal data
Guest name, email address and phone number; reservation details (date, time, party size, table, status); free-text notes, which may include dietary, accessibility or health-related information you or your guest choose to add; online payment status and amount (not card numbers); gift card and voucher codes; review ratings and comments.
If you use Staff planning: employee name, optional email address and phone number, position, contracted hours and manager notes; planned shifts; unavailability, time-off and swap requests with notes; confirmed hours worked; and short text answers to your onboarding checklist. No identity documents or citizen service numbers (BSN) are collected through Tafels, and you agree not to enter them.
If you use Email marketing: your contacts’ email addresses, names, language, consent records, subscription status and the campaigns sent to them.
4. Categories of data subjects
Your restaurant’s guests, anyone else whose details you enter into a booking (such as a person booking on someone else’s behalf), your employees and other people you plan if you use Staff planning, and the people on your marketing list if you use Email marketing.
5. Tafels’ obligations as processor
- We process personal data only on your documented instructions, as given through your use of Tafels’ features and settings, unless the law requires otherwise (in which case we’ll tell you first, unless prohibited from doing so).
- Anyone we let access this data is bound by confidentiality.
- We take appropriate technical and organisational security measures, as described in the Privacy Policy (security section), and keep them under review.
- We’ll help you respond to data subject requests (access, correction, erasure, and so on) about your guests, so far as that’s possible given how Tafels works.
- We’ll help you meet your own obligations around data protection impact assessments and prior consultation with a supervisory authority, where reasonably requested.
- We’ll tell you without undue delay after becoming aware of a personal data breach affecting your guests’ data, with what we know at the time.
- At the end of our agreement, at your choice, we’ll delete or return the personal data we process for you, except where we’re required by law to keep it.
- We’ll make available the information reasonably necessary to show we comply with this DPA, and allow for audits, by providing documentation on your written request.
6. Sub-processors
You give general authorisation for Tafels to use the sub-processors listed in the Privacy Policy (currently Stripe, SendGrid, and DirectVPS, our hosting provider), each engaged under terms that protect personal data to a standard consistent with this DPA. We’ll give you at least 30 days’ notice before adding or replacing a sub-processor, so you can object on reasonable data-protection grounds.
7. International transfers
Stripe and SendGrid (Twilio) are based in the United States; both are certified under the EU-U.S. Data Privacy Framework and additionally rely on the European Commission’s Standard Contractual Clauses as a fallback safeguard. DirectVPS, our hosting provider, is based in the Netherlands, so no international transfer applies there.
8. Liability
Liability under this DPA follows the liability provisions of the Terms of Service.
9. Governing law
This DPA is governed by the laws of the Netherlands, on the same basis as the Terms of Service.
10. Contact
Data protection questions about this DPA: privacy@tafels.app.