Scope and instructions
The restaurant identified in the order is the controller and the DriverDrops operator is the processor for restaurant personal data. Our independent business administration, billing and legally required processing are covered separately by the privacy notice.
Processing supports delivery coordination, access, shifts and pay estimates. It includes collecting, storing, displaying, organising, calculating, transmitting, restricting and erasing information during service provision and the agreed return or deletion process. People include restaurant workers, account users and delivery customers. Data includes identity and contact details, membership, delivery records, notes, shift and pay evidence and latest optional location.
The proposed agreement requires DriverDrops to follow documented lawful instructions, including valid service settings. If law requires other processing, DriverDrops informs the restaurant unless notice is prohibited. It flags instructions it considers unlawful. Special-category and criminal-offence information is not intended for the service and should not be deliberately entered without a separately agreed lawful arrangement.
Confidentiality and protection
The proposed agreement requires confidentiality for authorised personnel and access limited to their duties. It requires risk-appropriate technical and organisational security, maintained throughout processing.
Current product measures include encrypted production transport, restaurant and role access controls, protected sign-in credentials, encrypted mobile working storage and filtered error reporting. No individual measure guarantees protection against every incident.
Subprocessors and transfers
The final accepted provider register identifies authorised contracted subprocessors. The proposed agreement requires equivalent data-protection obligations, continued DriverDrops responsibility for those obligations, advance written notice of changes and an opportunity to raise reasonable data-protection objections. Unresolved objections require an alternative arrangement or ending the affected service.
Transfers outside the UK require an applicable lawful mechanism and any required assessment. Overseas support access is included in that assessment. A London database does not by itself establish that all processing remains in the UK. The published provider list is an inventory, not evidence that every listed provider has the same contractual role.
Requests, incidents and accountability
The proposed agreement requires DriverDrops to promptly forward rights requests concerning restaurant data and provide reasonable assistance with access, correction, deletion, restriction and portability. The restaurant remains responsible for decisions about its contested employment records.
DriverDrops must notify the restaurant without undue delay after becoming aware of a personal-data breach affecting its data, provide available information in stages, and assist with security, incident reporting, impact assessments and regulatory consultation as required.
DriverDrops must provide information needed to demonstrate compliance and allow and contribute to appropriate audits and inspections by the restaurant or its appointed auditor. Practical confidentiality and security arrangements cannot remove statutory rights or regulatory powers.
When processing ends
The proposed agreement provides for return or deletion of restaurant personal data at the restaurant's choice after service provision, including existing copies, unless law requires storage. The final agreement must document the actual return method, timing and backup isolation and expiry arrangements. Retained information remains protected and cannot be reused for ordinary service.
Restaurants remain responsible for lawful instructions, transparency and monitoring necessity. Neither party can use a contract to remove an individual's rights or its own statutory duties.