Version
Version 1.0 · Draft for legal review · Effective date to be confirmed
About this agreement
This Data Processing Agreement (the “DPA”) forms part of the Terms of Service between Monty and the Customer. It applies whenever Monty processes Customer Personal Data in providing the Services. If this DPA conflicts with the Terms, this DPA takes priority on data protection matters.
Monty is [company name], a company registered in England and Wales under company number [company number], whose registered office is at [registered office address].
Definitions
- Data Protection Law: the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and, where they apply, the EU GDPR and the laws of EU member states.
- Customer Personal Data: personal data in Customer Data that Monty processes on the Customer’s behalf, as described in Annex 1.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- Sub-processor: a third party engaged by Monty to process Customer Personal Data.
- Other terms, such as controller, processor, data subject and processing, have the meaning given in Data Protection Law. Capitalised terms not defined here have the meaning given in the Terms.
Roles
The Customer is the controller of Customer Personal Data and Monty is its processor. Where the Customer acts as a processor for another controller, for example a group company, Monty is its sub-processor.
Monty processes Customer Personal Data only on the Customer’s documented instructions. The Customer’s instructions are the Terms, this DPA, the Customer’s configuration and use of the Services, and any further written instructions it gives that are consistent with them. Monty will tell the Customer if it believes an instruction breaks Data Protection Law.
The Customer’s responsibilities
The Customer is responsible for:
- having a lawful basis for the processing, and any consent the law requires, including before marketing to guests;
- giving guests and staff the information the law requires, for example by linking to the Guest Privacy Notice alongside its own privacy notice;
- the accuracy of the personal data it provides, and the lawfulness of its instructions;
- not using the Services to collect special category data, such as health information, unless it has a lawful basis and has told Monty.
Confidentiality
Monty will make sure that everyone it authorises to process Customer Personal Data is bound by a duty of confidentiality, and only has access to the extent their work requires.
Security
Monty will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation and the risks involved. The measures in place are described in Annex 2. Monty may update them, provided the overall level of protection is not reduced.
Sub-processors
The Customer gives Monty general authorisation to engage Sub-processors. The current Sub-processors are listed on our Sub-processors page.
- Monty will give the Customer at least 30 days’ notice before adding or replacing a Sub-processor, by updating that page and telling account holders.
- The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may end the affected Services and receive a refund of prepaid fees for the unused period.
- Monty will impose data protection obligations on each Sub-processor that are no less protective than this DPA, and remains responsible for its Sub-processors’ performance.
International transfers
Monty will only transfer Customer Personal Data outside the UK, or where the EU GDPR applies outside the European Economic Area, where the transfer is covered by adequacy regulations or decisions, the UK Extension to the EU–US Data Privacy Framework, or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures required.
Assistance
Taking into account the nature of the processing, Monty will help the Customer:
- respond to requests from guests and staff to exercise their rights. If Monty receives such a request directly, it will pass it to the Customer without undue delay and will not respond itself unless instructed to;
- meet its obligations on security, breach notification, data protection impact assessments and prior consultation with the regulator.
Personal data breaches
Monty will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include, as far as it is known, the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed. Monty will take reasonable steps to contain the breach and will keep the Customer informed.
Deletion and return
When the Services end, the Customer may ask for a copy of its Customer Personal Data within 30 days. After that, Monty will delete Customer Personal Data from the Services within 90 days, and from backups as they expire, unless the law requires it to be kept.
Information and audits
Monty will make available the information reasonably needed to show that it complies with this DPA. Where that information is not enough, the Customer may carry out an audit, at its own cost, no more than once a year, on at least 30 days’ written notice, during business hours and subject to reasonable confidentiality obligations.
Liability and term
Each party’s liability under this DPA is subject to the limitations in the Terms. This DPA lasts for as long as Monty processes Customer Personal Data.
Annex 1: Details of the processing
| Subject matter | Providing the Services described in the Terms. |
|---|---|
| Duration | The term of the agreement, and the deletion period that follows it. |
| Nature and purpose | Collecting and storing guest feedback and reviews; alerting staff to problems and tracking them; sending messages to guests and staff on the Customer’s behalf; generating reports, summaries, sentiment scores and draft replies, including with AI; managing staff profiles, leaderboards and wallet passes. |
| Data subjects | The Customer’s guests; its staff and other Authorised Users. |
| Guest data | Ratings, comments and photos; language; email address and phone number where given; name where given in a guest issue; details of problems reported and how they were resolved; mailing list consent; the touchpoint and member of staff a response came through. |
| Staff data | Name, email address, phone number and photo; role and areas; activity in the Services, such as feedback collected and alerts handled; wallet pass details. |
| Special category data | Not intended. Guests may volunteer such information in free text, for example about an allergy. |
Annex 2: Security measures
- Hosting: Customer Personal Data is stored in a managed database hosted in the European Union (Sweden), encrypted at rest by the hosting provider, with regular backups.
- Encryption in transit: all connections to the Services use TLS.
- Access control: role-based permissions in the Monty app limit what each person can see and do within an account.
- Authentication: users sign in with one-time sign-in links or codes, or with a password stored only as a one-way hash.
- Staff access: Monty’s own staff access Customer Personal Data only where needed to provide support or run the Services.
- Suppliers: Sub-processors are chosen for their security practices and bound by written data protection terms.
- Incidents: suspected breaches are investigated, contained and, where required, reported as set out in this DPA.
- Deletion: data is deleted at the end of the agreement as set out above.
Annex 3: Sub-processors
The current list of Sub-processors, what each one does and where it processes data is on our Sub-processors page. Questions: help@monty.reviews.