Data Processing Agreement
Version of 16 September 2026
This agreement is made under Article 28 of the General Data Protection Regulation (GDPR). It forms part of the Terms of Service and applies to every restaurant using Restonaldo.
The parties
The data controller is the restaurant that signed up for Restonaldo ("you"). The data processor is Asad Siddiqi, sole trader trading as Restonaldo, reachable at hello@restonaldo.com ("we").
Subject, duration, nature and purpose
We process personal data only to provide Restonaldo to you: to receive, show, print and notify orders; to run your ordering website, dashboard and owner app; to send order receipts and notices to your customers on your behalf; and to store, back up and erase that data. The processing consists of collection, storage, display, transmission, backup and erasure. It lasts as long as your subscription, and until the data has been deleted as described below.
Data subjects and categories of data
Your customers: name, phone number, email address, what they ordered and when, and order notes. Order notes are free text and may contain allergy or other health information, which is a special category of data; it is only stored and shown to you as part of the order. Device identifiers and phone numbers are also kept as keyed (HMAC) hashes that cannot be turned back into the original.
Your owners and staff who log in: name, email address, password (only as a one-way hash), and push notification tokens for devices with the owner app.
Instructions
We process the data only on your documented instructions. The Terms of Service, this agreement and the settings you choose in Restonaldo, such as your retention period, are those instructions. If EU or Danish law requires us to process the data otherwise, we tell you first unless the law forbids it. If we believe an instruction breaks data protection law, we tell you straight away.
Confidentiality
Only Asad Siddiqi has access to the data, and only as far as needed to run and support the service. Anyone given access in future will be bound by confidentiality first.
Security (Article 32)
We protect the data with these measures:
- All traffic to websites, the dashboard, the owner app and the API is encrypted with HTTPS.
- Passwords are stored only as one-way hashes.
- Device identifiers are stored as keyed HMAC hashes, not in readable form.
- Each restaurant's data is kept apart from every other restaurant's, so no restaurant can see another's orders or customers.
- Backups are encrypted.
- Administrative access to the platform requires two-factor authentication.
- Customer details on orders are erased automatically after your retention period, 90 days by default.
Sub-processors
You give us general authorisation to use sub-processors. These are used today:
| Sub-processor | What it does | Location | Transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | Servers, database and backups | Germany (EU) | No transfer outside the EU |
| Cloudflare, Inc. | Media storage (R2) and video delivery; no order data | R2 in EU jurisdiction; US company | EU-US Data Privacy Framework |
| Apple Distribution International Ltd (iCloud Mail) | Email: signup, order receipts and notices | Ireland; transfers to Apple Inc., United States | EU Standard Contractual Clauses |
| 650 Industries, Inc. (Expo) | Push notifications to the owner app | United States | EU-US Data Privacy Framework |
Card payments from your customers are made on your own Stripe account, under your own agreement with Stripe, so Stripe is your provider there, not our sub-processor. Stripe also bills your subscription to us; for that we are the controller, as our privacy policy describes.
We tell you by email at least 30 days before adding or replacing a sub-processor. You may object within that time; if we cannot resolve your objection, you may cancel before the change takes effect. Every sub-processor is bound by data protection obligations equivalent to those in this agreement, and we remain responsible to you for them.
Helping you meet your obligations
We help you answer requests from your customers to exercise their rights: you can see their orders in your dashboard, and on request we find, export, correct or delete a customer's data. We also give you the information you reasonably need for a data protection impact assessment or a prior consultation with the supervisory authority.
Personal data breaches
If we become aware of a personal data breach affecting your data, we notify you without undue delay and at the latest within 48 hours, by email to your account address, with what we know of its nature, the data and people affected, its likely consequences, and what we are doing about it. We add details as we learn them.
When the agreement ends
Before your subscription ends you can ask for your data to be returned as an export. The data is deleted within 30 days after the subscription ends, and backups containing it roll off within a further 14 days, unless EU or Danish law requires us to keep it.
Demonstrating compliance
We make available the information and documentation needed to show that we meet this agreement, including this description of our measures and sub-processors, and we answer your written questions about it. If that is not enough, or a supervisory authority requires it, we allow and contribute to an audit on reasonable notice.
Acceptance
This agreement is accepted electronically together with the Terms of Service when you tick the box on the signup form, and the version you accepted is recorded with your account. On personal data, this agreement takes precedence over the Terms of Service. It is governed by Danish law.