Data processing agreement
- Your venue decides what personal data reaches UniKDS. We process it only to provide the service, on your instructions.
- On a Standalone license, orders stay on the screen. Only diagnostic captures and support reports reach us.
- We tell you of a personal data breach within 48 hours, and give 30 days' notice of a new sub-processor.
- For EU and UK venues, the standard contractual clauses are included. Nothing needs signing.
This Data Processing Agreement (“DPA”) forms part of the terms of service under which mypreorder Pty Ltd (ABN 87 611 967 376), Stirling Business Centre, 45 Delawney Street, Balcatta WA 6021, Australia (“mypreorder”, “we”, “us”) provides UniKDS (the “Service”) to the business that holds the license (the “Customer”, “you”).
It applies whenever we process Personal Data on your behalf in providing the Service. It is written to meet Article 28 of the EU General Data Protection Regulation and of the UK GDPR, and also applies under the Australian Privacy Act 1988 and any other data protection law that applies to the Service. If you need a signed copy, ask us at helpdesk@mypreorder.com.
1. Definitions
Data Protection Law: every law on the protection of personal data that applies to the processing under this DPA, including the GDPR, the UK GDPR and the Privacy Act 1988 (Cth).
GDPR: Regulation (EU) 2016/679. UK GDPR: the GDPR as it forms part of UK law.
Personal Data, processing, controller, processor, data subject and personal data breach have the meanings given in the GDPR.
Customer Personal Data: Personal Data that we process on your behalf in providing the Service, described in Annex 1.
Sub-processor: another business we engage to process Customer Personal Data.
SCCs: the standard contractual clauses for transfers to third countries adopted by the European Commission in Decision (EU) 2021/914. UK Addendum: the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
2. Roles
2.1 For Customer Personal Data, you are the controller and we are your processor. You decide what your point-of-sale system sends to the Service and what appears on your kitchen dockets.
2.2 For the data we hold to run our own business (back-office user accounts, billing contacts, license and device records, and security logs) we are a controller in our own right. Our privacy policy covers that data, and this DPA does not.
2.3 Your dealer and distributor. The Uniwell dealer that supplied your screens, and the distributor that supplies it, support your screens through our back office. That access is given for your purposes. Those businesses are bound by their agreements with us to keep it confidential and use it only to support you. Your support arrangement with them is between you and them.
3. Our obligations
We will:
- process Customer Personal Data only on your documented instructions. This DPA, the terms of service, and your use and configuration of the Service are your instructions. We will tell you if we believe an instruction breaks Data Protection Law;
- make sure that everyone we authorize to process Customer Personal Data is bound to keep it confidential;
- take the security measures in Annex 2;
- use Sub-processors only as section 4 allows;
- taking into account the nature of the processing, help you respond to requests from data subjects exercising their rights. If a data subject contacts us directly, we will pass the request to you and not answer it ourselves unless you ask us to;
- help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us;
- on termination, delete or return Customer Personal Data as section 6 sets out;
- make available to you the information needed to show that we meet this DPA, and allow for audits under section 7.
4. Sub-processors
4.1 You give us general authorization to engage Sub-processors. They are listed on the sub-processors page, which forms Annex 3.
4.2 We will tell you at least 30 days before adding or replacing a Sub-processor, by updating that page and emailing everyone who has asked to be told (ask at helpdesk@mypreorder.com). You may object on reasonable data protection grounds within that period. If we cannot address the objection, you may stop using the affected part of the Service.
4.3 We impose on each Sub-processor data protection obligations no less protective than this DPA, and we remain responsible to you for their performance.
5. Personal data breaches
5.1 We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
5.2 The notice will describe, as far as we then know: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will send further information as it becomes available.
5.3 Notifying you is not an admission of fault or liability.
6. Retention, return and deletion
6.1 On a Standalone license, orders are kept on the screen and are not sent to our servers. The only Customer Personal Data that reaches us from a Standalone screen is in diagnostic captures and support reports, and only when they are turned on or sent (Annex 1).
6.2 While the Service runs, we keep Customer Personal Data for the periods in our privacy policy, and remove or redact it automatically at the end of each.
6.3 When your use of the Service ends, you may ask us within 30 days for an export of the Customer Personal Data we hold. We will then delete it within 60 days, except where the law requires us to keep it. Database backups are kept for 7 days, so deleted data leaves them within a further 7 days.
7. Audits
7.1 We will answer your reasonable written questions about our compliance with this DPA, and provide any summaries of security assessments we hold.
7.2 Where those answers are not enough to show compliance, or a supervisory authority requires it, you may audit our compliance once in any 12 months, on at least 30 days’ written notice, during business hours, at your cost, through an independent auditor bound to confidentiality. An audit must not give access to other customers’ data.
8. International transfers
8.1 We store Customer Personal Data in Sydney, Australia. Some Sub-processors process limited data in other countries, as Annex 3 shows.
8.2 EU. Where the GDPR applies to your processing, the SCCs, Module Two (controller to processor), are incorporated into this DPA, with you as data exporter and us as data importer. For the SCCs:
- clause 7 (docking clause) applies;
- clause 9: option 2, general written authorization, with the notice period in section 4.2;
- clause 11: the optional language does not apply;
- clauses 17 and 18: the law and courts of Ireland;
- Annexes I and II of the SCCs are completed by Annexes 1 and 2 of this DPA, and Annex III by Annex 3.
8.3 UK. Where the UK GDPR applies, the UK Addendum is incorporated, completed with the information in this DPA. Either party may end it as its section 19 allows.
8.4 Switzerland. Where the Swiss Federal Act on Data Protection applies, the SCCs apply as in section 8.2, with the Swiss Federal Data Protection and Information Commissioner as the competent authority, and references to the GDPR read as references to that Act.
8.5 If the SCCs, the UK Addendum and this DPA conflict, the SCCs or the UK Addendum prevail.
9. Your obligations
You are responsible for having a lawful basis for the Customer Personal Data you send to the Service, for giving your customers and staff any notice the law requires, and for not sending data the Service does not need. The content of a kitchen docket is set by your POS: if you do not want a detail held, remove it from the docket layout.
10. Liability and duration
10.1 Each party’s liability under this DPA is subject to the limits in the terms of service, except where Data Protection Law or the SCCs do not allow it to be limited.
10.2 This DPA lasts for as long as we process Customer Personal Data on your behalf.
10.3 Apart from section 8.2, this DPA is governed by the law that governs the terms of service.
Annex 1: Details of the processing
| Subject matter | Displaying kitchen orders from your point-of-sale system on kitchen screens, and supporting those screens |
| Duration | For as long as you use the Service, then section 6 |
| Nature | Receiving, storing, displaying and printing orders; diagnostic capture when turned on; support reports when sent; storage and redaction |
| Purpose | Providing and supporting the Service |
| Data subjects | Your customers; your staff |
| Categories of data | Orders: order number, items, modifiers, staff notes and, if your POS includes them on the docket, customer name, table number, delivery address and phone number. Orders from an online ordering platform may also carry the name on the card, the last four card digits and the payer’s email address, never a full card number, expiry date or security code. Staff: display name and a hashed PIN. Diagnostic captures (off unless turned on, and off again after 48 hours): the raw docket data, the image produced and the app’s logs, for each docket received while on. Support reports: app logs, with email and network addresses masked |
| Special categories | None are needed. Free-text notes may mention an allergy or dietary need, which can be health data. The Service does not ask for it |
| Where it is held | Standalone licenses: orders stay on the screen and are not sent to us; diagnostic captures and support reports reach us when turned on or sent. Other licenses: orders are held on our servers so screens can share them, and their personal details are removed 60 days after the order |
| Frequency | Continuous while screens are in use |
Annex 2: Security measures
| Area | Measures |
|---|---|
| Hosting | Servers, database and file storage in Amazon Web Services, Sydney (ap-southeast-2) |
| Encryption | All traffic between screens, the back office and our servers over TLS. File storage encrypted at rest |
| Access control | Every request is checked against the account’s role and the business it belongs to, so one customer cannot see another’s data. Kitchen PINs, passwords and keys are stored hashed |
| Our staff | Production access limited to named mypreorder staff |
| Logs | Customer names, emails, phone numbers and card details are removed from server logs before they are written. Request records keep their contents for 30 days and the record for 90 |
| Minimization | Diagnostic capture is off by default, switches itself off after 48 hours, and its captures are deleted after 30 days. Order personal details are redacted at 60 days |
| Resilience | Automated daily database backups, kept for 7 days. A screen keeps working through an internet outage |
| Incident response | Error monitoring with alerts; breach notification under section 5 |
| Development | Code review and automated tests before release; security fixes prioritized |
Annex 3: Sub-processors
The current list is on the sub-processors page.