arrow_back
verified_user Tanda Legal
security EU GDPR (Regulation 2016/679) Compliant

Privacy Policy & Data Protection Notice

Effective Date: September 8, 2026 · Last Revised: September 2026

Tanda ("we", "our", or "the Platform") is a multi-tenant back-of-house operations platform dedicated to commercial kitchens and restaurants. We treat your operational confidentiality and staff privacy with the highest engineering rigor. This document explains transparently how personal and operational data is collected, processed, and safeguarded under the European Union General Data Protection Regulation (GDPR).

business

1. Data Controller & Contact Information

For personal data collected during sign-up, user authentication, and billing, the primary Data Controller is the legal operating entity of Tanda.

For operational data stored inside an individual restaurant workspace (including staff rosters, member permissions, recipes, suppliers, and internal kitchen notes), the Restaurant Workspace Owner acts as the Data Controller, and Tanda acts as the Data Processor under GDPR Article 28.

Privacy & DPO Inquiries:

Email: privacy@tanda.app

folder_shared

2. Categories of Personal Data Collected

We practice strict data minimization under GDPR Article 5(1)(c). We only collect what is strictly required to provide back-of-house services:

  • Account Identification: Email address, display name, and optional kitchen nickname.
  • Authentication & Passkeys: Public cryptographic key credentials for WebAuthn (Face ID, Touch ID, Windows Hello). Biometric templates never leave your local hardware enclave and are never transmitted to our servers.
  • Session & Device Telemetry: Session timestamps, user-agent headers, and masked IP addresses for active session audits and brute-force defense.
  • Operational & HACCP Logs: Food safety checklists, batch intake logs, storage temperatures, supplier names, and label photographs recorded for food safety regulatory compliance.
gavel

3. Lawful Bases for Processing (GDPR Article 6)

Article 6(1)(b) — Performance of a Contract

Processing your login credentials, team memberships, recipe costing, and workspace settings to provide the contracted Tanda software services.

Article 6(1)(c) — Legal Obligation (Food Safety Traceability)

Processing raw material batch numbers, reception temperatures, and expiration dates to assist restaurants in fulfilling European Union food hygiene and traceability mandates (Regulation EC No 178/2002 and Regulation EC No 852/2004).

Article 6(1)(f) — Legitimate Interests

Protecting the security and integrity of the platform: rate-limiting brute-force attacks, diagnostic error logging, and cross-tenant isolation enforcement.

Article 6(1)(a) — Consent (Optional AI Vision Features)

When workspace owners optionally configure an external vision AI API key for food label reading, label images are analyzed only upon user initiation. A manual entry fallback is always provided without sending images to external AI services.

cookie

4. Cookies & Zero-Tracker Commitment

Tanda operates a strict no-tracking policy. We do not embed Google Analytics, Meta Pixel, Hotjar, or advertising identifiers.

We only set strictly necessary authentication cookies (`sb-access-token`, `sb-refresh-token`, `pj2_ws_id`) with `HttpOnly`, `SameSite=Lax`, and `Secure` flags. Under the EU ePrivacy Directive (Directive 2002/58/EC) and GDPR Article 5(3), strictly necessary session cookies required for software functionality do not require a cookie consent banner.

hub

5. Sub-processors & International Transfers (GDPR Chapter V)

We engage vetted third-party cloud infrastructure providers under Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs):

Sub-processorPurposeLocationTransfer Safeguard
Supabase Inc.Database, Auth, Object StorageEuropean Union (Frankfurt / Ireland)EU Data Residency + DPA
Cloudflare, Inc.Edge Hosting, DDoS Defense, DNSGlobal Edge NetworkStandard Contractual Clauses (SCCs)
DeepSeek AI (Optional)Optical label text recognition (user opt-in)International / External APIZero-storage ephemeral OCR / Manual bypass available
Mapbox, Inc. (Optional)Kitchen address geocodingUnited States / GlobalStandard Contractual Clauses (SCCs)
schedule

6. Data Retention & Storage Limitation

  • User Accounts: Retained as long as your workspace membership is active.
  • Food Label Photos & Batch Logs: Retained permanently in your tenant's secure storage bucket to fulfill statutory food safety audit requirements, unless deleted by the workspace owner.
  • Diagnostic Error Logs: Telemetry and error logs in `client_error_logs` are automatically purged after 60 to 90 days.
  • Workspace Erasure: When an owner deletes a workspace in Settings, all related recipes, dishes, batches, and records are permanently purged via cascade deletion.
manage_accounts

7. Your Rights Under the GDPR (Articles 15–22)

As an EU data subject, you hold fundamental rights regarding your personal data:

Right of Access (Art. 15)

You can view your profile data and active device sessions at any time in Profile Settings.

Right to Rectification (Art. 16)

You can directly edit your display name, nickname, and security credentials in your profile.

Right to Erasure (Art. 17)

You may request deletion of your account and personal identifiers by contacting privacy@tanda.app.

Right to Data Portability (Art. 20)

You are entitled to receive your data in a structured, machine-readable format.

You also have the right to lodge a complaint with your national Data Protection Authority (DPA) if you believe your data has been handled contrary to EU regulation.

lock

8. Technical & Organizational Security (GDPR Article 32)

We employ bank-grade security standards across every software layer:

check_circle AES-256-GCM Encryption at Rest for sensitive secrets.
check_circle TLS 1.3 & Strict HSTS for all data in transit.
check_circle PostgreSQL Row Level Security (RLS) tenant isolation.
check_circle Automated Dual-Mode Rate Limiting on auth endpoints.

© 2026 Tanda. All rights reserved.

Terms of Service