Order and management solutions for restaurants a website or webshop for your restaurant in minutes


Data Processing Terms
Annex 1 – Data Processing Terms (GDPR)
A. Processing of personal data
Bistroo processes personal data on behalf of the Restaurant for the performance of the Agreement, including the processing of orders, payments and the provision of services. Anonymised data is also used for statistical purposes.
The data processed includes, among other things: name, address, email address, telephone number, payment details, IP address, and device and browser data.
Bistroo acts as the Processor and the Restaurant as the Controller.
1. Definitions
These terms (hereinafter: the ‘Data Processing Terms’) use a number of defined terms, the meaning of which is explained below. These terms are capitalised throughout the Data Processing Terms. The list below largely follows the definitions used in privacy laws and regulations.
Data Subject: The person to whom the personal data relates.
Processor: A natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller, without being subject to its direct authority.
Sub-processor: Another processor engaged by the Processor to carry out specific processing activities on behalf of the Controller.
Controller: A natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Special Categories of Personal Data: Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data for the purpose of uniquely identifying a person, data concerning health, or data concerning a person’s sex life or sexual orientation. This also includes personal data relating to criminal convictions and offences or related security measures.
Data Breach / Personal Data Breach: A breach of security that accidentally or unlawfully leads to - or where it cannot reasonably be ruled out that it may lead to - the destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Third Parties: Parties other than the Restaurant, Bistroo and their Employees.
Data Breach Notification Obligation: The obligation to report Data Breaches to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and (in some cases) to the Data Subject(s).
Employees: Persons working for Bistroo or for the Restaurant, either in employment or on a temporary basis.
Personal Data: Any information relating to an identified or identifiable natural person (the ‘Data Subject’) that is processed in the context of the Agreement; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Sensitive Personal Data: Personal data whose loss or unlawful Processing may lead to (among other things) stigmatisation or exclusion of the Data Subject, damage to health, financial loss or (identity) fraud.
These categories of personal data include in any event:
- Special categories of personal data
- Data about the financial or economic situation of the Data Subject
- (Other) data that may lead to stigmatisation or exclusion of the Data Subject
- Usernames, passwords and other login credentials
- Data that may be misused for (identity) fraud
Process / Processing: Any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of data.
Data Processing Terms: These terms (which also qualify as a data processing agreement).
GDPR: The General Data Protection Regulation, including the Dutch implementing act of this regulation.
2. Applicability and duration
These Data Processing Terms apply to all processing carried out by Bistroo and remain in force for as long as Bistroo processes personal data. They cannot be terminated. Confidentiality and liability continue to apply after termination.
3. Processing
- Bistroo processes data solely in accordance with the instructions of the Restaurant.
- The purposes and means of processing are determined by the Restaurant.
- Bistroo complies with privacy legislation; the Restaurant must have a lawful basis for processing.
- Access to data is limited to authorised employees.
- Bistroo may engage Sub-processors subject to the same obligations.
- Bistroo assists with requests from Data Subjects.
- Processing preferably takes place within the EEA, and otherwise subject to appropriate safeguards.
- Requests from authorities are legally assessed and, where possible, reported to the Restaurant.
4. Security
Bistroo takes appropriate technical and organisational measures. The Restaurant may carry out audits at its own expense.
5. Data breaches
Bistroo reports data breaches as soon as possible (target: within 48 hours). The obligation to notify the supervisory authority and Data Subjects lies with the Restaurant.
6. Confidentiality
Bistroo and its employees/Sub-processors are bound by confidentiality.
7. Liability
The Restaurant is responsible for lawful processing and indemnifies Bistroo against any breach of privacy legislation. The limitations set out in the Agreement also apply here.
8. Transfer
The Restaurant may not transfer its rights/obligations; Bistroo may.
9. Termination and data
Upon termination of the Agreement, data will be returned or destroyed, unless a statutory retention obligation applies. The costs are borne by the Restaurant.
10. Amendments
Amendments are only valid if agreed in writing (including by email).
11. Final provisions
- Bistroo provides information on compliance upon request.
- The parties cooperate with supervisory authorities.
- Dutch law applies; the Dutch courts have jurisdiction.
- Invalid provisions will be replaced by legally valid equivalents.