Data Processing Addendum
Last updated: 5 October 2026
This Data Processing Addendum (DPA) forms part of the Terms of Service between you (the venue operating an Orders Up account) and Important Small Things Limited (company number 16431951), registered at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. You accept it when you accept the Terms; there is nothing to sign or return.
It applies where we process personal data about your guests on your behalf. For that data you are the controller and we are your processor. It does not apply to your own account data, for which we are the controller — see our Privacy Policy.
Data protection law means the UK GDPR and the Data Protection Act 2018, and the EU GDPR where it applies to your use of the Service. Terms such as controller, processor, personal data, processing, personal data breach and data subject have the meanings given in that law. Where this DPA conflicts with the rest of the Terms on a data protection question, this DPA prevails.
1. What we process, and why
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex A. The processing lasts for as long as your account is open, plus the retention periods described in section 8.
2. We act only on your instructions
We process guest personal data only on your documented instructions, including on transfers outside the UK. Your instructions are: the Terms, this DPA, the settings and actions available to you in the Service, and any further written instruction we agree to. We will not process guest data for our own purposes, and we do not sell it, use it to build profiles, use it for advertising, or use it to train machine-learning models.
If we are required by law to process guest data beyond your instructions, we will tell you before doing so unless the law forbids it. If we believe an instruction of yours breaches data protection law, we will tell you and may pause that processing until it is resolved.
3. Confidentiality
Everyone we authorise to process guest data is bound by a duty of confidentiality and only gets access where they need it to run or support the Service. Access to production data is limited to the people who operate Orders Up.
4. Security
We implement appropriate technical and organisational measures to protect guest data, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as required by Article 32. The measures in place are listed in Annex B. We may change them as the Service develops, but not in a way that materially lowers the level of protection.
5. Sub-processors
You give us general written authorisation to engage sub-processors. Those currently engaged for guest data are listed in Annex C. Before we add or replace one, we will give you at least 30 days' notice by email to your account address.
If you reasonably object to a new sub-processor on data protection grounds within that notice period, tell us at support@ordersup.app and we will work with you to find a solution. If we cannot, you may cancel your subscription and we will refund the unused part of any prepaid period. We impose data protection obligations on every sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
6. Helping you answer guests' requests
Guests exercise their rights against you, as controller. You can handle these yourself, without waiting on us: Account → Your data → Export my data downloads everything your venue holds as a structured JSON file, which covers access and portability requests, and the order queue lets you delete an order or clear the queue, which erases that guest's data from the Service. If you need help with an unusual request, email us at support@ordersup.app and we will assist at no charge for reasonable volumes. If a guest contacts us directly about your venue's data, we will not respond on your behalf beyond telling them to contact you, and we will pass the request on.
7. Breaches, assessments and prior consultation
If we become aware of a personal data breach affecting guest data, we will notify you without undue delay and in any event within 72 hours of becoming aware, by email to your account address. In practice we aim to reach you much sooner, because your own deadline for deciding whether to report to the ICO runs from the point we tell you. The notification will describe the nature of the breach, the likely consequences, the measures we have taken or propose to take, and a contact point — as far as we know them at the time, with updates as we learn more. Reporting the breach to the ICO or to affected guests is your decision as controller; we will give you the information you need to make it.
We will also provide reasonable assistance with your data protection impact assessments and any prior consultation with the ICO, so far as they relate to our processing and the information is available to us.
8. Deletion and return
You can delete guest data at any time from the order queue. On the ending of your account, guest data follows the retention schedule in the Terms and the Privacy Policy: a lapsed venue's data is kept for 14 days so you can reactivate, then permanently deleted by an automated job. While your account is active, completed orders are deleted 90 days after completion and your venue activity log after 180 days.
To have your data returned rather than simply deleted, use Account → Your data → Export my data at any time while your account exists. It produces a structured, machine-readable JSON file covering your menu, settings, orders, team code names and activity log. Take that export before you cancel — after the deletion points above we do not keep copies, except where UK law requires us to retain something, in which case we keep only that and only for as long as required. Point-in-time backups held by our hosting provider expire on their own 30-day cycle (see Annex B).
9. Information and audits
We will make available the information you reasonably need to demonstrate that we meet our obligations under Article 28, and allow and contribute to audits. In the first instance we will answer your questions in writing and provide this DPA, our security measures and our sub-processors' own compliance documentation, which we expect will satisfy most requests.
If that is not enough, you may audit us once in any 12-month period (or more often if a regulator requires it, or after a personal data breach affecting your guests) on 30 days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality. You bear your own costs and our reasonable costs.
10. International transfers
Guest data is stored and processed on Cloudflare's infrastructure, which operates globally. Any transfer outside the UK is covered by appropriate safeguards under Article 46 — Cloudflare's Data Processing Addendum incorporates the UK International Data Transfer Addendum and the EU Standard Contractual Clauses. You instruct us to make those transfers as part of providing the Service.
11. Your obligations
You confirm that you have a lawful basis for collecting your guests' personal data, that you have given your guests the information data protection law requires (we display a short notice at the point a guest enters their name, but your own privacy notice remains your responsibility), and that your instructions to us comply with data protection law. You are responsible for what you and your staff do with the data inside the Service, including who you give team access codes to.
Guests can type free text into an order note. You should not encourage, and we ask that you do not collect, special category data (such as health or allergy information tied to an identifiable person) through that field. If you do, you are the controller for it and this DPA applies to it as guest data.
12. Term and liability
This DPA takes effect when you accept the Terms and lasts until we no longer process guest data on your behalf. The liability limits and exclusions in the Terms apply to this DPA. Nothing in it limits either party's liability to a data subject or a regulator under data protection law. It is governed by the law of England and Wales.
Annex A — Details of the processing
- Subject matter: providing the Orders Up ordering and queue-management service to your venue.
- Duration: the term of your subscription, plus the retention periods in section 8.
- Nature of the processing: collection, storage, structuring, display to your staff, and erasure — by automated means.
- Purpose: letting your guests place orders from their own phones and letting your staff see, work and complete those orders; keeping a short activity record of what your staff changed.
- Types of personal data: the name a guest types (which may be a first name or a nickname), a table or area label, the items ordered and any free-text note, and the times the order was placed and completed. Guests are not asked for an email address, phone number, address, date of birth or payment details, and no payment is taken through the Service.
- Categories of data subject: your guests. Your staff also appear in the venue activity log by the team code name you give them.
- Special category data: none is requested or required. See section 11.
Annex B — Technical and organisational measures
- Separation of venues. Every database query is scoped to a single venue, so one venue's data cannot be read or changed from another venue's account. This is a standing engineering rule, checked at code-review time.
- Encryption in transit. HTTPS everywhere, HTTP Strict Transport Security, and a Content Security Policy set at the edge. Encryption at rest is provided by Cloudflare for the database and file storage.
- Authentication. Owner passwords and staff team codes are stored only as salted PBKDF2-HMAC-SHA256 hashes with a unique per-record salt and a 600,000-iteration work factor (the current OWASP recommendation), never in plain text. Session tokens are HMAC-signed, carry a session version so a password reset or account lock ends live sessions immediately, and guests must enter the venue's access code to reach the ordering page.
- Abuse resistance. Rate limiting on credential, signup and lookup endpoints; temporary lockout after repeated failed logins; server-side validation of everything an order submits.
- Accountability. A per-venue activity log records who changed what, visible to you in your dashboard. Operator actions on our side are recorded separately.
- Data minimisation and deletion. Only the fields in Annex A are collected. An automated hourly job enforces the retention periods in section 8 without anyone having to remember.
- Access control. Production credentials are held as platform secrets, never in source control, and are available only to the people who operate the Service.
- Resilience. Cloudflare's database point-in-time recovery covers the previous 30 days, and explicit snapshots are taken before destructive maintenance.
- Logging. Error logs record the request path, venue and a request identifier rather than guest details, and are deleted after 90 days.
Annex C — Sub-processors
One sub-processor receives guest data: Cloudflare, Inc. (One Front Street, San Francisco, CA 94105, USA) — hosting, database, file storage, DNS and TLS for the whole Service; global infrastructure; covered by the Cloudflare Customer DPA including the UK International Data Transfer Addendum and EU Standard Contractual Clauses.
Our payment provider (Polar Software Inc.) and our email provider (Resend, Inc.) are named in the Privacy Policy because they process your account and billing data, for which we are the controller. Neither receives guest data, so neither is a sub-processor under this DPA.
13. Contact
Data protection questions, sub-processor objections and audit requests: support@ordersup.app. We are registered with the UK Information Commissioner's Office under reference ZC005879.
