Data Processing & Service Level Agreement
This is the agreement under which Hendra One processes personal data for its client venue companies, as required by Article 28 UK GDPR, together with the service levels we work to. It forms part of every client's Service agreement. The signable Word version is here: Data Processing & Service Level Agreement (.docx).
Made between [Client company legal name] (the "Client", acting as Controller) and Hendra Group Limited, trading as Hendra One (acting as Processor), covering the hospitality management platform: bookings, guest CRM, marketing, pre-orders, deposits, compliance and team tools (the "Service").
1. Definitions
"UK GDPR", "personal data", "processing", "data subject", "personal data breach" and related terms have the meanings given in the Data Protection Act 2018 and the UK GDPR. "Guest Data" means personal data of the Client's guests and staff processed in the Service, as described in Annex A.
2. Roles and scope
The Client is the Controller of Guest Data; Hendra One is its Processor. Hendra One processes Guest Data only on the Client's documented instructions, as set out in this Agreement and as given through the Service's configuration, unless required to do otherwise by law (in which case Hendra One will inform the Client unless the law prevents it).
3. Duration
This Agreement applies for as long as Hendra One processes Guest Data for the Client, and survives termination of the Service until all Guest Data is deleted or returned under section 10.
4. Hendra One's obligations
- Confidentiality: access to Guest Data is limited to personnel who need it to deliver the Service and who are bound by confidentiality obligations.
- Security: Hendra One implements and maintains the technical and organisational measures in Annex B (Article 32 UK GDPR).
- Assistance: Hendra One assists the Client with data subject requests (section 6), security, breach notification and data protection impact assessments, taking into account the nature of the processing.
- Records: Hendra One maintains records of processing and an audit trail of privacy-relevant actions within the Service.
- Instructions: Hendra One will inform the Client if, in its opinion, an instruction infringes UK data protection law.
5. Sub-processors
The Client gives general written authorisation for the sub-processors listed in Annex C. Hendra One will give at least 30 days' notice of any intended addition or replacement, during which the Client may object on reasonable data-protection grounds. Hendra One imposes data protection obligations on each sub-processor equivalent to those in this Agreement and remains liable for their performance.
6. Data subject rights
The Service provides the Client with built-in tools to honour data subject rights without engineering work:
- Subject access / portability: a one-click export assembling the guest's profile, bookings, feedback, guest-care records and vouchers in a structured, machine-readable format.
- Erasure: a one-click erasure that deletes the guest's profile, anonymises their bookings, feedback and guest-care records, removes waitlist and pre-order entries, and deletes any stored card from Stripe. Erasures require step-up two-factor authentication and are recorded in the audit trail.
- Objection / consent: marketing is opt-in only; every marketing, feedback and review email carries a signed unsubscribe link that takes effect immediately across all such emails.
Where a data subject contacts Hendra One directly, Hendra One will refer the request to the Client without undue delay.
7. Personal data breach
Hendra One will notify the Client without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Guest Data, and will provide the information reasonably required for the Client to meet its own notification obligations, cooperating fully in the investigation and remediation.
8. International transfers
Guest Data is hosted on Google Cloud infrastructure in the United States, and certain sub-processors process data in the United States (Annex C). Transfers are made under the UK Extension to the EU-US Data Privacy Framework where the sub-processor is certified, and otherwise under the UK International Data Transfer Agreement / Addendum. Hendra One will not transfer Guest Data to any other third country without ensuring an equivalent lawful transfer mechanism.
9. Audit
Hendra One will make available the information reasonably necessary to demonstrate compliance with this Agreement, and will allow and contribute to audits (including inspections) conducted by the Client or its auditor, on at least 14 days' notice, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach.
10. Return and deletion
On termination of the Service, Hendra One will, at the Client's choice, return Guest Data in a structured, commonly used, machine-readable format within 30 days, and will delete all Guest Data from the Service within 90 days of termination, except where retention is required by law. Automated retention also applies during the Service: booking records are anonymised after the Client's configured retention window (default 36 months, configurable 12 to 120 months), lapsed guest profiles are deleted on the same schedule, waitlist entries are deleted after the visit date, and stored cards are purged from Stripe within 7 days of the visit.
11. Service levels
Availability. Hendra One targets 99.5% monthly availability of the Service, excluding planned maintenance (notified at least 48 hours in advance and scheduled outside peak trading hours where practicable) and factors outside Hendra One's reasonable control. The Service runs on Google Cloud / Firebase infrastructure with Google's own redundancy and availability commitments beneath it.
Support. Support is available by email during business hours. Target response times:
| Severity | Meaning | Target response |
|---|---|---|
| P1 (Critical) | The Service is unavailable or guests cannot book at any of the Client's sites | 10 hours |
| P2 (Major) | A core feature (bookings, emails, deposits) is materially impaired | 1 business day |
| P3 (Minor) | A non-core feature is impaired, or a question / change request | 2 business days |
Data durability. Guest Data is stored in Google Cloud Firestore with multi-replica durability. Backups are taken automatically on a daily schedule (retained 14 days) and a weekly schedule (retained 14 weeks), and point-in-time recovery is enabled with a 7-day window, allowing the database to be restored to any moment within that window. Deletion protection is enabled on the production database. Scheduled platform jobs (booking emails, retention and hygiene sweeps) run automatically and are monitored.
12. Liability
Each party's liability under this Agreement is subject to the limitations and exclusions of liability in the main Service agreement. Nothing in this Agreement limits either party's liability where it cannot lawfully be limited.
13. General
This Agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. If there is a conflict between this Agreement and the main Service agreement regarding the processing of personal data, this Agreement prevails.
Annex A: Processing particulars
| Subject matter | Operation of the Hendra One hospitality platform for the Client's venues: bookings, waitlist, pre-orders, guest CRM and marketing, feedback and reviews, deposits and no-show protection, compliance and team management. |
|---|---|
| Duration | The term of the Service agreement, plus the wind-down period in section 10. |
| Nature and purpose | Collection, storage, organisation, use, disclosure by transmission (emails, payment processing) and erasure of Guest Data to take and manage bookings, communicate with guests, process payments and deposits, and run the Client's venues. |
| Data subjects | The Client's guests (diners, waitlist and pre-order party members); the Client's staff and contractors using or referenced in the Service. |
| Categories of data | Guests: name, phone, email, booking details, special requests, menu choices, visit history, optional date of birth, marketing preferences, feedback, guest-care notes, card token metadata (card numbers are held by Stripe only). Staff: account details, roles and permissions, holidays, training, checklists, and (where the Client uses the compliance module) accident records. |
| Special category data | Incidental only: dietary or allergy information volunteered in requests or menu choices; health information in accident records where the Client uses the compliance module (processed under the Client's legal obligations in employment and health & safety law). |
Annex B: Technical and organisational measures
- Encryption in transit (TLS) and at rest (Google Cloud managed encryption).
- Role-based access control enforced server-side: a per-site permission grid governs every staff capability; sensitive guest fields (date of birth, private notes) require elevated permission.
- Two-factor authentication for administrative accounts, with step-up re-authentication for irreversible actions (such as erasure); forced password change on temporary credentials, which expire if unused.
- Session control: sessions end automatically after a period of inactivity, and deactivating an account, resetting its password or withdrawing its access revokes any session already running on it rather than waiting for it to lapse.
- Tenant isolation, each client company's data is segregated by server-enforced security rules; cross-tenant access is denied by default.
- Abuse protection on guest-facing endpoints: Google reCAPTCHA / App Check attestation and per-endpoint rate limiting.
- Card data never touches the platform: capture, storage and charging are performed by Stripe (PCI-DSS Level 1); the platform stores only a token reference, and tokens are purged after the visit.
- Signed (HMAC) unsubscribe links so consent cannot be altered by third parties; consent changes are server-controlled and audited.
- Comprehensive audit trail of privacy-relevant actions (exports, erasures, consent changes, credential reveals).
- Automated data minimisation: nightly retention sweeps anonymise expired bookings, delete lapsed profiles, stale waitlist entries, expired verification codes and rate-limit counters, and purge stored cards.
- Self-hosted assets on guest pages: no third-party CDNs (such as font services) receive guest IP addresses.
- Documented breach response and sub-processor management.
Annex C: Approved sub-processors
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Google LLC (Google Cloud / Firebase) | Hosting, database, authentication, serverless compute, bot protection (reCAPTCHA) | United States | UK Extension to the EU-US Data Privacy Framework |
| Resend, Inc. | Transactional and marketing email delivery; delivery / open / click reporting | United States | UK Extension to the EU-US DPF / UK Addendum (SCCs) |
| Stripe Payments UK Ltd / Stripe, Inc. | Payments, deposits, card storage and charging for no-show protection | United Kingdom / United States | UK Extension to the EU-US Data Privacy Framework |
| Anthropic, PBC | Optional AI drafting of marketing email layouts. Receives venue branding and the staff-written brief only; no Guest Data is sent. | United States | UK Addendum (SCCs), no Guest Data transferred |
Version dated 23 July 2026. To execute this Agreement, download the Word version, complete the party details and signature blocks, and return a signed copy.