managero Data Processing Terms

These terms form part of the Terms of Service and take effect automatically when you open an account. You do not have to ask for them or sign anything.

The position, in short

Your restaurant is the controller of your employees' personal data. We are your processor. You decide what is recorded about your staff, why, and for how long. We hold it and act on your instructions. We do not use your employees' data for our own purposes. Article 28 of the UK GDPR requires that arrangement to be set out in writing.

Where you are a franchisee, a group or a multi-site operator, the controller is the legal entity that employs the staff, not the brand above it.


Part A: the Article 28(3) particulars

1. Subject matter of the processing

The provision of managero, a food-safety and workplace compliance record-keeping service, to the controller: recording, storing, attributing, retaining, displaying and exporting the controller's compliance records and the personal data those records contain.

2. Duration of the processing

From the creation of the account until the later of:

Records are retained for at least five years and nothing hard-deletes; see section 6 of the Privacy Policy.

The Terms of Service give free read-only access to historical records after cancellation, indefinitely. Processing therefore continues after the subscription ends, to preserve those records and give you access to them, and it continues until you instruct otherwise.

3. Nature and purpose of the processing

Nature: collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission by email, alignment, restriction, archiving, and making available by export to PDF and CSV. Also, where and only where the controller uses the import features, transmission of an uploaded document or photograph to a third-party AI model to produce a draft (clause 9.2).

Purpose: enabling the controller to create, keep and produce the records it is legally required to keep as a food business operator and as an employer, including: food-safety monitoring records, temperature records, delivery checks, cleaning and opening/closing checks, signed forms, allergen declarations made by the controller, traceability records, training and competency records, working time and rota records, accident and incident records, and evidence photographs.

We do not process your employees' personal data for any purpose of our own. It is not used to train any model, sold, used for marketing, or aggregated into a product.

4. Types of personal data

5. Categories of data subject


Part B: the obligations Article 28(3)(a) to (h) requires

6. Processing only on documented instructions: Article 28(3)(a)

We process personal data only on the controller's documented instructions, including as to transfers outside the UK, unless required to do otherwise by law, in which case we tell you before processing unless the law forbids us from telling you on important grounds of public interest.

Your documented instructions are: these terms; the Terms of Service; the configuration you choose in the app, including which capabilities you switch on, which forms you assign and which permissions you grant; and any further written instruction you send to hello@managero.co.uk.

We tell you if we consider an instruction to breach data protection law, and we do not carry out an instruction we believe to be unlawful without saying so first.

Your instruction switches the AI import on. Sending a document or photograph to Google's Gemini API (clause 9.2) happens only because a person in your business chose to use an import feature. It does not happen in the background.

7. Confidentiality: Article 28(3)(b)

Everyone we authorise to process your personal data is bound by an obligation of confidentiality, whether by contract or by a professional duty, and that obligation survives the end of their engagement.

Today the only person with production access is the individual named in section 1 of the Privacy Policy. The obligation above binds anyone added, before they are added.

8. Security: Article 28(3)(c), and Article 32

We implement appropriate technical and organisational measures. The measures in place:

Not claimed: no independent penetration test, security audit or certification has been carried out.

9. Sub-processors: Article 28(3)(d) and 28(2)

You give general written authorisation for the sub-processors listed below. We impose data protection obligations on each, and we remain fully liable to you for their performance.

9.1 Google Cloud / Firebase: hosting, authentication, database, file storage and serverless functions. Receives: everything in clause 4.

9.2 Google (Gemini, via the Google AI Studio API): form, menu and recipe import. Receives: the complete uploaded file where it is a photograph or a PDF, base64-encoded and unmodified, or the extracted text where it is a Word document. If a document you upload for import contains personal data, that personal data is sent to Google. This happens only when a person in your business uses an import feature. A sheet filed under Camera Upload is kept as an image and is not sent to any model. The exception is a temperature sheet you choose to transcribe from Camera Upload: that photograph is sent to Google in the same way as an import, and the values it proposes are confirmed by a person before anything is saved.

9.3 Domeneshop: SMTP delivery of invitations, alerts, digests, payment notices and the cancellation export. Receives: recipient email addresses and message content.

9.4 Stripe Payments UK Ltd: subscription payments. Receives: the account holder's own name, email and card details, and nothing else. No employee record, compliance record, incident report or photograph is sent to Stripe, so for the personal data covered by these terms Stripe is not a recipient. Cards are entered on Stripe's own page and we do not see or store a card number.

Changes. We give you at least 30 days' notice by email before adding or replacing a sub-processor. You may object on reasonable data protection grounds. If we cannot resolve your objection you may terminate without penalty, with clause 13 and section 8 of the Terms of Service applying in full: you leave with your records.

10. Assisting with data subject rights: Article 28(3)(e)

Data subjects should approach you; you are the controller. We help you answer them.

11. Assisting with Articles 32 to 36: Article 28(3)(f)

Taking into account the nature of the processing and the information available to us, we assist you with:

12. Audit: Article 28(3)(h)

We make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. In practice:

13. Deletion or return at the end: Article 28(3)(g)

At your choice, at the end of the provision of services, we delete or return all personal data, and delete existing copies, unless the law requires storage.

Return happens automatically and you do not have to ask. On cancellation the app generates a complete PDF and a complete CSV export and emails it to the account owner. That is a binding term of the Terms of Service, section 8.

Deletion is on your written instruction, and it is not the default. The default is retention with free read-only access, because you are legally required to keep these records. When you instruct deletion at hello@managero.co.uk we:

Deletion is irreversible and there is no backup to restore from afterwards. Take the export first.

What we may keep: what the law requires us to keep — our own billing and tax records — and only that.


Part C: general

14. International transfers

Personal data processed under these terms is stored in the United Kingdom, in Google Cloud region `europe-west2` (London), single-region, for both the Cloud Firestore database and the Cloud Storage bucket. The region was read back from the created database on 31 August 2026, and a Cloud Firestore database cannot be moved once it exists.

Two sub-processors process outside the UK: Google's Gemini API, for form, menu and recipe import only, and Stripe, for payments. Those transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses as incorporated into those sub-processors' terms. See section 5 of the Privacy Policy.

15. Your obligations as controller

Nothing here shifts your own duties. In particular:

16. Liability and precedence

Liability under these terms is subject to the limits in the Terms of Service, except where the UK GDPR does not permit a limit. Where these terms conflict with the Terms of Service on a matter of data protection, these terms prevail.

17. Law

Governed by the law of England and Wales; the courts of England and Wales have exclusive jurisdiction.


Last updated: 2026-08-31.