Updated March 2026
Data Processing Agreement
This DPA forms part of the Lekro Terms of Service and guarantees our commitment to global Data Protection regulations like GDPR.
1. Introduction and Scope
This Data Processing Agreement (“DPA”) forms part of the Lekro Terms of Service. It applies when Lekro (“Data Processor”) processes personal data on behalf of the Restaurant (“Data Controller”) that is subject to the General Data Protection Regulation (GDPR) or similar global data protection laws.
2. Details of the Processing
Subject Matter
The provision of the Lekro SaaS platform, including digital menu hosting and reservation management.
Nature/Purpose
To store, organize, and retrieve data as necessary to facilitate reservations between Restaurant and Diners.
Data Subjects
The Restaurant’s customers, patrons, and website visitors (“Diners”).
Types of Data
Names, emails, phone numbers, reservation times, and any other configurable data.
3. Obligations of the Data Processor
We process Diner data solely on the documented instructions of the Restaurant (providing platform functionality). We will not use this data for our own purposes.
All authorized personnel have committed to strict confidentiality. We implement robust, encrypted database architectures and industry-standard cloud infrastructure to protect against unauthorized access.
The Restaurant is primarily responsible for handling Diner requests. Lekro provides the necessary technical tools within the platform to allow the Restaurant to fulfill these requests (e.g., deleting a reservation).
- Sub-processors
The Restaurant grants Lekro general authorization to engage third-party sub-processors (like cloud hosting and CDNs) to support infrastructure, provided they are bound by equivalent data obligations.
- Breach Notify
In the event of a confirmed security breach leading to unauthorized disclosure of Diner data, we will notify the Restaurant without undue delay after becoming aware of the incident.
- Deletion or Return
Upon termination of the subscription or direct request, we securely delete or anonymize all associated Diner personal data from our active systems, unless storage is required by law.
7. Obligations of the Data Controller
The Restaurant explicitly warrants that it has all necessary legal rights, bases, and consents required to collect the personal data of its Diners and securely transfer it to Lekro for processing.