01Who We Are and Our Role
This Policy is drafted to meet the requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR. Section 10 applies in addition if you are a resident of a US state whose privacy law applies to us. Our Terms and Conditions govern your use of the Services and contain our data processing terms for restaurant data (Section 9 of the Terms).
- As a data controller
- We are the controller of the personal data of account holders and their representatives, visitors of our websites, people who contact us, and the technical and analytics data described in this Policy that we collect for our own purposes, including on the public menu pages of restaurants that use Tabres.
- As a data processor
- When a restaurant or other business (a “Merchant”) uses the Services to take orders, reservations, or payments, to publish menus, or to manage its staff, the Merchant is the controller of the personal data of its guests and staff (“Merchant Data”), and we process that data only on the Merchant’s behalf and instructions. If you are a guest or a staff member of a Merchant, the Merchant’s own privacy notice applies to that data, and you should direct requests about it to the Merchant. We will assist the Merchant in responding.
- Contact
- Questions and requests about personal data can be sent to [email protected]. Our full contact details are in Section 15.