unTill Air. Nothing holds you back. POS and payments in one app.
Last updated: 30.09.2026
1.1 This Data Processing Agreement (the "DPA") is entered into between unTill AIR B.V., a private limited liability company incorporated under the laws of the Netherlands, having its registered office at Korte Eeweg 11, 4424 NA Wemeldinge, the Netherlands, registered with the Dutch Chamber of Commerce under number 90937287 (the "Processor"), and the Customer as defined in the General Terms and Conditions (the "Controller").
1.2 This DPA forms an integral part of, and is subject to, the agreement between the Parties for the provision of the unTill Air Service (the "Agreement"). This DPA sets out the terms on which the Processor processes personal data on behalf of the Controller in connection with the Service.
1.3 This DPA applies only to the extent that the processing of personal data is governed by Regulation (EU) 2016/679 ("GDPR"). To the extent the Processor processes personal data as an independent controller (for example for its own marketing, billing, security and product-improvement purposes), such processing falls outside the scope of this DPA and is governed by the Processor's privacy policy.
1.4 Hereinafter collectively referred to as the "Parties" and individually as a "Party".
2.1 Terms used in this DPA that are defined in the GDPR - including "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" - have the meaning given to them in the GDPR.
2.2 Capitalised terms not defined in this DPA have the meaning given to them in the General Terms and Conditions. In the event of a conflict between this DPA and the remainder of the Agreement in respect of the processing of personal data, this DPA prevails.
2.3 This DPA supersedes any previously agreed data processing terms between the Parties relating to the same Service, unless expressly agreed otherwise in writing.
3.1 In respect of personal data processed under this DPA, the Controller acts as controller and the Processor acts as processor within the meaning of the GDPR.
3.2 The Processor shall process personal data only on the documented instructions of the Controller, as set out in the Agreement and this DPA, and solely to the extent necessary to provide the Service. The Controller's complete and final instructions are constituted by the Agreement, this DPA (including Annex 1) and the Controller's configuration and use of the Service. Any additional or divergent instruction requires the Processor's prior written agreement and may be subject to reasonable charges.
3.3 The subject matter, nature, purpose and duration of the processing, the categories of personal data and the categories of data subjects are described in Annex 1.
3.4 The Processor is not obliged to assess the lawfulness of the Controller's instructions. If the Processor, in its reasonable opinion, considers that an instruction infringes the GDPR or other applicable data protection law, it shall inform the Controller without undue delay, and may suspend performance of the instruction until the Controller confirms or amends it.
3.5 Where the Processor receives a legally binding request from a public authority, court or law enforcement body for the disclosure of personal data processed on behalf of the Controller, it shall, unless legally prohibited from doing so, inform the Controller without undue delay before responding, limit any disclosure to what is legally required, and challenge any request that appears unlawful or manifestly excessive.
4.1 The Controller warrants that it complies at all times with applicable data protection law in respect of (i) the personal data it enters into, uploads to or has processed through the Service, and (ii) the instructions it gives the Processor. The Controller is solely responsible for determining the purposes and means of the processing and for the existence of a valid legal basis.
4.2 The Controller warrants that it holds all rights, consents, legal bases and authorisations necessary to provide the personal data to the Processor and to authorise its processing as envisaged in the Agreement and this DPA. The Controller is solely responsible for the origin, accuracy, quality, content and lawfulness of the personal data and the manner in which it was obtained.
4.3 The Controller acknowledges that the Service is not designed as a reservation or guest-management system and is not intended for the structured recording of personal data relating to the Controller's end-customers or guests. The Controller further acknowledges that the Service nonetheless contains free-text and configurable input fields, into which the Controller and its Authorised Users may enter personal data. The Controller alone determines what personal data is entered into such fields. The Controller warrants that any personal data so entered is collected and processed lawfully, is limited to what is necessary for its point-of-sale administration, and complies with applicable data protection law. The Controller shall not use free-text or other input fields to record special categories of personal data in accordance with Article 4.4.
4.4 The Controller shall not provide, or cause the Processor to process, any special categories of personal data, unless expressly agreed in writing in advance and supported by a valid legal basis and appropriate safeguards provided by the Controller. Where the Controller nonetheless enters such data, it does so at its own risk and remains solely responsible for its lawfulness.
4.5 The Controller shall provide personal data to the Processor only if it has satisfied itself that the security measures in Annex 3 offer an appropriate level of security for the processing concerned.
4.6 To the extent third parties bring claims against the Processor arising from or relating to personal data or processing for which the Controller is responsible, the Controller shall indemnify and hold the Processor harmless, upon first request, against such claims, damages, fines and costs (including reasonable legal costs), except to the extent caused by the Processor's intent or deliberate recklessness.
5.1 The Processor shall implement and maintain appropriate technical and organisational measures to protect personal data against loss and unlawful processing, in accordance with Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing. The current measures are described in Annex 3. The Processor does not warrant that the measures will be effective under all circumstances.
5.2 The Processor may update or modify the security measures from time to time, provided that the overall level of security is not materially diminished. Where a change is expected to have a material adverse impact on the security level, the Processor shall, where reasonably practicable, inform the Controller in advance.
5.3 The Controller is responsible for the security of its own systems, accounts, devices, network connections, authentication credentials and access rights used to access the Service, and for configuring the available access, role and permission settings appropriately.
5.4 The Processor shall ensure that persons authorised to process the personal data are bound by an appropriate duty of confidentiality, whether contractual or statutory, and that access is limited to those who need it for the performance of the Service.
6.1 The Controller grants the Processor general written authorisation to engage sub-processors for the processing of personal data. The sub-processors engaged at the date of this DPA are listed in Annex 2.
6.2 The Processor shall impose on each sub-processor, by written agreement, data protection obligations that offer a level of protection materially equivalent to those in this DPA, to the extent appropriate to the services provided by that sub-processor. The Processor remains fully responsible to the Controller for the performance of its sub-processors' obligations.
6.3 The Processor shall inform the Controller of any intended addition or replacement of a sub-processor at least fourteen (14) days in advance, thereby giving the Controller the opportunity to object. The Controller may object within that period on reasonable and demonstrable data protection grounds. The Parties shall discuss any objection in good faith; if no reasonable solution is found, the Controller's sole remedy is to terminate the affected part of the Service, without prejudice to fees already incurred.
7.1 The core Service is hosted in data centres located within the European Union. Some sub-processors listed in Annex 2 may process personal data, or provide access to it, from outside the EEA, including for support, infrastructure and AI-assisted functionality. Any such transfer is subject to the safeguards set out in Article 7.2.
7.2 The Processor may transfer personal data to a country outside the EEA only where an adequate level of protection is ensured, including on the basis of an adequacy decision or appropriate safeguards under Chapter V GDPR (such as the European Commission's standard contractual clauses).
8.1 Taking into account the nature of the processing, the Processor shall assist the Controller, insofar as reasonably possible, in responding to requests by data subjects exercising their rights under Chapter III GDPR. The Processor may charge reasonable costs for such assistance.
8.2 The Processor shall not respond substantively to a data subject request itself, but shall forward it to the Controller without undue delay and in any event within three (3) working days of receipt. The Processor may inform the data subject that the request has been forwarded and provide the Controller's contact details.
9.1 Taking into account the nature of the processing and the information available to it, the Processor shall, where reasonably appropriate, provide the Controller with such assistance as is reasonable in the circumstances in connection with any data protection impact assessment (DPIA) carried out by the Controller and any related prior consultation with a supervisory authority. The Controller remains solely responsible for determining whether a data protection impact assessment or prior consultation is required and for carrying these out. The Processor may charge reasonable costs for assistance beyond the provision of standard information.
10.1 The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data. Where complete information is not available at the time of the initial notification, the Processor shall provide it in phases as it becomes available.
10.2 The notification shall include, to the extent known: (a) the nature of the breach, including where possible the categories and approximate number of data subjects and personal data records concerned; (b) the name and contact details of a contact point; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address and mitigate it.
10.3 The Controller is solely responsible for assessing whether the breach must be notified to the supervisory authority and/or to data subjects, for making any such notification within the applicable statutory deadlines, and for maintaining the register of breaches required by Article 33(5) GDPR. The Processor's notification to the Controller does not constitute an acknowledgement of fault or liability.
11.1 The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits conducted by the Controller or an independent auditor mandated by the Controller (who must not be a competitor of the Processor and must be bound by confidentiality).
11.2 Audits may take place at most once per calendar year, unless a material personal data breach attributable to the Processor warrants an additional audit, on at least thirty (30) working days' prior written notice specifying scope, nature and timing, during business hours, and without unreasonable disruption to the Processor's operations.
11.3 The Processor may satisfy its audit obligations by providing relevant extracts of a recent audit report or certification, prepared by an independent third party within the preceding year, where these reasonably address the Controller's request. The Processor does not warrant that it holds any such certification in its own name.
11.4 Audits are carried out at the Controller's cost, and the Processor may charge a reasonable fee for the time and resources spent in facilitating an audit, of which it will provide a prior estimate. If an audit reveals a material non-compliance attributable to the Processor, the Processor shall bear the reasonable costs of that audit.
11.5 Audits and their findings are Confidential Information of both Parties.
12.1 This DPA takes effect together with the Agreement and continues for as long as the Processor processes personal data on the Controller's behalf. Provisions that by their nature are intended to survive remain in force after termination.
12.2 This DPA terminates automatically upon termination of the Agreement.
12.3 Upon termination, the Processor shall, at the Controller's request, return or delete all personal data (including copies) within thirty (30) days. The Processor may give effect to deletion by irreversibly anonymising the personal data, unless the Controller requests actual deletion or return. This does not apply where: (i) Union or Member State law requires continued storage; (ii) the data is held in routine backups, in which case it will be deleted or overwritten in the ordinary course and in any event no later than six (6) months after termination; or (iii) the Controller has requested, or is exercising, a switch, data export or retrieval in respect of the Service, in which case the Processor shall retain the relevant personal data only for as long as necessary to complete it. The Controller is responsible for exporting and retrieving its data in good time using the Service's export functionality.
12.4 Where deletion is not technically feasible, the Processor shall inform the Controller and take reasonable measures to block the data from further processing and, where technically possible, to anonymise it.
13.1 The liability of the Parties under or in connection with this DPA is governed by, and subject to, the limitations and exclusions of liability set out in the General Terms and Conditions of unTill Air, which apply to this DPA as if set out in full. As between the Parties, each Party bears responsibility for the processing of personal data in accordance with the roles allocated under the GDPR, and the Controller's indemnity for data and instructions for which it is responsible applies in addition to, and is not limited by, the foregoing. Nothing in this Article limits any liability that cannot be excluded or limited under mandatory law.
14.1 The Processor may amend this DPA where reasonably necessary to comply with applicable law or to reflect changes to the Service or to sub-processors, on reasonable prior notice. Other amendments require the written agreement of both Parties.
14.2 This DPA is governed by the laws of the Netherlands. Disputes shall be submitted exclusively to the competent court having jurisdiction over the place of business of the Processor, unless mandatory data protection law requires otherwise.
Annex 1: Details of the processing
Processor identity and contact: unTill AIR B.V., Korte Eeweg 11, 4424 NA Wemeldinge, the Netherlands, KvK 90937287, email (privacy@untill.com)
Data Protection Officer: Not applicable
Duration of processing: From the effective date of the Agreement until its expiry or termination
Nature and purpose of processing: Provision of the unTill Air Service under the Agreement, and related maintenance and support.
Categories of data subjects: The Controller's Authorised Users and employees. In addition, the Controller may, through free-text fields and the digital-receipt functionality, enter data relating to the Controller's own guests or end-customers.
Categories of personal data: Account, contact and identification data of Authorised Users and employees, such as name, email address, telephone number and user ID; authentication and access data, including data used for two-factor authentication; where required by local fiscal law, identifiers such as the Belgian social-security number; support communications, including messages exchanged via the in-application support channel and WhatsApp; and any personal data that the Controller elects to enter into free-text fields, such as an order or table name, a kitchen or bar message, or a guest email address used to send a digital receipt.
Special categories of personal data: None. The Controller shall not enter special categories of personal data or data relating to criminal convictions and offences, including allergy, dietary or health information relating to a guest. Where the Controller nonetheless enters such data, it does so at its own risk and remains solely responsible for its lawfulness.
Frequency of processing: Continuous, for the duration of the Agreement.
Retention period: Retained for the duration of the Agreement and thereafter deleted in accordance with Article 12.3.
Annex 2: Sub-processors
Upon entry into force of this DPA, the Controller authorises the following sub-processors:
Hetzner Online GmbH
Place of establishment: Gunzenhausen, Germany and Finland (European Union)
Purpose: Hosting and storage of the Service and data
CM.com N.V. (trading as CM.com; including the 'Hello' support tool), KvK 70523770
Place of establishment: Breda, the Netherlands (European Union)
Purpose: AI-assisted customer support communication; communication services (SMS, notifications and transactional messaging)
Chargebee B.V., KvK 75453797
Place of establishment: Amsterdam, the Netherlands (European Union)
Purpose: Subscription management, billing and related onboarding communications
RetailForce Software GmbH
Place of establishment: Steyr, Austria (European Union)
Purpose: Fiscal integration and compliance with local tax authorities
Google Ireland Limited
Place of establishment: Dublin, Ireland (European Union)
Purpose: Infrastructure and performance monitoring (Firebase, Google Cloud); AI-assisted menu recognition (Gemini)
Intercom R&D Unlimited Company
Place of establishment: Dublin, Ireland (European Union)
Purpose: Customer communication, AI support chatbot and customer relationship management
Grafana Labs GmbH
Place of establishment: Berlin, Germany (European Union)
Purpose: Application performance monitoring and observability
Freshworks Technologies B.V.
Place of establishment: Utrecht, the Netherlands (European Union)
Purpose: Customer support ticketing and helpdesk communication
OpenAI Ireland Limited (ChatGPT)
Place of establishment: Ireland (European Union)
Purpose: AI-assisted menu recognition (processing of menu images to propose articles and prices)
BMC
Place of establishment: European Union
Purpose: Fiscalisation of transactions for the Belgian market (secure recording, signing and reporting to comply with local tax authorities)
Eutronix
Place of establishment: European Union
Purpose: Fiscalisation of transactions for the Belgian market (secure recording, signing and reporting to comply with local tax authorities)
fiskaly
Place of establishment: European Union
Purpose: Fiscalisation of transactions for the German market (secure recording, signing and reporting to comply with local tax authorities)
EFSTA IT Services GmbH
Place of establishment: European Union
Purpose: Fiscalisation of transactions for the German market (secure recording, signing and reporting to comply with local tax authorities)
Second-line support partner (selected by the Controller during the (online) order process)
Place of establishment: European Union
Purpose: (i) Receipt of summaries of support conversations generated by the Processor's AI support systems; and (ii) remote access to the Controller's environment within the Service for the purpose of resolving support requests.
This list will be updated to reflect any changes.
Annex 3: Technical and organisational security measures
Organisational measures:
Access to personal data restricted to personnel who need it for the Service, subject to confidentiality obligations;
Periodic review and evaluation of the effectiveness of security measures;
Procedures for retention and deletion in accordance with the Agreement.
Technical measures:
Encryption of data in transit (TLS) and, where applicable, at rest;
Role-based access control, unique accounts and, where available, multi-factor authentication;
Network segmentation, patch management, monitoring and alerting;
Regular encrypted backups stored within the EU/EEA;
Audit logging of relevant events, including login events;
Hosting on infrastructure located in the EU, in data centres in Germany and Finland certified to ISO/IEC 27001:2022 and BSI C5 Type 2.
Try unTill Air 14 days for free - no payment details needed. Customise the app effortlessly for your business.
We’ve gathered all the information you need, so you can quickly and easily find the answers you’re looking for.
We’ve gathered all the information you need, so you can quickly and easily find the answers you’re looking for.