Legal

Data processing addendum.

Last updated 15 September 2026Processor Abiroot SARL, LebanonStatus Draft summary

When your restaurant runs its menu and AI waiter on tamr, you decide why guest data is processed and we process it for you. This addendum sets out how, in line with Article 28 of the GDPR. [Lawyer to confirm: final terms of the addendum]

What this addendum covers

This addendum forms part of the Terms between Abiroot SARL ("tamr", the processor) and the restaurant that holds a tamr account ("you", the controller). It applies to personal data tamr processes on your behalf. It does not cover data tamr handles as a controller in its own right, such as your team's account and billing data or data used to keep the platform secure. Those are covered by our privacy policy.

Details of processing

Subject matter
Processing guest data to provide your digital menu, AI waiter, and the insights built on them.
Duration
For as long as you use tamr, plus the time needed to delete the data afterwards as described below.
Nature and purpose
Hosting and serving menus, answering guest questions with AI, transcribing voice notes, remembering returning guests' preferences, storing conversations, and producing insights and reports for you.
Data subjects
Guests who use your menu or AI waiter, and your staff who use the tamr dashboard.
Categories of data
Guest session identifiers, user agent and language, keyed pseudonyms, taste profiles (dietary tags, allergens mentioned, recommendations, visit counts), chat transcripts, voice transcripts, and menu interaction events. For staff: name, email and actions taken in the dashboard.
Special categories
Allergens and dietary needs a guest mentions may reveal health information or religious belief. [Lawyer to confirm: treatment of allergen and dietary data as special category data]
Retention
Set by you in Settings, Privacy. By default conversations are kept 365 days after they end and taste profiles 540 days after the last visit.

Instructions and confidentiality

  • tamr processes guest data only on your documented instructions. Your use of the product and your settings are those instructions.
  • If we believe an instruction breaks data protection law, we will tell you.
  • Everyone at tamr who can access the data is bound by confidentiality.
  • We do not sell guest data or use it for our own advertising.

Security measures

tamr keeps technical and organisational measures in place to protect the data, including encryption in transit, encrypted backups, isolation of each restaurant's data, role-based access and audit logging. The current measures are described on our security page.

Subprocessors

You authorise tamr to use the subprocessors on our subprocessors page. We bind each one to data protection terms that are at least as protective as this addendum, and remain responsible for them. We give you notice before adding or replacing a subprocessor, so you can object. [Lawyer to confirm: notice period and what happens on objection]

Helping with guest requests

We help you respond to guests who exercise their rights under data protection law.

  • Guests can delete their own taste profile, conversations and sessions at your restaurant with Forget me in the chat.
  • You can set retention windows and turn on redaction of phone numbers and emails in Settings, Privacy.
  • For access, export or other requests, email [email protected] and we will help you find and export or delete the data.
  • If a guest contacts us directly, we will pass the request to you.

We also give reasonable help with data protection impact assessments and consultations with authorities.

Personal data breaches

If we become aware of a personal data breach affecting your guest data, we will notify you without undue delay, with the information we have about what happened, the data involved and what we are doing about it. [Lawyer to confirm: maximum notification window in hours]

Deletion at the end

When you delete your restaurant or your account, we delete the guest data we process for you, including uploaded files. You can export data before you leave. Copies in our encrypted backups expire within about 4 weeks. We keep data longer only where the law requires it. [Lawyer to confirm: return of data on request and its format]

Audits

We make available the information you reasonably need to show that this addendum is being followed, and allow audits by you or an auditor you appoint, on reasonable notice. [Lawyer to confirm: audit frequency, notice and cost allocation]

International transfers

tamr is operated from Lebanon and hosts its main servers in Amsterdam, Netherlands. Where data is transferred outside the EU, we rely on Standard Contractual Clauses or equivalent safeguards. [Lawyer to confirm: transfer mechanism between the restaurant and tamr as a processor in Lebanon]

Getting the signed DPA

This page is a summary. A full data processing addendum, ready to sign, is available on request.

Request the signed DPA

Email [email protected] with your restaurant's legal name and the account it relates to.