Privacy Policy
Effective Date: [Insert date]
1. Introduction
DTU Strateg Pro ("we", "us", or "our") provides cloud-based point-of-sale (POS) software and related services for restaurants and hospitality businesses.
This Privacy Policy explains how we collect, use, store, and protect personal data when providing our services.
The data controller for personal data processed through our services is:
DTU Strateg Pro Ul. Leninova br. 29 Republic of North Macedonia
Privacy contact: [contact@prodanov.dev](mailto:contact@prodanov.dev)
2. Roles and Responsibilities
DTU Strateg Pro provides the technical platform and infrastructure.
Restaurant owners and businesses using our platform ("Venue Owners") are responsible for the personal data they enter into the system and for determining how that data is used within their business operations.
Venue Owners may add employees and manage access permissions. DTU Strateg Pro does not have an employment relationship with venue employees.
Customers placing orders through QR ordering interact with the restaurant's ordering system. DTU Strateg Pro does not have a direct customer relationship with those individuals.
3. Information We Collect
3.1 Venue Information
We may store information about venues, including:
- Venue name
- Address
- Phone number
- Email address
- Business information
- Opening hours
- Tables and seating information
- Menu and product information
3.2 Sales and Operational Data
The platform processes operational restaurant data, including:
- Orders
- Order timestamps
- Products and quantities
- Prices
- Discounts
- Payment status
- Fiscal receipt information
- Inventory information
- Supplier information
- Reports and analytics
- Audit records showing actions performed by users
3.3 Employee Information
Venue Owners may create employee records.
Employee data stored by the system is limited to:
- Employee name
- Access credentials required for local bridge operation
Employee permissions and actions may be recorded through audit logs.
3.4 User Account Information
Cloud users may include Venue Owners and authorized personnel.
Account data may include:
- Username/email
- Password hash
- Role and permission assignments
Passwords are stored using bcrypt hashing.
3.5 QR Ordering Information
Customers may place orders through QR codes provided at venues.
The QR ordering system does not require:
- Customer accounts
- Customer names
- Customer email addresses
- Customer phone numbers
When enabled by the Venue Owner, location verification may be requested when submitting an order.
Location data:
- Is requested only when the customer submits an order
- Is used to verify that the order originates from the venue
- Is stored only for successfully accepted orders
- Is not stored for rejected orders caused by location verification failure
Location information is not used to identify customers.
3.6 Supplier Information
Venue Owners may store supplier information, including:
- Supplier name
- Contact person
- Phone number
- Email address
- Supplied products
Suppliers may access purchase orders through temporary signed links. Suppliers do not create accounts.
Supplier links expire after 21 days and may be revoked by the Venue Owner.
3.7 Technical Information
We may process technical information necessary to operate and secure the service, including:
- Application logs
- System logs
- Bridge identifiers
- Machine-derived identifiers used for installation binding and license protection
- Bridge IP addresses
- Backup information
Technical logs may contain information such as IP addresses for operational purposes. Such information is not used to identify QR ordering customers.
4. How We Use Information
We process data for the following purposes:
Providing the Service
- Processing restaurant orders
- Managing inventory
- Managing menus and products
- Generating reports
- Managing suppliers
- Synchronizing local bridges with cloud services
Account Management
- Creating and authenticating accounts
- Managing permissions and roles
- Protecting accounts from unauthorized access
Security
- Preventing fraud and abuse
- Protecting software licenses
- Detecting unauthorized access attempts
- Maintaining system security
Reliability and Maintenance
- Creating backups
- Troubleshooting issues
- Monitoring system health
- Improving software functionality
Communication
We may send operational communications, including:
- Service-related emails
- Account-related notifications
- System notifications
The platform does not send marketing communications.
5. Legal Basis for Processing
Where applicable, we process personal data based on:
- Performance of contractual obligations
- Legitimate interests, including security, fraud prevention, service improvement, and maintaining reliable services
- Legal obligations, including accounting and tax requirements
6. Data Sharing
DTU Strateg Pro does not sell, rent, or commercially share personal data.
Data may be processed by infrastructure providers required to operate the service.
7. Infrastructure and Subprocessors
Our infrastructure is hosted on Amazon Web Services (AWS).
Services used include:
- Amazon EC2
- Amazon RDS
- Amazon S3
- Amazon SES
- Amazon ECR
- AWS Lambda
- AWS IoT Core
Services are hosted in the AWS EU Central (Frankfurt) region.
Data is stored within the European Union.
8. Provider Access to Data
DTU Strateg Pro may access venue data when necessary for:
- Technical support
- Maintenance
- Troubleshooting
- Service operation
Access is performed through an authorized account known to the Venue Owner.
Access is limited to situations where it is required.
9. Security Measures
We implement reasonable technical and organizational security measures, including:
- TLS encryption for communications
- Encrypted communication between local bridges and cloud services
- Venue-specific API authentication keys
- Password hashing using bcrypt
- Login rate limiting
- Restricted database access
- Secure storage of application secrets
- Local bridge authentication protection
Local bridge installations use device-based protection mechanisms to prevent unauthorized copying.
No system can guarantee absolute security. Users are responsible for protecting their credentials and maintaining appropriate security practices.
10. Cookies and Tracking
The platform does not use:
- Tracking cookies
- Advertising cookies
- Third-party cookies
- Analytics services
Authentication uses browser storage mechanisms rather than cookies.
11. Data Retention
Data is retained while the Venue Owner account remains active.
Venue data is deleted when requested by the Venue Owner.
Backups are automatically rotated and expire according to the backup retention cycle.
12. Data Requests
Venue Owners may request deletion of their stored data.
Employees and QR ordering customers should direct privacy requests to the relevant Venue Owner because the Venue Owner controls the operational data.
The platform currently does not provide automated data export functionality.
13. Account Termination
If a subscription expires or is terminated:
- The account enters a 7-day grace period.
- During this period, access may be limited.
- After the grace period, local bridge operation may be disabled until subscription renewal.
Accounts terminated for abuse may be suspended or disabled immediately.
14. Changes to This Policy
We may update this Privacy Policy periodically. Updated versions will be published through our services.