Effective date: 2 October 2026. Initial version; specialist legal review is planned.
1. Controller and contact
Mustafa Dogan, Niederhöchstädter Str. 1, 61476 Kronberg im Taunus, Germany, trading as Bontado, is responsible for the owner and staff account processing described here. Contact: info@bontado.de; telephone: +49 162 9095987. This notice concerns restaurant account holders and staff; it does not replace the restaurant’s notice to its customers or any required data-processing agreement.
2. Information processed
We process account names, email addresses, restaurant information, authentication and security records, permissions, service configuration, and information submitted in support requests. Depending on the features used, we also process uploaded content, order and reservation records, payment references, and operational activity. Passwords are handled through the authentication system; do not include passwords or payment credentials in support messages.
3. Purposes and legal grounds
We use necessary account information to create accounts, provide requested services, communicate service messages, and manage the business relationship. Article 6(1)(b) GDPR applies where necessary to perform a contract with you or take steps you request before entering it. Where you act for a restaurant business, account administration may instead rely on our legitimate interests under Article 6(1)(f) in providing that business with the service. Security and abuse prevention rely on legitimate interests in protecting users and systems. Processing required by law relies on Article 6(1)(c). Optional processing that requires consent relies on Article 6(1)(a); consent can be withdrawn without affecting earlier lawful processing.
4. Recipients and integrations
Authorised restaurant administrators and staff can access information within their permitted roles. Authorised Bontado personnel and service providers may access information where needed for hosting, storage, communications, security, support, and enabled integrations. We may disclose information where legally required. The production service uses Amazon Web Services for hosting, storage, delivery infrastructure, and email through Amazon SES. Its primary application database is hosted in Frankfurt, Germany. Content delivery and support operations may involve processing outside the European Economic Area. AWS’s data-processing terms include standard contractual clauses for applicable international transfers. Where Cloudflare Turnstile is enabled, it processes technical browser and network information for bot detection; see Cloudflare’s Turnstile Privacy Addendum. Optional map, payment, messaging, and other integrations process information needed for the features you enable. Contact us for information about the providers and applicable transfer safeguards for your use of the service.
5. Storage periods
We retain information for as long as needed for the purpose for which it was collected, taking account of account status, security needs, outstanding transactions, legal recordkeeping obligations, and legal claims. Account closure does not immediately erase records that must lawfully be retained. The relevant criteria are whether the service relationship remains active, whether an operational or security purpose remains, whether a retention obligation applies, and whether records are needed for an unresolved claim. Backup copies are subject to the applicable backup lifecycle; contact us for the retention information relevant to a specific record or deletion request.
6. Your rights
Subject to applicable conditions, you can request access, correction, deletion, restriction, and data portability. You may object to processing based on legitimate interests and withdraw consent for consent-based processing. Contact us using the details above; we may need proportionate information to confirm your identity. You can complain to a competent data protection supervisory authority, including the authority where you live, work, or consider an infringement occurred.
7. Required information and automated decisions
Information marked as required is needed to administer your account and provide the requested service; without it, registration or the relevant feature may be unavailable. Automated security safeguards can reject or limit suspicious requests. Contact us if such a safeguard prevents legitimate access so the problem can be reviewed.
8. Cookies and updates
The panel uses authentication and related browser storage to maintain access and application state. Panel storage also remembers language, selected restaurant, working drafts, and event cursors. You can clear browser storage through your browser settings; doing so may sign you out or remove unsaved local work. This notice does not authorise optional advertising or analytics tracking without any consent required by law. We will update this notice when relevant processing changes and communicate material changes as required.