RHome
ScheduleAnalyticsInboxSmart LinksMediaConnectionsSettings & Billing
RDFF ReachRelated legal documentLegal Centre

Service operator and data controller

DIRECT FOOD FINDER MARKETPLACE LTD

Company number
17418788
Registered office
27 Old Gloucester Street, London, WC1N 3AX, United Kingdom
Contact
support@directfoodfinder.com
View company record

On this page

1. Parties, scope and precedence2. Definitions3. Documented instructions and Customer duties4. Confidentiality and security5. Subprocessors6. Data-subject rights and compliance assistance7. Personal-data incidents8. Return and deletion9. International transfers10. United States service-provider restrictions11. Information and audits12. Processing details13. DPA contact

DFF Reach legal

Data Processing Addendum

Last updated: 20 September 2026

This Data Processing Addendum, or DPA, supplements the DFF Reach Terms of Service when a customer acts as a controller or business and DFF Reach processes Customer Personal Data on that customer's documented instructions. It is designed as a global baseline and incorporates mandatory processor terms where applicable.

When this DPA applies

  • The DPA applies to Customer Personal Data processed by DFF Reach on behalf of a customer, not to every independent provider relationship.
  • DFF Reach processes that data only on documented instructions, subject to law, confidentiality and security controls.
  • Approved subprocessors may be used under equivalent data-protection obligations.
  • Transfer and local-law supplements can be executed when a verified legal requirement applies.

1. Parties, scope and precedence

The customer that accepted the Terms is the Customer. DIRECT FOOD FINDER MARKETPLACE LTD is DFF Reach. This DPA applies only to the extent DFF Reach processes Customer Personal Data as a processor, service provider or contractor for the Customer.

For processing where DFF Reach determines its own purposes, such as account security, billing administration, fraud prevention and legal compliance, DFF Reach may act as an independent controller as described in the Privacy Policy.

If this DPA conflicts with the Terms on the protection of Customer Personal Data, this DPA prevails for that subject. Mandatory law prevails over both.

2. Definitions

Customer Personal Data means personal information submitted to or generated in DFF Reach on the Customer's behalf in connection with the service. Data Protection Law means privacy or data-protection law applicable to that processing. A Subprocessor is a processor engaged by DFF Reach to process Customer Personal Data for the service.

Controller, processor, business, service provider, contractor, personal data, personal information, processing and supervisory authority have the meanings given by the applicable Data Protection Law.

3. Documented instructions and Customer duties

DFF Reach will process Customer Personal Data only to provide, secure and support the service, carry out the Customer's documented use of product controls, and comply with lawful written instructions consistent with the agreement.

The Customer is responsible for having a lawful basis, giving required notices, configuring permissions, responding to its data subjects and ensuring that its instructions comply with law. The Customer must not submit data that the service is not designed or authorised to process.

  • Do not upload passwords, raw authentication secrets or complete payment-card or bank details.
  • Do not use DFF Reach as the primary record for special-category or highly sensitive data unless a released feature and written agreement expressly permits it.
  • Limit inbox, media, audience and contact data to what is necessary for an authorised business purpose.

4. Confidentiality and security

DFF Reach will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed.

DFF Reach will maintain appropriate technical and organisational measures proportionate to the risk, including account and brand access controls, server-side secrets, encryption of reusable provider authority, protected callbacks, secure transport, database isolation, audit records, release controls, backups and incident handling.

Security measures may evolve where the overall level of protection is not materially reduced.

5. Subprocessors

The Customer gives general authorisation for DFF Reach to use the suppliers listed in the current Subprocessor List. DFF Reach will impose data-protection obligations appropriate to the service and remains responsible for its subprocessor obligations as required by applicable law.

DFF Reach will publish or provide reasonable notice of a material new subprocessor. A Customer with a legally supportable objection must contact DFF Reach promptly and explain the data-protection grounds. The parties will attempt a practical resolution; where none is available, the affected service may need to be discontinued.

6. Data-subject rights and compliance assistance

Taking account of the nature of processing, DFF Reach will provide reasonable assistance through available product controls or support so the Customer can respond to a valid data-subject request.

DFF Reach will also provide reasonable information needed for a Customer's security assessment, breach response, data-protection impact assessment or consultation with a regulator, to the extent applicable and without disclosing another customer's information, privileged material or security secrets.

7. Personal-data incidents

DFF Reach will notify the affected Customer without undue delay after becoming aware of a confirmed personal-data breach involving Customer Personal Data where processor notification is required.

The notice will provide available information reasonably needed for the Customer's response. An initial notice may be incomplete and supplemented as the investigation develops. Notification is not an admission of fault.

8. Return and deletion

During the service, the Customer may use available export and deletion controls. After termination, DFF Reach will delete or return Customer Personal Data within the applicable operational process unless law, security, billing, fraud, dispute or evidence requirements require limited retention.

Data remaining in protected backups will be isolated from ordinary use and removed through the normal backup lifecycle. DFF Reach may retain anonymised or aggregated information that no longer identifies a person.

9. International transfers

Where Customer Personal Data is transferred across a border and Data Protection Law requires a transfer mechanism, the parties will use an applicable recognised mechanism, such as an adequacy decision, approved standard contractual clauses, a United Kingdom transfer addendum or another lawful safeguard.

This public DPA does not falsely state that one transfer form applies to every country. A Customer that requires an executed transfer module or local addendum should contact support@directfoodfinder.com before submitting data subject to that requirement.

10. United States service-provider restrictions

Where an applicable United States state privacy law treats DFF Reach as a service provider or contractor, DFF Reach will not sell or share Customer Personal Data for cross-context behavioural advertising, retain or use it outside the permitted business purposes, or combine it with unrelated personal information except where the law permits.

DFF Reach may use data to secure, maintain, debug and improve the contracted service where permitted and subject to the agreement.

11. Information and audits

DFF Reach will make available information reasonably necessary to demonstrate compliance with applicable processor obligations. Reviews should normally begin with current policies, security information, certifications or written responses where available.

If mandatory law gives the Customer a further audit right, the audit must be proportionate, coordinated in advance, protect other customers and security, avoid unreasonable disruption, and be subject to confidentiality. The Customer bears its audit costs unless the audit identifies a material breach by DFF Reach.

12. Processing details

Subject matter and purpose: operation of social planning, media, scheduling, publishing, analytics, inbox, link, support and workspace features selected by the Customer. Duration: for the agreement and the bounded deletion or retention period afterwards.

  • Data subjects may include the Customer's users, staff, clients, social account contacts, message participants and people appearing in authorised content.
  • Data may include account identifiers, provider identifiers, profile information, content, media metadata, schedules, publication records, messages where inbox features are enabled, support records and technical events.
  • Processing may include collection, storage, organisation, retrieval, transformation, transmission to an instructed provider, support, security, deletion and return.
  • Frequency is determined by the Customer's use of the service.
  • Special-category data and criminal-offence data are not intended categories unless a separately released feature and written agreement expressly permits them.

13. DPA contact

Contact support@directfoodfinder.com with the subject “DFF Reach DPA” for a signed copy, verified transfer supplement or processor question. A request must identify the contracting Customer and the legal requirement involved.

RDFF Reachby Direct Food Finder

A standalone social planning and publishing product. Every provider remains labelled by its verified release state.

PricingScheduleAnalyticsConnectionsLegal CentrePrivacy PolicyTerms of Service