Skip to content

Privacy Policy

We process personal data sparingly and solely in accordance with the GDPR. This policy applies to the marketing website and the gastronomx SaaS platform.

Last updated: June 2026

Note: This page is a template. The details marked in square brackets (company, address, representation, register, VAT ID) must be completed by the operator; the entire text must be legally reviewed before publication.

Controller

The controller for data processing is the entity named in the imprint. Please direct privacy enquiries to: datenschutz@gastronomx.com.

Hosting and server location

gastronomx runs on infrastructure within the European Union. Database, authentication and file storage are operated via Supabase with servers located in the EU. There is no planned transfer to third countries without appropriate safeguards.

Purposes and legal bases

We process data to provide and secure the service, to perform the contract (Art. 6(1)(b) GDPR), to comply with legal obligations (lit. c), on the basis of legitimate interests (lit. f) and – where required – your consent (lit. a).

Services used

Payment processing via Stripe as a processor; card data is processed exclusively at Stripe and never reaches our servers. [List any further services used – e.g. web analytics or email delivery – here.]

Cookies and consent

We use cookies and comparable technologies that are not strictly necessary only with your consent pursuant to Section 25 TDDDG. You can withdraw your consent at any time with effect for the future.

Tenant separation

Data of different businesses is processed strictly separately and isolated from one another at the database level through Row Level Security (RLS).

Retention period

We store personal data only for as long as necessary for the stated purposes or required by statutory retention periods. The data is deleted thereafter.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw any consent given. You also have the right to lodge a complaint with a data protection supervisory authority.

Processing on behalf of businesses

For the data of connected businesses we act as a processor. We provide operators with a data processing agreement (DPA) pursuant to Art. 28 GDPR.