PlansCompareFeaturesFAQSign in
Sign inPlan my setupPlan setupSetup

Tan-aw · Legal

Data Processing Addendum

The controller-to-processor terms governing Tan-aw's processing of personal data on the merchant's behalf.

Effective June 11, 2026Updated July 25, 2026Version 1.2

On this page

1Roles of the parties2Subject matter, duration, and scope3Controller obligations4Processor obligations5Data subjects and data categories6Sub-processors7Personal data breach8Return and deletion9Audit10Cross-border transfers11LiabilityADescription of processingBAuthorized sub-processorsCTechnical and organizational security measures
On this page tap to open
1Roles of the parties2Subject matter, duration, and scope3Controller obligations4Processor obligations5Data subjects and data categories6Sub-processors7Personal data breach8Return and deletion9Audit10Cross-border transfers11LiabilityADescription of processingBAuthorized sub-processorsCTechnical and organizational security measures

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between Tan-aw Information Technology Services ("Tan-aw", "Processor") and the Merchant ("Controller", "you"). It governs Tan-aw's processing of personal data on the Controller's behalf under Republic Act No. 10173 (the Data Privacy Act of 2012, "DPA Act"), its IRR, and NPC issuances. Terms not defined here have the meaning given in the Terms of Service.

In case of conflict on personal data matters, this DPA prevails over the Terms.

1

Roles of the parties

  • For Customer Personal Data (data about the Merchant's customers and staff processed through the Service), the Merchant is the Personal Information Controller (PIC) and Tan-aw is the Personal Information Processor (PIP).
  • For Tan-aw's own operation of the platform (merchant account administration, billing, security, product improvement using de-identified data), Tan-aw is the controller and its Privacy Policy applies.
  • Each party is responsible for its own compliance with the DPA Act, including any required registration of its data processing system and appointment of a Data Protection Officer with the NPC.
2

Subject matter, duration, and scope

Tan-aw processes Customer Personal Data only to provide the Service for the duration of the Terms and as described in Annex A. Tan-aw processes such data only on the Controller's documented instructions (which include the Terms, this DPA, and the Controller's configured use of the Service), unless required otherwise by law, in which case Tan-aw will inform the Controller unless legally prohibited.

3

Controller obligations

The Controller:

  • determines the purposes and means of processing its Customer Personal Data;
  • warrants it has a lawful basis and has given any required privacy notice and obtained any required consent (including for push notifications, optional customer names, the capture of fiscal and Senior Citizen/PWD data, the contact details, birthday month and day, and staff notes it records in its customer directory, and enrolment in any rewards programme it runs);
  • warrants, where it records marketing consent, that the consent was specific, freely given, evidenced, and opt-in per channel (NPC Circular 2023-04): it is responsible for the wording the data subject was shown, for honouring withdrawal promptly, and for not making enrolment in a rewards programme or the receipt of any service conditional on agreeing to marketing. Tan-aw records the consent as the Controller instructs and sends no marketing message; the Controller must not treat a stored consent record as a substitute for its own lawful-basis assessment;
  • acknowledges that keeping a customer directory or running a rewards programme makes its customers identified individuals, which may bring the Controller within the NPC's own registration and Data Protection Officer requirements, and is responsible for meeting those requirements for its own processing;
  • acknowledges that a free-text staff note can hold sensitive personal information a customer volunteers (for example an allergy), and is responsible for recording such a note only where it has the customer's consent or another lawful basis under the DPA Act, and for the heightened care that information requires;
  • is responsible for the accuracy and lawfulness of the data and instructions it provides; and
  • will not instruct Tan-aw to process data unlawfully.
4

Processor obligations

Tan-aw will:

  1. process Customer Personal Data only on the Controller's documented instructions and only as needed to provide the Service;
  2. ensure persons authorized to process the data are bound by confidentiality;
  3. implement appropriate organizational, physical, and technical security measures (Annex C);
  4. engage sub-processors only under Section 6;
  5. assist the Controller, taking into account the nature of processing, in responding to data-subject requests (Annex A describes the data Tan-aw holds) and in meeting the Controller's security, breach-notification, and (where applicable) privacy-impact-assessment obligations;
  6. notify the Controller of a personal data breach without undue delay (Section 7);
  7. at the Controller's choice, delete or return Customer Personal Data at the end of the Service, subject to retention required by law (Section 8);
  8. make available information reasonably necessary to demonstrate compliance and allow for audits under Section 9; and
  9. inform the Controller immediately if, in Tan-aw's view, an instruction infringes the DPA Act, its IRR, or an NPC issuance.
5

Data subjects and data categories

The data subjects and categories of personal data are described in Annex A. They include anonymous customer identifiers and push tokens, optional customer names, order data, and — where the Controller chooses to capture them — identified customer records (contact details, birthday month and day, staff notes, per-channel marketing-consent history, and visit and rewards-points history) and fiscal/tax identifiers and Senior Citizen/PWD ID data, which are sensitive personal information requiring heightened protection.

Where the Controller keeps a customer directory or runs a rewards programme, its customers are identified individuals rather than anonymous ones. The Controller should account for that change in its own privacy notice, consent practice, records of processing, and NPC registration assessment.

6

Sub-processors

  • The Controller provides a general authorization for Tan-aw to engage the sub-processors listed in Annex B to provide the Service, including the transfer of personal data offshore to the locations stated there (notably Singapore for hosting and the United States for application performance monitoring).
  • Tan-aw will flow down to each sub-processor, by written agreement, obligations of confidentiality, security aligned to the NPC's requirements (NPC Circular 2023-06), personal data breach notification, audit / inspection, data-subject-rights assistance, and return or deletion of personal data (substantially the same as those in this DPA), and remains responsible for its sub-processors' performance.
  • Tan-aw will give the Controller advance notice of any intended addition or replacement of a sub-processor, and the Controller may object on reasonable data-protection grounds.
7

Personal data breach

Tan-aw will notify the Controller without undue delay, and in any event within forty-eight (48) hours of knowledge of, or reasonable belief that, a personal data breach affecting Customer Personal Data has occurred, so that the Controller can meet its own obligation under NPC Circular 16-03 to notify the NPC and affected data subjects within seventy-two (72) hours of knowledge. Tan-aw will provide the information the Controller reasonably needs for those notifications. The parties will cooperate in investigating and remediating the breach. As the PIC, the Controller is generally responsible for notifying the NPC and affected data subjects.

8

Return and deletion

On termination or expiry of the Service, Tan-aw will, at the Controller's election and within a reasonable period (after an export window), return and/or delete Customer Personal Data. Fiscal and statutory-discount records (receipts, invoices, source documents, Senior Citizen / PWD substantiation records, and TINs) must by law be preserved for the BIR-required period (currently five (5) years from the applicable filing deadline following NIRC Section 235 as amended by RA 11976 and RR 7-2024); the Controller remains the accountable taxpayer, and on termination these records are included in the Controller's export for its continued preservation. Tan-aw deletes its copies after the export window unless the Controller purchases archival or Tan-aw is required to retain them by law or a legal hold. While Tan-aw holds records within their mandatory retention period, the RA 10173 Section 16 erasure right does not attach to them. Retention windows are described in the Privacy Policy Section 8.

9

Audit

Tan-aw will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable prior notice, no more than once per year (unless required by an authority or following a breach), during business hours, subject to confidentiality and without compromising other merchants' data or platform security.

10

Cross-border transfers

Personal data is processed offshore by certain sub-processors (Annex B), notably Microsoft Azure in Singapore (cloud hosting and infrastructure) and New Relic in the United States (application performance monitoring). The Philippines imposes no data-localization requirement, and neither provider operates a datacenter within the Philippines, so this offshore processing is necessary to deliver the Service; it is lawful provided appropriate cross-border safeguards are in place.

For these transfers the parties adopt the NPC's Model Contractual Clauses for Cross-Border Transfers of Personal Data (NPC Advisory No. 2024-01), which are voluntary under NPC guidance and are incorporated here as contractual safeguards. They require confidentiality, sub-processor approval, audit rights, minimum security, and protection of data-subject rights. They are backed by each sub-processor's own data processing agreement carrying the 2021 EU Standard Contractual Clauses (Microsoft Products & Services DPA) and the EU-US Data Privacy Framework with 2021 SCCs as fallback (New Relic DPA). Tan-aw remains responsible for the transferred data and ensures it receives a level of protection comparable to RA 10173 (Section 21). The Controller authorizes these transfers to the extent necessary to provide the Service.

11

Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits any liability that cannot be limited under the DPA Act.


A

Description of processing

Item Detail
Subject matter Provision of the Tan-aw ordering, notification, fiscal, and payment-recording Service.
Duration For the term of the Terms of Service (operational data retained per plan: Starter up to 31 days, Standard and above up to 5 years while subscribed). Customer-directory profiles and rewards records follow the same plan windows. Erasing a customer strips every identifier from the profile and forfeits unused points, while the de-identified row is retained so historical orders and points-ledger entries keep a valid reference. On exit, data is exported and then deleted per Section 8 (optional paid archival; legal holds excepted).
Nature & purpose Creating and tracking orders; delivering "order ready" notifications; recording receipts and statutory discounts; recording payment method/reference; maintaining the Controller's own directory of identified customers (contact details, birthday month and day, staff notes, and visit history) so it can recognize and serve a returning diner; operating the Controller's rewards programme (enrolment, points accrual on a settled sale, redemption against a settlement, reversal, and manual adjustment); recording and evidencing per-channel marketing consent and its withdrawal — Tan-aw sends no marketing message and has no sending capability; account and security operations.
Categories of data subjects The Controller's customers — anonymous where they only track an order, and identified where the Controller records them in its customer directory or enrols them in its rewards programme; the Controller's Authorized Users/staff; Senior Citizen / PWD beneficiaries named on receipts.
Categories of personal data App install identifier; push notification token + platform; order claim/link tokens; optional customer name; order contents and status; notification delivery logs; payment method, amount, and reference number; staff name, email, federated identity, role, audit logs, session/IP data. Where the Controller keeps a customer directory or rewards programme: customer display name; customer phone number and email address (encrypted at rest, located through a keyed, per-organization one-way index and shown masked in staff search); birthday month and day only, never the year; free-text staff notes about the customer; merchant-defined tags; per-channel marketing-consent records (channel, grant or withdrawal, source, timestamp, the version of the consent text shown, and the staff member who recorded it); visit count, lifetime spend, and first/last visit timestamps; rewards enrolment, points balance, and the append-only points ledger with its order and settlement references.
Sensitive personal information Customer Taxpayer Identification Numbers (encrypted); Senior Citizen / PWD ID type and number (ID number encrypted at rest; never written to logs, snapshots, or exports in readable form). A free-text staff note may also hold sensitive details a customer volunteers (for example an allergy); the Controller is responsible for the lawful basis of such a note (Section 3).
Special note No card primary account numbers (PANs) are stored by Tan-aw; card/e-wallet details are processed by the payment gateway.
B

Authorized sub-processors

Sub-processor Role / service Personal-data categories Processing location Transfer mechanism / safeguards
Microsoft Corporation (Microsoft Azure) Cloud infrastructure & hosting (AKS), database, storage, key management; optionally Azure Monitor / Application Insights / Log Analytics (observability) Substantially all platform data: account/profile, order & transaction records, payment metadata (no PAN), operational records, application logs Azure Southeast Asia (Singapore) (no Azure region exists in the Philippines) Microsoft Products and Services DPA (incorporated into the Product Terms) with 2021 EU SCCs (+ UK IDTA); mapped to the NPC Model Contractual Clauses per Section 10
Microsoft Entra External ID Authentication / identity Staff and signed-in-customer identity claims: email, name, federated identifiers, MFA assurance Microsoft global infrastructure Microsoft Products & Services DPA / 2021 EU SCCs; mapped to NPC MCCs
New Relic, Inc. Application performance monitoring, error tracking, infrastructure metrics, log management (telemetry only) Technical telemetry: IP addresses, device/session identifiers, account/user IDs embedded in traces, request metadata, error payloads, performance metrics, all PII-minimized at source United States (EU region selectable) New Relic DPA (incorporated into its Terms of Service); EU-US Data Privacy Framework certified, with 2021 SCCs as fallback; mapped to NPC MCCs
Google Firebase Cloud Messaging (FCM) Push notification delivery (Android + cross-platform) Device push token, platform, message metadata Google global infrastructure Firebase Data Processing and Security Terms (incorporated into the Firebase ToS) with EU SCCs; mapped to NPC MCCs
Apple Push Notification service (APNs) iOS push notification delivery Device push token, message metadata Apple global infrastructure Apple Developer Program License Agreement (Section 3.3.7(C) / Attachment 1); no personal data is included in push payloads

Tan-aw's subscription-billing payment gateway is not listed above because it does not process Customer Personal Data: Customers never pay through the Service, and the gateway handles only the Merchant's own payment method for Tan-aw subscription fees, a relationship in which Tan-aw acts as controller, disclosed in the Privacy Policy (Section 7) and governed by the gateway's own data-sharing terms.

The customer directory and rewards programme add no sub-processor. Customer contact details, marketing-consent records, and points ledgers are held in the platform's own database on the infrastructure already listed above, and Tan-aw sends no marketing message. Any future SMS or email sending provider engaged to deliver marketing on the Controller's behalf would be a new entry in this Annex and is therefore subject to Section 6: advance notice to the Controller and the Controller's right to object on reasonable data-protection grounds. Until such a provider appears in this Annex, no marketing can be sent through the Service, whatever consent has been recorded.

C

Technical and organizational security measures

  • Encryption in transit: TLS for all API and web traffic.
  • Encryption at rest of sensitive and contact identifiers: field-level encryption (symmetric AES via Fernet) for Taxpayer Identification Numbers, Senior Citizen/PWD ID numbers, and the customer phone numbers and email addresses held in a Merchant's customer directory; these are never emitted to logs, snapshots, or backups in readable form. Encryption keys are managed so the data remains producible for a BIR audit within the retention window. (Applied as the "appropriate" technical measure under RA 10173 Section 20 / IRR Rule VI Section 28(g) and NPC Circular 2023-06, not as an absolute statutory mandate.)
  • Searchable without a readable column: encrypted customer contact details are found through a keyed one-way index (HMAC-SHA256 under a rotatable secret held outside the database), never by reading the stored values. The index is salted per organization, so the same contact detail held by two Merchants produces two unrelated values and a leaked index cannot correlate one person across tenants. Staff-facing search results show contact details masked.
  • Authentication: federated identity via Microsoft Entra External ID with multi-factor authentication for high-trust roles; strong password hashing for local credentials; short-lived sessions with refresh-token rotation.
  • Access control & tenant isolation: strict per-organization data isolation with object-level authorization on every route, so one merchant cannot access another's data; least-privilege, role-based access for staff.
  • Auditing: organization audit logs of sensitive actions. Marketing consent and rewards points are held in append-only ledgers, enforced at the database, so a grant, a withdrawal, or a points correction is recorded as a new entry and an existing entry cannot be edited or deleted.
  • Maintenance & retention: routine pruning of stale device tokens and notification logs; tiered retention/erasure of order data; and erasure of a customer-directory entry that removes every identifier (name, contact details, birthday, staff notes, tags, and the cached marketing-consent flags) while preserving referential integrity for historical orders and ledger entries.

Related documents

Terms of ServiceThe agreement between Tan-aw and the businesses that subscribe to and use the platform.Read →Privacy PolicyHow Tan-aw collects, uses, shares, and protects personal data across the platform and ReadyNa.Read →Refund PolicyHow Tan-aw refunds the subscription fees merchants pay for the platform.Read →

Questions about this document?

Reach the Tan-aw team. We usually reply within two business days.

dpo@tan-aw.com

© 2026 Tan-aw Information Technology Services · DTI Business Name Reg. No. 8229411 · Selenia 208, Mirea Residences, Amang Rodriguez Avenue, Santolan, Pasig City

The all-in-one cloud POS for food businesses.

Terms & ConditionsPrivacy PolicyRefund Policy

© 2026 Tan-aw Information Technology Services · Santolan, Pasig City · +63 917 114 4927 · hello@tan-aw.com. All rights reserved.