PlatoQR
Contact Pricing
Register Log in

Privacy Policy

This notice explains what data we process, why we process it, and your rights.
If you use PlatoQR for a restaurant, you may also be a controller for certain processing (e.g., bookings).

Effective date: August 30, 2025 Last updated: August 30, 2025

1. Overview

This Privacy Policy explains how PlatoQR processes personal data when you access the website, create an account, or use the Services (including viewing public pages via QR).

Privacy roles

In some cases PlatoQR acts as a controller (e.g., account and platform management). If you enable modules such as contact forms or bookings, the restaurant may be the controller for end-customer data.

2. Data Controller

The controller for personal data processed through the Platform is:

Service
PlatoQR
Email
postmaster@platoqr.com
Form
Go to Contact page

If your restaurant collects data (e.g., bookings), the restaurant is responsible for providing its own notice to end customers and complying with applicable law.

3. Categories of personal data

We may process the following categories of personal data depending on how you use the service:

Account data

  • Name, email, credentials (password stored as hash).
  • Preferences (e.g., language) and profile settings.
  • Support communications.

Restaurant/business data

  • Business name, address, contacts, opening hours.
  • Menu, dishes, prices, allergens, images.
  • Content published on PlatoQR pages.

End-customer data (if you use contact/bookings)

  • Name, phone/email, date/time, party size.
  • Customer notes (e.g., preferences).
  • Data needed for notifications and reminders.

Technical data & logs

  • IP address, user agent, device and browser data.
  • Security logs and abuse prevention.
  • Performance and diagnostics data.

We do not intentionally collect special categories of data (e.g., health). If you submit sensitive information in notes, you do so at your own responsibility.

4. Purposes and legal bases

We process data for the following purposes (and legal bases):

Provide the Services
Contract: account creation, publishing pages/menus, platform features.
Support and communications
Contract / legitimate interest: support, responses, technical communications.
Security and abuse prevention
Legitimate interest: protect infrastructure, monitor fraud/abuse, logging.
Legal obligations
Legal obligation: accounting/tax compliance, lawful requests.
Product improvement
Legitimate interest: aggregated analysis and UX improvement (not direct marketing).
Marketing

If we enable newsletters or promotional communications in the future, we will rely on an appropriate legal basis (typically consent) and provide a clear opt-out.

5. Retention

We keep data for as long as necessary to provide the Services and meet legal obligations:

  • Account data: for the life of the account and a reasonable period after closure.
  • Support requests: as needed to handle the request and for audit purposes.
  • Technical logs: for limited periods proportionate to security and diagnostics.
  • Legal obligations: for the period required by applicable law.

6. Processors and recipients

To deliver the Services, we may share data with vendors (processors) that help us run infrastructure and communications:

  • Hosting and infrastructure (servers, storage, CDN).
  • Email services for transactional notifications.
  • Monitoring and security services (logging, anti-abuse).
  • Payment providers (only if paid plans are enabled).

We share only what is necessary and require appropriate security and confidentiality commitments from vendors.

7. International transfers

Some vendors may process data outside the European Economic Area.

  • In such cases we implement appropriate safeguards (e.g., Standard Contractual Clauses).
  • We apply supplementary measures when required.
  • You can request information about safeguards by contacting us.

8. Security

We use reasonable technical and organizational measures to protect data:

  • Access controls, segregation, and least-privilege principles.
  • Encryption in transit (HTTPS) and application protections.
  • Monitoring and logging for abuse prevention.

9. Your rights

Under GDPR you may exercise the following rights (subject to legal limitations):

  • Access, rectification, and update of data.
  • Erasure and restriction of processing.
  • Data portability (where applicable).
  • Objection to processing based on legitimate interest.
  • Lodge a complaint with the competent supervisory authority.
How to exercise them

To exercise your rights, email postmaster@platoqr.com. We will respond within the time limits set by law.

10. Children

The Services are not intended for children. We do not knowingly collect children’s data. If you believe a child provided data, contact us to remove it.

11. Changes to this notice

We may update this Privacy Policy. We will publish the updated version on this page and indicate the “last updated” date.

12. Contact

If you have questions about this Privacy Policy or our data processing, contact us using the details below.

Service
PlatoQR
Email
postmaster@platoqr.com
Form
Go to Contact page

Note: this Privacy Policy does not replace the notices restaurants must provide to their customers when collecting data via contact forms or bookings.

PlatoQR

Design better digital experiences with PlatoQR.

Explore

Pricing Help center

Contact

LinkedIn
EN ▾
© PlatoQR 2026. All rights reserved.
Privacy policy Terms