← Company information

Data Processing Agreement

Resto360 · 10xBetter

English translation provided for convenience. The Thai version is the binding document.

Effective from 17 August 2026

This Data Processing Agreement (“DPA”) is made between 10XBETTER CORPORATION LIMITED, operating under the brand Resto360 by 10xBetter (“the data processor” or “Resto360”), and the customer or user of Resto360 (“the data controller” or “the customer”).

This DPA forms part of the Terms of Service for Resto360 and applies where Resto360 processes personal data on behalf of the customer, on the customer's instructions.

1. Purpose of this DPA

This DPA sets out the duties and responsibilities of the parties in relation to personal data that the customer enters into Resto360. Such data may include:

2. Roles of the parties

For personal data the customer enters into the system for use in the customer's own business:

the customer acts as data controller and Resto360 acts as data processor.

Resto360 processes that data on the customer's lawful instructions and within the scope of the Service.

The roles may differ for activities where Resto360 itself determines the purposes and means of processing; those activities are governed by the Privacy Policy.

3. Processing instructions

Resto360 processes personal data in accordance with:

  1. the customer's instructions
  2. the scope of the services the customer has selected
  3. the terms of the agreement
  4. applicable law

If Resto360 receives an instruction it considers may be unlawful, it will notify the customer as appropriate.

4. Categories of personal data

The data Resto360 may process depends on the services the customer enables, for example:

Employee data

Customer data

Business and transaction data

5. The customer's duties

The customer is responsible for:

6. Resto360's duties

Resto360 will:

  1. process data on the customer's instructions
  2. limit access to data to those who need it
  3. keep the data confidential
  4. apply appropriate security measures
  5. assist the customer in responding to data subject rights, as reasonable
  6. notify the customer of a personal data breach in accordance with the agreed conditions
  7. cooperate reasonably with audits relating to the processing
  8. delete or return data on the agreed conditions when the Service ends

7. Confidentiality

Resto360 will require personnel who can access personal data to keep it confidential and to access it only as necessary to perform their duties.

8. Security measures

Resto360 applies appropriate measures such as:

These measures may be updated as appropriate to technology and risk.

9. Sub-processors

The customer acknowledges that Resto360 may use external providers to support the Service, such as cloud infrastructure, databases, email, messaging, security, monitoring and other technical services.

Resto360 will require sub-processors to protect data to a standard appropriate to the nature of the processing.

10. International transfers

Where data is transferred or sent abroad through a sub-processor, Resto360 will act in accordance with applicable data protection law and put appropriate safeguards in place as the law requires.

11. Personal data breach

If Resto360 detects a personal data breach affecting the customer's data, it will follow its incident management process and notify the customer as appropriate. The notification may include:

The customer is responsible for notifying the authority or the data subjects where the law requires the customer to do so.

12. Data subject requests

If a data subject contacts Resto360 to exercise rights in data for which the customer is controller, Resto360 will coordinate with, or pass the request to, the customer as appropriate.

Resto360 may assist in locating, correcting, exporting, deleting or restricting the processing of data, within the capabilities of the system and on the customer's instructions.

13. Audit and cooperation

Where there is reasonable cause, Resto360 will provide the information or cooperation the customer needs to demonstrate that processing complies with this DPA and applicable law.

An audit must not unduly affect security, the confidentiality of other customers, or the operation of the system.

14. Return and deletion of data

On termination of the agreement, the customer may ask Resto360 to:

This is subject to the capabilities of the system and to retention requirements under law.

Resto360 may retain some data as necessary to comply with law, prevent fraud, or exercise legal claims.

15. Sensitive personal data

If the customer enters sensitive personal data as defined by law, the customer is responsible for establishing a legal basis, obtaining consent, or putting other necessary measures in place before processing.

Resto360 will process such data on the customer's instructions and within the scope of the relevant services.

16. Shared responsibility

The parties agree to cooperate in good faith in complying with data protection law.

The customer is responsible for the purposes and legal bases of collecting the data.

Resto360 is responsible for processing the data as data processor within the scope set out in this DPA and the relevant agreement.

17. Term

This DPA applies for as long as Resto360 processes personal data on behalf of the customer, and ends when that processing is no longer necessary, unless law or contract provides otherwise.

18. Changes to this DPA

Resto360 may update this DPA to reflect law, technology or the way the Service is provided, and will notify the customer of material changes.

19. Contact

Resto360 by 10xBetter
Operated by 10XBETTER CORPORATION LIMITED

Registered name
10XBETTER CORPORATION LIMITED
Company registration no.
0105569132707
Registered address
30 Soi Rong Phim Kong Salak, Sukhumvit 63 Road, Vadhana, Bangkok 10110, Thailand
Website
resto360.co
Email
support@resto360.co
Data protection officer
dpo@resto360.co
← Back to homepage
Effective: 17 August 2026