1. Roles of the parties
Where RTR processes personal information on behalf of a customer through the service, the customer acts as the controller (or equivalent decision-maker under applicable law) and Read the Room Systems Inc., operating as RTR Systems / ReadTheRoom ("RTR," "we," "us"), acts as the processor or service provider. This reflects the Terms of Service: the customer determines which business records it provides, the purposes for which it uses them, and who it authorizes to access them, and RTR processes those records to provide the customer's service.
This draft addendum supplements the Terms of Service. Where an agreed data-processing addendum applies, it controls conflicts concerning the processing of personal information, as stated in the Terms.
2. Subject matter and duration
The subject matter of processing is the provision of RTR's restaurant operations software — including access management, cashouts, tips, payments reconciliation, labour information, reporting, communications, and related workflows — as described in the Terms of Service and the customer's order.
Processing lasts for the term of the customer's service arrangement, plus any period in which records are retained as described in section 11 and the Privacy Policy.
3. Nature and purpose of processing
RTR processes customer personal information to provide the agreed service, carry out authorized instructions, support users, investigate service problems, and maintain security and reliability, consistent with section 4 of the Terms of Service. This includes storing records, computing reports and reconciliation views, delivering operational messages through configured channels, and, where AI features are used or enabled, sending the relevant question, conversation history, and retrieved records to the AI services supporting the feature.
RTR will not use customer personal information for its own independent purposes, sell it, or share it for cross-context behavioural advertising.
4. Types of personal data
The personal information processed depends on the features and integrations the customer uses, and may include the categories described in the Privacy Policy:
- Account and contact information (name, email address, verification status, mobile number, account identifiers).
- Access and activity records (organization and restaurant memberships, roles, invitations, access changes, the person who made an action, timestamps, recorded reasons).
- Workforce and operating records (employee names and identifiers, work assignments, schedules, time punches, hours, wage rates, sales attribution, performance measures, cashouts, tips, payouts, adjustments, and related notes).
- Transaction records (orders, items, amounts, payment status, transaction identifiers, payment method, card brand and last four digits).
- Messages and requests (support correspondence, operational messages, AI questions and conversation history).
- Technical information (IP address, browser and device information, session identifiers, sign-in times, errors, service usage, security or diagnostic records).
Data subjects may include the customer's employees and contractors (including, where applicable, staff who are minors, subject to the customer's employment-law and privacy obligations), as well as account holders and contacts.
5. Customer instructions
RTR will process customer personal information only on the customer's documented instructions, including the instructions embodied in the Terms of Service, the customer's order and configuration, and authorized user actions within the service. The customer is responsible for having the rights, notices, permissions, and lawful basis needed to submit customer data to RTR, as stated in the Terms of Service.
If RTR believes an instruction would violate applicable data-protection law, it will inform the customer before carrying it out, where permitted.
6. Sub-processors
RTR engages the sub-processors listed in the Privacy Policy sub-processor list to process customer personal information on its behalf. RTR will impose data-protection obligations on each sub-processor that are no less protective than those in this addendum, limited to the agreed service purposes.
RTR will update the published sub-processor list if its sub-processors change and will give customers notice of a material change before it takes effect where required. A customer that objects to a new sub-processor on reasonable data-protection grounds may contact [email protected] to discuss the concern.
7. Security measures
RTR uses safeguards appropriate to the information and service, including encrypted connections, authentication, and access controls, as described in the Privacy Policy. Access to customer personal information is limited to personnel and sub-processors who need it to provide the service and who are subject to appropriate confidentiality duties.
No service can guarantee absolute security. Specific security commitments beyond this draft, if any, belong in a written agreement.
8. Personal-data breach notification
If RTR becomes aware of a personal-data breach affecting customer personal information, it will notify the affected customer without undue delay and provide information reasonably needed for the customer to meet its own notification obligations, including the nature of the breach, the categories and approximate number of records concerned, and the measures taken or proposed. Where an incident requires notification under applicable law, RTR will provide the required notices, consistent with the Privacy Policy.
9. Assistance with data-subject requests
RTR will assist the customer, as reasonably required, in responding to requests from individuals to exercise their rights of access, correction, deletion, or objection, including by providing the tools and information described in the Privacy Policy and the data deletion request instructions. Where RTR receives such a request directly and the customer is responsible for it, RTR will direct the request to the customer where appropriate.
10. Audit
On reasonable written request and no more than once per year (unless a breach or regulator requires otherwise), RTR will make available information reasonably necessary for the customer to verify RTR's compliance with this addendum, subject to confidentiality protections and conducted so as not to unreasonably disrupt the service or compromise other customers' information.
11. Return and deletion
At the end of the service arrangement, RTR will, at the customer's written direction, return or delete customer personal information within a reasonable period, except where applicable law, backup practices, or legitimate security or dispute-resolution needs require retention, as described in the Privacy Policy. Backup copies are deleted on their normal rotation cycle.
12. General
This draft does not limit rights available under applicable law. Liability under this addendum is subject to the limitations in the Terms of Service unless a written agreement says otherwise. Unless a separate written agreement says otherwise, this addendum is governed by the laws of Ontario and the federal laws of Canada applicable there, consistent with the Terms of Service.
Questions about this draft can be sent to [email protected]. RTR does not provide legal advice; customers should have this draft reviewed by their own counsel before agreement.