Privacy notice
How therestao handles personal data for the website and restaurant platform.
Effective 2 September 2026 · version privacy-v2026-09-02
1. Controller and contact
The provider identified on the invoice, trading as therestao, is controller for account, sales, security, and billing administration. A restaurant customer is normally controller for staff, supplier, guest, and operational data it enters; therestao processes that data to provide the service. Contact: therestao@umakue.se, Kista Gårdsväg 8, 164 55 Stockholm, Sweden.
2. Data we process
We process account and contact details, organization and branch data, roles, authentication and security evidence, billing and invoice metadata, support communications, device and request identifiers, audit history, and restaurant operational data submitted by authorized users.
Payment-card details are entered with Stripe and are not displayed to therestao staff. Supplier documents may be sent to the configured AI provider only after current Owner consent, confirmed provider readiness, and an explicit eligible analysis action. The organization's separate, one-time AI trial is limited to five document-analysis uses; Platform Admin cannot reset or increase it, and paid monthly page credits do not replenish it.
3. Purposes and legal bases
We process data to form and perform the B2B agreement, secure and operate the service, provide support, prevent abuse, maintain audit evidence, invoice customers, and meet legal obligations. Depending on the processing, the legal basis is contract, legal obligation, legitimate interests, or consent where required.
4. Recipients and subprocessors
Service data may be processed by infrastructure and delivery providers such as Vercel and Neon, Stripe for billing, and OpenAI for consented supplier-document analysis. Email, private media storage, and monitoring providers are used only when configured. We do not sell personal data.
5. International transfers
Where data is processed outside the EU/EEA, therestao relies on an applicable adequacy decision, standard contractual clauses, or another lawful safeguard and limits the transferred data to what the service requires.
6. Retention
Data is retained only as long as needed for the service, security, dispute handling, billing, accounting, and legal obligations. Operational and audit history is preserved rather than silently deleted where integrity or legal evidence requires it. Retention periods vary by record type and contract state.
7. Your rights
Subject to GDPR conditions, individuals may request access, correction, deletion, restriction, portability, or object to processing, and may withdraw consent without affecting prior lawful processing. Contact therestao@umakue.se. You may also complain to Integritetsskyddsmyndigheten (IMY).
8. Security and automated decisions
We use role-based access, tenant scoping, encryption in transit, bounded processing, audit logs, and provider controls. No AI proposal is used to make a solely automated legal or similarly significant decision about a person.
9. Cookies and changes
We use essential session and security storage needed to sign in and operate the service. Non-essential analytics or marketing storage requires the applicable notice or consent. Material notice changes receive a new version and effective date.