Legal

Data processing addendum

Last updated 13 August 2026

When you log a floor note about a server, or invite a manager, you are collecting personal data about your own people. That makes you the controller of it and us the processor, and data protection law expects the two of us to have that written down. This is that document, and it applies automatically to every member without anything needing to be signed.

On this page

  1. Who does what
  2. What we process for you
  3. Our commitments
  4. Sub processors
  5. Security measures
  6. Breaches
  7. Helping you answer requests
  8. International transfers
  9. Return and deletion
  10. Audits
  11. What we need from you

1. Who does what

For the personal data you enter about your staff and your guests, you are the data controller, because you decide what to collect and why. We are the data processor, acting on your instructions.

For your own account information, our billing records and how we run and improve the product, we are the controller, and that is covered by our privacy policy rather than here.

This addendum forms part of our terms of service. Where the two disagree about the handling of personal data, this document wins.

2. What we process for you

ItemDetail
Subject matterProviding the Reviews to Revenue course and toolkit
DurationFor as long as your account is open, and afterwards until you ask us to delete it
NatureStoring, organising, analysing, displaying and emailing
PurposeReputation tracking, floor notes, team management, guest experience tools and reporting
Categories of peopleYour employees and managers, and guests who appear in public reviews or in entries you make
Categories of dataNames, work email addresses, job roles, observations about work performance, review text and display names, and anything else you choose to enter
Special category dataNone is required, and you should not enter any

Worth being blunt about that last line. Floor notes are for what happened on the floor, so please do not record health information, disciplinary allegations or anything about someone's private life in them. The product is not built to hold that and it would put obligations on both of us that neither of us wants.

3. Our commitments

We will process personal data only on your documented instructions, which for practical purposes means the actions you take in the product and anything you ask us in writing, unless the law requires otherwise, in which case we will tell you before we act unless we are forbidden from doing so.

We will make sure anyone with access is bound by confidentiality.

We will not sell your data, will not use it for our own marketing, and will not use it to train AI models.

We will help you meet your own obligations, including data protection impact assessments and consultations with a regulator, to the extent it is reasonable given what we do.

4. Sub processors

You give us general authorisation to use the sub processors below. If we add or replace one, we will update this page and email members at least 30 days before the change takes effect, and if you object on reasonable data protection grounds you may cancel without penalty.

Sub processorWhat it doesWhere
SupabaseDatabase, authentication and back end functionsUnited States
NetlifyWebsite and portal hostingGlobal network
StripePayments and subscriptionsUnited States and Ireland
ResendSending and receiving emailUnited States
ApifyPublic review and ranking collectionEuropean Union
VimeoCourse video hostingUnited States
OpenAIDrafting replies, reading menus and notesUnited States
AnthropicDrafting replies, reading menus and notesUnited States

Each sub processor is bound by terms that protect the data to a standard at least as high as this one, and we stay responsible to you for what they do.

5. Security measures

6. Breaches

If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within 48 hours of becoming aware, giving you what we know about what happened, who is affected, the likely consequences and what we are doing about it.

Reporting to a regulator is your decision as controller, and we will give you what you need to make it.

7. Helping you answer requests

If one of your staff asks you for a copy of their data, or asks you to delete or correct it, the tools in the product let you find, edit and remove floor notes and team records yourself, which is usually the quickest route.

Where you need more than the product can do, email us and we will help at no charge. If a request comes to us directly from one of your staff, we will not answer it ourselves, we will pass it to you, because it is your call to make.

8. International transfers

Some sub processors are based in the United States, so personal data is transferred outside the United Kingdom and the European Economic Area. Those transfers rely on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, which are incorporated into this addendum by reference.

9. Return and deletion

You can export your data at any time while your account is open. When an account closes we keep the data rather than deleting it automatically, because most people come back and starting again from nothing is a poor way to be treated. Ask us to delete it and we will, other than anything we must keep for legal or accounting reasons and backups, which expire on their own cycle.

Ask us to delete it sooner and we will.

10. Audits

We will give you the information you reasonably need to show that we are meeting these obligations. For most members that means this page and our answers to your questions, and we are happy to complete a security questionnaire if your group requires one.

11. What we need from you

Two things, and they are the ones people most often miss.

First, tell your team that floor notes are being logged, what is recorded and what it is used for. You are the controller, so that duty sits with you, and it takes one line in a team briefing.

Second, make sure you have a lawful basis for what you enter. For observations about work performance that is normally straightforward, but the responsibility for it is yours rather than ours.

If your group needs this signed as a standalone agreement rather than accepted as part of the terms, email [your@email address] and we will send a signable copy.