1. Overview
This Privacy Policy explains how PlatoQR processes personal data when you access the website, create an account, or use the Services (including viewing public pages via QR).
Privacy roles
In some cases PlatoQR acts as a controller (e.g., account and platform management). If you enable modules such as contact forms or bookings, the restaurant may be the controller for end-customer data.
2. Data Controller
The controller for personal data processed through the Platform is:
3. Categories of personal data
We may process the following categories of personal data depending on how you use the service:
Account data
- Name, email, credentials (password stored as hash).
- Preferences (e.g., language) and profile settings.
- Support communications.
Restaurant/business data
- Business name, address, contacts, opening hours.
- Menu, dishes, prices, allergens, images.
- Content published on PlatoQR pages.
End-customer data (if you use contact/bookings)
- Name, phone/email, date/time, party size.
- Customer notes (e.g., preferences).
- Data needed for notifications and reminders.
Technical data & logs
- IP address, user agent, device and browser data.
- Security logs and abuse prevention.
- Performance and diagnostics data.
We do not intentionally collect special categories of data (e.g., health). If you submit sensitive information in notes, you do so at your own responsibility.
4. Purposes and legal bases
We process data for the following purposes (and legal bases):
Provide the Services
Contract: account creation, publishing pages/menus, platform features.
Support and communications
Contract / legitimate interest: support, responses, technical communications.
Security and abuse prevention
Legitimate interest: protect infrastructure, monitor fraud/abuse, logging.
Legal obligations
Legal obligation: accounting/tax compliance, lawful requests.
Product improvement
Legitimate interest: aggregated analysis and UX improvement (not direct marketing).
Marketing
If we enable newsletters or promotional communications in the future, we will rely on an appropriate legal basis (typically consent) and provide a clear opt-out.
5. Retention
We keep data for as long as necessary to provide the Services and meet legal obligations:
- Account data: for the life of the account and a reasonable period after closure.
- Support requests: as needed to handle the request and for audit purposes.
- Technical logs: for limited periods proportionate to security and diagnostics.
- Legal obligations: for the period required by applicable law.
6. Processors and recipients
To deliver the Services, we may share data with vendors (processors) that help us run infrastructure and communications:
- Hosting and infrastructure (servers, storage, CDN).
- Email services for transactional notifications.
- Monitoring and security services (logging, anti-abuse).
- Payment providers (only if paid plans are enabled).
7. International transfers
Some vendors may process data outside the European Economic Area.
- In such cases we implement appropriate safeguards (e.g., Standard Contractual Clauses).
- We apply supplementary measures when required.
- You can request information about safeguards by contacting us.
8. Security
We use reasonable technical and organizational measures to protect data:
- Access controls, segregation, and least-privilege principles.
- Encryption in transit (HTTPS) and application protections.
- Monitoring and logging for abuse prevention.
9. Your rights
Under GDPR you may exercise the following rights (subject to legal limitations):
- Access, rectification, and update of data.
- Erasure and restriction of processing.
- Data portability (where applicable).
- Objection to processing based on legitimate interest.
- Lodge a complaint with the competent supervisory authority.
How to exercise them
To exercise your rights, email postmaster@platoqr.com. We will respond within the time limits set by law.
10. Children
The Services are not intended for children. We do not knowingly collect children’s data. If you believe a child provided data, contact us to remove it.
11. Changes to this notice
We may update this Privacy Policy. We will publish the updated version on this page and indicate the “last updated” date.
12. Contact
If you have questions about this Privacy Policy or our data processing, contact us using the details below.