1. Processing schedule — to be agreed
| Item | Proposed scope |
|---|---|
| Parties | The named takeaway customer as controller; UNLIMIT DIGITAL LTD as processor. |
| Subject matter and purpose | Administration of the controller’s delivery, driver and cash-reconciliation records. |
| Nature of processing | Collection on instructions, storage, retrieval, calculation, display, export and authorised deletion. |
| Individuals | Takeaway staff, delivery drivers, customers and delivery contacts. |
| Personal information | Account/contact details, delivery addresses, receipt identifiers, cash/pay amounts, shift/mileage records, notes and latest on-shift coordinates. |
| Duration | The agreed service term plus a defined return/deletion period and limited lawful holds. Actual periods are not yet approved. |
2. Documented instructions and confidentiality
The proposed processor obligation is to process only on the controller’s documented instructions, including instructions for transfers, unless applicable law requires otherwise. The processor must notify the controller of a binding legal requirement where legally permitted and flag an instruction it considers unlawful.
Access must be limited to authorised personnel bound by confidentiality. The final schedule must identify who may issue instructions and how changes are recorded.
3. Security and assistance
The parties must agree technical and organisational measures proportionate to the risks. Implemented application measures include password hashing, tenant checks, session revocation, origin validation and dated activity entries. These are not a complete production security schedule.
The proposed assistance covers individual rights, security assessments, DPIAs and regulatory consultation. The company must establish a tested incident process and notify the controller without undue delay after becoming aware of a personal data breach, supplying available information and follow-up updates. The controller separately assesses any regulator notification deadline.
4. Subprocessors and transfers
Appoint subprocessors only under prior specific or general written authorisation, with equivalent data-protection obligations. If general authorisation is used, define change notices and a meaningful opportunity to object. Identify each legal entity, service, data location and transfer mechanism in an agreed annex.
Production hosting and other subprocessors are unappointed. No placeholder provider list constitutes customer authorisation, and a standard clause link alone does not complete a transfer assessment.
5. Audit, return and deletion
The processor must make necessary compliance information available and allow and contribute to proportionate audits and inspections. Scope, secure evidence sharing and confidentiality should be documented without frustrating statutory audit rights.
At the controller’s choice, return or delete personal data after the service, and delete copies unless applicable law requires storage. Specify export formats, timeframes, backup handling and limited legal holds. The current application does not yet implement that complete workflow.
5A. Driver checks, monitoring and messaging instructions
The web/backend pilot now supports business-directed driver expiry/reference records and review decisions, activity reports, private incident media and business-driver messages. Before production use, agree these categories, purposes, authorised roles, providers/transfers, retention, rights assistance and security measures in the processing schedule. Automated government or insurance checks, released native identity onboarding, automatic customer arrival messaging and shared-driver matching remain outside the implemented schedule.
For the intended business-directed driver-check service, the engaging business performs and determines its required checks, retains the necessary evidence and communicates decisions and notices. The processor records and protects data on lawful documented instructions; it does not certify right to work, driving entitlement or insurance cover. Responsibility for a statutory check cannot be removed by this allocation.
Limit evidence access to authorised reviewers, maintain access/decision records, protect transfers and stored files, and use separate retention schedules. Customer contact and channel permission records must be sufficient for the instructed service message. Sharing between businesses or use for unrelated marketing requires its own authority and assessment; no such permission is implied.
Actual processing determines controller and processor roles. Where the company determines its own purposes or means, such as platform security or a future matching service, assess and disclose the resulting role and lawful basis. The company must meet its own statutory duties and inform the controller if, in its opinion, an instruction infringes applicable data-protection law. No service-term disclaimer removes those obligations or individual statutory remedies.
6. Before this agreement can take effect
- Name the customer and authorised signatories; settle the service contract and precedence provisions.
- Complete the retention, security, approved-subprocessor and transfer annexes.
- Publish working incident/privacy contacts and test assistance, return and deletion procedures.
- Obtain appropriate legal review and record mutual agreement. This page is not an executed DPA.
Official guidance & references
The sources below inform the review. They do not certify this product or replace the company’s operational responsibilities.
EDPB: controller and processor responsibilitiesEU General Data Protection Regulation