Draft · not legal advice
Privacy Policy
Last updated 25 September 2026.
This is a working draft for the Directo product so a public site can link a Privacy page. It is not counsel, not a DPA, and not a completed GDPR Article 13/14 notice for every tenant. A counsel-reviewed text will replace it. Of the facts below, who and how long are the real ones today; where describes the production setup being installed, not a server that already holds data.
Who this covers
Directo is restaurant software: QR menu, staff ops, and Admin 365°. The service is operated by Alex V. Nita, the business of Alexandru Valentin Niță (KvK 42134694) — the “operator” on these pages. Its legal form, address, VAT id and contact details are in the Operator block at the bottom.
- Operator as controller. For what it decides on its own to run the product securely — credentials (password hashes), second-factor secrets, sessions, the security audit log, and the organisation and venue profile of the account holder — the operator decides why and how the data is processed and is the controller.
- Operator as processor. For everything a venue records while running its restaurant — guests (name, phone, e-mail if given, orders, feedback, reservations, waitlist notes, marketing consent), staff identity and records (name, e-mail, job, schedules, clock punches, geofence proof at punch; staff accounts are created by the venue for its employees) and uploaded files — the venue is the controller and the operator processes the data on the venue’s instructions. Whether the operator is processor or joint controller for staff identity is a question for counsel. A written DPA between the venue and the operator is pending counsel.
Data we expect to process
- Venue profile: name, slug, hours, address, maps links, public Presence copy.
- Staff: name, email, job, permission set, clock punches, optional geofence proof at punch.
- Guests: name/phone/email if they give it, orders, feedback, reservations, waitlist notes.
- Files the venue uploads (HACCP, contracts, menus). Those are the venue’s documents.
Purposes and legal bases
- Creating and running accounts, taking and serving orders, reservations and the waitlist — performance of a contract, GDPR art. 6(1)(b).
- Order totals, dates and VAT lines kept after a guest’s erasure — a legal obligation (bookkeeping and VAT law), art. 6(1)(c).
- The security audit log, rate limiting, session revocation and two-factor authentication — the operator’s and the venue’s legitimate interest in keeping accounts and venue data safe, art. 6(1)(f).
- Offers sent to a guest — consent, art. 6(1)(a), given by ticking an unticked box and withdrawable at any time without affecting what happened before.
A guest’s name is needed to serve the order; phone and e-mail are optional and only used for the order status, a reservation or, with consent, offers. An account e-mail is required to use the product as staff or owner — without it no account can be created. No other data is mandatory. Directo takes no automated decisions with legal or similarly significant effects and does no profiling.
Marketing consent and your rights
A guest is only contacted with offers after ticking an unticked box at checkout or on the feedback form, and only when they left a phone or email; the venue records when and where the consent was given and can withdraw it on request. A guest can ask the venue for a copy of their data (the venue downloads it as JSON from Admin → Guests) or for erasure: name, phone, email and notes are removed from the profile, orders, reservations, waitlist and feedback, while order totals and dates stay for the venue's books. Owners and staff can ask the operator for the same about their own account.
Under the GDPR you have the right of access (art. 15), to rectification (art. 16), to erasure (art. 17), to restriction of processing (art. 18), to data portability (art. 20 — the JSON export is the portable copy), to object (art. 21), to withdraw consent at any time (art. 7(3)) and to lodge a complaint with a supervisory authority (art. 77) — see below.
How long we keep it
Identity fields — a guest’s name, phone, e-mail and notes — are erased on request, in one irreversible step that is logged. Order totals, dates and VAT lines are not erased: the venue must keep them for its bookkeeping obligations, which this draft takes as 5 years in Romania (Legea contabilității nr. 82/1991 art. 25, as amended in 2023) and 7 years in the Netherlands (Awr art. 52) — counsel confirms which term applies to order and VAT records. Sessions expire or are revoked; security audit rows are kept with the organisation. When a venue leaves Directo, its data is exported on request and then deleted in full within 30 days; the venue keeps the export for its own bookkeeping. Account data is kept while the account exists and deleted within 30 days after closure; the operator’s own invoices to venues are kept 7 years (Awr art. 52). Counsel confirms the two 30-day terms.
Where it lives
Production is being set up on a Hetzner Cloud server operated by Hetzner Online GmbH in Falkenstein, Germany (EU) for the API, the Postgres database, Redis, uploaded files, the nightly database backups and the web app. Until go-live there is no production tenant: the public Demo Bistro preview runs on Vercel and reaches a demo API on an operator-controlled host in the EU through a Cloudflare tunnel. This paragraph switches to the present tense in the commit that marks Hetzner live on Subprocessors. Data is not transferred outside the EU/EEA, with one exception listed there: Vercel, a US company, serves pull-request previews of the web app and the public preview, under Vercel’s data processing addendum (standard contractual clauses / EU-US Data Privacy Framework — counsel confirms). Two possible further recipients, EU region intended, are the e-mail provider and Sentry; neither is connected today.
What we do not do in this draft
- No sale of guest lists. Growth send is a stub — SMS is not connected.
- No continuous staff location tracking. Location is only at clock-in / clock-out.
- Connect partners stay Setup or Coming soon until a secret ref is stored for real.
Supervisory authorities
The operator is established in the Netherlands, so its lead supervisory authority is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). Anyone can also complain to the authority of the country where the venue is: guests and staff of a Romanian venue to the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, dataprotection.ro); those of a Dutch venue to the Autoriteit Persoonsgegevens. We would rather hear from you first — see Contact.
Contact
Requests about your data — access, a copy, correction, erasure, restriction, objection, withdrawing marketing consent — go to hello@alexvnita.com; a guest can also ask the venue directly, which handles them from Admin → Guests. The operator is a sole proprietorship whose core activity is not large-scale monitoring or the processing of special categories of data, so it is not required to appoint a Data Protection Officer and has not appointed one; Alexandru Valentin Niță, the holder, answers data requests personally, within one month (GDPR art. 12(3)). The full operator identity (address, KvK, BTW-id, phone) is in the Operator block below. Until counsel signs off, this page is a draft; a production tenant other than Demo Bistro will see the reviewed version.
Operator
The party that runs the Directo service and answers for these pages.
- Trade name
- Alex V. Nita
- Legal form
- eenmanszaak (sole proprietorship / ZZP), registered in the Netherlands
- Holder
- Alexandru Valentin Niță
- Address
- Poolcirkelstraat 171334 BM AlmereThe Netherlands
- KvK
- 42134694
- BTW-id
- NL005525228B71
- hello@alexvnita.com
- Phone
- +31 6 16044216
- Website
- alexvnita.com