Skip to content
Security & privacy

Your data belongs to you – safe in Europe.

gastronomx is built privacy-first from the ground up. We only promise what we can keep – here you see exactly how we protect your data and that of your guests.

Hosted in the EU · GDPR-compliant · payments secured via Stripe

How we protect your data

Hosted in the EU

Your data and that of your guests is processed and stored on servers within the European Union.

GDPR-compliant

gastronomx is designed around the requirements of the GDPR – from data minimisation to data subject rights.

Strict tenant isolation

Every business sees only its own data. At the database level, row-level security ensures data is never visible between businesses.

Secure payments

Payments run through Stripe, a PCI-DSS-certified provider. Card data is processed directly at Stripe and never touches our servers.

Data processing agreement (DPA)

For processing on your behalf, we provide a data processing agreement in line with Art. 28 GDPR.

Deletion & retention concept

We keep data only as long as necessary and then delete it under clear rules – including export on request.

2FA for admin access

Administrative access can be additionally secured with two-factor authentication.

Frequently asked questions about security & privacy

Is gastronomx GDPR-compliant?

Yes. gastronomx is designed around the requirements of the GDPR: EU hosting, data minimisation, documented consents and a data processing agreement under Art. 28 GDPR.

Where is my data stored?

Your data is processed and stored on servers within the European Union.

How do you ensure no other business can see my data?

Through strict tenant isolation at the database level (row-level security), every business sees only its own data.

Get started securely – in minutes.

Try gastronomx for free. GDPR-compliant and hosted in the EU.