Business data terms
Data Processing Addendum
This Addendum forms part of the PeckQ Terms when IMPI TECH processes guest personal information for a restaurant customer.
1. Parties and roles
The “Customer” is the restaurant business using PeckQ. “IMPI TECH” is IMPI TECH (PTY) LTD, registration number 2016/356031/07. For guest waitlist information, Customer is the responsible party/controller and IMPI TECH is the operator/processor. Terms such as personal information, processing, operator, processor, responsible party, controller, data subject, and supervisory authority have their meanings under applicable data protection law.
2. Processing details
| Subject | Operation of PeckQ's restaurant waitlist and queue-linked messaging. |
|---|---|
| Duration | For the service term and the documented retention/deletion period. |
| People | Waitlist guests and authorized restaurant users where their data appears in guest operations. |
| Data | First name, normalized phone number/messaging identity, party size, restaurant/location, waitlist state and timestamps, final outcome, queue-linked messages, and necessary delivery/security metadata. |
| Purpose | Join, manage, message, audit, secure, support, and retain the restaurant's waitlist as described in the Terms and Privacy Policy. |
3. Customer instructions
IMPI TECH will process guest personal information only on Customer's documented instructions expressed through the agreement and lawful use of PeckQ, unless law requires otherwise. IMPI TECH will inform Customer if an instruction appears to violate applicable data protection law, where legally permitted. Customer is responsible for its lawful basis, notices, instructions, staff authorization, and accuracy of data it controls.
4. Confidentiality and security
IMPI TECH limits access to people and providers who need it and are subject to suitable confidentiality duties. Security measures include encryption in transit and at rest, tenant-scoped authorization, least-privilege cloud access, protected credentials, conditional data operations, auditability, backups, and privacy-aware logs. Measures may evolve while maintaining an appropriate level of protection for the risk.
5. Subprocessors
Customer authorizes IMPI TECH to use subprocessors needed to operate PeckQ. Current core subprocessors include Amazon Web Services for cloud infrastructure and Meta/WhatsApp for guest messaging. Relevant authentication and payment providers may process data in their separate roles. IMPI TECH remains responsible for imposing appropriate data-protection obligations on subprocessors acting on its behalf.
We will publish or otherwise provide reasonable notice of a material new subprocessor. Customer may raise a reasonable data-protection objection before the change takes effect; if it cannot be resolved, either party may end the affected service.
6. International transfers
IMPI TECH may process data in countries outside Customer's country. PeckQ's primary application infrastructure is in AWS's Frankfurt region. Where required, IMPI TECH will use an applicable lawful transfer mechanism and reasonable supplementary safeguards.
7. Data-subject requests
Taking account of the nature of processing, IMPI TECH will provide reasonable assistance so Customer can respond to verified data-subject requests. If IMPI TECH receives a request concerning Customer-controlled guest data, it may direct the requester to Customer and notify Customer, unless law prohibits this.
8. Incidents and compliance assistance
IMPI TECH will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer-controlled data and will provide reasonably available information needed for Customer's legal assessment. IMPI TECH will reasonably assist with risk assessments, regulator enquiries, and compliance information in light of the processing and information available to it.
9. Return and deletion
On termination or a valid instruction, IMPI TECH will delete or return Customer-controlled personal information where reasonably supported, unless law requires retention. Draft messaging data is generally retained up to seven days; established customer and waitlist history is generally retained up to 12 months after the latest waitlist entry. Technical backup and TTL deletion may complete later under protected lifecycle controls.
10. Information and audit
IMPI TECH will make information reasonably necessary to demonstrate compliance with this Addendum available to Customer. If that is insufficient, the parties may agree a proportionate audit that protects other customers, confidentiality, and security and avoids unreasonable disruption or cost.
11. Priority and contact
If this Addendum conflicts with the Terms about processing Customer-controlled personal information, this Addendum controls. Other Terms remain unchanged. Questions and requests: contact@peckq.com. IMPI TECH (PTY) LTD's registered and service address is 244 Boshoff Street, Muckleneuk, Pretoria, 0181, South Africa.