Personal Data Processing Notice
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
Carteia processes personal data in a dual role: Controller for restaurateurs' data, Processor for end-customers' data. This notice is therefore organised on two levels.
Preamble — the two roles of Carteia
Carteia processes personal data in a dual role, depending on whom the data refers to:
Toward the restaurateurs who subscribe to the service, Carteia is the Data Controller.
Toward the end customers of restaurants (bookings, orders, loyalty programmes), Carteia is a Processor on behalf of the restaurant, which remains the Controller.
The relationship described at Level 2 is governed in detail by the Data Processing Agreement (DPA) signed by the restaurateur upon activation.
The Data Controller (for the Level 1 data) is:
Carteia
Un progetto di Mind3D P.IVA 03732170794
VAT IT03732170794
Website: carteia.app
Privacy contact: privacy@carteia.app
General/legal contact: info@carteia.app
For any privacy matter, the dedicated address is privacy@carteia.app.
Notice in detail
Level 1 · Carteia is ControllerNotice for restaurateurs (SaaS customers)
For the restaurateur's account data, Carteia is the Data Controller.
1.1 Categories of data processed
- Identification and contact data of the business and its representative: company name, VAT/tax code, address, certified email (PEC), email, phone;
- Legal representative's data: first and last name, date of birth, tax code, email (for business verification and legal formalities during onboarding);
- Credentials and account data: login email, authentication data, roles and permissions of collaborators;
- Billing and payment data: subscribed plan, amounts, payment data (handled through the payment provider — Carteia does not store card numbers);
- Electronic signature data: evidence of acceptance of the Terms of Service (signature image, timestamp, IP address, user agent, tamper-proof SHA-256 hash);
- Technical logs and usage data: IP addresses, access events, error diagnostics, service usage statistics.
1.2 Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Provision of the SaaS service and performance of the contract | 6.1.b — performance of a contract |
| Invoicing, tax and accounting obligations | 6.1.c — legal obligation |
| Business verification, ToS acceptance, fraud prevention | 6.1.b / 6.1.c / 6.1.f |
| Security, diagnostics, abuse prevention | 6.1.f — legitimate interest |
| Service improvement and usage statistics | 6.1.f — legitimate interest |
| Direct marketing communications (if enabled) | 6.1.a — consent / soft opt-in |
1.3 Nature of the provision
Providing identification, billing and legal-representative data is necessary to activate and deliver the service: refusal makes it impossible to enter into the contract. Data for marketing purposes is optional.
1.4 Retention periods
- Account and contract data: for the duration of the relationship and 30 days after termination (then deletion/anonymisation);
- Accounting/tax data and documents (invoices): 10 years (Art. 2220 of the Italian Civil Code);
- Evidence of ToS acceptance and consents: for the duration of the relationship + the applicable limitation period;
- Technical/security logs: 6 months.
Level 2 · Carteia is ProcessorNotice for restaurants' end customers
For end-customer data collected through the platform, the restaurant is the Controller and Carteia acts as Processor on its behalf, under the DPA. Purposes and legal bases are determined by each restaurant; the following describes the processing carried out by Carteia on its behalf.
2.1 Categories of data processed
- Booking data: name, phone, optional email, date/time, number of guests, notes;
- Waitlist data: name, contact, requested time;
- Table-ordering data (where the add-on is enabled): items ordered, table, amounts;
- Loyalty data: loyalty account, points balance, transactions, rewards;
- Consents: recording of date, time and version of the notice accepted, for evidentiary purposes;
- Menu visit statistics: collected in aggregated and anonymous form.
2.2 Allergen filter and dietary preferences
The public menu's allergen filter works in an anonymous, client-side way: it lets the customer hide incompatible dishes without creating an account, without uniquely identifying them and without storing the selections made. It therefore involves no collection of personal data and no processing of special categories of data (Art. 9 GDPR). Any allergy information voluntarily communicated to the restaurant (e.g. in a booking note) is processed by the restaurant as Controller.
2.3 Recipients
End-customer data is accessible to the restaurant Controller and its authorised collaborators, as well as to Carteia (Processor) and its technical sub-processors (Section 3).
2.4 Exercising rights
Requests concerning end-customer data must be addressed to the restaurant as Controller. Carteia, as Processor, assists the restaurant in handling requests (Art. 28.3.e and 28.3.f GDPR), but does not independently decide on the purposes of the processing.
Section 3Recipients and processors
Carteia relies on providers acting as processors under Art. 28 GDPR, bound by agreement:
| Provider | Function |
|---|---|
| Postgres database | Database hosting, authentication, storage |
| AWS Hosted | Application hosting and delivery |
| Stripe | Payment processing |
| Anthropic, OpenAI, Meta AI | AI assistance (e.g. menu import and structuring) |
| Sentry | Error monitoring and diagnostics |
| AWS provider | Service email delivery |
Only with prior consent (cookies/analytics and marketing tools): Google (Google Analytics 4) and Meta (Meta/Facebook Pixel) may receive browsing data.
Section 4Non-EU transfers
Some providers may process data outside the European Economic Area. Such transfers are covered by Standard Contractual Clauses (SCC) under Implementing Decision (EU) 2021/914 and/or by adequacy decisions of the European Commission, with supplementary measures where necessary.
Section 5Automated decision-making and artificial intelligence
Carteia uses AI tools (Anthropic, OpenAI, Meta AI) as support for activities such as menu import and structuring. No solely automated decisions are made that produce legal effects or similarly significantly affect data subjects within the meaning of Art. 22 GDPR. End-customer data is not used to train AI models.
Section 6Rights of the data subject
Within the limits of Art. 15–22 GDPR, you have the right to: access, rectification, erasure ("right to be forgotten"), restriction, objection, portability and, where processing is based on consent, withdrawal of consent at any time (without prejudice to processing already carried out).
- For data processed by Carteia as Controller (Level 1): privacy@carteia.app.
- For end-customer data (Level 2): contact the restaurant as Controller; Carteia will assist it.
You also have the right to lodge a complaint with the supervisory authority — in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
Section 8Changes to this notice
Carteia may update this notice. Material changes are communicated through the service and/or by email. The date at the top indicates the latest revision.
Section 9Contacts
For any request regarding data processed by Carteia: privacy@carteia.app.