UK GDPR Data Processing Agreement
Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) forms part of the Master Software-as-a-Service Agreement or other applicable service agreement (“SaaS Agreement”) entered into between OrderWeb Ltd, a company incorporated in England and Wales (“OrderWeb”, “Processor”, “we”, “us”); and the restaurant, food-service business, merchant or other entity subscribing to and using the OrderWeb multi-tenant platform (“Controller”, “Customer”). This DPA governs the Processing of Personal Data by OrderWeb on behalf of the Controller in connection with the provision of the OrderWeb platform and related services.
Last updated: 9 August 2026
OrderWeb provides software functionality including online food ordering, delivery and collection ordering, customer accounts, shops, gift cards, loyalty functionality, table reservations, communications and payment integrations.
In providing these services, OrderWeb may host, store, organise, transmit and otherwise Process Personal Data relating to the Controller’s customers, employees and authorised users.
1. Definitions and interpretation
For the purposes of this DPA:
Applicable Data Protection Law means all data protection and privacy laws applicable to the Processing covered by this DPA, including, where applicable, the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), the Data (Use and Access) Act 2025, and any legislation that amends, replaces or succeeds them.
Customer Data means Personal Data Processed by OrderWeb on behalf of the Controller through the provision of the Services.
Data Subject means an identified or identifiable natural person to whom Personal Data relates.
Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data transmitted, stored or otherwise Processed.
Services means the OrderWeb software-as-a-service platform and associated hosting, ordering, booking, loyalty, messaging, payment-integration, administration and related functionality provided to the Controller.
The terms Controller, Processor, Personal Data, Processing, Sub-processor, Data Subject and Supervisory Authority shall have the meanings given to them under Applicable Data Protection Law.
2. Roles of the parties
2.1 Processing on behalf of the Controller
Where OrderWeb Processes Customer Data solely for the purpose of providing the Services in accordance with the Controller’s instructions:
- the restaurant or subscribing entity acts as the Controller; and
- OrderWeb Ltd acts as the Processor.
This includes, where applicable, Processing required to provide online ordering, delivery and collection functions, restaurant customer records, table bookings, loyalty functionality, gift card or shop transactions, transactional communications and related restaurant administration.
2.2 OrderWeb acting as an independent Controller
Nothing in this DPA prevents OrderWeb from acting as an independent Controller where OrderWeb determines the purposes and means of Processing Personal Data for its own legitimate and lawful business purposes.
Such Processing may include, where applicable:
- managing OrderWeb’s contractual relationship with the Controller;
- maintaining OrderWeb administrator and business contact records;
- account and platform security;
- authentication, security logging and abuse prevention;
- fraud prevention;
- legal and regulatory compliance;
- accounting, taxation and corporate record keeping;
- service administration;
- protecting the security, availability and integrity of the OrderWeb platform; and
- establishing, exercising or defending legal claims.
Processing carried out by OrderWeb as an independent Controller is outside the scope of this DPA and shall instead be governed by Applicable Data Protection Law and any applicable OrderWeb privacy notice.
2.3 No sale of Customer Data
OrderWeb shall not sell Customer Data or use Customer Data for unrelated advertising or marketing purposes except where separately authorised by the relevant Data Subject or Controller and permitted by Applicable Data Protection Law.
3. Details of Processing
The parties acknowledge the following particulars of Processing.
3.1 Subject matter and duration
The subject matter of Processing is the provision of the OrderWeb Services to the Controller.
Processing shall continue for the duration of the SaaS Agreement and for such limited period thereafter as is reasonably necessary to return, export, secure, back up or delete Customer Data in accordance with this DPA and Applicable Data Protection Law.
3.2 Nature and purpose
OrderWeb may Process Customer Data for purposes including:
- collecting and receiving customer information;
- validating customer and order information;
- creating and managing customer accounts;
- receiving and routing online orders;
- facilitating delivery and collection;
- managing table reservations;
- operating restaurant loyalty programmes;
- administering restaurant shops and gift cards;
- generating transactional records;
- facilitating communications requested by the Controller;
- routing payment-related information to authorised payment service providers;
- supporting customer service and order administration;
- maintaining operational records relating to the Services; and
- hosting, storing, organising, retrieving, transmitting and deleting Customer Data.
3.3 Categories of Data Subjects
Data Subjects may include:
- customers and prospective customers of the Controller;
- individuals placing food or retail orders;
- delivery customers;
- table-booking customers;
- loyalty programme members;
- gift card purchasers and recipients;
- authorised restaurant administrators;
- restaurant owners and managers;
- employees or personnel authorised to use the Services; and
- other individuals whose Personal Data the Controller submits to the Services.
3.4 Types of Personal Data
Depending on the Services used and the information provided by the Data Subject, Customer Data may include:
- first and last names;
- email addresses;
- telephone numbers;
- delivery addresses;
- billing addresses;
- account identifiers;
- encrypted or cryptographically hashed passwords;
- authentication and session information;
- order history;
- items ordered;
- quantities and pricing information;
- delivery or collection preferences;
- customer instructions and order notes;
- table-booking details;
- booking times and party information;
- loyalty points and loyalty transaction history;
- customer preferences;
- marketing consent records;
- gift card information;
- transaction status;
- merchant references;
- payment-provider transaction identifiers;
- Stripe Payment Intent or equivalent identifiers;
- Worldpay, Global Payments, Adyen, Teya or other payment-provider reference identifiers;
- masked payment information made available by payment providers, such as card brand or last four digits, where applicable; and
- technical information reasonably required to operate and secure the Services.
3.5 Payment card information
OrderWeb's Services are designed so that raw payment card credentials are collected and processed by authorised third-party payment service providers rather than being stored within OrderWeb's application databases.
OrderWeb does not intentionally collect or store:
- full payment card Primary Account Numbers (“PAN”);
- payment card PINs; or
- card verification values such as CVV, CVC or equivalent security codes.
Depending on the payment integration used, OrderWeb may Process payment tokens, payment-provider transaction identifiers, payment status information, merchant references and masked card information supplied by payment providers.
Where payment functionality is embedded into an OrderWeb page using secure payment fields, frames or components supplied by a payment service provider, cardholder data is intended to be transmitted directly to that payment provider in accordance with the applicable integration.
Nothing in this DPA constitutes a representation that any party satisfies a particular PCI DSS validation level or Self-Assessment Questionnaire unless that compliance status has been separately established.
4. Documented instructions
OrderWeb shall:
1. Process Customer Data only on documented instructions from the Controller, including instructions contained within the SaaS Agreement, this DPA, configuration of the Services and documented requests made through authorised support channels;
2. not Process Customer Data for purposes inconsistent with those instructions unless required to do so by Applicable Law; and
3. where legally permitted, inform the Controller before Processing Customer Data pursuant to a legal requirement that is inconsistent with the Controller’s instructions.
If OrderWeb reasonably believes that an instruction infringes Applicable Data Protection Law, OrderWeb may inform the Controller and suspend the affected Processing until the parties have reasonably resolved the issue.
5. Confidentiality and personnel
OrderWeb shall ensure that persons authorised to Process Customer Data:
- are subject to appropriate contractual, professional or statutory confidentiality obligations;
- are granted access to Customer Data only where reasonably necessary for their responsibilities;
- receive appropriate data protection and information-security guidance or training; and
- Process Customer Data only in accordance with this DPA and OrderWeb’s applicable security policies.
6. Security of Processing
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of Processing and the risks to Data Subjects, OrderWeb shall maintain appropriate technical and organisational measures designed to protect Customer Data.
Such measures may include, as appropriate to the relevant systems and risks:
- logical separation between tenants;
- application-level and database-level access controls;
- database schema separation and/or verified Row-Level Security controls where implemented;
- encryption of sensitive credentials and secrets at rest using industry-standard cryptographic methods;
- encryption of data in transit using TLS;
- access controls based on business need;
- multi-factor authentication for privileged access where appropriate;
- production access restrictions;
- security logging and monitoring;
- secure software-development practices;
- vulnerability management;
- data backup and recovery procedures;
- incident response procedures;
- credential and secret-management controls;
- authentication protections; and
- periodic review of security controls.
Where OrderWeb specifies particular encryption algorithms, cloud architectures, hosting configurations or security technologies in technical documentation, such specifications may be updated from time to time where reasonably necessary to maintain or improve security, provided that OrderWeb does not materially reduce the overall level of protection afforded to Customer Data.
7. Sub-processors
7.1 General authorisation
The Controller grants OrderWeb general written authorisation to appoint Sub-processors where reasonably necessary to provide, secure, support or maintain the Services.
7.2 Sub-processor obligations
OrderWeb shall ensure that each Sub-processor that Processes Customer Data is subject to written contractual obligations that provide data-protection safeguards appropriate to the Processing and that are no less protective in material respects than the obligations applicable to OrderWeb under this DPA, to the extent required by Applicable Data Protection Law.
OrderWeb shall remain responsible to the Controller for the performance of its Sub-processors in accordance with Applicable Data Protection Law.
7.3 Changes to Sub-processors
OrderWeb shall maintain a current list of material Sub-processors used to Process Customer Data.
OrderWeb shall provide reasonable advance notice of the appointment of a new material Sub-processor or replacement of an existing material Sub-processor.
Unless otherwise agreed in the SaaS Agreement, OrderWeb shall endeavour to provide at least fourteen (14) days’ notice before a new material Sub-processor begins Processing Customer Data.
The Controller may raise a reasonable written objection based on legitimate data-protection concerns during the applicable notice period.
The parties shall work in good faith to resolve any such objection.
Where no reasonable alternative can be agreed, either party may terminate the affected part of the Services in accordance with the applicable SaaS Agreement.
8. International transfers
OrderWeb shall not make a restricted transfer of Customer Data outside the United Kingdom unless the transfer is permitted under Applicable Data Protection Law.
Where a restricted international transfer occurs, OrderWeb shall ensure that an appropriate lawful transfer mechanism or exception applies.
Depending on the circumstances, such mechanism may include:
- applicable UK adequacy regulations;
- the UK International Data Transfer Agreement (“IDTA”);
- the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses;
- another appropriate safeguard recognised under UK data-protection law; or
- another lawful basis for the restricted transfer permitted by Applicable Data Protection Law.
Where required, OrderWeb shall undertake or participate in any applicable transfer risk assessment or equivalent data-protection assessment and implement reasonable supplementary measures where necessary.
Nothing in this DPA shall be interpreted as stating that a particular transfer mechanism applies to a Sub-processor unless that mechanism is in fact applicable to the relevant Processing and contractual relationship.
9. Data Subject rights
Taking into account the nature of the Processing, OrderWeb shall provide reasonable assistance to the Controller to enable the Controller to respond to requests from Data Subjects exercising rights under Applicable Data Protection Law.
Such rights may include, where applicable:
- access;
- rectification;
- erasure;
- restriction of Processing;
- objection;
- data portability; and
- rights relating to automated decision-making.
Where reasonably possible, OrderWeb may provide administrative or technical functionality enabling the Controller to fulfil such requests directly.
If OrderWeb receives a request directly from a Data Subject relating primarily to Customer Data Processed on behalf of the Controller, OrderWeb shall, where appropriate and legally permitted, direct the Data Subject to the Controller or notify the Controller of the request.
OrderWeb shall not independently respond to the substantive merits of such a request on the Controller’s behalf unless authorised or legally required to do so.
10. Assistance with compliance
Taking into account the nature of Processing and the information available to OrderWeb, OrderWeb shall provide reasonable assistance to the Controller with compliance obligations arising under Applicable Data Protection Law in relation to the Services, including where applicable:
- security of Processing;
- investigation of Personal Data Breaches;
- Data Protection Impact Assessments (“DPIAs”);
- consultations with the Information Commissioner’s Office or another competent Supervisory Authority; and
- reasonable information-security and Processing enquiries.
11. Personal Data Breaches
OrderWeb shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
To the extent information is reasonably available, OrderWeb shall provide the Controller with information necessary to assist the Controller in assessing and complying with its obligations under Applicable Data Protection Law.
Such information may include:
- the nature of the Personal Data Breach;
- the categories of affected Data Subjects;
- the categories of affected Personal Data;
- an approximate number of affected Data Subjects or records where reasonably ascertainable;
- the likely consequences of the Personal Data Breach;
- measures taken or proposed to contain, remediate or mitigate the Personal Data Breach; and
- a relevant contact point for further information.
Where all information is not available at the same time, OrderWeb may provide information in phases without undue further delay.
The Controller remains responsible for determining whether notification to the ICO, another Supervisory Authority or affected Data Subjects is required, except to the extent Applicable Law imposes a separate obligation directly on OrderWeb.
12. Deletion and return of Customer Data
Upon termination or expiry of the Services, and subject to the terms of the SaaS Agreement, OrderWeb shall, at the Controller’s choice where reasonably practicable:
- return or make available an export of relevant Customer Data; and/or
- delete Customer Data held in active systems.
OrderWeb may retain Customer Data where and to the extent Applicable Law requires continued retention.
Where continued retention is legally required, OrderWeb shall:
- retain only the Personal Data reasonably necessary for the applicable legal requirement;
- protect the retained Personal Data in accordance with this DPA; and
- limit further Processing to the purpose for which retention is legally required, except where otherwise permitted by law.
Customer Data contained within routine backups may remain for the applicable backup-retention period, provided that such data remains protected, is not restored or otherwise Processed except as necessary for disaster recovery, security or legal purposes, and is deleted or overwritten in accordance with OrderWeb’s normal backup lifecycle.
OrderWeb’s own records that it Processes as an independent Controller, including corporate accounting, contractual, security or legal records, are not subject to deletion under this clause merely because they relate to the Controller.
13. Audit and compliance information
OrderWeb shall make available to the Controller information reasonably necessary to demonstrate compliance with the Processor obligations set out in Article 28 UK GDPR.
Subject to appropriate confidentiality, security and operational safeguards, OrderWeb shall permit reasonable audits or inspections relating to its Processing of Customer Data.
Unless required by a Supervisory Authority or necessary following a material security incident:
- audits shall be conducted on reasonable prior written notice;
- audits shall normally occur no more than once in any twelve-month period;
- audits shall take place during normal business hours;
- audits shall not unreasonably interfere with OrderWeb’s business operations;
- auditors shall be subject to appropriate confidentiality obligations; and
- audits shall not compromise the confidentiality or security of other OrderWeb customers.
Where reasonably sufficient, OrderWeb may satisfy an audit request by providing relevant security questionnaires, policies, certifications, independent audit reports or other compliance materials rather than permitting direct access to production infrastructure.
14. Controller responsibilities
The Controller is responsible for:
- determining whether its use of the Services complies with Applicable Data Protection Law;
- establishing an appropriate lawful basis for Processing Personal Data;
- providing required privacy information to Data Subjects;
- ensuring that Customer Data submitted to OrderWeb has been collected lawfully;
- determining appropriate retention periods;
- responding to Data Subject requests as Controller;
- obtaining any legally required consent for marketing communications, cookies or similar technologies;
- managing its marketing preferences and communications in accordance with PECR and other Applicable Data Protection Law;
- configuring its use of the Services appropriately; and
- ensuring that authorised users access the Services securely.
The Controller shall not instruct OrderWeb to Process Personal Data in a manner that violates Applicable Data Protection Law.
15. Liability
The allocation and limitation of liability between the parties shall be governed by the SaaS Agreement, except to the extent that Applicable Data Protection Law requires otherwise.
Nothing in this DPA excludes or limits liability where such exclusion or limitation is prohibited by law.
16. Order of precedence
If there is a conflict between this DPA and the SaaS Agreement concerning the Processing or protection of Customer Data, this DPA shall prevail to the extent of that conflict.
All other provisions of the SaaS Agreement remain in effect.
17. Changes in law
If Applicable Data Protection Law changes in a manner that requires amendment of this DPA, the parties shall cooperate in good faith to make such amendments as are reasonably necessary to maintain compliance.
OrderWeb may update this DPA where reasonably necessary to reflect:
- changes in Applicable Data Protection Law;
- regulatory guidance;
- changes to the Services;
- changes to Sub-processors;
- changes to international-transfer mechanisms; or
- improvements to security or data-protection practices,
provided that any such update does not materially reduce the protection afforded to Customer Data contrary to Applicable Data Protection Law.
18. Governing law
This DPA and any non-contractual obligations arising out of or in connection with it shall be governed by the laws of England and Wales.
The courts of England and Wales shall have exclusive jurisdiction to settle disputes arising out of or in connection with this DPA, subject to any mandatory rights or powers of a competent Supervisory Authority.
Schedule 1 — Processing details
Controller: The restaurant, food-service business, merchant or other entity subscribing to the OrderWeb Services.
Processor: OrderWeb Ltd.
Subject matter: Provision of the OrderWeb multi-tenant SaaS platform.
Duration: For the duration of the applicable SaaS Agreement, together with any limited retention or deletion period described in this DPA.
Nature of Processing: Collection, receipt, organisation, hosting, storage, retrieval, consultation, use, routing, transmission, support, security, backup, deletion and other Processing reasonably necessary to provide the Services.
Purposes: Online ordering, delivery and collection, customer accounts, table bookings, loyalty functionality, shops, gift cards, communications, restaurant administration and payment integration.
Categories of Data Subjects: Restaurant customers, prospective customers, loyalty members, booking customers, authorised restaurant administrators, managers, owners and personnel.
Categories of Personal Data: Names, telephone numbers, email addresses, delivery and billing addresses, order information, booking information, account information, loyalty information, preferences, consent records, transaction references, payment status information and associated technical information.
Special Category Data: The Services are not designed for the routine Processing of Special Category Data. The Controller shall not intentionally submit Special Category Data unless such Processing has been expressly agreed and an appropriate lawful basis exists.
Raw payment card data: OrderWeb does not intentionally store full PAN, PIN or CVV/CVC information in its application databases.
Schedule 3 — Technical and organisational measures
OrderWeb shall maintain technical and organisational measures appropriate to the nature and risk of the Processing.
Measures may include:
Access control
- role-based access controls;
- least-privilege access principles;
- restricted production-system access;
- multi-factor authentication for privileged systems where appropriate;
- access revocation procedures; and
- authentication and session-management controls.
Data security
- encryption in transit;
- appropriate encryption or cryptographic protection for sensitive stored credentials and secrets;
- tenant-isolation controls;
- database access controls;
- secrets management; and
- secure backup procedures.
Application security
- secure software-development practices;
- dependency and vulnerability management;
- validation of user input;
- access-control enforcement;
- security logging;
- monitoring; and
- deployment and change-management controls.
Operational security
- incident-management procedures;
- backup and recovery processes;
- business-continuity considerations;
- personnel confidentiality obligations;
- security awareness;
- logging and monitoring; and
- periodic review of relevant security controls.
Payment security
OrderWeb shall maintain payment integrations designed to avoid the storage of full payment-card numbers and card verification values within OrderWeb application databases.
Where possible, payment-card entry shall be handled through hosted payment pages, secure hosted payment components or other mechanisms supplied by authorised payment service providers.
Schedule 2 — Sub-processors
OrderWeb shall maintain an accurate and current list of material Sub-processors.
At the date of this DPA, OrderWeb may use providers within the following categories, subject to the Controller’s actual configuration and the Services enabled.
The inclusion of a provider in this Schedule does not mean that every Controller’s Customer Data is necessarily Processed by that provider. The providers used depend on the Services, integrations and configuration selected by the Controller and OrderWeb.
OrderWeb may publish or otherwise make available an updated Sub-processor list containing further details regarding Processing locations and applicable safeguards.
| Sub-processor | Core processing activity | Geographic region & safeguards |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, computing, storage, networking, database or related hosting services where configured | Processing locations depend on the OrderWeb infrastructure configuration. Restricted transfers, where applicable, shall be protected in accordance with Clause 8. |
| Google Cloud Platform | Cloud infrastructure, storage, computing, logging or related hosting services where configured | Processing locations depend on the OrderWeb infrastructure configuration. Restricted transfers, where applicable, shall be protected in accordance with Clause 8. |
| Stripe | Payment processing integration, payment tokens, transaction identifiers, payment status, hosted checkout, secure payment interfaces and webhook communications | Stripe acts in accordance with its applicable contractual and data-protection terms. Any restricted transfers shall be handled using an applicable lawful transfer mechanism. |
| Worldpay | Payment processing integration, transaction authorisation, payment references and settlement-related functionality | Processing locations and transfer mechanisms are governed by the applicable Worldpay arrangement. |
| Global Payments | Payment integration, Pay-by-Link or other hosted payment functionality, transaction references and settlement-related functionality | Processing locations and transfer mechanisms are governed by the applicable Global Payments arrangement. |
| Adyen | Payment processing integration, hosted payment sessions, transaction references and payment status | Processing locations and transfer mechanisms are governed by the applicable Adyen arrangement. |
| Teya | Payment processing or hosted payment functionality where enabled | Processing locations and transfer mechanisms are governed by the applicable Teya arrangement. |
| Twilio | Transactional SMS, communications and related delivery metadata where enabled | Any restricted transfer shall be handled using an applicable lawful transfer mechanism. |
| SendGrid / applicable email delivery provider | Transactional email, order notifications and related delivery metadata where enabled | Any restricted transfer shall be handled using an applicable lawful transfer mechanism. |
Execution and sign-off
IN WITNESS WHEREOF, the parties agree to this Data Processing Agreement through their duly authorised representatives.
For the Processor
OrderWeb Ltd
Authorised signature: _______________________
Name: ____________________________________
Title: _____________________________________
Date: _____________________________________
For the Controller
[Restaurant / business legal name]
Authorised signature: _______________________
Name: ____________________________________
Title: _____________________________________
Date: _____________________________________
Related documents: Master SaaS Agreement · Privacy Policy · Terms & Conditions · Cookie Policy · Sub-processor List
Questions? Contact us or email mail@orderweb.co.uk.