Data Processing Policy
Which party is responsible for which data when a restaurant takes orders through Morsl.
Last updated
1. Purpose of this document
This policy sets out how dot bm ltd., which operates Morsl, processes personal data on behalf of the restaurants that use the platform (“Restaurants”), and where our own responsibility begins and ends. It sits alongside our Privacy Policy, which is written for individuals, and our Terms of Service. It is written against the Personal Information Protection Act 2016 (PIPA).
Restaurants operating under other data-protection regimes — for example a UK or EU business using Morsl — should contact us for a signed data processing agreement in the form their own regulator expects.
2. Who is responsible for what
The single most important distinction in this document. Two categories of data flow through the platform and they have different owners.
Where we act as processor
For data about diners and their orders — name, contact details, order contents, notes, collection or delivery address — the Restaurant is the controller and Morsl is the processor. The Restaurant decides why that data exists and what happens to it. We handle it on their documented instructions, which in practice means: running the ordering page, delivering orders to their kitchen, and storing the order history their dashboard shows.
We do not use diner data for our own purposes. We do not market to a Restaurant’s diners, and we do not share one Restaurant’s diner data with another.
Where we act as controller
For data we determine the purpose of ourselves, Morsl is the controller:
- Restaurant account and staff login details
- Billing and commercial contact information
- Platform usage, error, and security logs generated by running the service
- Website analytics for morsl.food
3. Categories of data processed
Diner data (processed for the Restaurant)
- Contact information: name, email address, phone number
- Order details: items, modifiers, special requests, order and collection times
- Delivery address, where the Restaurant offers delivery
- Payment outcome — whether payment succeeded, the amount, and a reference. Card numbers are handled by the payment provider and never reach Morsl’s systems
Restaurant data (processed by us as controller)
- Business name, address, opening hours, and contact details
- Staff account names, email addresses, and hashed passwords
- Sign-in history, dashboard activity, and support correspondence
4. Sub-processors
We use a small number of suppliers to run the platform. Each is bound by contract to process data only on our instructions and to a standard of security no lower than our own. They fall into these categories:
- Cloud hosting and managed database infrastructure
- Payment processing
- Transactional email delivery
- Error monitoring and application performance tracking
A current list of named sub-processors is available to any Restaurant on request from hello@morsl.food. We will give notice before adding a sub-processor that handles diner data.
5. International transfers
Some infrastructure suppliers operate outside Bermuda, which means data may be stored or processed overseas. Where that happens, we rely on suppliers who provide a comparable standard of protection and contractual safeguards to match.
6. Security measures
- Encryption of data in transit using current TLS
- Passwords stored using a one-way hash, never in readable form
- Access to production systems restricted to named individuals who need it
- Per-restaurant data isolation, so one Restaurant cannot reach another’s orders or menus
- Regular dependency and vulnerability patching
7. Data subject requests
Where a diner contacts us about data belonging to a Restaurant, we will not act on it ourselves — the Restaurant is the controller and the decision is theirs. We will pass the request to that Restaurant promptly and give them whatever assistance they need to answer it, including extracting or deleting records.
Where a request concerns data we control — a Restaurant staff account, for instance — we handle it directly under our Privacy Policy.
8. Breach notification
If we become aware of a breach affecting personal data we process for a Restaurant, we will notify that Restaurant without undue delay, with what we know about the cause, the scope, and what we are doing about it. The Restaurant, as controller, is responsible for notifying its diners and the regulator where the Personal Information Protection Act 2016 (PIPA) requires it; we will support that with whatever information it needs.
9. Retention and deletion
We retain diner and order data for as long as the Restaurant’s account is active, or as its own record-keeping obligations require. When a Restaurant leaves the platform, we give it a reasonable opportunity to export its data, then delete or anonymise it. Backups age out on their own retention cycle after that.
10. Contact
dot bm ltd.
Data protection enquiries: hello@morsl.food
Web: morsl.food