Contracting entity: THYNKR SYSTEMS LTD
Company number: 15306717
Registered office: Office 2, 1st Floor, 73 Station Passage, London, England, E18 1JL
Product / trading name: TableSyncAI / TableSync
Website: https://tablesyncai.com
General contact: info@tablesyncai.com
Telephone: +44 (0)333 011 8207
Last updated: 1 October 2026
Version 1.0
3. Data Processing Agreement (DPA)
3.1 Scope
This Data Processing Agreement ("DPA") forms part of the agreement between THYNKR SYSTEMS LTD ("Processor", "THYNKR") and the customer using TableSyncAI ("Controller", "Customer") where THYNKR processes Personal Data on the Customer's behalf.
This DPA applies to processing subject to the UK GDPR, Data Protection Act 2018 and, where applicable, other data-protection legislation including the EU GDPR.
Capitalised terms not defined here have the meanings given in the main Agreement or applicable Data Protection Law.
3.2 Roles
The Customer is the Controller of Customer Personal Data where it determines the purposes and means of processing.
THYNKR is the Processor when it processes that data solely on the Customer's documented instructions to provide the Services.
The parties acknowledge that THYNKR may separately act as Controller for limited processing undertaken for its own legitimate purposes, such as account administration, billing, platform security, legal compliance and establishment or defence of claims. Such controller processing is governed by THYNKR's Privacy Policy.
3.3 Details of Processing
Subject matter
Provision, operation, maintenance, support and security of TableSyncAI and associated restaurant technology services.
Duration
For the duration of the Agreement and any lawful retention or transition period thereafter.
Nature and purpose
Collection, storage, organisation, retrieval, transmission, hosting, analysis, support, deletion and other processing necessary to provide the contracted Services.
Categories of data subjects
May include:
- restaurant customers and prospective customers;
- restaurant staff and authorised users;
- Customer administrators;
- delivery or collection recipients;
- loyalty customers;
- Customer contacts;
- suppliers and business contacts recorded by the Customer; and
- other individuals whose data the Customer lawfully submits.
Types of Personal Data
May include:
- names;
- contact details;
- delivery or collection details;
- order information;
- account identifiers;
- staff details;
- role and permission data;
- transaction references;
- customer communications;
- device and technical identifiers;
- IP addresses;
- audit logs;
- loyalty information; and
- other Personal Data submitted through configured fields.
Special-category data
The Services are not designed as a general repository for special-category data. Allergy notes or similar information may, in context, constitute health-related Personal Data and must only be supplied where the Controller has a lawful basis and appropriate safeguards.
3.4 Controller Instructions
THYNKR will process Customer Personal Data only:
- on documented instructions from the Customer, including instructions embodied in the Agreement and use of configured Service features; or
- where processing is required by applicable law.
If law requires processing outside the Customer's instructions, THYNKR will inform the Customer before processing unless the law prohibits that notice.
THYNKR will promptly inform the Customer if, in THYNKR's reasonable opinion, an instruction infringes applicable Data Protection Law. THYNKR may suspend the affected processing until the parties resolve the issue.
3.5 Confidentiality
THYNKR will ensure that personnel authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality.
3.6 Security
Taking into account the state of the art, implementation costs, nature, scope, context and purposes of processing, and the risk to individuals, THYNKR will maintain appropriate technical and organisational measures under Article 32 or equivalent applicable requirements.
Measures may include, as appropriate:
- encryption in transit;
- encryption at rest where appropriate;
- access control and least privilege;
- authentication controls;
- logical tenant separation;
- secure development practices;
- logging and monitoring;
- backup and restoration procedures;
- vulnerability and patch management;
- incident-response procedures;
- resilience and recovery controls;
- personnel confidentiality obligations; and
- periodic review of security effectiveness.
The Customer acknowledges that security measures may evolve as technology and threats change, provided THYNKR does not materially reduce the overall protection of Customer Personal Data.
3.7 Subprocessors
The Customer grants THYNKR general written authorisation to engage subprocessors necessary to provide the Services.
THYNKR will:
- maintain information about material subprocessors;
- impose written data-protection obligations providing a level of protection appropriate to the processing and consistent with applicable Article 28 requirements;
- remain responsible to the Customer for performance of the subprocessor's applicable data-protection obligations to the extent required by law; and
- provide notice of a new material subprocessor through the published subprocessor page, account notification, email or another reasonable mechanism.
The Customer may object to a new subprocessor on reasonable data-protection grounds by notifying THYNKR within 14 days of receiving notice.
The parties will work in good faith to address a valid objection. If no commercially reasonable solution is available, either party may terminate the materially affected Service without penalty for the unused prepaid period relating to that Service.
An objection does not create a right to dictate THYNKR's technology architecture or require THYNKR to provide a materially different service at no additional cost.
3.8 Data Subject Requests
Taking into account the nature of the processing, THYNKR will provide reasonable assistance to enable the Customer to respond to requests from Data Subjects exercising rights under applicable Data Protection Law.
If THYNKR receives a request relating to Customer Personal Data for which the Customer is Controller, THYNKR may direct the Data Subject to the Customer unless law requires THYNKR to respond directly.
THYNKR will not independently fulfil a Controller's Data Subject request except on documented instruction or where legally required.
3.9 Assistance With Compliance
Taking into account the nature of processing and information available to THYNKR, THYNKR will provide reasonable assistance with:
- security obligations;
- Personal Data breach assessment and notification;
- data-protection impact assessments;
- prior consultation with regulators where required; and
- other obligations under Articles 32–36 or equivalent provisions.
Where assistance goes materially beyond standard product functionality or information reasonably available from THYNKR's compliance materials, THYNKR may charge reasonable professional-services fees where legally permitted and agreed in advance.
3.10 Personal Data Breaches
THYNKR will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
The notification will provide information reasonably available to THYNKR, which may include:
- the nature of the incident;
- affected data or individuals where known;
- likely consequences where known;
- measures taken or proposed; and
- a contact point for further information.
Information may be provided in phases as investigation continues.
Notification of an incident is not an admission of fault or liability.
The Customer remains responsible for determining whether it must notify a regulator or affected Data Subjects unless applicable law provides otherwise.
3.11 Deletion and Return
Upon termination or expiry of the affected Service, THYNKR will, at the Customer's choice and subject to available product functionality, return or delete Customer Personal Data within a reasonable period, unless:
- applicable law requires retention;
- the data is contained in secure backups that cannot reasonably be isolated immediately; or
- retention is required for establishment, exercise or defence of legal claims.
Data retained in backup systems will remain protected and will be deleted or overwritten according to ordinary secure backup-retention cycles.
3.12 Audits and Information Rights
THYNKR will make available information reasonably necessary to demonstrate compliance with applicable Article 28 obligations.
Where appropriate, THYNKR may satisfy audit requests by providing current third-party audit reports, certifications, security documentation, questionnaires or other evidence.
If additional audit is reasonably required:
- the Customer must provide at least 30 days' written notice unless a regulator or confirmed material incident reasonably requires shorter notice;
- audits must occur during normal business hours;
- audits must not unreasonably disrupt operations;
- the auditor must be independent and bound by confidentiality;
- the audit must avoid access to other customers' data or THYNKR trade secrets beyond what is reasonably required;
- no more than one Customer-requested audit may take place in a twelve-month period unless required by law or following a material breach; and
- the Customer bears its audit costs and THYNKR's reasonable costs of supporting non-routine audits, except where the audit identifies a material breach by THYNKR.
Nothing in this clause limits a regulator's lawful powers.
3.13 International Transfers
THYNKR will not make a restricted transfer of Customer Personal Data unless an applicable lawful transfer mechanism is in place.
Where required, the parties will incorporate or execute an appropriate mechanism, which may include:
- the UK International Data Transfer Agreement;
- the UK Addendum to EU Standard Contractual Clauses;
- applicable Standard Contractual Clauses;
- adequacy arrangements; or
- another legally recognised safeguard.
The parties will cooperate with any required transfer-risk, data-protection or supplementary-measures assessment.
If a transfer mechanism is amended, replaced or invalidated, the parties will cooperate in good faith to implement a lawful replacement.
3.14 Government Requests
Unless prohibited by law, THYNKR will seek to direct a governmental request for Customer Personal Data to the Customer where appropriate.
Where THYNKR must respond directly, it will disclose only information legally required and may challenge an overbroad or unlawful demand where reasonable and lawful.
3.15 Controller Obligations
The Customer warrants that:
- it has a lawful basis for processing Customer Personal Data;
- it provides required privacy information;
- it has obtained required consents where consent is relied upon;
- its instructions comply with Data Protection Law;
- it will not submit Personal Data that the Services are not designed to process without prior agreement;
- it will use appropriate account-security controls; and
- it will respond to Data Subject requests and regulator communications for which it is Controller.
3.16 Liability
Liability under this DPA is subject to the liability provisions of the Agreement, except to the extent applicable Data Protection Law prohibits contractual limitation.
Nothing in this DPA relieves either party of direct statutory obligations imposed on it by Data Protection Law.
3.17 Priority
If this DPA conflicts with the Agreement concerning processing of Customer Personal Data, this DPA takes priority for that subject matter.
Where mandatory transfer clauses apply, those clauses take priority to the extent required by law.
3.18 Changes in Data Protection Law
The parties will cooperate in good faith to amend this DPA where reasonably necessary to comply with a material change in applicable Data Protection Law or binding regulatory requirements.