Ga naar hoofdinhoud
← Back to TablePlay

This text is a translation of the Dutch version. In case of any difference between the translation and the Dutch original, the Dutch version prevails. Dutch law applies to this agreement.

Processor Agreement and Security Policy TablePlay Including subprocessor list, technical and organizational measures, responsible disclosure, and accessibility statement

TablePlay by Jimani Jimani B.V. Albert Plesmanweg 122, 4462 GC Goes Dutch Commercial Register (KvK) 91644453 - VAT NL865722729B01 support@tableplay.online

Version 1.0 Last updated: July 10, 2026

Legal review note This document has been prepared for business use by TablePlay. Have the final publication, international application, current suppliers, technical setup, and country-specific rules periodically reviewed by legal counsel.

Table of Contents Part A - Processor Agreement Annex 1 - Subprocessors Annex 2 - Technical and Organizational Measures Part B - Security and Coordinated Vulnerability Disclosure Part C - Accessibility Statement

Processor Agreement and Security Policy TablePlay

Page 2 of 10

Part A - Processor Agreement Article 1 - Parties This processor agreement applies between the business customer of TablePlay as Controller and Jimani B.V., operating under the trade name TablePlay by Jimani, Albert Plesmanweg 122, 4462 GC Goes, Dutch Commercial Register (KvK) 91644453, as Processor. The parties are jointly referred to as the Parties.

Article 2 - Applicability and formation This agreement applies insofar as TablePlay processes personal data on behalf of and for the benefit of the Customer and forms an integral part of the main agreement. It is formed by electronic acceptance, signature, or actual use of the Service. For processing activities for which TablePlay independently determines the purposes and means, TablePlay is the controller and the Privacy Statement applies. In the event of any conflict regarding processing on behalf of the Customer, this Processor Agreement shall prevail over the General Terms and Conditions.

Article 3 - Subject matter, duration, and nature TablePlay processes personal data for restaurant-related game, table, QR, score, leaderboard, dashboard, and support functionalities. The processing continues for the duration of the main agreement and a limited period thereafter for deletion, return, backup rotation, statutory obligations, and legal protection. The processing may include collecting, recording, organizing, structuring, storing, consulting, calculating, combining within the restaurant context, displaying, transmitting, restricting, deleting, and anonymizing.

Article 4 - Purposes • Linking QR codes to restaurant and table. • Starting and conducting game sessions. • Processing temporary nicknames, game selections, answers, scores, and results. • Facilitating table-versus-table games and temporary leaderboards. • Displaying restaurant-related statistics. • Preventing duplicate, fraudulent, or technically invalid sessions. • Technical support, security, continuity, and recovery. • Deleting or anonymizing after retention periods.

Article 5 - Categories of data subjects • Guests and players of the Customer. • Contact persons, users, employees, and auxiliary persons of the Customer. • Persons referenced in a support ticket.

Article 6 - Categories of personal data • Temporary nickname, table number or unique table ID, and restaurant or location ID. • Game session ID, selected game, game mode, answers, actions, score, result, and ranking. • Date, time, and temporary language setting. • Technical session, IP, browser, and device data insofar as present in security logs.

Processor Agreement and Security Policy TablePlay

Page 3 of 10 • Name and business email address of a contact person and content of support inquiries. • Other data entered within the agreed functionality. TablePlay is not intended for special categories of data, criminal, medical, or biometric data, or extensive directly identifiable guest profiles. The Customer shall not instruct such processing without prior written agreement.

Article 7 - Documented instructions The main agreement, this Processor Agreement, customer portal settings, and lawful support requests constitute instructions. TablePlay does not process data for other purposes, except for statutory obligations, TablePlay's own security and legal protection purposes, or processing after adequate anonymization. If TablePlay suspects that an instruction is unlawful, it shall inform the Customer, unless legally prohibited from doing so, and may suspend performance. Additional extensive instructions may be invoiced separately.

Article 8 - Obligations of the Customer The Customer is responsible for lawfulness, valid legal basis, information to Guests, lawful instructions, data minimization, internal security and protection of login credentials. The Customer is responsible for accuracy and quality, does not request real names of Guests and does not use Game Data for individual marketing or profiling without an independent legal basis. Security incidents and unlawful instructions are reported without delay.

Article 9 - Confidentiality Persons under the authority of TablePlay are given access only to the extent necessary, are bound by confidentiality and process only in accordance with instructions. This obligation remains in force after termination. Disclosure to third parties takes place solely on the basis of this agreement, the principal agreement or the law.

Article 10 - Security TablePlay takes appropriate technical and organizational measures taking into account the state of the art, costs, nature, scope, context, purpose and risk. The measures are set out in Appendix 2 and may be adjusted as long as the general level of protection is not materially reduced. No system can guarantee absolute security.

Article 11 - Data Breaches TablePlay informs the Customer without undue delay after becoming aware of a breach involving personal data processed on behalf of the Customer. Where possible, information is provided regarding the nature, systems, categories of data and data subjects, consequences, measures and contact information. Information may be provided in stages. TablePlay investigates, mitigates, preserves relevant evidence and carries out remediation. The Customer assesses the statutory notification obligation and TablePlay provides reasonable support. A notification does not constitute an acknowledgment of liability. Work resulting from circumstances within the Customer's responsibility may be carried out at reasonable cost.

Article 12 - Requests from Data Subjects Direct requests concerning the Customer's role are in principle forwarded. TablePlay responds independently only upon instruction, in its own capacity or in case of a statutory obligation. TablePlay provides reasonable support with access, rectification, erasure, restriction, portability and objection.

Data Processing Agreement and Security Policy TablePlay

Page 4 of 10

Because Guests do not have an Account, identification may be limited. Restaurant, table, date, time, nickname and game context may be required. Data is not provided if it is not sufficiently established that it relates to the requester.

Article 13 - Support with Compliance TablePlay provides reasonable support with security, data breach assessments, data protection impact assessments, prior consultation and necessary documentation. Substantial support beyond the standard service may be invoiced, unless it results from a failure of TablePlay.

Article 14 - Subprocessors The Customer grants general consent for the subprocessors listed in Appendix 1. TablePlay may add, replace or remove such subprocessors and maintains an up-to-date electronic list. In the event of a new material subprocessor, TablePlay will in principle provide thirty days' prior notice. Within that period, the Customer may raise a reasoned objection on specific data protection grounds. The parties shall seek additional safeguards, limitation or a technical alternative. If no reasonable solution exists, the Customer may terminate the directly affected part prior to deployment. TablePlay imposes materially equivalent obligations and remains responsible to the extent required by the GDPR.

Article 15 - International Transfers Personal data is processed within a European region where possible. Subprocessors or group companies may be established outside the EEA or have access from outside the EEA. Where required, TablePlay uses adequacy decisions, standard contractual clauses, additional measures or other valid mechanisms. Upon reasonable request, information is provided with due regard for confidentiality.

Article 16 - Requests from Authorities TablePlay provides data solely to competent authorities in the event of a lawful obligation. Where permitted, the Customer is informed in advance. TablePlay assesses authority, scope and legal validity and limits disclosure where possible.

Article 17 - Audits and Information TablePlay shall make reasonable information available, including security documentation, audits, certifications, questionnaires, or assurance statements. If this is insufficient, the Customer may require an audit no more than once per calendar year, with thirty days' notice, during business hours, conducted by an independent expert bound by confidentiality obligations, without harm to security, confidentiality, or other customers. The Customer shall bear the costs unless a material attributable breach is established. TablePlay may shield source code, other customer data, vulnerability details, and commercially sensitive information where a sufficient alternative exists.

Article 18 - Return and Deletion Upon termination, TablePlay shall delete or return, at the Customer's choice and insofar as technically and legally possible, data that is processed solely on behalf of the Customer. The choice shall be communicated no later than within thirty days. In the absence of a choice, TablePlay may delete or anonymize in accordance with the standard policy. Backups may contain data for a maximum of one month and shall be used exclusively for recovery purposes.

Data Processing Agreement and Security Policy TablePlay

Page 5 of 10

Data that is legally required to be retained, necessary for legal defense, or anonymized need not be deleted.

Article 19 - Liability The liability provisions of the General Terms and Conditions shall also apply. Each party is responsible for its own privacy obligations. The Customer shall indemnify TablePlay against claims arising from unlawful instructions, lack of a legal basis, insufficient information, unlawful use of Game Data, or the entry of prohibited sensitive data, to the extent permitted by law.

Article 20 - Term and Termination This Data Processing Agreement shall end when TablePlay no longer processes personal data on behalf of the Customer. Confidentiality, security, deletion, liability, and audits shall remain in effect insofar as their nature so requires.

Article 21 - Governing Law and Disputes This Data Processing Agreement shall be governed by Dutch law. Disputes shall be handled in accordance with the General Terms and Conditions.

Appendix 1 - Subprocessors Supplier

Service

Possible data

Region / role

Supabase

Database, authentication, storage, and backend Accounts, table data, nicknames, sessions, scores Primary and logs EU region insofar as configured; core subprocessor

Vercel

Hosting, runtime, content delivery, and IP address, logging request, browser, device, and application data EEA and possibly US; hosting subprocessor

Twilio SendGrid

Transactional and operational email Name, email address, account information, content, International; and delivery statusemail subprocessor

OpenAI / other AI provider Only when AI functions are activated

Limited data necessary for the function Depending on configuration; potential subprocessor

Stripe

Business data, invoices, transactions, and payment status International; role varies per processing

Payments, invoicing, and fraud

Google / Meta / LinkedIn Analytics and marketing after consent Website, device, advertising, and conversion data International; generally not a subprocessor for re

The current list is made available via the website or the customer portal. In the event of a material new subprocessor, the notification and objection procedure set out in Article 14 shall apply. TablePlay shall not provide identifiable guest data to an AI provider for general model training, unless this is later explicitly, lawfully, and transparently arranged otherwise.

Appendix 2 - Technical and Organizational Measures 1. Access Security • Unique user accounts and secure authentication. • Hashed passwords and restriction of administrative privileges. • Access based on role and necessity. • Revocation of access when no longer required. • Additional authentication measures where appropriate.

2. Logical Data Separation • Separation between business Accounts and tenant-specific authorization.

Data Processing Agreement and Security Policy TablePlay

Page 6 of 10 • Supabase Row Level Security where technically applicable. • Restriction of access to other Customers' data. • Unique table identifiers.

3. Transport and Storage • HTTPS- and TLS-secured connections. • Secure communication between browser, application, backend, and APIs. • Storage with selected cloud providers. • Restricted employee access and contractual confidentiality obligations. • No storage of passwords in directly readable form.

4. Availability, Logging, and Recovery • Backups and recovery facilities where appropriate. • Monitoring of technical errors and relevant login attempts. • Detection and investigation of anomalous use. • Backups in principle for a maximum of one month. • Logs in principle for a maximum of one year, unless longer retention is required for an incident or dispute.

Data Processing Agreement and Security Policy TablePlay (part 4 of 5). The parts will be pasted back together after translation, so use the same terms and the same form of address throughout the document. This is a legal document. Translate completely and literally; omit nothing and add nothing. Preserve line breaks, blank lines, numbering, and bullet points exactly. Leave proper names, company names, e-mail addresses, URLs, Chamber of Commerce and VAT numbers, version numbers, and standard numbers unchanged. Use the legal terminology customary in the target country. Deliver ONLY the translated text. No introduction, no explanation, no code block wrapping.

5. Secure development and supplier management • Version control, code review, and controlled implementation where appropriate. • Restriction of secrets and keys in source code. • Timely updates of relevant components. • Assessment and remediation of reported vulnerabilities. • Selection of professional suppliers, contractual arrangements, and transfer mechanisms.

6. Data minimization and incident management • No mandatory real names, e-mail, or phone number for Guests. • Temporary nicknames and limited leaderboard visibility. • Deletion or anonymization after retention periods. • Internal escalation process, investigation, registration, notification obligation assessment, and remedial measures.

Part B - Security and Coordinated Vulnerability Disclosure 1. Purpose and reporting address TablePlay attaches importance to the security of the website, Platform, infrastructure, and data. Potential technical vulnerabilities may be reported confidentially via support@tableplay.online with the subject line Security report - confidential.

2. Content of a report • Clear description of the vulnerability. • Domain, endpoint, screen, or system involved.

Data Processing Agreement and Security Policy TablePlay

Page 7 of 10 • Reproducible steps and potential impact. • Limited screenshots or technical evidence. • Browser, device, or environment used. • Contact details and, if applicable, a proposal for secure communication.

3. Permitted actions • Only actions necessary to establish the existence [of the vulnerability]. • Keep impact and data access as limited as possible. • Do not modify, delete, or download data belonging to third parties. • Do not affect availability and stop as soon as sufficient evidence exists. • Only investigate systems that are demonstrably under the control of TablePlay.

4. Prohibited actions • Social engineering, phishing, physical attacks, brute force, and credential stuffing. • Account takeovers, denial-of-service, malware, or persistent access. • Modifying, erasing, copying, or disclosing data. • Actual manipulation of payments, invoices, coupons, or scores. • Investigation of external suppliers without their consent. • Burdensome automated scans. • Disclosure before a reasonable investigation and remediation period has been provided. • Extortion or coercing payment through threats.

5. Response and disclosure TablePlay endeavors to confirm receipt within five business days, assess the report, ask questions where necessary, inform the reporting party on the main points, and mitigate a verified vulnerability as soon as reasonably possible. The remediation period depends on severity, complexity, suppliers, and necessary testing. TablePlay does not guarantee a fixed period. Details will not be disclosed until TablePlay agrees, a reasonable date has been agreed upon, or at least ninety days have elapsed without a reasonable substantive response or remediation attempt. Personal data, authentication data, and exploit code will not be published.

6. No general bug bounty and legal approach TablePlay does not operate a general bug bounty program, and a report does not entitle the reporter to payment, an assignment, or publicity. TablePlay may, at its own discretion, provide a token of appreciation. TablePlay will, in principle, not take legal action against a researcher who acts in good faith, within this policy, without causing damage, confidentially, and without extortion. This commitment does not apply in cases of evidently criminal, harmful, fraudulent, or disproportionate actions and does not bind third parties or authorities.

Data Processing Agreement and Security Policy TablePlay

Page 8 of 10

7. security.txt TablePlay may publish a technical file at /.well-known/security.txt containing the reporting address, policy link, languages, expiration date, and, if applicable, an encryption key. This file must be periodically checked and renewed.

Part C - Accessibility Statement 1. Ambition and reference framework TablePlay strives to make the website, registration, customer portal, and guest games usable for a broad group of users, including persons with visual, auditory, motor, or cognitive impairments. Where reasonably possible, the principles of WCAG 2.2 level AA are used as a technical and substantive reference framework. This does not constitute a guarantee that every component is fully compliant under all circumstances.

2. Current status The full environment has not yet been independently and comprehensively audited. TablePlay therefore does not currently claim full formal WCAG 2.2 AA conformity. Potential limitations concern real-time game components, time pressure, drag-and-drop, animations, external payment or authentication pages, translations, older color displays, and touch-oriented functions.

3. Measures • Semantic HTML and usable labels where appropriate. • Keyboard operation of essential functions and visible focus. • Sufficient contrast and scalable text. • Alternative texts for informative images. • No essential information conveyed by color alone. • Understandable error messages and consistent navigation. • Clear buttons and links. • Support for common browsers and screen sizes. • Limitation of unnecessary animation. • Understandable language in the guest environment. • Automated and manual tests where possible.

4. Games and time pressure Some games are by their nature time-bound. Where technically and content-wise possible, TablePlay may offer alternative play modes, extended time limits, less movement, visual alternatives for sound, and text or symbols in addition to color. Not every game mode is equally suitable for every user. Restaurants are encouraged to offer multiple game types.

Data Processing Agreement and Security Policy TablePlay

Page 9 of 10

5. Responsibility of the business customer The Customer remains responsible for physical and operational accessibility of the Location, including placement of QR codes, legibility of printed materials, alternative assistance, accessibility of screens, support by staff and own content. QR codes are placed so as to be reachable and visible, and where reasonably possible an alternative is provided to Guests who cannot scan independently.

6. Notification and alternative access Accessibility issues may be reported via support@tableplay.online stating the page or game, device, browser, assistive technology, description and desired solution. TablePlay aims to acknowledge receipt within five business days and to provide a substantive response within a reasonable period. Where possible, information may be offered by email, support, an alternative instruction, manual processing, or another game option.

7. Disproportionate burden and improvement An adaptation may be postponed when it is not technically feasible, materially compromises security, changes the fundamental nature of a game, is dependent on an external supplier, or constitutes a disproportionate organizational or financial burden. TablePlay will then consider an alternative. TablePlay may take accessibility into account in design, testing, prioritization, user feedback and external audits and may update this statement accordingly.

8. Contact TablePlay by Jimani - Jimani B.V. - Albert Plesmanweg 122 - 4462 GC Goes - The Netherlands - Trade Register No. 91644453 - VAT NL865722729B01 - support@tableplay.online.

Data Processing Agreement and Security Policy TablePlay

Page 10 of 10

Additional Sub-processor List This sub-processor list forms part of the Data Processing Agreement and Security Policy of TablePlay. The current list may change when suppliers, regions, or functions change.

Supplier: Supabase Service: database, authentication, storage, and backend. Possible data: accounts, table data, nicknames, sessions, scores, and logs. Region / role: primarily EU region insofar as configured; core sub-processor.

Supplier: Vercel Service: hosting, runtime, content delivery, and logging. Possible data: IP address, request, browser, device, and application data. Region / role: EEA and possibly the US; hosting sub-processor.

Supplier: Twilio SendGrid Service: transactional and operational email. Possible data: name, email address, account information, content, and delivery status. Region / role: international; email sub-processor.

Supplier: OpenAI / other AI supplier Service: only when AI features are activated. Possible data: limited data necessary for the feature. Region / role: depending on configuration; potential sub-processor. TablePlay does not provide identifiable guest data to an AI supplier for general model training, unless this is later expressly, lawfully, and transparently arranged otherwise.

Supplier: Stripe Service: payments, invoicing, and fraud. Possible data: business data, invoices, transactions, and payment status. Region / role: international; role differs per processing activity.

Supplier: Google / Meta / LinkedIn Service: analytics and marketing after consent. Possible data: website, device, advertising, and conversion data. Region / role: international; generally not a sub-processor for restaurant game data.