We process contact and account data, business and restaurant details, team memberships and roles, invitation data, tenant and domain settings, provisioning and deployment statuses, operational identifiers and audit events to provide and administer the subscribed platform services (Art. 6(1)(b) GDPR). Security, traceability and reliable operations also rely on Art. 6(1)(f) GDPR.
Team members may receive data from the inviting owner or editor. Required contract and configuration data must be provided if the corresponding service is to be used. Team invitations expire after 7 days. Operational and audit data is retained for the contract term and afterwards according to statutory duties and objective requirements for security, evidence and legal claims.
For the optional Startklar service, we process uploaded menus, photographs, logos and other supplied files, source links, instructions, checksums, material and workflow status, access roles and audit information. Access is limited to the tenant and authorised Speisando administrators. Processing is necessary for the commissioned content transfer under Art. 6(1)(b) GDPR. Materials supplied in the dashboard are removed 90 days after completion, cancellation or a full refund. Website content and media already published or transferred manually to the Runtime are not affected by this deletion process.
The internal media library stores files, metadata, checksums, categories, share packages and authorised editors. Share links remain valid for 1, 7 or 30 days and can no longer be accessed after expiry or revocation. The Media Manager performs no automatic deletion; files, packages and associations remain until they are deleted manually.