Data Processing Addendum

Last updated: June 19, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Plato (the “Processor”) and the restaurant customer (the “Controller”) for the provision of the Plato platform. It governs Plato’s processing of personal data on the Controller’s behalf and applies where Plato processes guest data submitted through the Service.

1. Roles of the parties

The Controller (the restaurant) determines the purposes and means of processing guest personal data. Plato acts solely as a Processor and processes guest personal data only on the Controller’s documented instructions, including as set out in the agreement and this DPA.

2. Scope of processing

Plato processes guest contact details, reservation history, preferences, dietary/allergy notes, and message content for the purpose of operating reservations, floor and waitlist management, guest messaging, and reporting on the Controller’s behalf, for the duration of the agreement.

3. Subprocessors

The Controller authorizes Plato to engage the following subprocessors, each bound by data protection obligations no less protective than this DPA: Supabase (database and authentication hosting), Resend (email delivery), Twilio (SMS/WhatsApp delivery), Meta (WhatsApp Business), Anthropic (AI features), Google Places (location lookup), and Stripe (payments). Plato will give notice of changes to this list and provide an opportunity to object.

4. Security

Plato implements appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, tenant isolation, and least-privilege service credentials. Plato personnel with access to personal data are bound by confidentiality obligations.

5. Breach notification

Plato will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and will provide information reasonably available to help the Controller meet its own notification obligations.

6. Data return and deletion

On termination of the agreement, Plato will, at the Controller’s choice, return or delete the Controller’s guest personal data, except where retention is required by law. The Controller may also export or request deletion of guest data during the term.

7. Audit

Plato will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and security conditions.

8. Contact

Data protection requests under this DPA can be sent to hi@plato.company.