Data processing annex (GDPR) — English summary
Article 28 GDPR annex to the SimplyRestau terms and conditions
This page is not a contract. It is an unofficial, informational summary provided as a courtesy to English-speaking readers. The only binding text is the French document Annexe relative au traitement des données personnelles (version 2026.07.1). In the event of any discrepancy, omission or ambiguity, the French version prevails. This summary is not a data processing agreement and cannot be signed, relied on or produced in its place.
What is changing in version 2026.08.1 (drafted, not yet in force)
A version 2026.08.1 of the French annex has been drafted and legally reviewed, but is not yet applicable. It only takes effect once SimplyRestau dates the French text and publishes it to the catalogue; until then, version 2026.07.1 above remains the sole current and binding version. In outline, once in force, it will add a "Bookings" entry to the register of processing carried out on your behalf: hosting reservations, sending confirmations and reminders — by email and, optionally, SMS reminders through an EU-based aggregator —, retention periods of your choice from ninety days to three years in ninety-day steps (three hundred and sixty-five days by default; thirty days for bookings left unconfirmed), automatic irreversible anonymisation, a standing instruction to erase data on a guest's direct request, with each operation logged. Where you switch on the anti-no-show bank guarantee, only technical references to the guarantee are processed on your behalf; card data stays with your own payment provider. The clause currently excluding a guest booking or ordering feature from this version's contractual scope (see "Instructions and scope of processing" above) is removed accordingly. The list of further sub-processors will remain available on request.
This is a thematic overview of the coming version, not a section-by-section summary. Once 2026.08.1 is in force, this English page will be updated to summarise it in full.
Roles
For the data you enter into the solution for your own purposes, you act as the controller and DevMeOn as the processor within the meaning of Article 28 of the GDPR. Each party complies with the obligations that fall to it.
Instructions and scope of processing
DevMeOn processes the data only on your documented instructions, in order to host, secure, display, maintain, back up and return the content of the solution for the duration of the agreement. Data subjects may include authorised users and people identifiable in the content submitted. The data may include professional identity and contact details, permissions, technical logs, images and menu content. In the contractual scope of this version, SimplyRestau does not provide a guest booking or ordering feature.
Confidentiality and security
DevMeOn ensures that authorised personnel are bound by confidentiality and implements measures appropriate to the risk: access control, encryption of communications, patch management, backups, relevant logging and incident management procedures.
Sub-processors
You give general authorisation for the use of the providers needed for hosting, email delivery, translation, monitoring and payment. DevMeOn informs you of any substantial change and lets you raise a reasoned objection on data protection grounds. Sub-processors are bound by equivalent obligations.
Transfers
DevMeOn informs you of the relevant location of processing and frames any transfer outside the European Economic Area using a mechanism recognised by the GDPR, supplemented where necessary by appropriate measures.
Assistance
Taking into account the nature of the processing, DevMeOn reasonably assists you in responding to data subject requests, securing processing, notifying breaches and carrying out impact assessments. Manifestly excessive requests, or requests unrelated to the service, may be quoted for separately.
Personal data breaches
DevMeOn informs you as soon as possible after becoming aware of a breach affecting data processed on your behalf, and passes on the available information you need to meet your own obligations.
Return and deletion of data
At the end of the services concerned, DevMeOn returns or deletes the data according to your choice and the features available, unless the law requires it to be kept. Backup copies are purged on their normal cycle and remain protected until they are deleted.
Audit
DevMeOn makes available the information reasonably needed to demonstrate compliance with the annex. A further audit may be carried out at most once a year, on reasonable notice, without disrupting the service, under confidentiality and at your expense — except where an incident or breach has been established.
Read the binding text
This summary does not reproduce the annex in full. The binding document is the French text: Annexe relative au traitement des données personnelles (version 2026.07.1) — SHA-256 fingerprint f46c26dfa137cb0be16bba4a23846619db85e52cc854e2af861ddc33f6d026fc, taken from the published document catalogue, so you can verify you are reading the accepted text. Questions in English are welcome at contact@simplyrestau.fr, but only the French text is legally binding.