Data processing addendum
Last updated: 2026-08-25 · v2026-08-25
This addendum applies where Pronto Sage processes personal data on behalf of a restaurant that uses ForkPI. It forms part of the Terms of service and, if the two documents conflict about the processing of that data, this addendum prevails.
Authoritative language
This document is published in English. The English text is legally authoritative. Any translation is provided for convenience only.
Roles
For the operational data a restaurant creates while serving its guests, the restaurant is the controller and ForkPI is the processor.
For ForkPI accounts, authentication and platform security, subscription administration and ForkPI's own service telemetry, ForkPI is the controller in its own right. Those are described in the Privacy policy and are outside this addendum.
Subject matter, duration, nature and purpose
- Subject matter and duration
- Providing the ForkPI service under the Terms of service, for as long as the customer's workspace exists plus the post-termination export period stated there.
- Nature and purpose
- Hosting, storing, transmitting and displaying the customer's operational data so the customer can run table service, take and decide orders, coordinate preparation and delivery, manage reservations, and record bills and payment status for a visit.
- Data subjects and data
- The customer's staff and other authorised users; diners at its tables; people who make a reservation. Staff account, role and service-action records; table-visit data including orders, notes and service requests; reservation contact details; uploaded content; and technical identifiers such as session credentials. ForkPI does not require special-category data; a dietary or allergen note entered by a diner is processed as ordinary order content.
Processing on documented instructions
ForkPI processes customer personal data only on the customer's documented instructions, as set out in the Terms of service, this addendum, and the customer's use and configuration of the service. If applicable law requires other processing, ForkPI informs the customer before doing so unless that law prohibits notice.
ForkPI does not sell customer personal data, use it for advertising, or use it to train models. Personnel authorised to process it are bound by confidentiality and have access only where their role requires it.
Security measures
Customer isolation enforced in the database; role-based access control within a workspace; encryption in transit; hashing of passwords and of session, guest and device credentials; encryption at rest of provider credentials and second-factor secrets; security audit logging; off-host backups with tested restoration; and controls that deny security-sensitive, authorisation and financial operations when the required authority cannot be confirmed.
Subprocessors
The customer gives general authorisation for ForkPI to engage subprocessors. ForkPI imposes data-protection obligations on each that are no less protective than this addendum, and remains responsible for their performance.
The current list is available from [email protected]. ForkPI gives notice before adding or replacing a subprocessor, and the customer may object on reasonable data-protection grounds; if the objection cannot be resolved, the customer may terminate the affected part of the service.
Assistance, breach and audit
Where a data subject contacts ForkPI directly about customer personal data, ForkPI refers the request to the customer and assists in responding. ForkPI provides reasonable assistance with data protection impact assessments and prior consultation.
ForkPI notifies the customer without undue delay after becoming aware of a personal data breach affecting customer personal data, with the information reasonably available to it.
ForkPI provides the information reasonably necessary to demonstrate compliance with this addendum. It allows and contributes to audits on reasonable notice, no more than once in any twelve-month period unless a breach has occurred. Audits are subject to confidentiality and must not compromise other customers' data.
Return, deletion and transfers
On termination, the customer may export its data during the period stated in the Terms of service. After that, ForkPI deletes customer personal data from live systems unless retention is required by law. Individual backups are not edited; any copy held in a backup is deleted when that backup expires under its normal schedule and remains subject to this addendum until then.
Where customer personal data is transferred to a country without an adequacy decision, the transfer is made under an appropriate safeguard such as the Standard Contractual Clauses, incorporated by reference and completed consistently with this addendum.
This addendum is governed by the law stated in the Terms of service: the laws of Kazakhstan. Contact: [email protected].