Data Processing Agreement

Who is responsible for what when a venue's guest information sits in our system. This forms part of the Terms of Service and applies to every venue with an account.

Last updated: 10 August 2026

This agreement is between OneTable Technologies Pty Ltd, trading as OneReserve, and the venue that holds a OneReserve account (“you”). It forms part of our Terms of Service, and where the two conflict on the handling of guest information, this document wins.

1. Why this is not a GDPR-style agreement

Australian privacy law does not divide the world into “controllers” and “processors”. The Australian Privacy Principles bind any APP entity that holds personal information, and we both hold your guests’ information — you in your restaurant, us in the system you asked us to run.

That means neither of us can contract out of our own obligations by naming the other responsible. What this agreement can do, and does, is say who actually performs each task, so nothing falls between us while each of us remains answerable for our own compliance.

2. Who decides what

DecisionWho makes it
What guest information is collected, and what staff record about a guestYou
Which of your staff can see it, and in what roleYou
Whether to take deposits, and what your booking page asks forYou
How the information is stored, secured and backed upUs
Which sub-processors we use, and where they areUs — subject to clause 4

3. What we will and will not do with it

We will use your guests’ information only to:

  • provide the service to you, as the Terms describe;
  • send the booking mail your settings ask us to send;
  • keep the platform secure and working; and
  • comply with a law that requires it.

We will not market to your guests, sell their information, use it to build a cross-venue profile, or use it to train any model. Your guest list is yours and is never pooled with another venue’s.

Our staff access your data only where support or diagnosis requires it. If we need to look at a specific booking to answer a support request, we will say so.

4. Sub-processors, and where your data physically is

We use these providers, each limited to its function:

ProviderFunctionCountry
RailwayApplication and database hostingSingapore
StripeDeposit paymentsUnited States, Ireland
ResendBooking and account emailUnited States
SentryError reportingUnited States

Your guests’ information is stored in Singapore, not Australia, and you need to know that because your own privacy policy has to say so. Australian Privacy Principle 8 makes you responsible for a disclosure you make to an overseas recipient, and passing guest details into OneReserve is such a disclosure. We take reasonable steps to ensure each provider above handles the information consistently with the APPs.

If we add or change a sub-processor in a way that changes what is held or which country it is held in, we will give you 30 days’ notice by email before it takes effect. If that is unacceptable to you, you may cancel within those 30 days and we will refund the unused part of your current period — the one case where we do.

5. Security

We take the steps Australian Privacy Principle 11 requires: passwords hashed and never stored in readable form, access to your data restricted to your own staff, encryption in transit, a patched and monitored platform, and card details that never reach our systems at all.

Your side of this matters as much as ours. Most breaches of a system like this begin with a shared or reused staff password, not with the server. Give each staff member their own account, remove people when they leave, and give a role no wider than the job needs.

6. Data breaches — who tells whom, and when

The Notifiable Data Breaches scheme (Part IIIC of the Privacy Act) requires notification of an eligible data breach — one likely to result in serious harm — to the Office of the Australian Information Commissioner and to the people affected.

If the breach is in our systems: we will tell you without undue delay and within 72 hours of becoming aware, with what we know, who is affected, and what we are doing. We will make the assessment and, where the scheme requires it, we will notify the Commissioner and the affected individuals.

If the breach is on your side — a staff account shared or stolen, a device lost, a guest list emailed to the wrong person — it is yours to assess and notify, and we will give you whatever information from the system you need to do it.

Where we both hold the affected information, section 26WM means a notification by one of us discharges the other. We will agree in writing which of us notifies before either of us does, so your guests are not told twice about one incident, and never told twice with two different accounts of it.

Neither of us will name the other publicly in connection with an incident before we have both seen the statement — except where the law requires it, in which case that obligation wins and we will tell the other as soon as we can.

7. When a guest asks for their information

Guests deal with you, so a request will usually reach you first. Under Australian Privacy Principles 12 and 13 you must give access and make corrections, and the console gives you the tools to do both directly.

If a request reaches us instead, we will not answer it on your behalf. We will forward it to you within 5 business days and help you respond. Where a guest asks for erasure, the console can erase their identifying details while leaving the booking record intact, so your covers and revenue history stay accurate.

If we ever receive a law enforcement or government request for your guests’ information, we will tell you before responding unless the law forbids us from telling you.

8. Keeping it, and getting it back

We keep your guest records for as long as your account is open, because a restaurant needs its own booking history. We do not delete them on a timer, and deciding how long you need them is your call, not ours — Australian Privacy Principle 11.2 asks you to destroy or de-identify information you no longer need.

You can export your bookings and guest records at any time while your account is open. After termination we keep them available for export for 30 days, then delete them. Ask us and we will delete them sooner.

Backups age out on their own cycle, so a deletion may persist in a backup for a short period afterwards. We do not restore deleted data from a backup to bring it back.

9. Showing our work

Ask, and we will tell you in writing what we hold for you, where it sits, who we share it with and what security we apply. We do not offer on-site audits — we are a small team and pretending otherwise would be a commitment we could not keep — but we will answer specific questions in writing, and we will not charge for it.

10. Term

This agreement applies for as long as you hold a OneReserve account, and clauses 6, 7 and 8 continue to apply until your data has been deleted.

Questions about any of it: [email protected].

Contact

OneTable Technologies Pty Ltd
ABN 32 651 220 405
Adelaide, South Australia
[email protected]