Data Processing Agreement
The terms on which we process personal data on your behalf, under Article 28 of the UK and EU GDPR. It forms part of our Terms of Service and applies automatically — there is nothing to sign.
Last updated: 26 August 2026
1. Roles and scope
This agreement applies where you use Modus Reservations ("Modus", "we") to process personal data. In that processing you are the controller and we are the processor: you decide what data goes into the platform and why, and we act on your instructions.
Two things fall outside it, and both are covered by our Privacy Policy instead. We are the controller for your own account data — the name and email of the people who sign in, billing records, and how the product is used — because we decide those purposes ourselves. And we are a controller for the security and abuse-prevention logs we keep about the Service as a whole.
This agreement takes effect when you accept the Terms of Service, and lasts as long as we process personal data for you.
2. What we process, and why
| Subject matter | Providing the Modus reservation and hospitality management platform. |
| Duration | For as long as your account is active, plus the retention periods set out in the Privacy Policy. |
| Nature and purpose | Storing, organising, retrieving, transmitting and deleting personal data so that you can take bookings, manage staff, and run your venues. |
| Types of personal data | Guest names, email addresses, phone numbers, booking details, dietary and access notes you record. Staff names, contact details, dates of birth, home addresses, emergency contacts, pay rates, worked hours, leave, and documents you upload. |
| Categories of data subject | Your guests, your staff, and the members of your organisation who use the dashboard. |
| Special category data | Not required by the Service. You may enter it — a dietary or access note about a guest, a right-to-work document about a member of staff — and where you do, you remain responsible for having a lawful basis and an Article 9 condition for it. |
3. Our obligations
We will:
- Process personal data only on your documented instructions, which include your use of the Service and its settings, unless we are required to do otherwise by law — in which case we will tell you first, unless the law forbids it.
- Tell you if, in our opinion, an instruction infringes data protection law.
- Never sell personal data, and never use it to train machine learning models. Where an AI feature is used, the data sent is what is needed to answer that request and nothing more.
- Assist you, taking into account the nature of the processing and the information available to us, in meeting your own obligations under Articles 32 to 36 — security, breach notification, and data protection impact assessments.
4. Confidentiality and staff
Anyone we authorise to process your personal data is bound by a duty of confidence, has access limited to what their role requires, and is made aware of their obligations. Access to production systems requires two-factor authentication.
Support access to a customer's account is recorded in that account's audit log, is time-limited, and is read-only unless a named administrator has authorised otherwise.
5. Security measures
We implement appropriate technical and organisational measures under Article 32. The current measures are described in full on our Security page and include, in summary:
- Encryption in transit (TLS) and at rest.
- Envelope encryption with separately held keys for stored credentials and secrets.
- Tenant isolation enforced in the data-access layer, with automated tests that assert one organisation cannot read another's.
- Role-based access control within an organisation, and an audit log of every change.
- Point-in-time database recovery, and access to production limited to named individuals.
These measures may change as the Service develops. We will not materially reduce the overall level of security during your subscription.
6. Subprocessors
You give general authorisation for us to engage subprocessors. The current list is published at modusreservations.com/subprocessors, with the date each was added.
We will give you 30 days' notice before a new subprocessor begins processing, by email to the account owner and by updating that page. If you object on reasonable data-protection grounds within those 30 days, we will work with you to find an alternative; where none is available you may terminate the affected part of the Service without penalty, with a refund of prepaid fees for the remaining term.
Each subprocessor is bound by written terms no less protective than these, and we remain fully liable to you for their performance.
7. Helping you answer data subjects
The Service is built so you can answer most requests yourself, without waiting for us:
- Access and portability — download everything held about one guest from the guest page, or your whole organisation's data from Developers → Export.
- Erasure — erase a guest from the guest page. Their identifying details are removed from the guest book, from every booking, and from the waitlist, while the booking itself survives without a name so your covers and takings are unchanged.
- Rectification — guest and staff records are editable throughout.
Where a request reaches us instead of you, we will not respond to it on our own account. We will forward it to you promptly and help you answer it. If self-service does not cover what is being asked, write to us and we will assist.
8. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data. Notification goes by email to your account owner.
The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we do not have all of that at once, we will send what we have and follow up rather than wait.
Notifying you is not an admission of fault by either party. Reporting to a supervisory authority or to affected individuals is your decision as controller; we will give you what you need to make it.
9. International transfers
Personal data is processed in the United States and the European Union, as set out on the subprocessors page.
Where personal data is transferred outside the UK or EEA, the transfer is covered by the European Commission's Standard Contractual Clauses (Module Two or Three as applicable), together with the UK Information Commissioner's International Data Transfer Addendum for UK transfers, or by the receiving party's certification under the EU–US Data Privacy Framework and its UK Extension. Those clauses are incorporated into this agreement by reference and take precedence over it in the event of conflict.
We do not currently offer a choice of hosting region. If EU-only processing is a requirement for you, tell us — we would rather know than have you assume.
10. Return and deletion
You can export your organisation's data at any time while your account is active, in a machine-readable format, from Developers → Export.
On termination we delete your personal data within 30 days, unless you ask us to delete it sooner or the law requires us to keep it — financial records retained for tax purposes being the ordinary example. Deletion covers backups on their normal rotation rather than instantly; backup copies are not restored into service and expire within 35 days.
11. Audits and information
We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will contribute to audits conducted by you or an auditor you appoint.
In practice, our Security page and a written security questionnaire will answer most of it. Where they do not, an on-site or remote audit may be requested once per year, on 30 days' notice, during business hours, subject to confidentiality, and in a way that does not disrupt the Service. We may charge our reasonable costs for audits beyond the first in any twelve-month period.
We do not currently hold SOC 2 or ISO 27001 certification, and we say so plainly rather than let an audit clause imply otherwise.
12. Liability and precedence
Each party's liability under this agreement is subject to the limitations and exclusions in the Terms of Service.
Where this agreement conflicts with the Terms of Service, this agreement prevails on matters of data protection. Where it conflicts with the Standard Contractual Clauses, those clauses prevail.
13. How this is accepted
This agreement is incorporated into the Terms of Service and takes effect when you accept them. There is nothing to sign and nothing to request — a document every customer has already accepted is worth more than one a sales conversation has to produce.
If your organisation requires a signed copy or a negotiated variation, write to hello@modusreservations.com.
A note on what this is
This document is provided as the standard basis on which we process data, and is not legal advice to you. If data protection compliance is material to your organisation, have your own adviser review it — and tell us what it is missing.