Data Processing Agreement

Data processing agreement entered into under art. 28 of Regulation (EU) 2016/679.

Last updated: September 25, 2026
Where a restaurant uses AurelTable to receive bookings and orders, it collects personal data relating to its own guests. In respect of that data the restaurant is the controller and NB Studio is the processor, acting on the restaurant’s behalf. Art. 28 of the Regulation requires that the relationship be governed by a written instrument: this agreement satisfies that requirement and is accepted on subscription to the service.

1Parties and definitions

1.1. The controller is the restaurant subscribing to AurelTable, which determines the purposes and means of processing the personal data of its guests.

1.2. The processor is NB Studio di Nico Boccia, VAT number IT03154820645, with registered office in Montella (AV), Italy; certified email nico.boccia@pec.it.

1.3. Data subjects are the guests of the restaurant.

1.4. The expressions “personal data”, “processing”, “sub-processor” and “personal data breach” bear the meanings given to them in Regulation (EU) 2016/679.

2Subject matter and duration

2.1. The processor processes the personal data of data subjects for the sole purpose of providing the controller with the AurelTable features, namely the management of bookings and orders, the transmission of the related electronic mail and the production of statistics in aggregate form.

2.2. This agreement runs for the term of the service contract and terminates with it.

3Categories of data and of data subjects

3.1. The processing concerns, in respect of guests making a booking, name, telephone number, WhatsApp number, email address, party size and any notes; and, in respect of guests placing a takeaway or delivery order, name, telephone number, email address, delivery address and items ordered.

3.2. No special categories of data within the meaning of art. 9 of the Regulation are envisaged. The controller undertakes not to enter data of that nature in free-text fields.

4Obligations of the processor

4.1. The processor processes personal data only on the documented instructions of the controller and ensures that persons authorised to process the data have undertaken a duty of confidentiality or are under an appropriate statutory obligation of secrecy.

4.2. The processor implements the security measures required by art. 32 of the Regulation, as particularised in article 7, and complies with the conditions for engaging a sub-processor set out in article 6.

4.3. The processor assists the controller in responding to requests by data subjects and in discharging its obligations as to security, breach notification and impact assessment, as particularised in article 8.

4.4. At the controller’s election the processor deletes or returns the data on termination, as particularised in article 10, and makes available the information necessary to demonstrate compliance with art. 28, permitting the audits provided for in article 11.

5Instructions of the controller

5.1. The controller’s documented instructions consist of this agreement, the service contract and the settings adopted by the controller in the management panel.

5.2. Where the processor considers that an instruction infringes the Regulation or other data protection provisions, it shall immediately inform the controller.

6Sub-processors

6.1. The controller authorises the processor to engage the sub-processors listed below, which are necessary for the provision of the service. The processor imposes upon them, by contract, data protection obligations equivalent to those contained in this agreement and remains liable to the controller for their performance.

Sub-processorActivityLocationSafeguard
Supabase, Inc.Database and authentication; data hosted on Amazon Web Services infrastructure, London region (eu-west-2)Data: United Kingdom. Entity: SingaporeUK adequacy and Standard Contractual Clauses
Amazon Web ServicesCloud infrastructure on which Supabase operatesEntity: United States. Data: United KingdomStandard Contractual Clauses and UK adequacy
CloudflareHosting, content delivery, bot protection and image storageUnited StatesStandard Contractual Clauses
StripePayments and booking card holdsUnited States and IrelandStandard Contractual Clauses
ResendTransactional emailUnited StatesStandard Contractual Clauses
OpenAIMenu optical character recognition, assistant, translationsUnited StatesStandard Contractual Clauses

6.2. The processor informs the controller of any intended addition or replacement of a sub-processor, affording the controller the opportunity to object on legitimate grounds.

7Security measures

7.1. The processor implements the following technical and organisational measures: encryption of communications by means of HTTPS/TLS; access control and isolation of each restaurant’s data from that of every other, enforced at database level; storage of passwords by means of a strong hashing algorithm; rate limiting and protection against automated access; backups managed by the database provider; and data minimisation, only the data required by the booking and ordering features being processed.

8Assistance to the controller

8.1. The processor assists the controller, so far as technically possible, in responding to requests for the exercise of data subject rights and in discharging its obligations as to the security of processing.

8.2. In the event of a personal data breach the processor informs the controller without undue delay after becoming aware of it, providing the information necessary to enable the controller to make the notifications required to its supervisory authority and to data subjects.

9Transfers to third countries

9.1. Transfers to third countries are made solely to the sub-processors listed in article 6 and rest upon an adequacy decision, as regards the United Kingdom, or upon the Standard Contractual Clauses adopted by the European Commission, as regards the United States providers.

10Deletion or return of data

10.1. On termination, at the controller’s election, the processor deletes or returns all personal data of data subjects and deletes existing copies, save where retention is required by law.

10.2. Unless otherwise instructed, account data is deleted within 30 days of termination; bookings and orders are in any event deleted within 12 months of their respective dates.

10.3. The controller may at any time obtain a copy of the data independently, by means of the export function in the management panel.

11Audits

11.1. The processor makes available to the controller the information necessary to demonstrate compliance with the obligations arising under this agreement and permits reasonable audits, including by documentation, on reasonable notice and subject to the confidentiality of other customers.

12Application outside the European Union

12.1. Where the Regulation does not apply, the allocation of responsibilities under this agreement is unchanged: the controller determines the purposes of the processing and the processor acts upon its instructions, which corresponds to the role of service provider under United States state privacy laws. The personal data of data subjects is not used for the processor’s own purposes, is not sold and is not shared; reference is made to Your Privacy Choices. The security measures, the list of sub-processors and the retention periods set out above apply without modification.

13Acceptance

13.1. This agreement is taken to be executed and accepted by the controller upon activation and use of the AurelTable service and forms an integral part of the Terms of Service. The Italian version prevails in the event of discrepancy.