This Data Processing Agreement (“DPA”) forms part of the Terms of Service between CartaGrid Limited and the Subscriber. By using the CartaGrid platform, the Subscriber agrees to the terms of this DPA.

1. Definitions

2. Scope and Purpose

This DPA governs the processing of personal data by CartaGrid Limited in its capacity as a data processor on behalf of the Subscriber in connection with the CartaGrid allergen compliance platform.

CartaGrid processes personal data solely to provide the services described in the Terms of Service and for no other purpose without the prior written consent of the Controller.

3. Details of Processing

ElementDetail
Subject matterAllergen compliance, menu management, HACCP records, and related food safety services
DurationFor the term of the subscription and for 7 years thereafter, in line with UK food safety audit requirements
Nature of processingStorage, retrieval, organisation, structuring, disclosure, and deletion of personal data
PurposeDelivery of allergen compliance platform services; regulatory audit trail maintenance; real-time operational alerting to designated venue staff
Categories of dataAccount data (name, email, job role); operational data (menu items, allergen records, HACCP records); staff training and certification data; usage and audit data; payment data; customer allergen declarations (special category health data under UK GDPR Article 9)
Categories of data subjectsSubscriber personnel (venue managers, kitchen staff, front-of-house staff); end customers submitting allergen declarations

4. Processor Obligations

CartaGrid Limited shall, as data processor:

5. Sub-processors

The Controller gives CartaGrid Limited general written authorisation to engage sub-processors to process personal data on the Controller's behalf, in accordance with UK GDPR Article 28(2).

CartaGrid shall:

The Controller may object to a new sub-processor on reasonable data protection grounds within 14 days of notification. If the parties cannot resolve the objection, CartaGrid will, as its sole remedy, either not appoint the sub-processor for the Controller's account or permit the Controller to terminate the affected service without penalty.

Real-time operational alerts (e.g. CCP breaches, allergen declarations, staff training expiry, dish change approvals) are routed via a staff alerting and notification sub-processor to designated venue staff channels. The Controller is responsible for ensuring access to those channels is restricted to authorised personnel at their venue.

6. Security Measures

CartaGrid implements the following technical and organisational measures to protect personal data:

7. Personal Data Breaches

TimeframeAction
Within 24 hoursInitial notification to Controller confirming that a breach has occurred or is suspected, with available preliminary details
Within 48 hoursConfirmation of the nature of the breach, categories and approximate number of data subjects and records affected
Within 72 hoursFull incident report including likely consequences, measures taken or proposed to address the breach
Within 7 daysCompleted post-incident review and remediation report

The Controller is responsible for determining whether to notify the Information Commissioner's Office (ICO) and affected data subjects in accordance with UK GDPR Articles 33 and 34. CartaGrid will provide reasonable assistance to support such notifications.

8. Data Subject Rights

CartaGrid shall provide reasonable assistance to the Controller in fulfilling requests from data subjects to exercise their rights under UK GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. Where CartaGrid receives a direct request from a data subject, it shall promptly forward the request to the Controller without acting upon it unless instructed to do so.

9. Data Transfers

Some personal data processed by CartaGrid is transferred to sub-processors located outside the United Kingdom. All such transfers are conducted under appropriate safeguards, including Standard Contractual Clauses approved by the ICO (UK Addendum to EU SCCs) where applicable. Transfer mechanisms for each sub-processor are listed at cartagrid.com/sub-processors.

10. Audit Rights

The Controller may, on reasonable prior written notice of not less than 30 days and no more than once per calendar year, audit CartaGrid's compliance with this DPA, either by requesting relevant documentation or by appointing a mutually agreed third-party auditor. CartaGrid shall provide all reasonable assistance and access necessary for such audit. Any audit shall be conducted during business hours and at the Controller's expense.

11. Term and Termination

This DPA shall remain in force for the duration of the subscription and shall terminate automatically on the expiry or termination of the Terms of Service. On termination, CartaGrid shall, at the Controller's election, delete or return all personal data, unless retention is required by applicable law. Confirmation of deletion will be provided in writing within 30 days of termination.

12. Breach Notification Procedure

Detection and Containment. On detection of a suspected breach, CartaGrid's designated data protection lead is notified immediately. Preliminary containment measures are implemented within two hours of detection, including suspension of affected access credentials and isolation of affected systems where necessary.

Assessment. CartaGrid assesses the likely scope, nature, and severity of the breach, including the categories and approximate volume of personal data and data subjects affected, and the likely consequences for those data subjects.

Notification. The Controller is notified in accordance with the timeline set out in Clause 7 of this DPA, sent to the primary contact email address registered to the Subscriber's account. CartaGrid will provide a single designated point of contact for the duration of the incident.

Remediation and Review. Following containment, CartaGrid conducts a full post-incident review and implements remediation measures to prevent recurrence. A written remediation report is provided to the Controller within 7 days of the incident being resolved.

13. Governing Law

This DPA is governed by the laws of England and Wales. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.

14. Contact

CartaGrid Limited
14 Clifton Moor Business Village, James Nicholson Link, York YO30 4XG
operations@cartagrid.com
cartagrid.com