HappyBag Legal Centre

Data Processing Agreement

Last updated: 29 July 2026 · Version v1.0

These documents explain how HappyBag protects your data and how the platform should be used.

Status

This page summarises how HappyBag processes personal data on behalf of restaurants. A full, signable DPA is being prepared for commercial launch.

For legal review: Replace this summary with the solicitor-approved DPA, including standard contractual clauses where data leaves the UK/EEA.

Roles

The restaurant is the data controller for its customer data. HappyBag acts as a data processor, processing that data only to provide the platform and on the restaurant's instructions.

Scope of processing

  • Subject matter: providing the HappyBag ordering and customer platform
  • Duration: for as long as the restaurant's account is active
  • Data subjects: the restaurant's customers and staff users
  • Data types: names, phone numbers, order history, marketing consent

Security and subprocessors

Access to restaurant data is restricted to the owning account. We use reputable infrastructure, messaging and email providers as subprocessors and require appropriate data protection commitments from them.

Assisting the controller

HappyBag provides built-in tools for exporting customer data, deleting a customer, anonymising a customer and managing marketing consent, so restaurants can respond to data subject requests directly.

Request a copy

To request the DPA for signature, email privacy@happybag.co.