GDPR & Security

Last updated: 20 July 2026

Gastavo is built in Europe, for European hospitality. Privacy is not an afterthought — anonymous-by-design guest feedback is the product. This page summarizes how we comply with the General Data Protection Regulation (GDPR) and how we secure your data.

Anonymous by design

Data residency

Security measures

Roles and agreements

For guest feedback, the restaurant is the data controller and Gastavo acts as processor. A Data Processing Agreement (DPA) covering our processing and our subprocessors is available to every customer — request it at hello@gastavo.nl.

Subprocessors

Data subject requests

Guests or restaurant users can exercise their GDPR rights (access, correction, deletion, portability, objection) by emailing hello@gastavo.nl. We respond within 30 days. Complaints can be lodged with the Autoriteit Persoonsgegevens.

Incident response

In the unlikely event of a personal data breach, we notify affected customers and, where required, the supervisory authority within 72 hours of becoming aware, in line with Articles 33–34 GDPR.