Data Processing Agreement

Last updated: 13 September 2026

1. About this Agreement

1.1 This Data Processing Agreement ("DPA") forms part of the Terms and Conditions ("Terms") between Make a Rezzy Ltd, a company registered in England and Wales under company number 16048393, whose registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ ("We", "Us", "Our") and each Business that uses Our Platforms to manage its reservations, guests and marketing ("the Business", "You", "Your").

1.2 This DPA applies wherever We process Guest Data on Your behalf. It sets out the terms required by Article 28 of the UK General Data Protection Regulation ("UK GDPR").

1.3 If there is a conflict between this DPA and the Terms, this DPA takes precedence in relation to the processing of Guest Data.

2. Definitions

2.1 In this DPA, the following expressions have the following definitions. Any expression not defined here has the meaning given in the Terms or in Data Protection Law.

3. Roles of the Parties

3.1 In relation to Guest Data, You are the controller and We are Your processor.

3.2 We are a controller in our own right, and this DPA does not apply, for personal data We process for Our own purposes. This includes:

3.3 Where a guest books with You through Our Website, We and You each act as independent controllers of the booking details. Once those details are held in Your Business Account they are Guest Data.

3.4 You are responsible for ensuring You have a lawful basis for the Guest Data You collect, import or ask Us to process, and for the instructions You give Us.

4. Details of the Processing

4.1 Subject matter and purpose - Providing Our reservation, guest management, payment, marketing and reporting services to You under the Terms.

4.2 Nature of the processing - Collecting, storing, organising, displaying, filtering, exporting, sending communications to, synchronising with systems You connect, and deleting Guest Data.

4.3 Duration - For as long as You use Our Platforms, and afterwards until the Guest Data is deleted under section 11.

4.4 Categories of data subjects:

4.5 Types of personal data:

4.6 Dietary requirements and accessibility needs can reveal information about health, which is special category data. You should only record what You need to serve the guest.

5. Our Obligations

5.1 We will only process Guest Data on Your documented instructions, including with regard to transfers outside the UK, unless the law requires otherwise. If it does, We will tell You before processing unless the law prevents Us from doing so.

5.2 Your instructions are the Terms, this DPA, and the actions You take in Your Business Account, such as adding a guest, sending a campaign, connecting an integration or exporting a list.

5.3 We will tell You promptly if We believe an instruction breaks Data Protection Law.

5.4 We will ensure that everyone We authorise to process Guest Data is bound by a duty of confidentiality.

5.5 We will not sell Guest Data or use it for Our own purposes, except to create aggregated and anonymised information that does not identify You, Your guests or any individual, as permitted by section 5.4 of the Terms.

6. Security

6.1 We will put in place appropriate technical and organisational measures to protect Guest Data, as required by Article 32 of the UK GDPR. These are described in Annex 1.

6.2 We may update these measures over time, provided the overall level of security is not reduced.

7. Sub-processors

7.1 You give Us general authorisation to engage Sub-processors. Our current Sub-processors are listed in Annex 2.

7.2 We will give You at least 30 days' notice by email before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period. If We cannot resolve Your objection, You may end Your use of the affected service without penalty.

7.3 Each Sub-processor processes Guest Data under a written contract with Us, which may be that Sub-processor's standard terms and data processing agreement. That contract requires the Sub-processor to protect Guest Data to substantially the same standard as this DPA. We remain responsible to You for the performance of Our Sub-processors.

7.4 Services You choose to connect to Your Business Account using Your own account with that service, such as Square or Spektrix, are not Our Sub-processors. Data is shared with them on Your instruction and under Your own agreement with them, and We are not responsible for how they process it.

8. International Transfers

8.1 Guest Data is hosted in the United Kingdom. Where a Sub-processor processes Guest Data outside the UK, We will ensure the transfer is covered by UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

9. Assisting You

9.1 Taking into account the nature of the processing, We will assist You in responding to requests from data subjects exercising their rights. Our Platforms let You view, correct, export and delete guest records yourself. If We receive a request directly, We will pass it to You and will not respond to it without Your authorisation.

9.2 We will provide reasonable assistance to help You meet Your obligations on security, Personal Data Breach notification, data protection impact assessments and prior consultation with the Information Commissioner's Office, taking into account the information available to Us.

10. Personal Data Breaches

10.1 We will notify You without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Guest Data.

10.2 Our notification will describe, as far as We know at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the steps We have taken or propose to take. We will provide further information as it becomes available.

10.3 You are responsible for deciding whether to notify the Information Commissioner's Office and affected data subjects.

11. Return and Deletion of Guest Data

11.1 You can export Your guest list at any time from Your Business Account.

11.2 When You stop using Our Platforms, You should export any Guest Data You wish to keep. We will delete Guest Data within 90 days of Your Business Account being closed, unless the law requires Us to keep it.

11.3 Guest Data held in backups will be deleted as the backups expire in the ordinary course.

12. Information and Audits

12.1 We will make available to You the information reasonably necessary to demonstrate compliance with this DPA.

12.2 We will allow for and contribute to audits, including inspections, carried out by You or an auditor You appoint. You must give Us at least 30 days' written notice, audits must take place during normal business hours no more than once a year (unless required by a regulator or following a Personal Data Breach), and the auditor must be bound by confidentiality. Each party bears its own costs.

13. Liability and Term

13.1 Each party's liability under this DPA is subject to the limitations set out in the Terms, except where Data Protection Law does not allow liability to be limited.

13.2 This DPA continues for as long as We process Guest Data on Your behalf.

13.3 We may update this DPA as described in section 8 of the Terms. Changes to the Sub-processor list follow section 7 of this DPA.

Annex 1 - Security Measures

Annex 2 - Sub-processors

Sub-processor Purpose Location
DigitalOcean Application hosting and database United Kingdom
Amazon Web Services File storage, and marketing email delivery United Kingdom
Amazon Web Services Booking confirmations, reminders and other service emails United Kingdom
Stripe Deposit and payment processing United Kingdom, Ireland and United States
Expo Push notifications to the management app United States
Sentry Error monitoring European Union
OpenAI and Anthropic AI writing and audience suggestions, when You use them United States