AI Restaurants ← Back to homepage
Compliance

GDPR Compliance

A transparent overview of how AI Restaurants implements the GDPR for restaurant owners, guests and regulators.

Regulation: EU 2016/679Effective: 20 April 2026Privacy contact: privacy@ai-restaurants.de
This page is for restaurant owners, restaurant guests and regulators reviewing our data protection and processor practices.

01Scope and roles

The GDPR applies to personal data processing for people in the EEA. AI Restaurants is controller for its own account, billing, security and platform data, and processor for restaurant guest data processed on documented instructions from the restaurant operator.

02Legal bases

  • GDPR Art. 6(1)(b) contract performance for account, billing and support
  • Art. 6(1)(f) legitimate interests for security, fraud detection and aggregated analytics
  • Art. 6(1)(c) legal obligations
  • Art. 6(1)(a) consent for guest contact data and marketing messages

03Data subject rights

  • Access, rectification, erasure, restriction, portability, objection, consent withdrawal and rights relating to automated decisions

Use privacy@ai-restaurants.de to exercise rights.

04Consent management

Guest data collection uses active opt-in consent, separate optional marketing choices, visible purpose information, no pre-ticked boxes, recorded consent proof and one-click unsubscribe links.

05Privacy by design

The platform uses data minimization, purpose limitation, automated retention cleanup, pseudonymous internal identifiers, opt-in defaults, role-based access and audit logging.

06Processors

Processors include the providers required to operate the platform, each governed by GDPR Art. 28 obligations and SCCs where needed.

Processor Purpose Data location Safeguard
Supabase / PostgreSQLDatabase hostingEU / EEAAVV + SCCs
SMTP providerTransactional and marketing email deliveryEU / EEAAVV
Application hostAPI and web server infrastructureEU / EEAAVV

07Third-country transfers

Where data leaves the EEA, we rely on GDPR Chapter V safeguards such as standard contractual clauses, adequacy decisions and supplementary measures.

08Retention and deletion

Guest contact, visit and redemption data is generally kept for 24 months from last activity or until deletion request. Consent proof is kept for consent duration plus 12 months; IP addresses are anonymized after 30 days.

09Security measures

Controls include TLS, encrypted database connections, bcrypt password hashing, secure cookies, CSRF protection, input validation, RBAC, MFA for production access and tamper-resistant audit logs.

10Data breaches

Report security issues to security@ai-restaurants.de. Where legally required, we notify supervisory authorities within 72 hours after becoming aware.

11Data processing agreement

Restaurant owners enter into a GDPR Art. 28 DPA through the Terms of service. Separate signed documents can be requested at legal@ai-restaurants.de.

12For restaurant guests

The restaurant is generally controller and AI Restaurants is processor. You may contact the restaurant or write to privacy@ai-restaurants.de with the restaurant name.

Guest portal and rectification

In the guest portal, you can view your guest profile, visits, rewards, and communication preferences. To protect reward integrity, birthday and phone number can be updated once through self-service. Your right to rectification of inaccurate or incomplete personal data remains available at any time; send requests to privacy@ai-restaurants.de. Email changes require additional verification because email is used for secure guest access.

13Privacy contact

Privacy and legal contact

Privacy: privacy@ai-restaurants.de

Legal/DPO: legal@ai-restaurants.de

Security: security@ai-restaurants.de