Data Processing Addendum (DPA)
Last updated: July 9, 2026
This Data Processing Addendum forms part of the BiteSlot Terms of Service between BiteSlot and the Merchant. It governs how BiteSlot processes personal data contained in Merchant Data on the Merchant's behalf.
1. Roles
For End Customer and staff personal data that the Merchant collects and processes through the Service, the Merchant is the data fiduciary (controller) and BiteSlot is the data processor, within the meaning of the Digital Personal Data Protection Act, 2023 and, where applicable, the GDPR. For the Merchant's own account and billing data, BiteSlot acts as a data fiduciary as described in the Privacy Policy.
2. Scope, purpose and duration
BiteSlot processes personal data only to provide, support and secure the Service, on the Merchant's documented instructions (which include the Terms of Service, plan configuration and use of Service features), and not for its own purposes. Processing continues for the duration of the subscription, plus the 30-day post-termination export window, after which data is deleted as described in Section 8.
3. Data subjects and categories of data
- Data subjects: the Merchant's End Customers, staff, delivery personnel and suppliers.
- Categories: names, phone numbers, email addresses, delivery addresses, order and reservation history, loyalty balances, staff roles, schedules and timesheet records, and payment metadata (transaction identifiers and status — never full card or bank credentials, which are held by the payment gateway).
- The Service is not designed for, and the Merchant agrees not to submit, sensitive categories such as health or biometric data.
4. BiteSlot's obligations
- Process personal data only as instructed, unless required otherwise by law (in which case we inform the Merchant unless legally prohibited).
- Ensure persons authorised to process the data are bound by confidentiality obligations.
- Implement the technical and organisational measures in Section 5.
- Assist the Merchant, by appropriate technical means, in responding to data-subject requests (access, correction, erasure) and in meeting its security and breach-notification obligations.
- Delete or return personal data at the end of the engagement (Section 8).
- Make available the information reasonably necessary to demonstrate compliance with this DPA (Section 9).
5. Security measures
BiteSlot implements and maintains, and keeps improving, technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit using TLS.
- Encrypted backups taken regularly and tested for restorability.
- Role-based access control within the platform and least-privilege access for BiteSlot personnel.
- Authentication controls including rate limiting and login throttling; support for two-factor authentication.
- Logical separation of each Merchant's data within the platform.
- Audit and system logging, and monitoring for abuse and anomalous activity.
- Separation of production and development environments.
Security measures evolve; we may update them provided the overall level of protection is not reduced.
6. Sub-processors
The Merchant authorises BiteSlot to engage sub-processors for hosting, payment processing, email/SMS/WhatsApp delivery, real-time messaging, analytics and error monitoring. The current categories and providers are listed in the Privacy Policy; a current detailed list is available on request at hello@biteslot.com. We will give at least 30 days' notice before adding a new sub-processor that processes personal data; if the Merchant reasonably objects on data-protection grounds and we cannot offer an alternative, the Merchant may terminate the affected service with a pro-rata refund of prepaid fees. BiteSlot remains responsible for its sub-processors' performance.
7. Personal data breaches
BiteSlot will notify the Merchant without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the Merchant's data, and will provide information reasonably required for the Merchant to meet its own notification obligations, including to the Data Protection Board of India.
8. Deletion and return
For 30 days after termination or expiry of the subscription, the Merchant may export its data via the dashboard or by request. Thereafter BiteSlot deletes the personal data from production systems within 30 days, and from backups in the ordinary rotation cycle, except where retention is required by law.
9. Audit and information rights
On reasonable written request (no more than once per 12 months), BiteSlot will provide written descriptions of its security practices and responses to reasonable security questionnaires sufficient to demonstrate compliance with this DPA. Where this is insufficient to meet a legal requirement, the parties will agree the scope, timing and cost of any further audit, conducted with minimal disruption and subject to confidentiality.
10. Data location and transfers
Personal data is hosted with reputable cloud infrastructure providers, primarily on servers located in India. Any processing outside India will be subject to safeguards providing equivalent protection and to applicable law.
11. Liability and precedence
This DPA is subject to the limitations of liability in the Terms of Service. If this DPA conflicts with the Terms of Service on the subject of personal-data processing, this DPA prevails.
12. Contact
Data-protection enquiries: hello@biteslot.com · SF/16, Surdhara Complex, Nikol Gam Rd, Khodiar Nagar, Ahmedabad, Gujarat 382350