Last updated: 21 June 2026
Data Processing Agreement (summary)
This page summarises how Kiteline processes personal data on behalf of kitchen software customers. A full signed DPA is available on request for B2B contracts.
Roles
You (the customer) are the data controller for kitchen and staff data you enter. Kiteline is the data processor when hosting the service for you.
What we process
- Staff account details (name, email, role)
- Operational kitchen data (logs, recipes, allergens, labels, waste)
- Technical logs for security and support
Our obligations
- Process data only to provide the Kiteline service
- Maintain appropriate security (HTTPS, hashing, isolation)
- Assist with data subject requests where applicable
- Notify you of personal data breaches without undue delay
- Use sub-processors listed in our Privacy Policy
Sub-processors
Hosting (Render), database (Neon Postgres when configured), payments (Stripe), email (SMTP provider), and security tools (e.g. Cloudflare Turnstile) may process data on our behalf. See the sub-processors section in our Privacy Policy.
Retention & deletion
Data is retained while your account is active. Backups are kept for disaster recovery (typically 30–90 days). Email contact@kiteline.uk for export or deletion requests.
Request a full DPA
Email contact@kiteline.uk with your company name and we will send a standard UK GDPR Data Processing Agreement for signature.