Legal
Terms of Service
Last updated: July 10, 2026
These Terms govern access to and use of SimpleTable for restaurants, authorised users, and guests using public booking experiences.
Agreement to These Terms
These Terms of Service (the “Terms”) govern access to and use of SimpleTable, including the website at mysimpletable.com, restaurant administration tools, public booking pages, and related products and services that link to these Terms (collectively, the “Services”).
The Services are provided by SIA “Simple Systems Group”, a company registered in Latvia with registration number 40203744434 and legal address Bauskas iela 73 k-1 - 31, Rīga, LV-1004, Latvia (“SimpleTable”, “Company”, “we”, “us”, or “our”).
These Terms apply to:
- Business Customers: restaurants, cafés, bars, hospitality businesses, and other organisations that create an account, start a trial, or purchase a subscription;
- Authorised Users: individuals permitted by a Business Customer to access its account; and
- Guests: individuals who use a public booking page or otherwise interact with the Services to make or manage a reservation.
By creating an account, selecting a paid plan, accepting an order form, or otherwise using the Services, you agree to these Terms. If you use the Services on behalf of a business or other legal entity, you confirm that you have authority to bind that entity.
1. Definitions
“Account Data” means information relating to a Business Customer or Authorised User account, including contact, authentication, billing, plan, and support information.
“Customer Content” means information and materials submitted, uploaded, configured, or displayed by or for a Business Customer through the Services, including restaurant details, menus or descriptions, logos, policies, booking settings, and communications.
“Customer Data” means Account Data, Customer Content, reservation records, Guest Data, and other data processed through a Business Customer’s use of the Services. Customer Data does not include SimpleTable’s software, system-generated security information, or properly anonymised and aggregated statistics that cannot reasonably identify a person or Business Customer.
“Guest Data” means personal data relating to Guests, such as names, contact details, reservation details, party size, booking notes, preferences, consent records, and communications.
“Order” means an online checkout, order form, plan selection, or other document that identifies the subscription plan, billing period, price, or additional commercial terms.
“Subscription Term” means the paid monthly, annual, or other period selected in an Order.
2. The Services
SimpleTable is a cloud-based restaurant reservation and table-management platform. Depending on the plan and features available, the Services may allow Business Customers to manage restaurant profiles, opening hours, tables, capacity, availability, booking rules, reservations, cancellations, Guest Data, communications, analytics, gift cards, loyalty features, integrations, and related operations.
SimpleTable may provide a public booking page through which Guests can request, create, modify, or cancel reservations, subject to the availability, approval settings, policies, and instructions established by the relevant Business Customer.
Feature availability may vary by plan, location, device, integration, or release stage. Beta, preview, or testing features may be changed or withdrawn and may be subject to additional terms.
SimpleTable does not own, operate, manage, or control the restaurants or other hospitality businesses using the Services. Each Business Customer remains responsible for its venue, products, services, staffing, availability, prices, booking policies, legal compliance, accessibility, and Guest experience.
SimpleTable does not currently operate a general restaurant marketplace or rank Business Customers against one another. Public booking pages are associated with the relevant Business Customer. If we introduce discovery, comparison, or ranking features, we will provide any transparency information required by applicable law.
3. Accounts and Authorised Users
Business Customers must provide accurate, current, and complete account information and keep it updated. Each Business Customer is responsible for:
- protecting login credentials and using appropriate account-security practices;
- all activity conducted through its account, except to the extent caused by SimpleTable’s breach of these Terms;
- ensuring that Authorised Users comply with these Terms;
- promptly removing access for people who are no longer authorised; and
- notifying us without undue delay of suspected unauthorised access or security incidents affecting its account.
Accounts may not be shared between unrelated businesses, sold, transferred, or used to impersonate another person or entity without our written permission.
4. Business Customer Responsibilities
The Business Customer is responsible for configuring the Services to reflect its actual operations and for reviewing reservations and messages generated through its account. In particular, the Business Customer must:
- maintain accurate opening hours, availability, capacity, booking rules, contact information, and policies;
- honour or lawfully manage reservations made through its booking page;
- clearly communicate cancellation, no-show, deposit, refund, age, accessibility, and other venue policies to Guests;
- comply with applicable consumer, tax, food-safety, accessibility, marketing, employment, and hospitality laws;
- obtain all permissions, notices, and lawful bases required to collect and use Customer Data;
- use Guest Data only for legitimate reservation, service, legal, and properly authorised marketing purposes;
- avoid collecting excessive personal data; and
- ensure a valid legal basis and appropriate safeguards before recording special-category personal data, such as allergy, health, or accessibility information.
The Business Customer is the seller and provider of its own products and services. Unless a feature expressly states otherwise, SimpleTable is not the merchant of record, contracting restaurant, payment recipient, employer, agent, or representative of the Business Customer.
5. Guest Bookings
A reservation made through SimpleTable is an arrangement between the Guest and the relevant Business Customer. SimpleTable supplies the booking technology but is not a party to the restaurant reservation and does not guarantee that either party will fulfil it.
Guests must provide accurate booking information and comply with the Business Customer’s displayed policies. The Business Customer is responsible for reservation acceptance, changes, cancellations, deposits, no-show charges, refunds, venue services, food and drink, and the Guest experience.
A booking confirmation may be automated. A Business Customer may cancel, modify, reject, or request confirmation of a reservation where permitted by its policies and applicable law.
SimpleTable may transmit booking confirmations, reminders, changes, and other messages on behalf of the Business Customer. Marketing messages require an appropriate legal basis and, where required, the Guest’s consent. Guests may use available unsubscribe or opt-out controls for marketing communications, but operational reservation messages may still be sent where necessary to provide the requested booking service.
Questions or complaints about a venue, reservation, charge, service, food, or refund should normally be directed first to the relevant Business Customer. Questions about the technical operation of SimpleTable may be directed to us.
6. Free Trial, Subscriptions, and Payment
6.1 Fourteen-day free trial
Eligible new Business Customers may receive a 14-day free trial beginning when the trial account is activated. No subscription fee is charged during the trial unless an Order clearly states otherwise.
The free trial does not automatically convert into a paid subscription. At the end of the 14-day trial, access to the business administration features will be blocked or suspended until the Business Customer actively selects a paid plan and provides or confirms the required payment details.
6.2 Paid subscriptions and renewal
After a Business Customer actively selects a paid plan, the subscription begins and renews automatically for successive periods of the same length unless cancelled before the next renewal date. By selecting a paid plan, the Business Customer authorises us or our payment provider to charge the applicable recurring fees and taxes to the selected payment method.
The applicable plan, billing period, price, included features, and usage limits are shown at checkout or in the relevant Order. All payments are made in euros unless the Order states otherwise.
6.3 Payment information and providers
The Business Customer must maintain accurate billing information and a valid payment method. Payments may be processed by a third-party payment service provider under that provider’s terms and privacy notice. We do not require the Business Customer to provide full payment-card details directly to us where the payment provider collects them.
6.4 Taxes
Prices are shown as inclusive or exclusive of applicable taxes as stated at checkout or on the invoice. The Business Customer is responsible for applicable VAT, sales, use, withholding, or similar transaction taxes, except taxes based on SimpleTable’s net income. A VAT identification number will be used only where valid and legally applicable.
6.5 Failed or overdue payments
If a payment fails or becomes overdue, we may retry the payment method, notify the Business Customer, restrict paid features, or suspend the account after providing a reasonable opportunity to resolve the issue. The Business Customer remains responsible for undisputed fees accrued before suspension or termination.
6.6 Cancellation
A Business Customer may cancel a subscription through the account settings or by contacting us. Cancellation takes effect at the end of the current paid Subscription Term, and access continues until then unless the account is suspended for another lawful reason.
6.7 Refunds
Except where an Order states otherwise or applicable law requires a refund, fees already paid are non-refundable. If we terminate a paid subscription for convenience rather than for the Business Customer’s breach, we will refund the prepaid fees attributable to the unused part of the current Subscription Term.
6.8 Price changes
We may change subscription prices for a future renewal period by giving reasonable advance notice. A price increase will not apply retroactively to an already-paid period. The Business Customer may cancel before the increase takes effect.
7. Acceptable Use
You may use the Services only for lawful purposes and in accordance with these Terms. You must not, and must not assist another person to:
- use the Services in violation of applicable law, third-party rights, or binding industry rules;
- access another customer’s account or data without authorisation;
- upload malware, harmful code, or material designed to disrupt or compromise the Services;
- circumvent security controls, usage limits, authentication, or access restrictions;
- probe, scan, or test vulnerabilities without our written permission;
- reverse engineer, decompile, or attempt to derive source code except to the limited extent such restriction is prohibited by mandatory law;
- scrape, harvest, or systematically extract data except through authorised exports, integrations, or interfaces;
- send spam or marketing messages without the legally required permission;
- submit unlawful, defamatory, fraudulent, discriminatory, infringing, or misleading Customer Content;
- resell, sublicense, or provide the Services to unrelated third parties unless an Order expressly permits it;
- use the Services to build or train a competing service using unauthorised access to our non-public software, interfaces, or documentation; or
- interfere with the integrity, security, or normal operation of the Services.
Reasonable use of authorised APIs, exports, integrations, and browser functions is permitted in accordance with their documentation and applicable plan limits.
8. Intellectual Property
SimpleTable and its licensors retain all rights, title, and interest in and to the Services, including the software, source code, databases, interfaces, designs, documentation, trademarks, and other content supplied by us. No ownership rights are transferred under these Terms.
Subject to payment of applicable fees and compliance with these Terms, we grant the Business Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the Subscription Term to access and use the Services for its internal business operations and to operate its public booking page.
SimpleTable may use a Business Customer’s name, logo, and venue information only as necessary to provide and display that Business Customer’s configured booking page and related Services. We will not use a Business Customer’s name or logo in public marketing, customer lists, case studies, or advertising without permission.
If you voluntarily provide suggestions or feedback, you grant us a non-exclusive, worldwide, royalty-free right to use that feedback to improve and develop the Services. This does not give us ownership of Customer Data or confidential information.
9. Customer Content and Data
As between the parties, the Business Customer retains ownership of its Customer Content and its rights in Customer Data. The Business Customer grants SimpleTable a limited, non-exclusive, worldwide licence to host, copy, transmit, display, format, back up, and otherwise process Customer Content and Customer Data only as necessary to:
- provide, maintain, secure, support, and improve the Services;
- follow the Business Customer’s documented instructions;
- prevent fraud, abuse, and security incidents;
- comply with law and valid legal process; and
- exercise our rights and perform our obligations under these Terms.
The Business Customer confirms that it has the rights and lawful grounds necessary for SimpleTable to process Customer Content and Customer Data as described in these Terms.
We may create and use aggregated or anonymised information for analytics, security, product improvement, and business reporting only where the information does not identify, and cannot reasonably be used to re-identify, a Guest, Authorised User, or Business Customer.
10. Privacy and Data Protection
Our processing of personal data is described in the SimpleTable Privacy Policy available at mysimpletable.com/privacy. The Privacy Policy is a transparency notice and does not replace any contract, consent, lawful basis, or other requirement imposed by data-protection law.
For Account Data and information that SimpleTable determines the purposes and means of processing, SimpleTable generally acts as a data controller. For Guest Data and other personal data processed on the documented instructions of a Business Customer, the Business Customer generally acts as controller and SimpleTable acts as processor.
The parties will comply with applicable data-protection and electronic-communications laws, including the EU General Data Protection Regulation where applicable. The data-processing terms in Appendix A form part of these Terms whenever SimpleTable processes personal data on behalf of a Business Customer.
The Business Customer must provide Guests and Authorised Users with any notices required for its processing and must ensure that its use of messaging, analytics, marketing, and integration features has a lawful basis.
11. Data Processing
Appendix A is the Data Processing Addendum between SimpleTable and the Business Customer. It governs the processing of personal data by SimpleTable as processor on behalf of the Business Customer.
Where the Business Customer enables an integration or instructs SimpleTable to send data to a third party, the Business Customer is responsible for confirming that the transfer and the third party’s use are lawful. SimpleTable remains responsible for subprocessors appointed by SimpleTable as described in Appendix A.
12. Data Export, Switching, and Deletion
12.1 Exportable data
Subject to applicable law and technical availability, exportable Customer Data may include restaurant profiles, locations, tables, opening hours, availability rules, booking policies, reservations, Guest records, booking notes, consent records, communications metadata, gift-card or loyalty records where enabled, and account configuration data.
Exportable data does not include SimpleTable source code, software, proprietary algorithms, internal system architecture, credentials, security-detection information, internal operational logs, data that belongs to another customer, or internal data whose disclosure would create a material security risk or reveal protected trade secrets. These exclusions will not be used to prevent or unreasonably delay a lawful switch.
12.2 Switching request and notice
A Business Customer may request an export, switch to another provider, move to its own systems, or request erasure by contacting us. The maximum notice period to initiate a switching process is 30 calendar days unless a shorter period is agreed.
12.3 Transitional period and assistance
We will cooperate in good faith, provide reasonable information and assistance, maintain appropriate security, and use reasonable efforts to complete the transfer of exportable data in a structured, commonly used, machine-readable format within a transitional period of no more than 30 calendar days after the notice period.
If completion within 30 calendar days is technically infeasible, we will notify the Business Customer within 14 working days of the switching request, explain the reason, and identify an alternative transitional period that will not exceed seven months where applicable law imposes that limit. The Business Customer may request one reasonable extension of the transitional period.
12.4 Retrieval and erasure
After the transitional period ends, exportable Customer Data will remain available for retrieval for at least 30 calendar days, unless a longer period is agreed. After the retrieval period, we will delete or anonymise exportable Customer Data within a reasonable period, except where continued retention is required by law, necessary to establish or defend legal claims, maintained in secure backup cycles for a limited period, or otherwise permitted under the Data Processing Addendum.
12.5 Charges
Standard self-service exports and ordinary switching assistance are not subject to a switching fee. Optional custom development, exceptional manual migration work, or professional services requested by the Business Customer may be separately agreed and charged, provided that such charges do not restrict rights that cannot lawfully be limited. From January 12, 2027, no switching charge will be imposed where prohibited by applicable law.
12.6 Data formats and technical information
Available formats, data structures, procedures, known restrictions, and technical limitations will be described in the Services, relevant documentation, or information supplied in response to a switching request. We are not required to create a new service, disclose source code, transfer intellectual property belonging to SimpleTable or another person, or compromise the security or integrity of the Services.
13. Third-Party Services
The Services may rely on or connect with third-party hosting, database, authentication, email, messaging, payment, analytics, calendar, point-of-sale, or other providers. Third-party services may be governed by their own terms and privacy notices.
We are not responsible for a third-party service selected, configured, or contracted directly by the Business Customer. We remain responsible for our obligations regarding subprocessors that we appoint to process personal data on our behalf.
An integration may become unavailable because a third party changes or discontinues its service or access terms. We will use reasonable efforts to provide notice where the change materially affects the Services and we have advance knowledge of it.
14. Availability and Support
We will use reasonable care and skill to provide the Services and maintain appropriate technical and organisational safeguards. However, no online service can be guaranteed to be uninterrupted, error-free, or immune from every security incident.
The Services may be unavailable because of maintenance, updates, internet or telecommunications failures, third-party outages, force majeure events, security measures, or circumstances beyond our reasonable control. Where reasonably practicable, we will provide advance notice of planned maintenance that is expected to cause material disruption.
Unless an Order contains a separate service-level agreement, no specific uptime, response-time, recovery-time, or support-resolution commitment applies.
The Business Customer should maintain reasonable operational procedures for situations where the Services are temporarily unavailable, including access to essential reservation information where appropriate.
15. Changes to the Services and Terms
We may improve, update, add, replace, or discontinue features. We will not materially reduce the core functionality of a paid plan during an already-paid Subscription Term without a legitimate reason, reasonable notice where practicable, and an appropriate remedy where required by law.
We may amend these Terms. For material changes, we will notify affected Business Customers on a durable medium, such as email or an in-account notice that can be stored, at least 15 days before the change takes effect. We will provide a longer notice period where reasonably necessary for the Business Customer to make significant technical or commercial adaptations.
A Business Customer may cancel before a materially adverse change takes effect. Continued use after the effective date constitutes acceptance of the revised Terms, except where applicable law requires another form of acceptance.
The notice period does not apply to purely editorial changes or where an immediate change is required by law or is reasonably necessary to address fraud, malware, spam, a data breach, a serious cybersecurity risk, or another unforeseen and imminent danger. We will explain such changes as soon as reasonably practicable.
16. Suspension and Termination
16.1 Suspension
We may restrict or suspend all or part of an account where reasonably necessary because of:
- overdue undisputed fees after notice and a reasonable opportunity to pay;
- a material or repeated breach of these Terms;
- fraud, unlawful activity, spam, abuse, or infringement of third-party rights;
- a security threat or risk to the Services, other customers, or Guests;
- a legal or regulatory requirement; or
- usage that materially exceeds documented limits or threatens system stability.
Where appropriate and legally permitted, we will give the Business Customer a statement of reasons and an opportunity to remedy the issue before or promptly after suspension. We will limit the restriction to what is reasonably necessary.
16.2 Termination by the Business Customer
The Business Customer may terminate these Terms by cancelling its subscription and ceasing use of the Services. The subscription remains active until the end of the paid Subscription Term unless otherwise agreed.
16.3 Termination by SimpleTable for breach
We may terminate for a material breach that is not remedied within 14 days after written notice. We may terminate immediately where the breach cannot reasonably be remedied, where continued service would be unlawful, where there is fraud or a serious security threat, or where repeated breaches justify immediate termination under applicable law.
16.4 Termination by SimpleTable for convenience or discontinuation
We may terminate a Business Customer’s entire paid service for convenience or discontinue the Services by providing at least 30 days’ advance notice and a statement of reasons, unless a longer period is required by an Order or applicable law. Where we terminate for convenience during a prepaid Subscription Term, we will provide the refund described in Section 6.7.
16.5 Effect of termination
On termination, the right to use the Services ends, subject to any retrieval and switching period under Section 12. Accrued payment obligations and provisions that by their nature should survive termination will remain effective, including intellectual-property, confidentiality, data-protection, liability, dispute, and general provisions.
17. Confidentiality
Each party may receive non-public business, technical, financial, security, or commercial information from the other party that is identified as confidential or that a reasonable person would understand to be confidential (“Confidential Information”).
The receiving party will use Confidential Information only to perform or receive the Services, protect it using reasonable care, and disclose it only to personnel, advisers, and service providers who need to know it and are bound by appropriate confidentiality obligations.
Confidential Information does not include information that the receiving party can demonstrate was lawfully known without restriction, becomes public without breach, is received lawfully from a third party without a duty of confidentiality, or is independently developed without use of the other party’s Confidential Information.
A party may disclose Confidential Information where required by law or valid legal process, provided it gives notice where legally permitted and reasonably cooperates in seeking protective treatment.
18. Warranties and Disclaimers
Each party warrants that it has authority to enter into these Terms. SimpleTable warrants that it will provide the paid Services with reasonable care and skill and substantially in accordance with applicable documentation.
If SimpleTable materially breaches the warranty above, the Business Customer must notify us with reasonable details. We will use reasonable efforts to correct the non-conformity. If we cannot do so within a reasonable period, the Business Customer may terminate the affected paid Service and receive a pro-rata refund of prepaid fees for the unused period. This is the Business Customer’s primary contractual remedy for breach of the service warranty, without limiting rights that cannot lawfully be excluded.
Except for the express warranties in these Terms and to the maximum extent permitted by law, the Services are provided on an “as available” basis. We do not warrant that the Services will be completely uninterrupted or error-free, that every reservation will be completed, that a Business Customer or Guest will perform a reservation, or that third-party integrations will always remain available.
SimpleTable does not provide legal, tax, accounting, food-safety, medical, or regulatory advice. Business Customers are responsible for obtaining professional advice where needed.
19. Indemnification
The Business Customer will defend and indemnify SimpleTable against a third-party claim, and resulting reasonable losses, damages, costs, and legal fees, to the extent the claim arises from:
- Customer Content infringing the third party’s intellectual-property or other rights;
- the Business Customer’s unlawful collection, use, disclosure, or marketing use of personal data;
- the Business Customer’s venue, products, services, charges, refunds, policies, or Guest relationship;
- the Business Customer’s material breach of these Terms; or
- fraud, wilful misconduct, or unlawful acts by the Business Customer or its Authorised Users.
This obligation applies only if SimpleTable promptly notifies the Business Customer of the claim, provides reasonable cooperation at the Business Customer’s expense, and allows the Business Customer to control the defence and settlement. The Business Customer may not settle a claim in a manner that admits fault by, imposes non-monetary obligations on, or fails to fully release SimpleTable without our written consent, which will not be unreasonably withheld.
SimpleTable will defend and indemnify the Business Customer against a third-party claim that the unmodified paid Services, when used as permitted, directly infringe that third party’s copyright, trademark, or patent. We may modify or replace the affected Service, obtain continued usage rights, or terminate the affected Service and refund prepaid unused fees. This obligation does not apply to claims caused by Customer Content, third-party integrations, unauthorised modifications, or use contrary to documentation or these Terms.
20. Limitation of Liability
Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for fraud, fraudulent misrepresentation, intentional misconduct, death or personal injury caused by negligence, or other liability that applicable law requires to remain unlimited.
Subject to the paragraph above, neither party will be liable for indirect, incidental, special, exemplary, or consequential loss, or for loss of profit, revenue, anticipated savings, goodwill, or business opportunity, except to the extent such loss forms part of a third-party claim covered by an indemnity in these Terms.
Subject to the first paragraph of this Section, SimpleTable’s total aggregate liability arising out of or relating to the Services or these Terms will not exceed:
- for a Business Customer on a paid plan, the subscription fees paid or payable by that Business Customer for the Services during the 12 months immediately preceding the event giving rise to the claim; or
- for a Guest or a Business Customer that has paid no subscription fees, EUR 100.
The limitations in this Section apply regardless of the legal theory of liability and to the maximum extent permitted by law. They do not limit a person’s mandatory rights under applicable consumer or data-protection law.
21. Governing Law and Disputes
These Terms are governed by the laws of the Republic of Latvia, excluding conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods.
Before starting court proceedings, the parties will attempt in good faith to resolve a dispute informally. The complaining party should send a written description of the issue and requested resolution. The parties will allow 30 days after receipt of the notice for informal negotiations, unless urgent interim relief is reasonably necessary.
For disputes with a Business Customer, the courts of Latvia with jurisdiction in Riga will have exclusive jurisdiction, except where mandatory law requires otherwise.
If a Guest or other individual qualifies as a consumer, nothing in these Terms removes mandatory consumer protections or any right to bring a claim in a court that has jurisdiction under applicable consumer law.
22. General Terms
22.1 Notices
We may send operational and legal notices to the email address associated with the account, through the Services, or by another durable medium. Notices to SimpleTable must be sent using the contact details in Section 23. A notice is deemed received when delivered, except where applicable law requires another rule.
22.2 Electronic contracting
The parties agree that contracts, Orders, notices, and records may be created and delivered electronically. This does not waive any mandatory formal requirement imposed by law.
22.3 Entire agreement and order of precedence
These Terms, an applicable Order, the Privacy Policy, and Appendix A constitute the agreement regarding the Services. If there is a conflict, the following order applies unless expressly stated otherwise: a signed Order, Appendix A for personal-data processing, these Terms, and then the Privacy Policy.
22.4 Assignment
The Business Customer may not assign these Terms without our prior written consent, which will not be unreasonably withheld. We may assign these Terms as part of a merger, reorganisation, financing, or sale of all or substantially all of the relevant business or assets, provided that the assignee assumes our obligations and the assignment does not materially reduce the Business Customer’s rights.
22.5 Force majeure
Neither party is liable for delay or failure caused by events beyond its reasonable control, such as natural disasters, war, civil unrest, labour disputes, government action, widespread telecommunications failure, utility failure, or major third-party infrastructure outages. This does not excuse payment obligations for Services already provided.
22.6 Severability
If a provision is unlawful or unenforceable, it will be modified to the minimum extent necessary to make it enforceable or, if that is not possible, severed. The remaining provisions continue in effect.
22.7 Waiver
A failure or delay in exercising a right is not a waiver. A waiver must be clear and applies only to the specific circumstance for which it is given.
22.8 Relationship
The parties are independent contractors. These Terms do not create a partnership, franchise, employment, fiduciary, or agency relationship. SimpleTable is not an agent for a Business Customer in its relationship with Guests unless a specific feature and written agreement expressly state otherwise.
22.9 No third-party beneficiaries
Except where these Terms expressly grant rights to Guests or data subjects, these Terms do not create enforceable rights for a third party.
22.10 Language
If these Terms are translated, the English version controls to the extent permitted by law, unless a translated version expressly states that it is authoritative.
23. Contact Information
SIA “Simple Systems Group”Registration number: 40203744434
Bauskas iela 73 k-1 - 31
Rīga, LV-1004
Latvia
Telephone: +371 20 408 625
Email: simpletable19@gmail.com
Appendix A - Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms between SimpleTable and the Business Customer whenever SimpleTable processes personal data on behalf of the Business Customer.
A1. Roles and instructions
For personal data processed through the Services on behalf of the Business Customer, the Business Customer is the controller and SimpleTable is the processor, unless applicable law determines otherwise. SimpleTable will process personal data only on documented instructions from the Business Customer, including the instructions contained in the Terms, an Order, the Business Customer’s configuration and use of the Services, and support requests.
If SimpleTable believes an instruction infringes applicable data-protection law, we will inform the Business Customer unless prohibited by law. SimpleTable may process personal data where required by Union or Member State law, in which case we will inform the Business Customer before processing unless the law prohibits that notice.
A2. Details of processing
Subject matter: provision of restaurant reservation, table-management, communications, support, security, hosting, and related Services.
Duration: the period during which SimpleTable provides the Services and any limited retention period described in the Terms or required by law.
Nature and purposes: collection, storage, organisation, retrieval, consultation, transmission, communication, support, security, backup, deletion, and other processing necessary to provide the Services on the Business Customer’s instructions.
Categories of data subjects: Guests, prospective Guests, customers of the Business Customer, Authorised Users, employees, contractors, and business contacts.
Types of personal data: names, email addresses, telephone numbers, reservation dates and times, party size, preferences, notes, communications, consent and opt-out records, account identifiers, IP addresses, device and usage information, and other data submitted by or for the Business Customer.
Special-category data: the Services are not designed to require special-category data. Where the Business Customer chooses to record information such as allergies, health, accessibility, or dietary information, the Business Customer must ensure that the processing is necessary, proportionate, secure, and supported by a valid legal basis.
A3. Confidentiality
SimpleTable will ensure that persons authorised to process personal data are bound by confidentiality obligations and receive access only to the extent necessary for their duties.
A4. Security
Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risk to individuals, SimpleTable will implement and maintain appropriate technical and organisational measures designed to protect personal data. Measures may include, as appropriate:
- encryption in transit and appropriate protection of stored data;
- role-based access controls, authentication, and least-privilege access;
- logging, monitoring, and measures intended to detect security events;
- secure development, change-management, patching, and vulnerability-management practices;
- backup, recovery, resilience, and business-continuity measures appropriate to the Services;
- incident-response procedures;
- personnel confidentiality and security awareness; and
- risk-based assessment of subprocessors.
The Business Customer is responsible for securely configuring its account, managing Authorised Users, and using available security features.
A5. Subprocessors
The Business Customer gives SimpleTable general written authorisation to appoint subprocessors to support hosting, database, authentication, payment, email, messaging, analytics, customer support, monitoring, and other Service functions.
SimpleTable will ensure that each subprocessor is bound by data-protection obligations that provide an appropriate level of protection. SimpleTable remains responsible for the subprocessor’s performance of its processor obligations to the extent required by applicable law.
We will maintain an up-to-date list of subprocessors and make it available through the Services, on our website, or upon request. We will provide reasonable advance notice of a new subprocessor where the change may affect the processing of personal data. The Business Customer may object on reasonable data-protection grounds. The parties will work in good faith to resolve the objection; if no reasonable solution is available, the Business Customer may discontinue the affected feature or terminate the affected Service.
A6. International transfers
SimpleTable will not transfer personal data outside the European Economic Area unless the transfer complies with applicable data-protection law, including through an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism. Where necessary, SimpleTable will implement supplementary measures appropriate to the transfer risk.
A7. Data-subject requests
Taking into account the nature of processing, SimpleTable will provide reasonable assistance to the Business Customer through appropriate technical and organisational measures to respond to requests from data subjects. If SimpleTable receives a request relating to data for which the Business Customer is controller, we will direct the requester to the Business Customer or notify the Business Customer, unless legally prohibited.
A8. Security incidents
SimpleTable will notify the Business Customer without undue delay after becoming aware of a personal-data breach affecting personal data processed on behalf of the Business Customer. The notice will include available information reasonably necessary for the Business Customer to meet its legal obligations. SimpleTable will take reasonable steps to contain, investigate, mitigate, and remediate the incident.
A9. Assistance and compliance information
Taking into account the nature of processing and information available to SimpleTable, we will provide reasonable assistance with data-protection impact assessments, prior consultations, security obligations, and breach notifications where required by applicable law.
We will make available information reasonably necessary to demonstrate compliance with this DPA. No more than once in any 12-month period, unless required by a regulator or following a material incident, the Business Customer may request a reasonable audit. Audits must be conducted during normal business hours, with reasonable notice, subject to confidentiality and security requirements, and without unreasonable disruption. The Business Customer is responsible for its audit costs unless the audit identifies a material breach by SimpleTable.
A10. Return and deletion
At the end of the Services, SimpleTable will, at the Business Customer’s choice and subject to Section 12, return or delete personal data processed on behalf of the Business Customer, unless applicable law requires retention. Personal data in secure backups may remain until overwritten in the ordinary backup cycle, provided it remains protected and is not used for another purpose.
A11. Controller obligations
The Business Customer is responsible for the lawfulness, fairness, accuracy, quality, and transparency of its processing; for providing lawful instructions; for responding to data subjects; and for determining whether the Services and available safeguards are appropriate for its processing activities.
A12. Conflict
If this DPA conflicts with the main Terms regarding the processing of personal data on behalf of the Business Customer, this DPA controls.