Data Processing Agreement
Last updated: 13 September 2026
1. About this Agreement
1.1 This Data Processing Agreement ("DPA") forms part of the Terms and Conditions ("Terms") between Make a Rezzy Ltd, a company registered in England and Wales under company number 16048393, whose registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ ("We", "Us", "Our") and each Business that uses Our Platforms to manage its reservations, guests and marketing ("the Business", "You", "Your").
1.2 This DPA applies wherever We process Guest Data on Your behalf. It sets out the terms required by Article 28 of the UK General Data Protection Regulation ("UK GDPR").
1.3 If there is a conflict between this DPA and the Terms, this DPA takes precedence in relation to the processing of Guest Data.
2. Definitions
2.1 In this DPA, the following expressions have the following definitions. Any expression not defined here has the meaning given in the Terms or in Data Protection Law.
- Data Protection Law - The UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any other law relating to personal data that applies to either party.
- Guest Data - Personal data about Your guests and staff that is held in Your Business Account, including guest profiles, bookings, notes, tags, marketing consent records, spend data and any data You import or connect from other systems.
- Business Account - The area of Our Platforms used to manage a Business, including the management website, the management app and the booking widget.
- Sub-processor - A third party We engage to process Guest Data on Your behalf.
- Personal Data Breach - A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Guest Data.
- controller, processor, data subject and processing - Have the meanings given in the UK GDPR.
3. Roles of the Parties
3.1 In relation to Guest Data, You are the controller and We are Your processor.
3.2 We are a controller in our own right, and this DPA does not apply, for personal data We process for Our own purposes. This includes:
- accounts that guests create on Our Website, and the bookings and reviews they make through it;
- the user accounts of Your staff and Our billing records for You;
- analytics, security and fraud prevention on Our Platforms;
- the advertising We run for Businesses, as described in section 7 of the Terms.
3.3 Where a guest books with You through Our Website, We and You each act as independent controllers of the booking details. Once those details are held in Your Business Account they are Guest Data.
3.4 You are responsible for ensuring You have a lawful basis for the Guest Data You collect, import or ask Us to process, and for the instructions You give Us.
4. Details of the Processing
4.1 Subject matter and purpose - Providing Our reservation, guest management, payment, marketing and reporting services to You under the Terms.
4.2 Nature of the processing - Collecting, storing, organising, displaying, filtering, exporting, sending communications to, synchronising with systems You connect, and deleting Guest Data.
4.3 Duration - For as long as You use Our Platforms, and afterwards until the Guest Data is deleted under section 11.
4.4 Categories of data subjects:
- Your guests and prospective guests;
- Your staff, where their details are recorded against bookings or activity.
4.5 Types of personal data:
- names, email addresses and phone numbers;
- booking details, including dates, party sizes, tables, special requests and occasions;
- visit history, spend and payment status (not card details);
- notes, tags and segments You add;
- marketing consent records and email engagement;
- any other information You or Your guests enter, which may include dietary requirements or accessibility needs.
4.6 Dietary requirements and accessibility needs can reveal information about health, which is special category data. You should only record what You need to serve the guest.
5. Our Obligations
5.1 We will only process Guest Data on Your documented instructions, including with regard to transfers outside the UK, unless the law requires otherwise. If it does, We will tell You before processing unless the law prevents Us from doing so.
5.2 Your instructions are the Terms, this DPA, and the actions You take in Your Business Account, such as adding a guest, sending a campaign, connecting an integration or exporting a list.
5.3 We will tell You promptly if We believe an instruction breaks Data Protection Law.
5.4 We will ensure that everyone We authorise to process Guest Data is bound by a duty of confidentiality.
5.5 We will not sell Guest Data or use it for Our own purposes, except to create aggregated and anonymised information that does not identify You, Your guests or any individual, as permitted by section 5.4 of the Terms.
6. Security
6.1 We will put in place appropriate technical and organisational measures to protect Guest Data, as required by Article 32 of the UK GDPR. These are described in Annex 1.
6.2 We may update these measures over time, provided the overall level of security is not reduced.
7. Sub-processors
7.1 You give Us general authorisation to engage Sub-processors. Our current Sub-processors are listed in Annex 2.
7.2 We will give You at least 30 days' notice by email before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period. If We cannot resolve Your objection, You may end Your use of the affected service without penalty.
7.3 Each Sub-processor processes Guest Data under a written contract with Us, which may be that Sub-processor's standard terms and data processing agreement. That contract requires the Sub-processor to protect Guest Data to substantially the same standard as this DPA. We remain responsible to You for the performance of Our Sub-processors.
7.4 Services You choose to connect to Your Business Account using Your own account with that service, such as Square or Spektrix, are not Our Sub-processors. Data is shared with them on Your instruction and under Your own agreement with them, and We are not responsible for how they process it.
8. International Transfers
8.1 Guest Data is hosted in the United Kingdom. Where a Sub-processor processes Guest Data outside the UK, We will ensure the transfer is covered by UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
9. Assisting You
9.1 Taking into account the nature of the processing, We will assist You in responding to requests from data subjects exercising their rights. Our Platforms let You view, correct, export and delete guest records yourself. If We receive a request directly, We will pass it to You and will not respond to it without Your authorisation.
9.2 We will provide reasonable assistance to help You meet Your obligations on security, Personal Data Breach notification, data protection impact assessments and prior consultation with the Information Commissioner's Office, taking into account the information available to Us.
10. Personal Data Breaches
10.1 We will notify You without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Guest Data.
10.2 Our notification will describe, as far as We know at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the steps We have taken or propose to take. We will provide further information as it becomes available.
10.3 You are responsible for deciding whether to notify the Information Commissioner's Office and affected data subjects.
11. Return and Deletion of Guest Data
11.1 You can export Your guest list at any time from Your Business Account.
11.2 When You stop using Our Platforms, You should export any Guest Data You wish to keep. We will delete Guest Data within 90 days of Your Business Account being closed, unless the law requires Us to keep it.
11.3 Guest Data held in backups will be deleted as the backups expire in the ordinary course.
12. Information and Audits
12.1 We will make available to You the information reasonably necessary to demonstrate compliance with this DPA.
12.2 We will allow for and contribute to audits, including inspections, carried out by You or an auditor You appoint. You must give Us at least 30 days' written notice, audits must take place during normal business hours no more than once a year (unless required by a regulator or following a Personal Data Breach), and the auditor must be bound by confidentiality. Each party bears its own costs.
13. Liability and Term
13.1 Each party's liability under this DPA is subject to the limitations set out in the Terms, except where Data Protection Law does not allow liability to be limited.
13.2 This DPA continues for as long as We process Guest Data on Your behalf.
13.3 We may update this DPA as described in section 8 of the Terms. Changes to the Sub-processor list follow section 7 of this DPA.
Annex 1 - Security Measures
- Data is encrypted in transit using TLS between browsers, apps and Our servers, and between Our servers and Sub-processors.
- Our servers are hosted in UK data centres operated by providers that maintain recognised security certifications.
- Access to Business Accounts is restricted by role. Staff only see the Businesses they have been granted access to.
- Passwords are stored using one-way hashing and are never stored in a readable form.
- Card details are handled by Stripe and are never stored on Our servers.
- Access to production systems is limited to authorised personnel.
- Changes to key records are audit-logged, and errors are monitored so problems can be investigated.
- Data is backed up regularly.
Annex 2 - Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean | Application hosting and database | United Kingdom |
| Amazon Web Services | File storage, and marketing email delivery | United Kingdom |
| Amazon Web Services | Booking confirmations, reminders and other service emails | United Kingdom |
| Stripe | Deposit and payment processing | United Kingdom, Ireland and United States |
| Expo | Push notifications to the management app | United States |
| Sentry | Error monitoring | European Union |
| OpenAI and Anthropic | AI writing and audience suggestions, when You use them | United States |