managero Data Processing Terms
These terms form part of the Terms of Service and take effect automatically when you open an account. You do not have to ask for them or sign anything.
The position, in short
Your restaurant is the controller of your employees' personal data. We are your processor. You decide what is recorded about your staff, why, and for how long. We hold it and act on your instructions. We do not use your employees' data for our own purposes. Article 28 of the UK GDPR requires that arrangement to be set out in writing.
- Controller: the business that opened the managero account.
- Processor: Toby Nieman, a sole trader, trading as managero. For its own account and billing records, managero is a controller in its own right; see section 2 of the Privacy Policy.
- Processor's contact for data protection: hello@managero.co.uk
Where you are a franchisee, a group or a multi-site operator, the controller is the legal entity that employs the staff, not the brand above it.
Part A: the Article 28(3) particulars
1. Subject matter of the processing
The provision of managero, a food-safety and workplace compliance record-keeping service, to the controller: recording, storing, attributing, retaining, displaying and exporting the controller's compliance records and the personal data those records contain.
2. Duration of the processing
From the creation of the account until the later of:
- the controller instructing deletion under clause 13; and
- the end of the period the controller is legally required to retain the records.
Records are retained for at least five years and nothing hard-deletes; see section 6 of the Privacy Policy.
The Terms of Service give free read-only access to historical records after cancellation, indefinitely. Processing therefore continues after the subscription ends, to preserve those records and give you access to them, and it continues until you instruct otherwise.
3. Nature and purpose of the processing
Nature: collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission by email, alignment, restriction, archiving, and making available by export to PDF and CSV. Also, where and only where the controller uses the import features, transmission of an uploaded document or photograph to a third-party AI model to produce a draft (clause 9.2).
Purpose: enabling the controller to create, keep and produce the records it is legally required to keep as a food business operator and as an employer, including: food-safety monitoring records, temperature records, delivery checks, cleaning and opening/closing checks, signed forms, allergen declarations made by the controller, traceability records, training and competency records, working time and rota records, accident and incident records, and evidence photographs.
We do not process your employees' personal data for any purpose of our own. It is not used to train any model, sold, used for marketing, or aggregated into a product.
4. Types of personal data
- Identity: name; date of birth; gender where a controller records it.
- Contact: email address; telephone number; postal address where a controller records one.
- Emergency contact: name, relationship and telephone number of a third party nominated by the employee.
- Employment and competency: role, permissions, sites worked at, shifts, shift swaps and working patterns, training records, certificates, quiz papers, answers and scores.
- Right-to-work check data where the controller uses that form: full name, date of birth, document type and reference, and an image of the identity document.
- Authentication: account email and Firebase Authentication identifiers. Passwords are handled by Firebase Authentication and are not accessible to us.
- Records and attribution: every temperature, check, delivery, correction and note, each attributed to a named person with a timestamp.
- Signatures: signature images, and the associated audit block comprising the time of signing, the signer's IP address, the browser user agent, the account email and a hash of the signed content.
- Images: photographs taken as evidence, Camera Uploads of completed sheets, photographs answering questions in forms, and photographs of incident scenes, in which people frequently appear.
- Special category data (Article 9): data concerning health, in the form of descriptions of injuries, the treatment given and who gave it, recorded in incident reports; and any health information a controller enters into a free-text field. The Article 9(2) conditions this product is designed around are set out in section 3.3 of the Privacy Policy.
- Data relating to criminal allegations or offences is not a category this service is designed to hold, and controllers should not enter it into free-text fields.
5. Categories of data subject
- The controller's employees, workers and volunteers.
- The controller's owners and managers.
- Third parties named in emergency contact details.
- People injured on the controller's premises or by its activities, including customers, contractors, delivery drivers and members of the public.
- Witnesses to incidents.
- Named individuals at the controller's suppliers, where recorded on a delivery.
- Any identifiable person appearing in an evidence photograph.
Part B: the obligations Article 28(3)(a) to (h) requires
6. Processing only on documented instructions: Article 28(3)(a)
We process personal data only on the controller's documented instructions, including as to transfers outside the UK, unless required to do otherwise by law, in which case we tell you before processing unless the law forbids us from telling you on important grounds of public interest.
Your documented instructions are: these terms; the Terms of Service; the configuration you choose in the app, including which capabilities you switch on, which forms you assign and which permissions you grant; and any further written instruction you send to hello@managero.co.uk.
We tell you if we consider an instruction to breach data protection law, and we do not carry out an instruction we believe to be unlawful without saying so first.
Your instruction switches the AI import on. Sending a document or photograph to Google's Gemini API (clause 9.2) happens only because a person in your business chose to use an import feature. It does not happen in the background.
7. Confidentiality: Article 28(3)(b)
Everyone we authorise to process your personal data is bound by an obligation of confidentiality, whether by contract or by a professional duty, and that obligation survives the end of their engagement.
Today the only person with production access is the individual named in section 1 of the Privacy Policy. The obligation above binds anyone added, before they are added.
8. Security: Article 28(3)(c), and Article 32
We implement appropriate technical and organisational measures. The measures in place:
- Tenant isolation enforced by the server. Firestore and Cloud Storage security rules scope every document and every file to the owning account. The rules are evaluated by Google's infrastructure, not by the browser, so a modified client cannot bypass them.
- Encryption. In transit by TLS. At rest by Google Cloud's default encryption.
- Write-once evidence. Signature images, evidence photographs, uploaded imports and vault documents refuse update and delete at the storage rules layer. Signed forms and quiz attempts refuse update at the database layer.
- No hard deletion. The database rules define a deletion predicate that always returns false and apply it to every record collection. Removal is archiving.
- Least privilege inside the account. Access to incident and injury records requires the account owner or an explicit permission; they are excluded from general employee views and from the digest email.
- Secrets held server-side. The AI API key and the SMTP credentials are held in Secret Manager and bound to individual Cloud Functions. Neither is present in the browser bundle.
- Authentication delegated. Passwords are managed by Firebase Authentication and are not seen or stored by us.
- Public links are scoped and single-use. The incident counter-signature link is a hashed single-use token that shows the signer only what they need to sign, and the token is destroyed on use.
- Availability and resilience. Google Cloud's managed durability, plus the export in clause 13, which is a copy you hold yourself.
Not claimed: no independent penetration test, security audit or certification has been carried out.
9. Sub-processors: Article 28(3)(d) and 28(2)
You give general written authorisation for the sub-processors listed below. We impose data protection obligations on each, and we remain fully liable to you for their performance.
9.1 Google Cloud / Firebase: hosting, authentication, database, file storage and serverless functions. Receives: everything in clause 4.
9.2 Google (Gemini, via the Google AI Studio API): form, menu and recipe import. Receives: the complete uploaded file where it is a photograph or a PDF, base64-encoded and unmodified, or the extracted text where it is a Word document. If a document you upload for import contains personal data, that personal data is sent to Google. This happens only when a person in your business uses an import feature. A sheet filed under Camera Upload is kept as an image and is not sent to any model. The exception is a temperature sheet you choose to transcribe from Camera Upload: that photograph is sent to Google in the same way as an import, and the values it proposes are confirmed by a person before anything is saved.
9.3 Domeneshop: SMTP delivery of invitations, alerts, digests, payment notices and the cancellation export. Receives: recipient email addresses and message content.
9.4 Stripe Payments UK Ltd: subscription payments. Receives: the account holder's own name, email and card details, and nothing else. No employee record, compliance record, incident report or photograph is sent to Stripe, so for the personal data covered by these terms Stripe is not a recipient. Cards are entered on Stripe's own page and we do not see or store a card number.
Changes. We give you at least 30 days' notice by email before adding or replacing a sub-processor. You may object on reasonable data protection grounds. If we cannot resolve your objection you may terminate without penalty, with clause 13 and section 8 of the Terms of Service applying in full: you leave with your records.
10. Assisting with data subject rights: Article 28(3)(e)
Data subjects should approach you; you are the controller. We help you answer them.
- The app is the first line of assistance. Access and portability are largely self-service: the PDF and CSV exports produce everything held for a site and date range in a portable, machine-readable form, at any time, at no charge, including after cancellation. Rectification of most fields is available to you in the app.
- Where the app cannot do it, we do. For anything the interface does not reach — deleting a leaver's date of birth, phone number and emergency contact details, removing a right-to-work image after its retention period, removing a photograph that captured something it should not have — write to hello@managero.co.uk. We perform it at no charge and confirm in writing what was done.
- Timescale. We respond to a request for assistance within 7 days, so that you can meet your own one-month deadline.
- If a data subject contacts us directly we do not answer for you. We acknowledge them, tell them which business is the controller, tell them to approach you, and pass the request to you promptly.
- Where a right cannot be met, notably erasure of records you are legally required to keep, we say so and explain why. See section 6 of the Privacy Policy.
11. Assisting with Articles 32 to 36: Article 28(3)(f)
Taking into account the nature of the processing and the information available to us, we assist you with:
- Security (Article 32): clause 8, and answering your questions in writing.
- Breach notification (Articles 33 and 34). We notify you without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting personal data we process for you. We tell you what happened, which categories and roughly how many data subjects and records are affected, the likely consequences, what we have done and what we propose to do, and we give you what you need for your own notification. You decide whether to notify the ICO under your 72-hour duty in Article 33 and whether to notify affected individuals under Article 34.
- Data protection impact assessments (Article 35) and prior consultation (Article 36): we provide the information about the service you reasonably need. Injury and health records, evidence photographs of identifiable people, and right-to-work document images make a DPIA worth doing.
12. Audit: Article 28(3)(h)
We make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. In practice:
- Ask, at hello@managero.co.uk, and we answer in writing within 30 days.
- The security rules that enforce tenant isolation can be produced and read; the measures in clause 8 are inspectable in the code.
- One audit per year at your cost is reasonable; more if a breach or a regulator requires it.
- For the platform itself, Google's own certifications and audit reports are what exist, and we point you to them.
- We hold no certification of our own. If a certification is a condition of your using managero, say so before you sign up.
13. Deletion or return at the end: Article 28(3)(g)
At your choice, at the end of the provision of services, we delete or return all personal data, and delete existing copies, unless the law requires storage.
Return happens automatically and you do not have to ask. On cancellation the app generates a complete PDF and a complete CSV export and emails it to the account owner. That is a binding term of the Terms of Service, section 8.
Deletion is on your written instruction, and it is not the default. The default is retention with free read-only access, because you are legally required to keep these records. When you instruct deletion at hello@managero.co.uk we:
- confirm in writing what will be deleted, before we do it;
- delete the records and the associated files from Cloud Storage;
- confirm in writing when it is done.
Deletion is irreversible and there is no backup to restore from afterwards. Take the export first.
What we may keep: what the law requires us to keep — our own billing and tax records — and only that.
Part C: general
14. International transfers
Personal data processed under these terms is stored in the United Kingdom, in Google Cloud region `europe-west2` (London), single-region, for both the Cloud Firestore database and the Cloud Storage bucket. The region was read back from the created database on 31 August 2026, and a Cloud Firestore database cannot be moved once it exists.
Two sub-processors process outside the UK: Google's Gemini API, for form, menu and recipe import only, and Stripe, for payments. Those transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses as incorporated into those sub-processors' terms. See section 5 of the Privacy Policy.
15. Your obligations as controller
Nothing here shifts your own duties. In particular:
- Establish a lawful basis, and for injury records an Article 9(2) condition, for what you record.
- If you rely on Article 9(2)(b) for employee injury records, put an Appropriate Policy Document in place. Schedule 1, Part 4 of the Data Protection Act 2018 requires it.
- Give your staff a privacy notice covering what you record in managero.
- Only enter personal data you have a proper reason to hold, and keep free-text fields to the point.
- Consider the position before using AI import on a document containing personal data (clause 9.2).
- Control your own permissions: who can see incident records is your decision, made in the app.
- Report under RIDDOR where the law requires it. managero may raise a question about an incident; it files nothing and does not tell you an incident is outside RIDDOR.
16. Liability and precedence
Liability under these terms is subject to the limits in the Terms of Service, except where the UK GDPR does not permit a limit. Where these terms conflict with the Terms of Service on a matter of data protection, these terms prevail.
17. Law
Governed by the law of England and Wales; the courts of England and Wales have exclusive jurisdiction.
Last updated: 2026-08-31.