- Effective
- 2 August 2026
- Version
- 2.0.0
- Scope
- Venue staff, booking guests and HostedTable account holders
On this page
HostedTable Privacy Notice
This notice explains how personal information is used when venues, staff and guests use HostedTable.
1. Controller and processor roles
The venue is normally the controller of booking, guest, workforce and venue-operational data. DM Digital UK Services Ltd normally processes that data for the venue under the Data Processing Addendum.
We act as an independent controller for our own account administration, security, billing, support, platform telemetry, legal compliance and global HostedTable customer-account identity.
2. Information processed
- identity and contact information, including name, email and telephone number;
- booking details, party size, date, time, table, room, source, status and history;
- notes, preferences, accessibility, allergy and dietary information;
- customer-account credentials, verification records and venue memberships;
- staff accounts, roles, PINs, rota, timeclock, employment and audit records;
- communications, consent, suppression, email and SMS delivery information;
- device, browser, IP, session, security and diagnostic logs;
- pre-orders, reviews, event messages, support records and integration identifiers; and
- payment references where payment functionality is enabled, but not necessarily full card data.
3. Special-category information
Allergy, medical and accessibility notes may reveal health information. Venues should collect only what is necessary and identify an appropriate Article 9 condition. Guests should not submit unnecessary medical detail.
4. Purposes and lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Managing a booking and venue communications | Contract, steps at the guest’s request, or venue legitimate interests |
| Providing the HostedTable service to a venue | Our contract with the venue and processor instructions |
| Customer account creation and sign-in | Contract and legitimate interests in secure account administration |
| Security, fraud prevention, audit and service reliability | Legitimate interests, legal obligation or recognised legitimate interest where applicable |
| Marketing | Consent, soft opt-in or legitimate interests as permitted by PECR and data protection law |
| Legal claims and regulatory compliance | Legal obligation and legitimate interests |
5. Who receives information
Information may be shared with the selected venue, authorised venue staff, our personnel, hosting and communications suppliers, payment and integration providers, professional advisers, regulators, law enforcement and parties involved in a business transfer where lawful.
6. Cross-venue customer accounts
A registered customer account is a platform-level identity. Each venue sees only information relevant to that venue and information the account holder chooses to provide. Platform Super Administrators may access accounts for security, support, lawful administration and complaint handling.
7. International transfers
Some suppliers may process data outside the UK. We use an adequacy regulation or appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum where required, together with risk assessment and supplementary controls where appropriate.
8. Retention
Venue-controlled booking and workforce retention is determined by the venue and service settings. Platform account, security, billing and support information is retained in accordance with the Retention Schedule and legal requirements.
9. Rights
Depending on the processing and applicable exemptions, individuals may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent and review of significant solely automated decisions.
For booking or venue-specific information, contact the venue first. For a global HostedTable customer account or platform processing, use HostedTable support or the complaints route in the Legal Hub.
10. Data protection complaints
We provide a clear route for data protection complaints, acknowledge receipt within 30 days, investigate appropriately, keep the complainant informed and communicate the outcome without undue delay. Individuals may also complain to the Information Commissioner’s Office.
11. Children
HostedTable is not intended for children to create accounts independently. An adult should make bookings involving children. Venues remain responsible for any service specifically directed to children.
12. Security
We use proportionate technical and organisational measures. No system is completely secure. Users and venues must protect credentials and devices and report suspected compromise promptly.
Legal notices
Formal notices must be sent using the notice method stated in the applicable Order or through the authenticated customer portal. Where no method is stated, notices may be delivered to the registered office above. Operational support messages are not formal legal notices unless expressly identified as such.
Contracting entity: DM Digital UK Services Ltd, company number 17166861, registered office Hoults Yard, Mailing Exchange, Walker Road, Newcastle upon Tyne, NE5 2HL, United Kingdom.
