Data Processing Addendum
Last updated: March 27, 2026
1. Purpose
This Data Processing Addendum (DPA) applies when BellQR processes personal data on behalf of a restaurant customer under applicable data protection laws, including the GDPR.
2. Roles
- Restaurant customer: Controller
- BellQR: Processor
BellQR processes personal data only on documented instructions from the controller, unless otherwise required by law.
3. Processing Details
Processing may include collection, storage, organization, retrieval, and deletion of:
- Guest feedback data submitted through BellQR
- Restaurant account and operational data
- Limited technical usage data needed for security and product operation
4. Security and Confidentiality
BellQR applies appropriate technical and organizational measures to protect personal data, including access controls, encrypted transport, and confidentiality obligations for authorized personnel.
5. Subprocessors and Assistance
BellQR may use subprocessors for infrastructure, analytics, and service delivery under contractual data protection obligations.
BellQR will reasonably assist controllers with data subject requests and security incident handling relevant to BellQR processing.
6. Return and Deletion
On controller request or account termination, BellQR will delete or return personal data within a reasonable timeframe, unless retention is required by law.
7. Contact
For DPA questions or requests, contact: