Back to Home

Privacy Policy

Effective & Last Updated: July 1, 2026

Translation Disclaimer:This document was originally drafted in the English language. Any translated version is provided strictly for informational convenience. In the event of any discrepancy or misinterpretation between the English version and a translation, the English language version shall serve as the sole legally binding contractual framework.

Welcome to Qrdery. This Privacy Policy governs the processing of personal data by Qrdery LTD, a company registered under the laws of the Republic of Cyprus with registration number HE 491017, having its registered office at Pindou 4, Egkomi Lefkosias 2409, Cyprus (hereinafter referred to as "Qrdery", "we", "us", or "our").

We operate as a Business-to-Business (B2B) Software-as-a-Service (SaaS) platform providing digital ordering, restaurant table reservation management, and marketing loyalty solutions to business entities (our "Clients"), as well as direct consumer interfaces for our Clients' end-users and restaurant guests (our "End-Users"). We are fully committed to protecting the privacy and security of our platform users, including restaurant owners, staff members, kiosk systems, and dining guests.

This Privacy Policy outlines how data is collected, processed, and shared across our software platforms, web applications, cloud infrastructure, and integrated peripheral services in accordance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the European ePrivacy Directive (Directive 2002/58/EC), the Cyprus Data Protection Law 125(I)/2018, and applicable international privacy frameworks.

1. Important Information and Who We Are

1.1 Data Controller and Data Processor Roles

  • As a Data Controller: Qrdery acts as a Data Controller under Article 4(7) GDPR when we determine the purposes and means of processing personal data belonging to our Clients’ corporate representatives, platform account administrators, website visitors, sales leads, and individuals submitting direct inquiries to us.
  • As a Data Processor: When providing our cloud infrastructure, table reservation modules, QR-code ordering systems, and Loyalty Hub features, our Clients (the restaurants) act as the sole Data Controllers for their respective restaurant guests and staff End-Users. Qrdery processes that reservation, ordering, and loyalty data as a Data Processor under Article 4(8) GDPR, acting entirely on behalf of, and under the documented instructions of, our B2B Clients as set forth in our Data Processing Agreement (DPA). The Client remains responsible for determining the purposes and lawful basis for processing this data and for complying with its obligations as a Data Controller.

1.2 Privacy Governance

Data protection and privacy inquiries at Qrdery are managed internally by our core operations team. In accordance with the criteria set forth in Article 37 of the GDPR, the appointment of a formal, dedicated Data Protection Officer is not legally required for our current processing operations. All data protection inquiries, privacy-related concerns, or requests to exercise statutory legal rights may be directed straight to our privacy inbox at qrdery@qrdery.io.

1.3 Contact Details

  • Full Legal Entity Name: Qrdery LTD
  • Registration Number: HE 491017 (Cyprus)
  • Postal Address: Pindou 4, Egkomi Lefkosias 2409, Cyprus
  • Email Address: qrdery@qrdery.io

2. The Data We Collect and Technical Data Flows

Personal data means any information about an individual from which that person can be identified. We collect, use, store, and transfer different kinds of personal data depending on your relationship with us and the technical integrations activated on our platform:

2.1 Corporate Client & Website Visitor Data (Qrdery as Controller)

  • Identity Data: First name, last name, and professional title of authorized company representatives or website visitors who fill out our contact forms or request product demos.
  • Contact Data: Corporate email address, telephone number, billing address, and physical business location.
  • Marketing & Communications Data: Your preferences in receiving direct sales communications, updates, and newsletters from us.

2.2 End-User & Guest Data (Qrdery as Processor)

  • Reservation Data: First name, last name, phone number, email address, time/date of booking, and specific table or zone preferences submitted to a Client's restaurant.
  • Guest Profile & Ordering Data: Email addresses, phone numbers, first names, digital voucher/coupon balances, and restaurant visit histories. This includes active transaction payloads, items ordered, customizations, item modifiers, total prices, checkout methods, and text conversation histories with our contextual AI Assistant.

2.3 Technical, Cookie, and Usage Data (Collected Automatically)

  • Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting, browser plug-in types, operating system, platform, access timestamps, and unique device identifiers (e.g., device or hardware MAC addresses).
  • Geolocation Data: Approximate geographic location derived from IP addresses or real-time device location (subject to explicit device-level permission) to facilitate nearby restaurant identification, delivery radius mapping, and optimized delivery routing.
  • Cookie and Analytics Data: Information tracked via essential cookies and non-essential third-party analytics cookies (e.g., Google Analytics), including page interaction metrics, referral sources, and platform usage statistics.

2.4 Financial Data

All subscription and point-of-sale payments are securely routed via our third-party infrastructure. Qrdery does not store or process credit/debit card numbers, CVVs, or PINs directly on its servers. Financial transactions are governed entirely by our providers' certified privacy terms.

2.5 Children's Data & Client Responsibility

We do not intentionally collect Special Categories of Personal Data. Through our reservation modules and restaurant Loyalty Hub, individuals under the age of 18 may access the platform to book tables or collect coupons. Our B2B Clients, as Data Controllers, are entirely responsible for determining the legal basis for processing children's personal data, evaluating the applicable statutory age of consent under local laws, and obtaining any parental/guardian authorizations required under applicable law. Qrdery processes such data solely under documented instructions from the Client.

3. Core Platform & Infrastructure Providers (Subprocessors)

To deliver our Services efficiently, we utilize third-party infrastructure components. All platform providers process data in alignment with strict European security thresholds.

3.1 Supabase (Backend-as-a-Service & Relational Database)

  • Role: Serves as our primary cloud-hosted database architecture and serverless backend runtime engine.
  • Data Flow: Processes user authentication credentials, session tokens, secure password hashes, corporate profiles, digital menu catalogs, live order parameters, system internal audit logs, and cloud storage objects (menu imagery and generated invoices).
  • Data Sovereignty: Database instances are secured using advanced encryption at rest (AES-256) and in transit (TLS 1.3). All production database servers are provisioned exclusively within European nodes (e.g., Frankfurt, Germany).

3.2 Hostinger (Domain, DNS, and Business Mail Hosting)

  • Role: Manages our custom domains, retains critical DNS security configurations (DKIM, SPF, CNAME records), and hosts internal support and sales email mailboxes.
  • Data Flow: Processes full business emails exchanged with support or sales accounts (sender/recipient metadata, message text body, logs, and attached documents). Handled securely using TLS/SSL transmission protocols.

3.3 Google Cloud Platform & Google Workspace APIs

  • Role: Powers distributed platform storage, document automation, and productivity sync capabilities.
  • Data Flow: Handles secure OAuth 2.0 access credentials, refresh tokens, exportable order rows, operational reports, generated menu assets, and receipt archives synced with Google Sheets or Drive. Governed under Google's enterprise Cloud Data Processing Addendum (DPA).

4. Integrated Third-Party APIs & Payment Gateways

4.1 SumUp (In-Person POS Payment Processing & Hardware Integration)

  • Role: Facilitates physical card-present transactions at counter checkouts, tableside servicing, or self-service kiosks via SumUp hardware and mobile Tap-to-Pay integrations.
  • Data Flow: Processes merchant profile credentials, secure API access tokens, hardware reader pairing IDs, and transaction metadata (order references, currency codes, and transaction statuses). Cardholder financial metadata is processed entirely within SumUp's certified PCI-DSS Level 1 compliant environments. SumUp acts as an independent data controller for this specific financial transaction flow.

4.2 OpenAI (AI Guest Assistant & Automation API)

  • Role: Powers the integrated AI Guest Assistant system (real-time recommendations and allergy warnings), automates multi-language menu translations, and generates draft replies to customer reviews.
  • Data Flow: Processes unstructured guest text queries describing food preferences or personal allergen profiles, structural menu text, and raw public customer review text.
  • Privacy Controls: Personally Identifiable Information (PII) is structurally filtered prior to transmission. Enterprise API payloads are strictly segregated and are never utilized to train public foundational OpenAI models.

4.3 Fiskaly (Cloud-Based Fiscalization Systems)

  • Role: Automatically binds to sales workflows to handle formal transaction compliance, cancellations, and issue cryptographically signed digital receipts to satisfy regional tax audit laws (e.g., the Austrian RKSV).
  • Data Flow: Processes aggregated transaction totals, value-added tax rates (e.g., 10%, 13%, 20%), high-level item category summaries, register identification profiles, and cryptographic verification metadata stored within the secure, long-term Fiskaly SAFE cloud archive. Hosted exclusively within European data centers.

4.4 Twilio (SMS Verification & Transactional Gateway)

  • Role: Fires off real-time, automated transactional SMS notifications for order confirmations, delivery status updates, and kiosk event alerts.
  • Data Flow: Processes target recipient telephone numbers and custom alphanumeric text payload parameters under execution-level Data Protection Addendums (DPAs).

4.5 Mapbox (Geospatial Rendering & Address Validation)

  • Role: Powers the visual layout of delivery radiuses, converts text address structures into explicit geospatial coordinates, and computes optimized routing paths for delivery staff.
  • Data Flow: Processes delivery destination strings and calculated coordinate pairs programmatically and anonymously, without linking parameters to persistent end-user tracking identities.

5. Supplementary Engineering & Hardware Integrations

5.1 GitHub (Code Repository & Automated Diagnostics)

  • Role: Bridges core production codebases with active platform parameters via internal tracking environments for bug diagnostics, hotfixes, and software stability monitoring.
  • Data Flow: Processes developer OAuth scopes, deployment configurations, and structural platform runtime error logs containing temporary debugging paths. Regulated via multi-factor access with zero retention of production client data.

5.2 Sunmi Cloud Print (Cloud-Connected POS Kitchen Printing)

  • Role: Automatically routes completed digital orders or manual system updates directly to localized thermal receipt printers situated in the kitchen or front bar.
  • Data Flow: Processes structural print ticket layout details (menu item arrays, table or zone identifiers) and unique physical printer MAC addresses. Data is strictly operational and transiently handled.

5.3 Philips Hue (Smart Lighting API & Automated Cues)

  • Role: Connects with physical restaurant lighting ecosystems to provide instant visual cues (colored pulsing light routines) to alert staff of incoming digital orders inside noisy environments.
  • Data Flow: Processes local bridge credentials and automated internal network system trigger variables. No personal guest data is ever exposed to this localized IoT workflow.

5.4 Public Reference Databases (USDA FoodData & ExchangeRate-API)

  • Role: Imports underlying nutritional references for menu mapping workflows and processes immediate multi-currency checkout conversions.
  • Data Flow: Processes generic food ingredient keys and currency ISO symbols anonymously. No personal tracking vectors or customer identities are processed or transmitted.

6. How We Use Your Personal Data and Legal Bases

We will only use your personal data when the law allows us to. We rely on the following distinct legal bases under Article 6 of the GDPR:

6.1 Qrdery as a Data Controller (Our Website, Marketing & Client Operations)

  • To register your business as a new SaaS client and establish your account profile: Performance of a contract (Article 6(1)(b) GDPR).
  • To manage payments, subscriptions, fees, and collect money owed to us via Revolut: Performance of a contract and Legitimate interests to recover debts (Article 6(1)(b) and (f) GDPR).
  • To respond to website inquiries, demo requests, or contact form submissions: Legitimate interests to fulfill corporate communication requests (Article 6(1)(f) GDPR).
  • To optimize web performance and user behavior via Google Analytics: Explicit User Consent (Article 6(1)(a) GDPR). This data is only processed if you provide consent via our cookie banner.
  • To send marketing newsletters or product updates: Consent (Article 6(1)(a) GDPR) for prospects, or Legitimate interests (Article 6(1)(f) GDPR) for existing clients.

6.2 Qrdery as a Data Processor (SaaS Delivery)

  • To facilitate table reservations, digital ordering, fiscalization records, and Loyalty Hub features: Qrdery does not independently determine a lawful basis under Article 6 GDPR for guest data. Instead, we fulfill our technical obligations under Article 28 GDPR, processing data strictly to execute the service contract between Qrdery and the restaurant Client (the Data Controller).

7. Cookies and Third-Party Analytics

Our website and platform interfaces use cookies to distinguish you from other users.

  • Essential Cookies: These cookies are necessary for the functioning of the website and do not require consent under applicable cookie laws. They enable core system operations, security, account login, and session preservation.
  • Non-Essential Cookies (Analytics): We use Google Analytics to understand visitor behavior. We will only deploy these cookies on your browser if you provide explicit, prior consent via our cookie consent banner. You may withdraw your consent at any time through our Cookie Settings interface.

8. Our Article 28 Processor Obligations

When handling End-User data as a Data Processor, Qrdery binds itself to the structural requirements of Article 28 GDPR:

  • We process personal data solely on documented, written instructions from the Client.
  • We ensure that all personnel authorized to process personal data have committed themselves to contractual confidentiality obligations.
  • We implement appropriate technical and organisational measures intended to secure the data.
  • We maintain a current list of authorized subprocessors and notify Clients of any intended changes.
  • We assist the Client, via appropriate technical tools, in responding to End-Users exercising their data subject rights.
  • We assist the Client in ensuring compliance with security breach notification obligations.
  • At the choice of the Client, we delete or return all personal data upon termination of the SaaS agreement, unless statutory preservation applies.

9. International Data Transfers

Some of our third-party infrastructure providers operate data servers located outside the European Economic Area (EEA), notably within the United States. Whenever your personal data is transferred outside the EEA, we implement appropriate safeguards intended to ensure an essentially equivalent level of protection by enforcing the following safeguards:

  • Where applicable, transfers may rely on adequacy decisions adopted by the European Commission (such as the EU-US Data Privacy Framework).
  • Utilizing the Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Where required, we conduct Transfer Impact Assessments (TIAs) and implement supplementary technical measures (such as data encryption in transit and at rest) to protect datasets against unauthorized access.

10. Technical and Organizational Security Measures

We have implemented appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, preventing your personal data from being accidentally lost, compromised, altered, or accessed without authorization. Our architecture includes:

  • Secure Sockets Layer (HTTPS/TLS) encryption for data in transit.
  • Encryption of stored data using security features available within our hosting infrastructure (such as AES-256 cloud architectures).
  • Role-based access controls (RBAC) to limit data visibility to authorized personnel.
  • Multi-factor authentication (MFA) requirements for developer, hosting, and administrative environments.
  • Periodic database backups and system activity logs.
  • We have established formal internal protocols to handle any suspected data breach, and we will notify affected users and the relevant supervisory authorities without undue delay where required by applicable law.

11. Data Retention

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

  • Client Account Data: We store active account data for the duration of your active SaaS contract with us.
  • End-User Reservation & Loyalty Data: Reservation, ordering, and loyalty data is retained only for the period specified by the Client through our platform configuration or until deletion instructions are received under the applicable Data Processing Agreement.
  • Statutory Tax Retention Override: Upon the termination or closure of a client account, we are required under applicable legislation to retain core identity, financial, and transactional records for a mandatory statutory period of five (5) years under Cyprus corporate law for fiscal auditing purposes. Furthermore, regional financial laws demand that verified financial transactions and signed records within our cloud fiscal tracking environments (such as Fiskaly/Austrian RKSV receipt logs) remain archived for a mandatory minimum statutory holding window of up to seven (7) years under local tax laws. Following this, data is completely purged or permanently anonymized.

12. Your Legal Rights Under the GDPR

Under EU data protection laws, users (including corporate client representatives, restaurant staff, and end guests) possess the following comprehensive statutory rights regarding their personal data:

  • Right of Access (Article 15 GDPR): Request a clear, comprehensive copy of the personal data we hold about you.
  • Right of Rectification (Article 16 GDPR): Request the immediate modification or correction of incomplete or inaccurate data.
  • Right to Erasure / "Right to be Forgotten" (Article 17 GDPR): Request deletion of data, subject to lawful overrides like our statutory 5-year and 7-year fiscal tracking record obligations.
  • Right to Restriction of Processing (Article 18 GDPR): Request that we suspend or place constraints on the active processing of your data under specific conditions.
  • Right to Data Portability (Article 20 GDPR): Request a clean, standardized, machine-readable export format (such as JSON or CSV files) detailing your core account and activity logs.
  • Right to Object (Article 21 GDPR): Object to processing where we rely on a legitimate interest or direct marketing.
  • Right to Withdraw Consent (Article 7(3) GDPR): Withdraw your consent at any time where processing is consent-based (e.g., Google Analytics, newsletters).
  • Automated Decision-Making Rights (Article 22 GDPR): You have the right not to be subject to decisions based solely on automated processing. Qrdery does not make decisions producing legal or similarly significant effects based solely on automated processing.
  • To exercise your rights, contact us at qrdery@qrdery.io. We respond to verified requests within one calendar month.

12.1 Right to Lodge a Complaint

You have the right to lodge a complaint at any time with the supervisory authority for data protection issues in Cyprus:

  • Office of the Commissioner for Personal Data Protection
  • Website: https://www.dataprotection.gov.cy
  • Email: commissioner@dataprotection.gov.cy

13. Changes to this Privacy Policy

  • We may update this Privacy Policy from time to time to reflect regulatory shifts or operational changes. Unless otherwise stated, revisions become effective when the updated Privacy Policy is published. Material changes will be communicated via email or through the platform dashboard interface where legally required.