Legal · Updated July 2026
Data Processing Addendum
This addendum forms part of the Reserved Terms of Service and applies whenever we process personal data on your behalf. It reflects UK GDPR and EU GDPR requirements; a countersigned PDF is available on request for enterprise contracts.
1. Definitions
"Controller", "Processor", "Personal Data", "Data Subject", "Processing" and "Sub-processor" have the meanings given in UK GDPR. "Customer" means the venue subscribing to Reserved. "Reserved" means Reserved Technologies Ltd.
2. Roles
For guest data the Customer enters into Reserved, the Customer is the Controller and Reserved is the Processor. For Customer account and billing data, Reserved is a Controller and its Privacy Policy applies.
3. Scope and instructions
Reserved processes Personal Data only on the Customer's documented instructions, which are the Terms, this DPA, and reasonable configuration choices made in the product. Reserved will notify the Customer if an instruction, in its opinion, infringes applicable data protection law.
4. Nature and purpose of processing
- Nature: storage, access control, transmission, analysis, and deletion of Personal Data via a hosted SaaS platform.
- Purpose: to provide the Reserved service — reservations, guest CRM, marketing, analytics, integrations.
- Duration: for the term of the subscription plus the retention periods in the Privacy Policy.
- Data subjects: guests of the Customer's venue, and the Customer's staff users.
- Categories: identity data (name, email, phone), booking history, dietary/allergy notes, tags, spend history, communications metadata.
5. Confidentiality
Reserved ensures personnel authorised to process Personal Data are bound by written confidentiality obligations and receive appropriate data-protection training.
6. Security
Reserved implements appropriate technical and organisational measures, including: TLS 1.2+ in transit, AES-256 at rest, row-level security in the database, role-based access, least-privilege administrative access, logged and reviewed production access, secure SDLC, dependency and vulnerability scanning, and annual penetration testing. Current measures are summarised on the Trust page.
7. Sub-processors
The Customer authorises the sub-processors listed on the Trust page. Reserved will notify the Customer by email at least 30 days before adding a new sub-processor. The Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected service without penalty.
8. International transfers
Guest data is stored in the United Kingdom. Where a sub-processor operates in the EEA, transfers rely on the UK Adequacy Regulations 2021 and, where applicable, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
9. Assistance to the Customer
Reserved will assist the Customer, taking into account the nature of processing, in: (a) responding to Data Subject Rights requests via product features and, where necessary, technical assistance; (b) meeting security, breach notification, DPIA, and prior-consultation obligations.
10. Personal-data breaches
Reserved will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any confirmed Personal Data Breach affecting the Customer's data, together with information reasonably available to help the Customer meet its own notification obligations.
11. Return and deletion
On termination, and on request during the term, Reserved will make Personal Data available for export in CSV format. 30 days after termination, Reserved will delete Personal Data from production systems; backups are overwritten within a further 60 days.
12. Audit
Reserved will make available all information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior notice, and subject to confidentiality, the Customer may audit Reserved's processing no more than once every 12 months (or as required by a supervisory authority), by reviewing Reserved's most recent third-party audit reports and responses to a written questionnaire.
13. Liability
Each party's liability under this DPA is subject to the limits in the Terms of Service. Nothing in this DPA excludes liability where it cannot be excluded under applicable law.
14. Order of precedence
In case of conflict between this DPA and the Terms of Service, this DPA prevails for matters of personal data processing.
15. Signed copy
Enterprise customers can request a countersigned PDF at privacy@reserved.app. The version linked from this URL is the current DPA for all other customers.
See also our Privacy Policy and Terms.