Privacy Policy & Data Protection Notice
Effective Date: September 8, 2026 · Last Revised: September 2026
Tanda ("we", "our", or "the Platform") is a multi-tenant back-of-house operations platform dedicated to commercial kitchens and restaurants. We treat your operational confidentiality and staff privacy with the highest engineering rigor. This document explains transparently how personal and operational data is collected, processed, and safeguarded under the European Union General Data Protection Regulation (GDPR).
Table of Contents
1. Data Controller & Contact Information
For personal data collected during sign-up, user authentication, and billing, the primary Data Controller is the legal operating entity of Tanda.
For operational data stored inside an individual restaurant workspace (including staff rosters, member permissions, recipes, suppliers, and internal kitchen notes), the Restaurant Workspace Owner acts as the Data Controller, and Tanda acts as the Data Processor under GDPR Article 28.
Privacy & DPO Inquiries:
Email: privacy@tanda.app
2. Categories of Personal Data Collected
We practice strict data minimization under GDPR Article 5(1)(c). We only collect what is strictly required to provide back-of-house services:
- Account Identification: Email address, display name, and optional kitchen nickname.
- Authentication & Passkeys: Public cryptographic key credentials for WebAuthn (Face ID, Touch ID, Windows Hello). Biometric templates never leave your local hardware enclave and are never transmitted to our servers.
- Session & Device Telemetry: Session timestamps, user-agent headers, and masked IP addresses for active session audits and brute-force defense.
- Operational & HACCP Logs: Food safety checklists, batch intake logs, storage temperatures, supplier names, and label photographs recorded for food safety regulatory compliance.
3. Lawful Bases for Processing (GDPR Article 6)
Processing your login credentials, team memberships, recipe costing, and workspace settings to provide the contracted Tanda software services.
Processing raw material batch numbers, reception temperatures, and expiration dates to assist restaurants in fulfilling European Union food hygiene and traceability mandates (Regulation EC No 178/2002 and Regulation EC No 852/2004).
Protecting the security and integrity of the platform: rate-limiting brute-force attacks, diagnostic error logging, and cross-tenant isolation enforcement.
When workspace owners optionally configure an external vision AI API key for food label reading, label images are analyzed only upon user initiation. A manual entry fallback is always provided without sending images to external AI services.
5. Sub-processors & International Transfers (GDPR Chapter V)
We engage vetted third-party cloud infrastructure providers under Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs):
| Sub-processor | Purpose | Location | Transfer Safeguard |
|---|---|---|---|
| Supabase Inc. | Database, Auth, Object Storage | European Union (Frankfurt / Ireland) | EU Data Residency + DPA |
| Cloudflare, Inc. | Edge Hosting, DDoS Defense, DNS | Global Edge Network | Standard Contractual Clauses (SCCs) |
| DeepSeek AI (Optional) | Optical label text recognition (user opt-in) | International / External API | Zero-storage ephemeral OCR / Manual bypass available |
| Mapbox, Inc. (Optional) | Kitchen address geocoding | United States / Global | Standard Contractual Clauses (SCCs) |
6. Data Retention & Storage Limitation
- User Accounts: Retained as long as your workspace membership is active.
- Food Label Photos & Batch Logs: Retained permanently in your tenant's secure storage bucket to fulfill statutory food safety audit requirements, unless deleted by the workspace owner.
- Diagnostic Error Logs: Telemetry and error logs in `client_error_logs` are automatically purged after 60 to 90 days.
- Workspace Erasure: When an owner deletes a workspace in Settings, all related recipes, dishes, batches, and records are permanently purged via cascade deletion.
7. Your Rights Under the GDPR (Articles 15–22)
As an EU data subject, you hold fundamental rights regarding your personal data:
Right of Access (Art. 15)
You can view your profile data and active device sessions at any time in Profile Settings.
Right to Rectification (Art. 16)
You can directly edit your display name, nickname, and security credentials in your profile.
Right to Erasure (Art. 17)
You may request deletion of your account and personal identifiers by contacting privacy@tanda.app.
Right to Data Portability (Art. 20)
You are entitled to receive your data in a structured, machine-readable format.
You also have the right to lodge a complaint with your national Data Protection Authority (DPA) if you believe your data has been handled contrary to EU regulation.
8. Technical & Organizational Security (GDPR Article 32)
We employ bank-grade security standards across every software layer:
© 2026 Tanda. All rights reserved.