Data Processing Agreement
Updated
This data processing agreement applies between you and us. You are the restaurant that uses Portano. Portano is a sole proprietorship (eenmanszaak) registered with the Dutch Chamber of Commerce under number 42034499, with its registered address at Amperestraat 2d, 3112 MC Schiedam, the Netherlands. That address is the one held in the public registers and is for post. We do not receive visitors there. If you have a question about this agreement, mail hello@portano.nl. We reply within one working day.
You decide what happens to your guests’ data. We carry that out. In the words of the GDPR, you are the controller and we are the processor. This agreement sets out what article 28 GDPR asks of us both.
This agreement belongs with the Terms and Conditions and starts at the same moment they do. You do not have to sign anything separately for it. It runs for as long as we process personal data for you.
If this agreement contradicts the Terms and Conditions, what is written here applies to personal data. For everything else the Terms and Conditions continue to apply.
1 Definitions
The GDPR uses words of its own. We take them over here, so there is no doubt about what they mean.
- Personal data
- Any information about an identified or identifiable natural person. A guest’s name, email address, phone number and delivery address are personal data.
- Processing
- Everything you can do with personal data: collecting, recording, storing, retrieving, displaying, using, sending on and erasing.
- Data subject
- The person the data is about. In this agreement that is a guest of your restaurant.
- Controller
- The one who decides what personal data is processed for and how. That is you.
- Processor
- The one who processes personal data on the instructions of the controller. That is us.
- Sub-processor
- A party we bring in that processes your guests’ personal data while doing so. Annex B sets them out.
- Personal data breach
- A breach of security that leads to personal data being lost, destroyed or altered, or to someone gaining access to it or seeing it without being allowed to.
- GDPR
- Regulation (EU) 2016/679, the General Data Protection Regulation, known in Dutch as the AVG. Where we refer to an article without saying more, we mean an article of that regulation.
2 What this agreement covers, and who is what
3 Our instructions
4 Confidentiality
5 Security
6 Sub-processors
7 Transfers outside the EEA
8 Help with requests from guests
9 Help with a DPIA and with consulting the supervisory authority
10 Personal data breaches
11 Audits and information
12 Return and erasure
13 Liability
14 Term and termination
15 Changes
16 Governing law and disputes
17 Annex A: the processing
This annex describes what we process for you, as article 28(3) GDPR requires.
| Subject | What |
|---|---|
| Subject | Processing personal data of your guests, so that your ordering site, your app, your menu, your loyalty, your email and SMS and your kitchen screen work. |
| Nature and purpose | Collecting, recording, storing, retrieving, displaying, sending and erasing. The purpose is: taking orders and showing them in the kitchen, letting the payment run through our payment partner, sending confirmations, keeping loyalty, sending the campaigns you set up, collecting reviews and measuring how your restaurant is doing. |
| Categories of data subjects | Guests who order from you, create an account or sign up for your messages. |
| Categories of personal data | Name, email address and phone number. Delivery address with postcode, house number, street, city and geocoordinates. Date of birth, if a guest gives one themselves for a birthday reward. Order history with prices and notes on the order. Free text a guest types for the kitchen. Allergen tags that travel with an order. Loyalty balance and the overview of the points. Reviews with the comments alongside them. Marketing consent per channel. For email we also record when and where it was given or withdrawn. Push tokens. Consent for statistics. |
| Special categories of personal data | We do not ask for them. Portano has no field for health data and nowhere asks a guest about their health. Two places can still say something about it: the free text a guest types for the kitchen, and the allergen tags that travel with an order. Do not use those fields to record health data about a guest by name. What a guest puts in them themselves, we process only to get their order to them properly. |
| Duration | For as long as this agreement runs. Within that we keep guest data for seven years by default, the period the Dutch tax retention obligation holds for the records behind an order. If you instruct us to use a shorter period, or ask us to erase data sooner, we do that. When the agreement ends, article 12 applies. |
18 Annex B: sub-processors
We bring these parties in to deliver the service. Most of them can process personal data of your guests while doing so. Each of them receives data only for the function it has been brought in for, and only if that function is switched on for your restaurant. Where no guest data reaches a party, the row says so.
| Sub-processor | What for | Where |
|---|---|---|
| Hosting provider: OVH SAS | The servers the service and the database run on, and the nightly backup copy | France |
| Payment service provider | Handling payments from guests, and the payment page the guest pays on | Within the EEA, and outside the EEA under the European Commission’s standard contractual clauses, see article 7 of this agreement |
| Email service | Sending order confirmations and the campaigns you set up | Within the EEA, and outside the EEA under the European Commission’s standard contractual clauses, see article 7 of this agreement |
| SMS service | Sending text messages to guests | Within the EEA, and outside the EEA under the European Commission’s standard contractual clauses, see article 7 of this agreement |
| Push services of Apple and Google | Delivering push messages to a guest’s device | Within the EEA, and outside the EEA under the European Commission’s standard contractual clauses, see article 7 of this agreement |
| Product analytics service | Measuring how the service is used | European servers |
| Error monitoring service | Tracing and repairing failures and errors | Within the EEA, and outside the EEA under the European Commission’s standard contractual clauses, see article 7 of this agreement |
| Address lookup service of the Kadaster | Turning a postcode and house number into a street, a town and coordinates, so your delivery zones and rates work | The Netherlands |
| Object storage service for images | Keeping and showing the photographs you upload yourself. No guest data reaches it | Within the EEA, and outside the EEA under the European Commission’s standard contractual clauses, see article 7 of this agreement |
| Map tile service for the delivery area | The map tiles in the portal on which you draw your delivery area. No map appears on a page a guest sees, and no guest data reaches it | Within the EEA, and outside the EEA under the European Commission’s standard contractual clauses, see article 7 of this agreement |
If we add a sub-processor or replace one, article 6 of this agreement applies. You then hear about it at least thirty days beforehand. This annex belongs with the version of this agreement on our site, with the date on which it was last updated. If you want the trading name and the place of establishment of a party in this list, ask and you will get them.
19 Annex C: security measures
These are the measures we take today.
- Only people who need that access to do their work have access to personal data. If someone from Portano looks in on your restaurant through the portal, we record who did so, when and for which restaurant.
- All traffic between your browser, your app, the kitchen screen and our servers is encrypted along the way.
- Card details never reach us. The guest pays on our payment partner’s own payment page. We do not see or keep card numbers.
- Guests sign in with a one-time code that is sent each time. We keep no guest passwords.
- Tokens that grant access are stored hashed, and so cannot be read.
- Account numbers for payouts are shown masked on screen.
- The data sits on rented servers in the European Union.
- All restaurants sit in one database. Your restaurant’s data carries an identifier of its own, and the application makes sure a request reaches only the data of its own restaurant.
- Every night we make a backup copy of the database.
And this is what is not there. Portano has no ISO or SOC certification. No external security audit has been carried out and no penetration test has been done. Administrative access to the server and to the database itself is not separately logged, so it leaves no trace. The backup copies sit on the same infrastructure as the database, not in another location, and that we can restore them has not been shown in a test. We claim no encryption of the data as it sits on the disk, and the separation between restaurants sits in the application, not in the database itself. We write this down because you need to know it to make your own judgement. If it changes, this annex changes with it.