LEGALInternational data transfers
How we move data across borders — and the safeguards we apply.
INTERNATIONAL DATA TRANSFERS
Last updated October 5, 2026
TablePort LTD (Company No. 13723140) is registered in England and Wales, with development operations in Israel. This page describes how we handle the international transfer of personal data in compliance with applicable data protection laws, including the UK GDPR and EU GDPR.
Where Your Data Is Processed
Your personal data may be processed in the following countries:
| Country | Purpose | Location / transfer status |
|---|---|---|
| United Kingdom | Primary market, service delivery | UK entity and service operations |
| United States | Cloud infrastructure (AWS), payment processing (Stripe), analytics | Actual recipient/account transfer mechanism requires verification |
| Israel | Development and support operations | Assess the actual access/recipient and applicable adequacy scope |
Sub-Processors
We use the following third-party processors to deliver our services:
| Processor | Location | Purpose | Data Processed |
|---|---|---|---|
| Amazon Web Services (AWS) | US (reviewed API/database) | Cloud hosting, database, file storage | All service data |
| Stripe | US | Payment processing | Payment tokens, transaction data |
| PayPal (Zettle) | US / EU | In-person payment processing | Payment tokens, transaction data |
| Sentry | US | Error monitoring | Minimised error diagnostics; personal data in free text cannot be ruled out |
| Microsoft Clarity | US | Session analytics (with consent) | Page interaction data |
| Google Cloud | US | Maps, authentication | Location queries, OAuth tokens |
| OpenAI / Anthropic | US | AI-powered features | Operator-supplied feature inputs, which may contain personal data |
| Perplexity AI | US | Employee onboarding assistance | Operator-supplied employee text, including personal data |
| DA592 LTD (Masheev) | UK entity; EU/US hosting | Partner integration | Reservation and guest data on restaurant instructions |
| Slack | US | Internal notifications | Operational alerts, potentially including personal data |
Transfer Mechanisms
Restricted transfers require an applicable, verified mechanism for the actual recipient, service and account: for example adequacy within its scope, or executed SCCs with a UK Addendum where needed. Contract/account binding and transfer assessments remain pending where supporting evidence has not been recorded. We do not treat a vendor policy link, a processor's US headquarters, or a DPA signed by another legal entity as proof of a valid transfer mechanism for TABLEPORT LTD.
The reviewed TablePort API and primary Aurora database are configured in AWS us-east-1 (United States). Encrypted backup copies of the primary database are configured to be copied daily to AWS eu-west-2 (London, United Kingdom). This does not establish the location of every storage, backup or third-party service. A provider's headquarters is distinct from the processing location. Masheev is operated by the separate UK entity DA592 LTD and supports EU and US organisation regions. Its configured account region and downstream provider chain must be checked for the specific integration.
Supplementary Measures
The reviewed controls and limits include:
- Encryption in transit: Public service endpoints use HTTPS. Connections to the primary database must use TLS 1.2 or later. This notice does not certify the TLS version or certificate-verification configuration of every other internal, operator or provider connection.
- Encryption at rest: The primary database, its snapshots and its backup copies are encrypted at rest with AWS-managed keys. Other resources require resource-specific verification.
- Access controls: Application authorisation and AWS IAM control access. Least-privilege coverage requires policy review and is not established merely by using IAM.
- Data minimisation: The reviewed Console filters known identifiers and credentials from error diagnostics; free text can still contain personal data
- Analytics: Microsoft Clarity requires analytics consent. Sentry browser performance tracing, structured logs and metrics are disabled in the reviewed Console release.
Your Rights
You may request information about the applicable verified transfer mechanism and a copy of available executed safeguards. To make a request, contact us at [email protected].
Contact
TablePort LTD Email: [email protected]