Legal
Data Processing Agreement
Last updated: 25 June 2026
This DPA forms part of the Terms of Service between VenueCore Ltd (“Processor”) and the customer venue (“Controller”). It governs processing of personal data under UK GDPR and Regulation (EU) 2016/679 (“GDPR”) Article 28.
1. Subject matter & duration
Processor will process personal data on behalf of Controller for the duration of the subscription, solely to provide the VenueCore hospitality platform.
2. Nature & purpose
Hosting, storing, transmitting, displaying and analysing personal data necessary to operate EPOS, KDS, reservations, loyalty, staff scheduling, payments and AI-assisted diagnostics on Controller’s instructions.
3. Categories of data subjects
- Controller’s staff and contractors.
- Controller’s guests, diners, reservation holders and loyalty members.
- Suppliers and contacts entered into the platform.
4. Categories of personal data
- Identification: name, email, phone.
- Transactional: orders, receipts, tips, reservation history.
- Employment: shifts, time entries, role, pay-rate metadata.
- Preferences: allergens, dietary notes, marketing consent.
- Technical: IP, device, audit logs.
Controller will not knowingly submit special-category data (health, biometrics, political opinions) except limited allergen/dietary notes necessary for service.
5. Processor obligations
- Process only on documented instructions from Controller (the Terms, this DPA, in-app configuration).
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical & organisational measures (Annex II below).
- Notify Controller without undue delay (target: 48 hours) of any confirmed personal-data breach.
- Assist Controller with data-subject rights requests and DPIAs.
- On termination, return or delete personal data within 90 days, subject to legal retention.
6. Sub-processors
Controller authorises Processor to engage the sub-processors listed at /subprocessors. Processor will give 30 days’ notice by email of any addition or replacement; Controller may object on reasonable data- protection grounds, in which case the parties will work in good faith to resolve.
7. International transfers
Primary processing is in the EU. Transfers to the US (e.g. Stripe, Google via the Lovable AI Gateway) are covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses (Module 3, processor-to-processor), incorporated by reference.
8. Audits
Processor will make available all information necessary to demonstrate compliance with Article 28. Controller may request an audit once per 12 months on 30 days’ notice at Controller’s cost; Processor may satisfy this with a recent independent attestation (e.g. SOC 2 / ISO 27001 from underlying infrastructure providers — VenueCore itself is not yet certified) where available.
9. Liability
Liability under this DPA is subject to the limitations in the Terms of Service.
Annex I — Processing details
As described in sections 2–4 above. Frequency: continuous, for the duration of the subscription. Retention: per the Privacy Policy.
Annex II — Technical & organisational measures
- Encryption: TLS 1.2+ in transit, AES-256 at rest.
- Access control: role-based access, MFA available for admins, row-level security per tenant.
- Password handling: bcrypt hashing, leaked-password screening (HIBP).
- Logging: immutable audit log for admin actions, money movement, authentication, with 1-year retention.
- Backups: daily encrypted, EU-resident.
- Vulnerability management: dependency scanning, security scanner on every deploy.
- Incident response: documented 72-hour breach notification process.
- Personnel: confidentiality obligations, least-privilege production access.
Signing
This DPA is incorporated by reference into the Terms of Service. Customers requiring a countersigned copy on their own paper can request one at support@venuecore.solutions.