Data processing terms
Last updated 7 October 2026
These terms form part of our agreement with every business that uses UnitedPos. They cover the personal data the business puts into UnitedPos about its guests and staff, which we process on its behalf, as Article 28 of the UK GDPR requires.
Roles
The business is the controller of this data. United Payments Ltd is its processor. We process the data only to provide UnitedPos and only on the business's documented instructions, which are our agreement and the settings it chooses in UnitedPos, unless the law requires otherwise; if it does, we tell the business first unless the law forbids it.
What is processed
| Subject matter and purpose | Running the business's till, back office, bookings and online orders: taking and paying for orders, kitchen tickets, receipts, reports, staff sign-in and time records. |
|---|---|
| Duration | The agreement, then up to 30 days for export before deletion. |
| People | The business's guests and customers, people who book or order online, and its staff. |
| Kinds of data | Names, phone numbers, email addresses, orders, bookings, loyalty points, gift card balances, receipts; for staff, names, roles, PIN verifiers, clock-in times, rotas and pay rates. |
| Special category data | Allergies recorded against a table, an order or a customer are health data. They are used only so the kitchen can serve the guest safely. |
What we commit to
- Everyone at United Payments Ltd who can reach the data is bound to keep it confidential.
- We keep it secure with appropriate technical and organisational measures: encryption between tills, back office and servers, encryption on each till, access by role, audit trails and regular backups.
- We help the business answer requests from people exercising their rights, for example by finding, exporting or erasing a customer's details. The back office can erase a customer's personal details while keeping the sales figures.
- We help the business meet its own duties on security, breach reporting and data protection impact assessments, as far as our part allows.
- We tell the business without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting its data.
- When the agreement ends we return the data by export and then delete it, unless the law requires us to keep it.
- We give the business the information it reasonably needs to show these terms are kept, and allow audits on reasonable notice.
Sub-processors
The business gives general authorisation for us to use sub-processors for hosting, databases, the back office website and email delivery. We bind each by contract to terms that protect the data as these terms do, and remain responsible for them.
We keep a current list and send it on request to info@upayments.co.uk. We tell customers at least 30 days before adding or replacing a sub-processor, and the business may object on reasonable data protection grounds.
Payment providers and delivery platforms the business connects are not our sub-processors: the business has its own agreement with them.
International transfers
We host in the United Kingdom where we can. We transfer the data outside the UK only with a safeguard recognised by UK law, such as adequacy regulations or the International Data Transfer Agreement.
Contact
Questions about these terms or a request to sign a copy: info@upayments.co.uk.