Roles
For customer and restaurant data, TablePlay generally acts as processor on behalf of the business customer. For its own administration and security, TablePlay may be an independent data controller.
This text is a translation of the Dutch version. In case of any discrepancy between the translation and the Dutch original, the Dutch version shall prevail. This agreement is governed by Dutch law.
For customer and restaurant data, TablePlay generally acts as processor on behalf of the business customer. For its own administration and security, TablePlay may be an independent data controller.
We use technical and organisational measures such as access control, session security, logging and separated customer access.
TablePlay may use suppliers such as hosting, database, email and payment providers. These suppliers are used to deliver the service.
When a customer receives a privacy request that involves TablePlay data, we reasonably assist with export, correction or deletion.
TablePlay by Jimani Jimani B.V. Albert Plesmanweg 122, 4462 GC Goes Registered with the Dutch Chamber of Commerce (KvK) 91644453 - VAT NL865722729B01 support@tableplay.online
Version 1.0 Last updated: 10 July 2026
Legal review note This document has been prepared for business use by TablePlay. Have the final publication, international application, current suppliers, technical set-up and country-specific rules reviewed by legal counsel on a periodic basis.
Table of contents Part A - Data Processing Agreement Annex 1 - Sub-processors Annex 2 - Technical and organisational measures Part B - Security and Coordinated Vulnerability Disclosure Part C - Accessibility statement
Data Processing Agreement and Security Policy TablePlay
Page 2 of 10
Part A - Data Processing Agreement Article 1 - Parties This Data Processing Agreement applies between the business customer of TablePlay as Controller and Jimani B.V., trading as TablePlay by Jimani, Albert Plesmanweg 122, 4462 GC Goes, KvK 91644453, as Processor. The parties are jointly referred to as the Parties.
Article 2 - Applicability and formation This Agreement applies insofar as TablePlay processes personal data on the instructions and for the benefit of the Customer and forms an integral part of the main agreement. It is formed by electronic acceptance, signature or actual use of the Service. For processing in respect of which TablePlay independently determines the purposes and means, TablePlay is the controller and the Privacy Statement applies. In the event of any inconsistency regarding processing on behalf of the Customer, this Data Processing Agreement shall prevail over the General Terms and Conditions.
Article 3 - Subject matter, duration and nature TablePlay processes personal data for restaurant-related game, table, QR, score, leaderboard, dashboard and support functionalities. The processing lasts for the duration of the main agreement and a limited period thereafter for deletion, return, backup rotation, statutory obligations and legal protection. The processing may include collecting, recording, organising, structuring, storing, consulting, calculating, combining within the restaurant context, displaying, transmitting, restricting, deleting and anonymising.
Article 4 - Purposes • Linking QR codes to restaurant and table. • Starting and conducting game sessions. • Processing temporary nicknames, game choices, answers, scores and results. • Facilitating table-versus-table games and temporary leaderboards. • Displaying restaurant-related statistics. • Preventing duplicate, fraudulent or technically invalid sessions. • Technical support, security, continuity and recovery. • Deletion or anonymisation after retention periods.
Article 5 - Categories of data subjects • Guests and players of the Customer. • Contact persons, users, employees and auxiliary persons of the Customer. • Persons named in a support ticket.
Article 6 - Categories of personal data • Temporary nickname, table number or unique table ID and restaurant or location ID. • Game session ID, chosen game, game mode, answers, actions, score, result and ranking. • Date, time and temporary language setting. • Technical session, IP, browser and device data insofar as present in security logs.
Data Processing Agreement and Security Policy TablePlay
Page 3 of 10 • Name and business email address of a contact person and content of support enquiries. • Other data entered within the agreed functionality. TablePlay is not intended for special categories of data, criminal, medical or biometric data, or extensive directly identifiable guest profiles. The Customer shall not instruct such processing without prior written agreement.
Article 7 - Documented instructions The main agreement, this Data Processing Agreement, customer portal settings and lawful support requests constitute instructions. TablePlay shall not process data for other purposes, save for statutory obligations, its own security and legal protection purposes, or processing following adequate anonymisation. In the event of a suspected unlawful instruction, TablePlay shall inform the Customer, unless legally prohibited from doing so, and may suspend performance. Additional extensive instructions may be invoiced separately.
Artikel 8 - Verplichtingen van de Klant / Article 8 - Obligations of the Client The Client is responsible for lawfulness, valid legal basis, information to Guests, lawful instructions, data minimisation, internal security and protection of login credentials. The Client is responsible for accuracy and quality, does not require real names from Guests and does not use Game Data for individual marketing or profiling without an independent legal basis. Security incidents and unlawful instructions shall be reported without delay.
Artikel 9 - Geheimhouding / Article 9 - Confidentiality Persons under the authority of TablePlay are granted access only to the extent necessary, are bound by confidentiality obligations and process only in accordance with instructions. This obligation shall remain in force after termination. Disclosure to third parties shall only take place on the basis of this agreement, the principal agreement or the law.
Artikel 10 - Beveiliging / Article 10 - Security TablePlay shall implement appropriate technical and organisational measures, taking into account the state of the art, costs, nature, scope, context, purpose and risk. The measures are set out in Annex 2 and may be adjusted provided that the general level of protection is not materially reduced. No system can guarantee absolute security.
Artikel 11 - Datalekken / Article 11 - Data Breaches TablePlay shall inform the Client without undue delay after becoming aware of a breach of personal data processed on behalf of the Client. Where possible, information shall be provided on the nature, systems, categories of data and data subjects concerned, consequences, measures taken and contact details. Information may be provided in phases. TablePlay shall investigate, contain, preserve relevant evidence and carry out remediation. The Client shall assess the statutory notification obligation and TablePlay shall provide reasonable assistance. A notification does not constitute an admission of liability. Work performed due to circumstances within the Client's responsibility may be carried out at reasonable cost.
Artikel 12 - Verzoeken van betrokkenen / Article 12 - Requests from Data Subjects Direct requests concerning the Client's role shall in principle be forwarded. TablePlay shall only respond independently on instruction, in its own role, or where required by law. TablePlay shall provide reasonable assistance with access, rectification, erasure, restriction, portability and objection.
Verwerkersovereenkomst en Beveiligingsbeleid TablePlay / Data Processing Agreement and Security Policy TablePlay
Pagina 4 van 10 / Page 4 of 10
Because Guests do not have an Account, identification may be limited. Restaurant, table, date, time, nickname and game context may be required. Data shall not be provided if it is not sufficiently established that it relates to the requester.
Artikel 13 - Ondersteuning bij naleving / Article 13 - Assistance with Compliance TablePlay shall provide reasonable assistance with security, data breach assessments, data protection impact assessments, prior consultation and necessary documentation. Extensive assistance beyond the standard service may be invoiced, unless it results from a default by TablePlay.
Artikel 14 - Subverwerkers / Article 14 - Sub-processors The Client grants general authorisation for the sub-processors listed in Annex 1. TablePlay may add, replace or remove these and shall maintain a current electronic list. In the event of a new material sub-processor, TablePlay shall in principle inform the Client thirty days in advance. The Client may within that period raise a reasoned objection on specific data protection grounds. The parties shall seek additional safeguards, limitation or a technical alternative. If no reasonable solution exists, the Client may terminate the directly affected part prior to deployment. TablePlay shall impose materially equivalent obligations and shall remain responsible to the extent that the GDPR so provides.
Artikel 15 - Internationale doorgifte / Article 15 - International Transfer Personal data shall, where possible, be processed within a European region. Sub-processors or group companies may be established outside the EEA or may have access from outside the EEA. Where required, TablePlay shall use adequacy decisions, standard contractual clauses, supplementary measures or other valid mechanisms. Upon reasonable request, information shall be provided with due regard to confidentiality.
Artikel 16 - Verzoeken van autoriteiten / Article 16 - Requests from Authorities TablePlay shall only provide data to competent authorities pursuant to a lawful obligation. Where permitted, the Client shall be informed in advance. TablePlay shall assess competence, scope and legal validity and shall limit disclosure where possible.
Article 17 - Audits and information TablePlay makes reasonable information available, including security documentation, audits, certifications, questionnaires or assurance statements. If this is insufficient, the Customer may request an audit no more than once per calendar year with thirty days' notice, during office hours, by an independent expert bound by confidentiality obligations, without harm to security, confidentiality or other customers. The Customer bears the costs unless a material attributable breach is established. TablePlay may shield source code, other customer data, vulnerability details and commercially sensitive information where a sufficient alternative exists.
Article 18 - Return and deletion After termination, TablePlay shall delete or return, at the Customer's choice and insofar as technically and legally possible, data processed solely on behalf of the Customer. The choice shall be communicated no later than within thirty days. In the absence of a choice, TablePlay may delete or anonymise in accordance with the standard policy. Backups may contain data for a maximum of one month and shall be used solely for restoration purposes.
Processor Agreement and Security Policy TablePlay
Page 5 of 10
Legally required data, data necessary for legal protection, and anonymised data need not be deleted.
Article 19 - Liability The liability provisions of the General Terms and Conditions shall also apply. Each party is responsible for its own privacy obligations. The Customer shall indemnify TablePlay against claims arising from unlawful instructions, absence of a lawful basis, insufficient information, unlawful use of Game Data or the entry of prohibited sensitive data, to the extent permitted by law.
Article 20 - Term and termination This Processor Agreement shall end when TablePlay no longer processes personal data on behalf of the Customer. Confidentiality, security, deletion, liability and audits shall continue to apply insofar as their nature so requires.
Article 21 - Law and disputes This Processor Agreement is governed by Dutch law. Disputes shall be handled in accordance with the General Terms and Conditions.
Appendix 1 - Subprocessors Supplier
Service
Possible data
Region / role
Supabase
Database, authentication, storage and backend Accounts, table data, nicknames, sessions, scores Primary and logs EU region insofar as configured; core subprocessor
Vercel
Hosting, runtime, content delivery and IP address, logging request, browser, device and application data EEA and possibly US; hosting subprocessor
Twilio SendGrid
Transactional and operational e-mail Name, e-mail address, account information, e-mail content and International; delivery statuse-mail subprocessor
OpenAI / other AI supplier Only when AI functions are activated
Limited data necessary Depending for the functionon configuration; potential subprocesso
Stripe
Business data, invoices, transactions and payment status International; role varies per processing
Payments, invoicing and fraud
Google / Meta / LinkedIn Analytics and marketing after consent Website, device, advertising and conversion data International; generally not a subprocessor for re
The current list is made available via the website or the customer portal. In the event of a material new subprocessor, the notification and objection procedure set out in Article 14 shall apply. TablePlay does not provide identifiable guest data to an AI supplier for general model training, unless this is subsequently expressly, lawfully and transparently arranged otherwise.
Appendix 2 - Technical and organisational measures 1. Access security • Unique user accounts and secure authentication. • Hashed passwords and restriction of administrative rights. • Access based on role and necessity. • Revocation of access when no longer required. • Additional authentication measures where appropriate.
Processor Agreement and Security Policy TablePlay
Page 6 of 10 • Supabase Row Level Security where technically applicable. • Restriction of access to other Customers' data. • Unique table identifiers.
3. Transport and storage • HTTPS and TLS-secured connections. • Secure communication between browser, application, backend and APIs. • Storage with selected cloud providers. • Limited employee access and contractual confidentiality. • No storage of passwords in directly readable form.
4. Availability, logging and recovery • Backups and recovery facilities where appropriate. • Monitoring of technical errors and relevant login attempts. • Detection and investigation of anomalous use. • Backups in principle for a maximum of one month. • Logs in principle for a maximum of one year, unless longer retention is required for an incident or dispute.
5. Beveiligde ontwikkeling en leveranciersbeheer • Version control, code review and controlled deployment where appropriate. • Restriction of secrets and keys in source code. • Timely updates of relevant components. • Assessment and remediation of reported vulnerabilities. • Selection of professional suppliers, contractual arrangements and transfer mechanisms.
6. Data minimisation and incident management • No mandatory real names, email or telephone number for Guests. • Temporary nicknames and limited leaderboard visibility. • Deletion or anonymisation after specified periods. • Internal escalation process, investigation, registration, notification obligation assessment and remedial measures.
Part B - Security and Coordinated Vulnerability Disclosure 1. Purpose and reporting address TablePlay attaches importance to the security of the website, Platform, infrastructure and data. Possible technical vulnerabilities can be reported confidentially via support@tableplay.online with the subject line Security Report - Confidential.
2. Content of a report • Clear description of the vulnerability. • Domain, endpoint, screen or system involved.
Processor Agreement and Security Policy TablePlay
Page 7 of 10 • Reproducible steps and possible impact. • Limited screenshots or technical evidence. • Browser, device or environment used. • Contact details and, if applicable, a proposal for secure communication.
3. Permitted actions • Only actions that are necessary to establish the existence of the vulnerability. • Keep impact and data access as limited as possible. • Do not modify, delete or download any third-party data. • Do not affect availability and stop as soon as sufficient evidence exists. • Only investigate systems that are demonstrably under the control of TablePlay.
4. Prohibited actions • Social engineering, phishing, physical attacks, brute force and credential stuffing. • Account takeovers, denial-of-service, malware or persistent access. • Modifying, deleting, copying or disclosing data. • Actual manipulation of payments, invoices, coupons or scores. • Investigation of external suppliers without their consent. • Burdensome automated scans. • Disclosure before a reasonable investigation and remediation period has been provided. • Extortion or coercing payment through threats.
5. Response and disclosure TablePlay endeavours to confirm receipt within five business days, assess the report, ask questions where necessary, inform the reporter of the main outlines, and mitigate a verified vulnerability as soon as reasonably possible. The remediation time depends on severity, complexity, suppliers and necessary testing. TablePlay does not guarantee a fixed term. Details will not be disclosed before TablePlay agrees, a reasonable date has been agreed, or at least ninety days have elapsed without a reasonable substantive response or remediation attempt. Personal data, authentication data and exploit code will not be published.
6. No general bug bounty and legal approach TablePlay does not operate a general bug bounty programme and a report does not entitle the reporter to payment, an assignment or publicity. TablePlay may grant recognition at its own discretion. TablePlay will in principle not take legal action against a researcher who acts in good faith, within this policy, without causing damage, confidentially and without extortion. This undertaking does not apply in the case of evidently criminal, harmful, fraudulent or disproportionate actions and does not bind third parties or authorities.
Processor Agreement and Security Policy TablePlay
Page 8 of 10
7. security.txt TablePlay may publish a technical file at /.well-known/security.txt containing the reporting address, a link to the policy, languages, an expiry date and, where applicable, an encryption key. This file must be periodically checked and renewed.
Part C - Accessibility Statement 1. Ambition and reference framework TablePlay strives to make the website, registration, customer portal and guest games usable for a broad group of users, including persons with visual, auditory, motor or cognitive impairments. Where reasonably possible, the principles of WCAG 2.2 level AA are used as a technical and substantive reference framework. This does not constitute a guarantee that every component is fully compliant under all circumstances.
2. Current status The complete environment has not yet been independently and comprehensively audited. TablePlay therefore does not currently claim full formal WCAG 2.2 AA conformity. Possible limitations concern real-time game components, time pressure, drag-and-drop, animations, external payment or authentication pages, translations, older colour displays and touch-oriented features.
3. Measures • Semantic HTML and usable labels where appropriate. • Keyboard operation of essential functions and visible focus. • Sufficient contrast and scalable text. • Alternative text for informative images. • No essential information conveyed solely through colour. • Comprehensible error messages and consistent navigation. • Clear buttons and links. • Support for common browsers and screen sizes. • Limitation of unnecessary animation. • Comprehensible language in the guest environment. • Automated and manual testing where possible.
4. Games and time pressure Some games are by their nature time-bound. Where technically and content-wise possible, TablePlay may offer alternative playing modes, extended time limits, reduced movement, visual alternatives for sound and text or symbols in addition to colour. Not every game mode is equally suitable for every user. Restaurants are encouraged to offer multiple types of games.
Processing Agreement and Security Policy TablePlay
Page 9 of 10
5. Responsibility of the business Client The Client remains responsible for the physical and operational accessibility of the Location, including placement of QR codes, legibility of printed materials, alternative assistance, accessibility of screens, support by staff and own content. QR codes shall be placed so as to be reachable and visible, and where reasonably possible an alternative shall be offered to Guests who are unable to scan independently.
6. Reporting and alternative access Accessibility issues may be reported via support@tableplay.online, stating the page or game, device, browser, assistive technology, description and desired solution. TablePlay aims to acknowledge receipt within five working days and to provide a substantive response within a reasonable period. Where possible, information may be offered by email, support, an alternative instruction, manual processing or another means of playing.
7. Disproportionate burden and improvement An adjustment may be postponed where it is technically infeasible, materially compromises security, changes the fundamental nature of a game, is dependent on a third-party supplier, or constitutes a disproportionate organisational or financial burden. TablePlay will then consider an alternative. TablePlay may take accessibility into account in design, testing, prioritisation, user feedback and external audits and may update this statement accordingly.
8. Contact TablePlay by Jimani - Jimani B.V. - Albert Plesmanweg 122 - 4462 GC Goes - The Netherlands - Company Registration No. 91644453 - VAT NL865722729B01 - support@tableplay.online.
Processing Agreement and Security Policy TablePlay
Page 10 of 10
Additional sub-processor list This sub-processor list forms part of the Processing Agreement and Security Policy of TablePlay. The current list may change where suppliers, regions or functions change.
Supplier: Supabase Service: database, authentication, storage and backend. Possible data: accounts, table data, nicknames, sessions, scores and logs. Region / role: primarily EU region insofar as configured; core sub-processor.
Supplier: Vercel Service: hosting, runtime, content delivery and logging. Possible data: IP address, request, browser, device and application data. Region / role: EEA and possibly US; hosting sub-processor.
Supplier: Twilio SendGrid Service: transactional and operational email. Possible data: name, email address, account information, content and delivery status. Region / role: international; email sub-processor.
Supplier: OpenAI / other AI supplier Service: only where AI functions are activated. Possible data: limited data necessary for the function. Region / role: dependent on configuration; potential sub-processor. TablePlay does not provide identifiable guest data to an AI supplier for general model training, unless expressly, lawfully and transparently arranged otherwise at a later date.
Supplier: Stripe Service: payments, invoicing and fraud. Possible data: business data, invoices, transactions and payment status. Region / role: international; role varies per processing activity.
Supplier: Google / Meta / LinkedIn Service: analytics and marketing following consent. Possible data: website, device, advertising and conversion data. Region / role: international; generally not a sub-processor for restaurant game data.