Data Processing Agreement & Sub-processors
Last updated: June 14, 2026
This page describes how SHOPFILES LTD ("Processor") handles personal data on behalf of restaurant customers ("Controller") and lists our sub-processors. It applies in addition to our Privacy Policy and forms part of our Terms of Service. A countersigned DPA is available on request at privacy@tables.menu.
Roles
For data about a restaurant's diners (names on a shared table, orders, voice input), the restaurant is the controller and Tables.Menu is the processor. For account and billing data, Tables.Menu is the controller.
Our commitments as processor
- Process personal data only on documented instructions from the Controller.
- Ensure persons authorised to process data are bound by confidentiality.
- Apply appropriate technical and organisational security measures.
- Assist the Controller with data-subject requests and security obligations.
- Delete or return personal data at the end of the service, subject to legal retention.
- Make available information needed to demonstrate compliance.
Sub-processors
We use the following sub-processors to deliver the service:
- Stripe — payment processing and subscription billing.
- OpenAI — AI menu descriptions, translations, and voice ordering.
- Google, Apple, Facebook — optional social login (only if a user chooses them).
- Hosting provider — server hosting and storage within the EU where possible.
We will give notice of changes to this list so Controllers can object.
International transfers
Where a sub-processor processes data outside the EEA, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
Contact
Data protection enquiries: privacy@tables.menu.