Privacy Policy
⚠️ Notice: This text is a generic template and requires review by a lawyer before going into production.
1. Data Controller
The entity responsible for processing your personal data is [empresa], NIPC [NIPC], with registered office at [morada], contactable at [email] or [telefone].
Data Protection Officer (DPO): — [email DPO].
2. Data Collected
We collect the following personal data depending on the type of interaction:
- Reservations and orders: name, email, telephone, number of people, occasion, allergies and dietary preferences.
- Customer account: name, email, telephone, date of birth (optional), marketing preferences.
- Payments: amount, date, method (sensitive card data is processed directly by Stripe and never reaches our servers).
- Table via QR: optional identification (name, email, telephone) and participation in games/quizzes.
- Reviews and feedback: ratings, comments, language.
- Technical data: IP address, device identifiers, cookies, browsing data (see Cookie Policy).
3. Purposes and Legal Bases
The purposes for which we process your data, with the corresponding GDPR legal basis:
- Performance of the contract (reservations, orders, payments) — Art. 6(1)(b)
- Invoicing and tax obligations — Art. 6(1)(c)
- Loyalty programme and customer tier — Art. 6(1)(b)
- Marketing communications — Art. 6(1)(a) – consent
- Aggregated statistical analysis — Art. 6(1)(f) – legitimate interest
- Handling of complaints and ADR — Art. 6(1)(c)
4. Sub-processors
In order to provide the service, we share data with the following sub-processors:
- Supabase Inc. — database and authentication (EU/USA, with Standard Contractual Clauses)
- Stripe Payments Europe Ltd — payment processing (Ireland, transfers to the USA under SCC)
- Resend Inc. — sending of transactional emails (USA, SCC)
- Google LLC — Google Tag Manager, Maps, Business Profile (subject to cookie consent)
- Cloudflare Inc. — CDN and protection against abuse
- Vercel Inc. — application hosting
5. Retention Periods
- Reservation data: 5 years after the visit
- Invoices and tax documents: 10 years (legal obligation — Tax Code)
- Marketing data: until consent is withdrawn
- Reviews: indefinitely, unless deletion is requested
- Technical logs: 90 days
- Deleted customer account: 30 days until anonymisation
6. Your Rights
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict the processing
- Object to processing based on legitimate interest
- Data portability in a structured format
- Withdraw consent at any time (this does not affect prior processing)
You may exercise these rights in your customer area or by sending an email to [email DPO].
7. Complaints to the Supervisory Authority
You have the right to lodge a complaint with the National Data Protection Commission (CNPD): www.cnpd.pt — Av. D. Carlos I, 134 - 1.º, 1200-651 Lisboa.
8. Security
We adopt appropriate technical and organisational measures: TLS encryption, role-based access control, audit logs, encrypted backups, and periodic review of permissions.
9. Changes
This Policy may be updated. The version in force is displayed with the respective date. In the event of material changes, fresh acceptance will be requested at the next login.
10. Contact
For questions about this Policy, please contact:
- Email: [email]
- Telephone: [telefone]
- DPO: [email DPO]
- Address: [morada]
