Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Customer” or “Controller”) and Xorda Ltd (“Xorda”, the “Processor”). It governs the processing of personal data carried out by Xorda on your behalf when you use the platform, and reflects the requirements of Article 28 of the UK GDPR and the Data Protection Act 2018.

1. Roles

In respect of the personal data of your end customers (the people who call and order from your restaurant), you are the Controller and Xorda is the Processor. Xorda processes that personal data only on your documented instructions, which include the instructions given through your use of the platform and these terms, unless required to do otherwise by law.

2. Subject matter and nature of processing

The processing is carried out for the purpose of providing the Xorda phone-ordering and payment service: capturing an inbound caller's phone number, sending an ordering link by SMS, recording the order and its delivery/collection details, facilitating payment, and notifying the customer about the status of their order.

3. Categories of data and data subjects

  • Data subjects: your end customers
  • Personal data: phone number, order contents, and (for delivery orders) delivery address. No special-category data is intentionally processed

Card details are never stored by Xorda; payments are processed directly by Stripe, which acts as an independent controller / payment processor for that data.

4. Duration

Processing continues for as long as you maintain an active account, and for the limited retention period described in our Privacy Policy after an order is completed or your account is closed, after which data is deleted or anonymised.

5. Xorda's obligations

  • Process personal data only on your documented instructions
  • Ensure persons authorised to process the data are bound by confidentiality
  • Implement appropriate technical and organisational security measures (encryption in transit, access controls, row-level database isolation between restaurants, and signed-webhook verification)
  • Assist you, taking into account the nature of processing, in responding to data-subject requests and in meeting your security, breach-notification and impact-assessment obligations
  • Notify you without undue delay after becoming aware of a personal-data breach affecting your data
  • At your choice, delete or return all personal data at the end of the service, unless retention is required by law
  • Make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits on reasonable notice

6. Sub-processors

You authorise Xorda to engage the following sub-processors, each of which provides contractual data-protection guarantees:

  • Supabase — database and authentication hosting
  • Vercel — application hosting
  • Twilio — inbound call handling and SMS messaging
  • Stripe — payment processing
  • OpenAI — optional menu-photo import only (not used for calls)

We will give you reasonable advance notice of any intended addition or replacement of a sub-processor, giving you the opportunity to object on reasonable data-protection grounds.

7. International transfers

Where a sub-processor processes personal data outside the UK, that transfer is covered by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an applicable adequacy decision.

8. Your obligations

You warrant that you have a lawful basis to collect and have processed your end customers' personal data through the service, that you have provided your customers with appropriate privacy information, and that your instructions to Xorda comply with data-protection law.

9. Liability and governing law

Liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA is governed by the laws of England and Wales.

10. Contact

Data-protection queries: legal@xorda.co.uk