Processing Agreement and Security Policy TablePlay Including sub-processor list, technical and organizational measures, responsible disclosure and accessibility statement
TablePlay by Jimani Jimani B.V. Albert Plesmanweg 122, 4462 GC Goes KvK 91644453 - VAT NL865722729B01 support@tableplay.online
Version 1.0 Last updated: July 10, 2026
Legal review note This document has been prepared for business use by TablePlay. Have the final publication, international application, current suppliers, technical setup and country-specific rules reviewed periodically by legal counsel.
Table of Contents Part A - Processing Agreement Annex 1 - Sub-processors Annex 2 - Technical and organizational measures Part B - Security and Coordinated Vulnerability Disclosure Part C - Accessibility Statement
Processing Agreement and Security Policy TablePlay
Page 2 of 10
Part A - Processing Agreement Article 1 - Parties This processing agreement applies between TablePlay's business customer as Controller and Jimani B.V., operating under the name TablePlay by Jimani, Albert Plesmanweg 122, 4462 GC Goes, KvK 91644453, as Processor. The parties are jointly referred to as the Parties.
Article 2 - Applicability and formation This agreement applies to the extent that TablePlay processes personal data on behalf of and for the benefit of the Customer and forms an integral part of the principal agreement. It comes into being through electronic acceptance, signature or actual use of the Service. For processing for which TablePlay independently determines the purposes and means, TablePlay is the controller and the Privacy Statement applies. In the event of a conflict regarding processing on behalf of the Customer, this Processing Agreement shall prevail over the General Terms and Conditions.
Article 3 - Subject matter, duration and nature TablePlay processes personal data for restaurant-related game, table, QR, score, leaderboard, dashboard and support functionalities. The processing lasts for the duration of the principal agreement and a limited period thereafter for deletion, return, backup rotation, legal obligations and legal protection. The processing may include collecting, recording, organizing, structuring, storing, consulting, calculating, combining within the restaurant context, displaying, transmitting, restricting, deleting and anonymizing.
Article 4 - Purposes • Linking QR codes to restaurant and table. • Starting and conducting game sessions. • Processing temporary nicknames, game choices, answers, scores and results. • Facilitating table-versus-table games and temporary leaderboards. • Displaying restaurant-related statistics. • Preventing duplicate, fraudulent or technically invalid sessions. • Technical support, security, continuity and recovery. • Deletion or anonymization after retention periods.
Article 5 - Categories of data subjects • Guests and players of the Customer. • Contact persons, users, employees and auxiliary persons of the Customer. • Persons appearing in a support report.
Article 6 - Categories of personal data • Temporary nickname, table number or unique table ID and restaurant or location ID. • Game session ID, selected game, playing mode, answers, actions, score, result and ranking. • Date, time and temporary language setting. • Technical session, IP, browser and device data insofar as present in security logs.
Processing Agreement and Security Policy TablePlay
Page 3 of 10 • Name and business e-mail address of a contact person and content of support inquiries. • Other data entered within the agreed functionality. TablePlay is not intended for special categories of data, criminal, medical or biometric data, or extensive directly identifiable guest profiles. The Customer shall not instruct such processing without prior written agreement.
Article 7 - Documented instructions The principal agreement, this Processing Agreement, customer portal settings and lawful support requests shall be deemed instructions. TablePlay does not process data for other purposes, except for legal obligations, independent security and legal protection purposes, or processing after adequate anonymization. In the event of a suspected unlawful instruction, TablePlay shall inform the Customer, unless legally prohibited from doing so, and may suspend performance. Additional extensive instructions may be invoiced separately.
Article 8 - Obligations of the Client The Client warrants lawfulness, valid legal basis, information to Guests, lawful instructions, data minimization, internal security, and protection of login credentials. The Client is responsible for accuracy and quality, does not request real names from Guests, and does not use Game Data for individual marketing or profiling without an independent legal basis. Security incidents and unlawful instructions shall be reported without delay.
Article 9 - Confidentiality Persons under the authority of TablePlay are granted access only to the extent necessary, are bound by confidentiality, and process data only in accordance with instructions. This obligation continues to apply after termination. Disclosure to third parties shall only take place on the basis of this agreement, the principal agreement, or the law.
Article 10 - Security TablePlay implements appropriate technical and organizational measures, taking into account the state of the art, costs, nature, scope, context, purpose, and risk. The measures are set out in Schedule 2 and may be adjusted provided that the overall level of protection is not materially reduced. No system can guarantee absolute security.
Article 11 - Data breaches TablePlay shall inform the Client without undue delay after becoming aware of a breach involving personal data processed on behalf of the Client. Where possible, information will be provided regarding the nature, systems, categories of data and data subjects, consequences, measures, and contact information. Information may be provided in phases. TablePlay investigates, contains, preserves relevant evidence, and carries out remediation. The Client shall assess the statutory notification obligation, and TablePlay shall provide reasonable support. A notification does not constitute an admission of liability. Work carried out due to circumstances within the responsibility of the Client may be carried out against reasonable costs.
Article 12 - Requests from data subjects Direct requests concerning the Client's role will, in principle, be forwarded. TablePlay only responds independently upon instruction, in its own role, or where required by law. TablePlay provides reasonable support with access, correction, erasure, restriction, portability, and objection.
Data Processing Agreement and Security Policy TablePlay
Page 4 of 10
Because Guests do not have an Account, identification may be limited. Restaurant, table, date, time, nickname, and game context may be required. Data will not be provided if it is not sufficiently established that it relates to the requester.
Article 13 - Support for compliance TablePlay provides reasonable support with security, data breach assessments, data protection impact assessments, prior consultation, and necessary documentation. Extensive support beyond the standard service may be invoiced, unless it results from a default by TablePlay.
Article 14 - Sub-processors The Client grants general authorization for the sub-processors listed in Schedule 1. TablePlay may add, replace, or remove such sub-processors and maintains an up-to-date electronic list. In the event of a new material sub-processor, TablePlay shall, in principle, provide notice thirty days in advance. The Client may raise a reasoned objection within that period on specific data protection grounds. The Parties shall seek additional safeguards, limitation, or a technical alternative. If no reasonable solution exists, the Client may terminate the directly affected part prior to deployment. TablePlay imposes substantially equivalent obligations and remains responsible to the extent required by the GDPR.
Article 15 - International transfers Personal data shall, where possible, be processed within a European region. Sub-processors or group companies may be established outside the EEA or have access from outside the EEA. Where required, TablePlay uses adequacy decisions, standard contractual clauses, supplementary measures, or other valid mechanisms. Upon reasonable request, information will be provided with due regard to confidentiality.
Article 16 - Requests from authorities TablePlay shall only provide data to competent authorities where there is a lawful obligation to do so. Where permitted, the Client will be informed in advance. TablePlay assesses authority, scope, and legal validity, and limits disclosure where possible.
Artikel 17 - Audits and Information TablePlay makes reasonable information available, including security documentation, audits, certifications, questionnaires or assurance statements. If this is insufficient, the Client may request an audit at most once per calendar year with thirty days' notice, during office hours, by an independent expert bound by confidentiality obligations, without harm to security, confidentiality or other clients. The Client bears the costs unless a material attributable violation is established. TablePlay may shield source code, other client data, vulnerability details and commercially sensitive information where a sufficient alternative exists.
Article 18 - Return and Deletion After termination, TablePlay shall delete or return, at the Client's choice and insofar as technically and legally possible, data that is processed exclusively on behalf of the Client. The choice must be made known no later than within thirty days. In the absence of a choice, TablePlay may delete or anonymize in accordance with the standard policy. Backups may contain data for a maximum of one month and shall be used exclusively for recovery purposes.
Data Processing Agreement and Security Policy TablePlay
Page 5 of 10
Data that is legally required, necessary for legal defence, or anonymized data need not be deleted.
Article 19 - Liability The liability provisions from the General Terms and Conditions also apply. Each party is responsible for its own privacy obligations. The Client shall indemnify TablePlay against claims resulting from unlawful instructions, absence of a legal basis, insufficient information, unlawful use of Game Data or the input of prohibited sensitive data, insofar as legally permitted.
Article 20 - Term and Termination This Data Processing Agreement ends when TablePlay no longer processes personal data on behalf of the Client. Confidentiality, security, deletion, liability and audits shall remain in effect insofar as their nature requires this.
Article 21 - Governing Law and Disputes This Data Processing Agreement is governed by the laws of the Netherlands. Disputes shall be handled in accordance with the General Terms and Conditions.
Appendix 1 - Sub-processors Supplier
Service
Possible Data
Region / Role
Supabase
Database, authentication, storage and backend Accounts, table data, nicknames, sessions, scores Primary and logs EU region insofar as configured; core sub-processor
Vercel
Hosting, runtime, content delivery and IP address, logging request, browser, device and application data EEA and possibly USA; hosting sub-processor
Twilio SendGrid
Transactional and operational email Name, email address, account information, content and International; delivery statusemail sub-processor
OpenAI / other AI provider Only when AI functions are activated
Limited data necessary Dependent for the functionon configuration; potential sub-processor
Stripe
Business data, invoices, transactions and payment status International; role differs per processing
Payments, invoicing and fraud
Google / Meta / LinkedIn Analytics and marketing after consent Website, device, advertising and conversion data International; generally not a sub-processor for re
The current list is made available via the website or the customer portal. In the event of a material new sub-processor, the notification and objection procedure from Article 14 applies. TablePlay does not provide identifiable guest data to an AI provider for general model training, unless this is later explicitly, lawfully and transparently arranged otherwise.
Appendix 2 - Technical and Organizational Measures 1. Access Security • Unique user accounts and secure authentication. • Hashed passwords and restriction of administrative privileges. • Access based on role and necessity. • Revocation of access when no longer required. • Additional authentication measures where appropriate.
2. Logical Data Separation • Separation between business Accounts and tenant-based authorization.
Data Processing Agreement and Security Policy TablePlay
Page 6 of 10 • Supabase Row Level Security where technically applicable. • Restriction of access to data of other Clients. • Unique table identifiers.
3. Transport and Storage • HTTPS and TLS-secured connections. • Secure communication between browser, application, backend and APIs. • Storage at selected cloud providers. • Restricted employee access and contractual confidentiality. • No storage of passwords in directly readable form.
4. Availability, Logging and Recovery • Backups and recovery provisions where appropriate. • Monitoring of technical errors and relevant login attempts. • Detection and investigation of deviant use. • Backups in principle for a maximum of one month. • Logs in principle for a maximum of one year, unless longer retention is required for an incident or dispute.
5. Secure development and vendor management • Version control, code review and controlled deployment where appropriate. • Restriction of secrets and keys in source code. • Timely updates of relevant components. • Assessment and remediation of reported vulnerabilities. • Selection of professional vendors, contractual arrangements and transfer mechanisms.
6. Data minimization and incident management • No mandatory real names, email or phone number required for Guests. • Temporary nicknames and limited leaderboard visibility. • Deletion or anonymization after retention periods. • Internal escalation process, investigation, recording, assessment of notification obligations and remedial measures.
Part B - Security and Coordinated Vulnerability Disclosure 1. Purpose and reporting address TablePlay attaches importance to the security of the website, Platform, infrastructure and data. Potential technical vulnerabilities can be reported confidentially via support@tableplay.online with the subject line Security report - confidential.
2. Content of a report • Clear description of the vulnerability. • Domain, endpoint, screen or system involved.
Processor Agreement and Security Policy TablePlay
Page 7 of 10 • Reproducible steps and possible impact. • Limited screenshots or technical evidence. • Browser, device or environment used. • Contact details and any proposal for secure communication.
3. Permitted actions • Only actions necessary to establish the existence of the vulnerability. • Keeping impact and data access as limited as possible. • Not modifying, deleting or downloading any third-party data. • Not affecting availability and stopping as soon as sufficient evidence exists. • Only investigating systems demonstrably under the management of TablePlay.
4. Prohibited actions • Social engineering, phishing, physical attacks, brute force and credential stuffing. • Account takeovers, denial-of-service, malware or persistent access. • Modifying, deleting, copying or disclosing data. • Actual manipulation of payments, invoices, coupons or scores. • Investigation of external vendors without their consent. • Burdensome automated scans. • Disclosure before a reasonable period for investigation and remediation has been provided. • Extortion or coercing payment through threats.
5. Response and disclosure TablePlay aims to confirm receipt within five business days, to assess the report, to ask questions where necessary, to inform the reporter in general terms, and to mitigate a verified vulnerability as soon as reasonably possible. The remediation time depends on severity, complexity, vendors and necessary testing. TablePlay does not guarantee any fixed time period. Details will not be disclosed publicly before TablePlay agrees, a reasonable date has been agreed upon, or at least ninety days have elapsed without a reasonable substantive response or remediation attempt. Personal data, authentication data and exploit code will not be published.
6. No general bug bounty and legal approach TablePlay does not operate a general bug bounty program, and a report does not entitle the reporter to payment, engagement or publicity. TablePlay may provide recognition at its own discretion. In principle, TablePlay will not take legal action against a researcher who acts in good faith, within this policy, without causing damage, confidentially and without extortion. This commitment does not apply in cases of clearly criminal, harmful, fraudulent or disproportionate actions and does not bind third parties or authorities.
Processor Agreement and Security Policy TablePlay
Page 8 of 10
7. security.txt TablePlay may publish a technical file at /.well-known/security.txt containing the reporting address, policy link, languages, expiry date and, where applicable, an encryption key. This file must be periodically reviewed and renewed.
Part C - Accessibility Statement 1. Ambition and reference framework TablePlay strives to make the website, registration, customer portal and guest games usable for a broad range of users, including persons with visual, auditory, motor or cognitive impairments. Where reasonably possible, the principles of WCAG 2.2 level AA are used as a technical and substantive reference framework. This does not constitute a guarantee that every element is fully compliant under all circumstances.
2. Current status The complete environment has not yet been independently and comprehensively audited. TablePlay therefore does not currently claim full formal WCAG 2.2 AA conformity. Possible limitations relate to real-time game components, time pressure, drag-and-drop, animations, external payment or authentication pages, translations, older colour displays and touch-oriented functions.
3. Measures • Semantic HTML and usable labels where appropriate. • Keyboard operability of essential functions and visible focus. • Sufficient contrast and scalable text. • Alternative text for informative images. • No essential information conveyed solely through colour. • Understandable error messages and consistent navigation. • Clear buttons and links. • Support for common browsers and screen sizes. • Limitation of unnecessary animation. • Understandable language in the guest environment. • Automated and manual testing where possible.
4. Games and time pressure Some games are by nature time-bound. Where technically and content-wise possible, TablePlay can offer alternative play modes, extended time limits, less movement, visual alternatives for sound, and text or symbols in addition to colour. Not every game mode is equally suitable for every user. Restaurants are encouraged to offer multiple types of games.
Data Processing Agreement and Security Policy TablePlay
Page 9 of 10
5. Responsibility of the business customer The Customer remains responsible for the physical and operational accessibility of the Location, including placement of QR codes, legibility of printed materials, alternative assistance, accessibility of screens, support by staff, and its own content. QR codes will be placed accessibly and visibly, and where reasonably possible an alternative will be offered to Guests who cannot scan independently.
6. Reporting and alternative access Accessibility issues can be reported via support@tableplay.online with an indication of the page or game, device, browser, assistive technology, description, and desired solution. TablePlay aims to provide acknowledgement of receipt within five business days and a substantive response within a reasonable period. Where possible, information can be provided by e-mail, support, an alternative instruction, manual processing, or another game option.
7. Disproportionate burden and improvement An adjustment may be postponed if it is not technically feasible, materially compromises security, alters the fundamental nature of a game, is dependent on an external supplier, or constitutes a disproportionate organizational or financial burden. TablePlay will then consider an alternative. TablePlay may take accessibility into account in design, testing, prioritization, user feedback, and external audits, and may update this statement accordingly.
8. Contact TablePlay by Jimani - Jimani B.V. - Albert Plesmanweg 122 - 4462 GC Goes - The Netherlands - Chamber of Commerce (KvK) 91644453 - VAT NL865722729B01 - support@tableplay.online.
Data Processing Agreement and Security Policy TablePlay
Page 10 of 10
Additional Sub-processor List This sub-processor list forms part of the Data Processing Agreement and the Security Policy of TablePlay. The current list may change when suppliers, regions, or functions change.
Supplier: Supabase Service: database, authentication, storage, and backend. Possible data: accounts, table data, nicknames, sessions, scores, and logs. Region / role: primarily EU region insofar as configured; core sub-processor.
Supplier: Vercel Service: hosting, runtime, content delivery, and logging. Possible data: IP address, request, browser, device, and application data. Region / role: EEA and possibly US; hosting sub-processor.
Supplier: Twilio SendGrid Service: transactional and operational e-mail. Possible data: name, e-mail address, account information, content, and delivery status. Region / role: international; e-mail sub-processor.
Supplier: OpenAI / other AI supplier Service: only when AI functions are activated. Possible data: limited data necessary for the function. Region / role: dependent on configuration; potential sub-processor. TablePlay does not provide identifiable guest data to an AI supplier for general model training, unless explicitly, lawfully, and transparently arranged otherwise at a later date.
Supplier: Stripe Service: payments, invoicing, and fraud. Possible data: business data, invoices, transactions, and payment status. Region / role: international; role varies per processing activity.
Supplier: Google / Meta / LinkedIn Service: analytics and marketing following consent. Possible data: website, device, advertising, and conversion data. Region / role: international; generally not a sub-processor for restaurant game data.
