Last updated: September 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") supplements our Terms & Conditions and applies whenever Ordingo processes personal data on your behalf as your data processor — chiefly, your guests' order data. It's incorporated into our Terms by reference and accepted when you create an Ordingo account; where it conflicts with the Terms on data-protection matters, this DPA controls. Capitalized terms not defined here ("controller," "processor," "processing," "personal data," "data subject," "sub-processor") have the meaning given to them in the GDPR.
Roles of the parties
For guest personal data processed through Ordingo, you (the venue) are the controller and Ordingo is the processor, processing that data only on your documented instructions — which include the instructions built into how the service works (for example, routing an order to your kitchen display) and any additional instructions you give us in writing. For account, staff, and billing data you provide us directly about your own business, Ordingo is the controller, as described in our Privacy Policy.
Subject matter and duration
The subject matter of this DPA is Ordingo's processing of guest personal data to provide the ordering, kitchen-display, and related features of the service on your behalf. Processing lasts for as long as your Ordingo account is active, plus the retention period described in "Deletion and return of data" below.
Nature and purpose of processing
Ordingo collects, stores, transmits, and displays guest order data solely to operate the ordering platform for you: taking an order, routing it to your kitchen/bar display, tracking its status in real time, and retaining a record for your accounting and dispute-handling needs.
Categories of data and data subjects
Categories of personal data: the items ordered, the table/seat or QR code used, order status and timestamps, and any optional free-text note a guest chooses to add (which may incidentally include a name, phone number, or other detail the guest volunteers). We don't intentionally collect special categories of data (Article 9 GDPR), and you shouldn't design order-note fields or menu content to solicit them.
Categories of data subjects: the guests who place orders at your venue.
Processor obligations and confidentiality
Ordingo will process guest personal data only on your documented instructions, unless required to do otherwise by law (in which case we'll tell you before processing, unless the law prohibits it). We ensure that anyone we authorize to process the data — our own staff and contractors — is bound by confidentiality obligations.
Security measures
We use reasonable technical and organizational measures appropriate to the risk, including encryption of data in transit, hashed and salted password storage, access controls limiting who can reach production data, and logging of infrastructure access. No method of transmission or storage is perfectly secure, and these measures are reviewed and updated as the service evolves.
Sub-processors
You give Ordingo general authorization to engage sub-processors to help deliver the service. Our current sub-processors are: our cloud hosting provider (infrastructure), Stripe (payment processing), Resend (transactional email), and our AI provider(s) (currently Google, for the optional AI menu-import and AI-translation features) — each bound by a written agreement imposing data-protection obligations no less protective than this DPA.
We'll give you reasonable advance notice (by email to your account's admin) before adding or replacing a sub-processor that will process guest personal data. If you have a legitimate data-protection objection to a new sub-processor, tell us within a reasonable period of that notice and we'll work with you in good faith to address it — which may include your right to terminate the affected part of the service if we can't resolve the objection.
International data transfers
Where personal data is transferred outside the European Economic Area, we ensure an appropriate transfer mechanism is in place under applicable data-protection law — such as the European Commission's Standard Contractual Clauses, or another lawful safeguard offered by the receiving sub-processor — before the transfer takes place.
Assistance with data subject requests
Taking into account the nature of the processing, we'll reasonably assist you in responding to a data subject's request to exercise their GDPR rights (access, rectification, erasure, restriction, portability, or objection), and in complying with your own obligations around security, breach notification, and data protection impact assessments, where those obligations relate to Ordingo's processing.
Personal data breach notification
If we become aware of a personal data breach affecting guest personal data we process on your behalf, we'll notify you without undue delay, provide the information reasonably available to us about the breach, and cooperate with your investigation and any notifications you're legally required to make.
Deletion and return of data
On termination of your Ordingo account, we'll delete or anonymize the guest personal data we process on your behalf within 90 days, except to the extent we're required by law to retain it longer (for example, accounting or fraud-prevention records) — consistent with the Termination section of our Terms & Conditions.
Audit rights
On reasonable written request, no more than once per year (unless required following a security incident or by a regulator), we'll provide you with information reasonably necessary to demonstrate compliance with this DPA, such as a summary of our security measures or relevant certifications, and will reasonably cooperate with an audit you or your appointed auditor conducts, subject to confidentiality and to not disrupting the service for our other customers.
Contact us
Questions about this DPA can be sent to hello@ordingo.app.