DPA
This Data Processing Agreement (“Agreement”) forms part of the Terms & Conditions and applies to the processing of personal data by RMS France in the context of providing its Restaurant Management System services.
This Agreement is established in accordance with Article 28 of the General Data Protection Regulation (GDPR).
1. Parties
Data Controller:
The customer (restaurant, business, or organization) using RMS France services.
The customer (restaurant, business, or organization) using RMS France services.
2. Purpose of Processing
RMS France processes personal data solely for the purpose of providing, maintaining, and improving its Restaurant Management System platform, including but not limited to:
· Order management
· Reservation management
· POS operations
· Customer management
· Staff and delivery management
· Reporting and analytics
RMS France does not process personal data for any purpose other than those instructed by the Data Controller.
3. Categories of Personal Data
Depending on the services used, the following categories of personal data may be processed:
· Customer identification data (name, phone number, email)
· Order and reservation data
· Payment references (no storage of full card details)
· Staff data (name, role, schedules, permissions)
· Delivery-related information
· Technical data (IP address, device logs, usage logs)
4. Categories of Data Subjects
· Restaurant customers
· Restaurant staff and delivery personnel
· Authorized users and administrators
5. Processing Instructions
RMS France processes personal data only:
· On documented instructions from the Data Controller
· In compliance with applicable EU and French data protection laws
If RMS France believes an instruction violates GDPR, it will inform the Data Controller without undue delay.
6. Confidentiality
RMS France ensures that all persons authorized to process personal data:
· Are bound by confidentiality obligations
· Receive appropriate data protection training
7. Security Measures
RMS France implements appropriate technical and organizational measures to protect personal data, including:
· Secure authentication and access controls
· Role-based permissions
· Encrypted data transmission
· Regular system monitoring
· Backup and recovery mechanisms
These measures are designed to protect data against unauthorized access, loss, or disclosure.
8. Subprocessors
RMS France may engage subprocessors to deliver certain technical services (e.g. hosting, payment processing, SMS services).
RMS France ensures that:
· Subprocessors provide sufficient GDPR-compliant safeguards
· Subprocessors are bound by data protection obligations equivalent to this Agreement
A list of subprocessors may be provided upon request.
9. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), RMS France ensures appropriate safeguards are in place, including:
· EU Standard Contractual Clauses (SCCs), where applicable
10. Data Subject Rights Assistance
RMS France assists the Data Controller in fulfilling GDPR obligations related to:
· Right of access
· Right to rectification
· Right to erasure
· Right to restriction
· Right to data portability
· Right to objection
Requests are handled without undue delay.
11. Data Breach Notification
In the event of a personal data breach, RMS France will:
· Notify the Data Controller without undue delay
· Provide relevant information to support legal obligations under GDPR
12. Data Retention and Deletion
Upon termination of services, RMS France will:
· Delete or return all personal data to the Data Controller
· Retain data only where legally required
13. Audits and Compliance
RMS France makes available all information necessary to demonstrate compliance with this Agreement and GDPR.
Reasonable audits may be conducted by the Data Controller, subject to prior notice and confidentiality obligations.
14. Liability
Each party is responsible for its own compliance with GDPR obligations.
RMS France shall not be held liable for data processing activities carried out by the Data Controller in violation of GDPR.
RMS France shall not be held liable for data processing activities carried out by the Data Controller in violation of GDPR.
15. Governing Law
This Agreement is governed by French law.
Any disputes shall fall under the exclusive jurisdiction of the courts of France.
Any disputes shall fall under the exclusive jurisdiction of the courts of France.
16. Contact
For all data protection matters, contact: