Data Processing Agreement
Last updated: August 30, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Tacoter and each restaurant customer and applies where Tacoter processes personal data on the customer's behalf.
Table of contents
1. Definitions
- Controller: the restaurant, which determines the purposes and means of processing its diner data.
- Processor: Tacoter, which processes personal data on the controller's documented instructions.
- Data subject: an identified or identifiable individual, typically a diner or restaurant staff member.
- Personal data: information relating to a data subject, as defined by applicable privacy law.
2. Data Processing
Subject matter: provision of the Tacoter ordering, marketing and operations platform. Duration: for the term of the subscription plus the deletion window below.
- Categories of data subjects: diners, restaurant owners, restaurant staff.
- Categories of personal data: name, phone, email, delivery address, order history, saved preferences, payment tokens, message engagement.
- Purpose: hosting the ordering site, processing orders and payments, sending transactional and consented marketing messages, analytics and AI assistance.
- Tacoter processes personal data only on the controller's documented instructions, including these Terms, unless required by law.
3. Security Measures
- Encryption in transit (TLS 1.2+) and at rest for stored data.
- Row-level security so each restaurant can access only its own records.
- Role-based access control and least-privilege access for Tacoter personnel, with access logging.
- Secrets management, no card numbers stored on Tacoter systems, and PCI-compliant payment partners.
- Automated backups, restore testing, and monitoring with alerting.
- Confidentiality obligations for all personnel with access to personal data.
4. Subprocessors
The controller authorizes Tacoter to engage the subprocessors listed on our Subprocessors page. We impose data protection terms on each subprocessor that are no less protective than this DPA and remain liable for their performance.
We will give at least 30 days' notice before adding or replacing a subprocessor. The controller may object on reasonable data-protection grounds; if we cannot resolve the objection, the controller may terminate the affected service without penalty.
5. Data Subject Rights
Tacoter provides dashboard tools to export, correct and delete diner records. Where a data subject contacts Tacoter directly, we refer them to the relevant restaurant and assist the restaurant in responding within the statutory deadline.
6. Breach Notification
Tacoter will notify the controller without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting the controller's data, describing the nature of the breach, the categories and approximate number of records involved, likely consequences, and remediation steps.
7. Data Deletion
On termination, the controller has 30 days to export its data. After that window Tacoter deletes or anonymizes personal data within 60 days, except records retained to comply with legal obligations, which remain protected by this DPA until deleted.
DPA questions and signature requests: legal@tacoter.com.