Data Processing Addendum
Last updated
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Tahlib Private Limited ("Tahlib", "Processor") and the Customer ("Controller"). It applies to Customer Personal Data: personal data within Customer Data that Tahlib processes on the Customer’s behalf.
It is written to meet the requirements for processing contracts under India’s Digital Personal Data Protection Act, 2023, the data protection laws of the UAE, Saudi Arabia, Qatar, Bahrain, Oman and Kuwait, and the EU and UK GDPR, to the extent each applies ("Data Protection Law"). It applies automatically when you accept the Terms; no signature is needed.
On this page
1. Roles and instructions
The Customer is the controller (data fiduciary) and Tahlib is the processor (data processor) of Customer Personal Data. Tahlib processes it only on the Customer’s documented instructions. The Terms, this DPA and the Customer’s use and configuration of the Services are those instructions. Tahlib will tell the Customer if it believes an instruction breaks Data Protection Law, unless the law prevents it.
Tahlib may also process Customer Personal Data where the law requires it to; in that case it will tell the Customer first unless the law forbids it.
The Customer is responsible for the lawfulness of the data it collects and its instructions, including giving notices, obtaining consents (in particular for marketing messages and for face attendance) and answering its data subjects.
2. Details of the processing
| Subject matter and duration | Providing the Services for the term of the Customer’s account, and deletion afterwards as set out below. |
|---|---|
| Nature and purpose | Hosting, storing, organising, displaying, transmitting and deleting data so the Customer can take orders and payments, run its kitchen, deliveries, loyalty, marketing, workforce and reporting. |
| Data subjects | The Customer’s guests, employees and staff, riders, and people who leave reviews of the Customer. |
| Personal data | Guests: name, phone, email, language, addresses, orders, payment records (not card numbers), loyalty, feedback, consent records and, where provided, date of birth, gender, allergens and dietary needs. Employees: name, contact details, role, wage, schedules and time records. Riders: name, contact details, vehicle, optional bank details, delivery records and photos. |
| Sensitive data | Where the Customer uses face attendance: a numerical face template (biometric data), an enrolment photo, clock-in and clock-out photos, liveness results and, if enabled, device location. Allergen and dietary information may reveal health or religious information. |
3. Confidentiality of personnel
Tahlib allows access to Customer Personal Data only to personnel who need it to provide, secure or support the Services, and who are bound by confidentiality obligations.
4. Security
Tahlib implements and maintains appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, including those in the Annex below. Tahlib may update these measures provided it does not reduce the overall level of protection.
5. Sub-processors
The Customer gives general authorisation for Tahlib to engage the sub-processors listed on the Sub-processors page. Tahlib imposes data protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible for their performance.
Tahlib will update that page, and notify Customers who have asked to be notified, at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may cancel the affected Products and receive a refund of prepaid fees for the unused period.
Third-party services the Customer chooses to connect — its payment provider, delivery aggregators, WhatsApp business account and similar — are not Tahlib’s sub-processors. The Customer’s own agreement with them governs that processing.
6. Data subject requests
The Services let the Customer view and correct its guests’ and staff data, anonymise a guest, and erase an employee’s face template. Where a request cannot be handled with these tools — for example a request for a copy of someone’s data — Tahlib will, taking into account the nature of the processing, help the Customer respond to requests to exercise data subject rights. If Tahlib receives a request directly, it will refer the person to the Customer and will not respond itself except to confirm the referral.
7. Personal data breaches
Tahlib will notify the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, so the Customer can meet its own notification deadlines (including the 72-hour deadlines under Indian and other law). The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures taken or proposed. Tahlib will update the Customer as more becomes known and take reasonable steps to contain the breach.
8. Assistance and records
Tahlib will give the Customer reasonable assistance with data protection impact assessments and consultations with authorities relating to the Services, to the extent the Customer cannot do so with information already available to it.
9. International transfers
Tahlib is based in India, hosts production systems in the European Union, and uses sub-processors in other countries as listed. Tahlib transfers Customer Personal Data across borders only in accordance with Data Protection Law. Where the EU or UK GDPR applies to a transfer, the parties agree to the European Commission’s standard contractual clauses (and the UK addendum), which are incorporated by reference, with Tahlib as data importer. Where a GCC law requires a specific transfer mechanism or approval, Tahlib will cooperate with the Customer to put it in place.
10. Return and deletion
During the term the Customer can export or delete data using the Services. When the Customer’s account closes, the Customer may request an export within 30 days. Tahlib then deletes Customer Personal Data within 90 days, except where the law requires it to be kept, and except for backup copies, which are overwritten on their normal cycle and protected until then.
11. Information and audits
Tahlib will make available information reasonably needed to demonstrate compliance with this DPA, on written request to hello@tahlib.app. If that information is not sufficient, or an authority requires it, the Customer may audit Tahlib’s compliance once a year, on at least 30 days’ notice, during business hours, at the Customer’s cost, by an auditor bound by confidentiality, in a way that does not disrupt the Services or expose other customers’ data.
12. Face attendance
Face attendance is optional and off until the Customer enrols an employee. Before enrolling anyone, the Customer must give the employee notice and obtain the explicit consent Data Protection Law requires, and offer a PIN alternative where the law requires one. The Services record which manager confirmed consent and when.
Tahlib uses face templates only to match an employee at clock-in for that Customer, never to identify people across customers, and does not use them for any other purpose. The Customer can erase an employee’s template at any time, and decides how long clock-in photos are kept by purging them from the Services.
13. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not permit it. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails.
14. Annex — security measures
- Encryption of data in transit with TLS.
- Passwords hashed with argon2id; sign-in codes and staff PINs stored only as hashes; payment provider credentials encrypted at rest.
- Each customer’s data separated logically, with every request scoped to the tenant it belongs to.
- Role-based permissions within each account, so the Customer controls which staff can see or change what.
- An audit log of changes made in the dashboard, recording the user, time and IP address.
- Session management with revocable sign-in sessions, and verification of email addresses.
- Rate limits on sign-in, sign-up and one-time-code endpoints to resist automated attacks.
- Production access limited to personnel who need it, with production hosted by providers that maintain recognised security certifications.