GDPR Compliance

Last updated: May 2026

At Zain (a service by Zain RMS) we treat data protection as a pillar of the product, not as paperwork. This page explains how we comply with the General Data Protection Regulation (Regulation EU 2016/679, "GDPR") and the French Data Protection Act (Loi n° 78-17 of 6 January 1978), and what that means for your restaurant and your guests.

If you're looking for how we handle your data as the account holder, see our Privacy Policy. This page focuses on the data of your guests, which Zain processes on your behalf.

1. Roles: Who Is the Controller and Who Is the Processor

The GDPR distinguishes two roles. Understanding them is key to knowing who is responsible for what:

  • Your restaurant is the "data controller" for your guests' data (name, phone number, bookings, preferences). You decide what it's used for.
  • Zain is the "data processor": we process that data solely on your instructions and to provide you with the Service (managing bookings, replying on WhatsApp, reminders). We never use your guests' data for our own purposes.

2. Data Processing Agreement (DPA)

When you activate your account, you sign a Data Processing Agreement with us (art. 28 GDPR), which forms part of the Terms of Service. In it, we commit to:

  • Process data only in accordance with your documented instructions.
  • Ensure the confidentiality of anyone who accesses the data.
  • Apply appropriate technical and organisational security measures.
  • Assist you in responding to rights requests from your guests.
  • Delete or return the data at the end of the Service.
  • Allow and contribute to compliance audits.

Need a signed copy of the DPA for your compliance records? Write to us at info@zainagent.com.

3. What Data We Process on Your Behalf

To provide the Service, we process the minimum data necessary about your guests:

  • Identification and contact: name and phone number (WhatsApp).
  • Booking data: date, time, number of guests, table assigned.
  • Preferences and notes: allergies, special requests and visit history that you or the guest provide.
  • Conversations: the messages exchanged with the agent to handle the booking.

We do not request or need special categories of data (art. 9 GDPR). We recommend you do not enter sensitive data that isn't essential for the Service.

4. Sub-processors

We rely on trusted providers that comply with the GDPR and with whom we have signed the corresponding agreements. Each one processes data only for the function indicated:

  • Insforge — PostgreSQL database in the cloud (EU).
  • Vercel — web application hosting (USA, Standard Contractual Clauses).
  • Meta (WhatsApp Business API) — messaging channel with your guests.
  • Resend — transactional email delivery (USA, SCCs).
  • Paddle — processing of your subscription payments (does not process guest data).

We will inform you in advance of any change to this list so you can object if you consider it necessary.

5. International Transfers

When a provider processes data outside the European Economic Area, the transfer is safeguarded by Standard Contractual Clauses approved by the European Commission or other appropriate safeguards provided for in Chapter V of the GDPR. The primary database is hosted in the EU.

6. Security Measures

We apply technical and organisational measures proportionate to the risk (art. 32 GDPR):

  • Encryption in transit (HTTPS/TLS) across all communications.
  • Role-based access control and the principle of least privilege.
  • Isolation of each restaurant's data (multi-tenant with row-level security).
  • Backups and audit logs.
  • Payment data never passes through our servers: it is processed by Paddle, which holds PCI DSS certification.

7. Security Breach Notification

If we detect a security breach affecting your guests' data, we will notify you without undue delay and, at the latest, within 72 hours of becoming aware of it, with the information you need to fulfil your notification obligations as controller (arts. 33 and 34 GDPR).

8. Your Guests' Rights

Your guests can exercise their rights of access, rectification, erasure, objection, restriction and portability. As controller, you are the one who handles those requests; we, as processor, assist you:

  • You can view, edit and delete a guest's data from your dashboard.
  • If you need to export or delete data in bulk, write to us and we will handle it together.
  • When you cancel the Service, we delete your guests' data within a maximum of 90 days, unless legally required to retain it.

9. Your Responsibility as a Restaurant

For processing to comply with the GDPR, as controller it is your responsibility to:

  • Inform your guests that their data is processed to manage their booking (you can link to this page and your own policy).
  • Have a legal basis for the processing (usually performance of the booking or consent).
  • Use the Service only for the agreed purposes and not enter unnecessary data.

10. Contact and Complaints

For any queries about data protection or to request the signed DPA: info@zainagent.com.

Both you and your guests may lodge a complaint with the French Data Protection Authority (CNIL), the supervisory authority, at www.cnil.fr.

Zain RMS.