GDPR & Security
Gastavo is built in Europe, for European hospitality. Privacy is not an afterthought — anonymous-by-design guest feedback is the product. This page summarizes how we comply with the General Data Protection Regulation (GDPR) and how we secure your data.
Anonymous by design
- Guests never create accounts, and we never ask them for names, emails, or phone numbers.
- Feedback pages contain no advertising trackers, no analytics cookies, and no fingerprinting.
- The only identifiers stored with feedback are the restaurant, the table, and a timestamp.
Data residency
- All customer and feedback data is stored in the European Union (Supabase, EU region).
- Where a processor operates outside the EU (OpenAI for comment categorization), transfers are safeguarded by EU Standard Contractual Clauses. Mollie, our payment processor, is based in the Netherlands.
- Feedback comments sent to OpenAI are used only to generate categories and summaries — never for AI model training.
Security measures
- Every restaurant’s data is isolated with database Row Level Security — one customer can never read another’s data.
- All traffic is encrypted in transit (TLS); data is encrypted at rest.
- Authentication is handled by Supabase Auth, with Google sign-in as an option; passwords are stored as salted hashes, never in plain text.
- Payment details are handled entirely by Mollie (PCI-DSS Level 1); they never touch our servers.
- Access to production systems is restricted and logged.
Roles and agreements
For guest feedback, the restaurant is the data controller and Gastavo acts as processor. A Data Processing Agreement (DPA) covering our processing and our subprocessors is available to every customer — request it through the Support page in your dashboard.
Subprocessors
- Supabase — database & authentication (EU)
- Vercel — hosting
- OpenAI — AI categorization & summaries (US, SCCs)
- Mollie — payments
- Resend — email delivery
Data subject requests
Guests or restaurant users can exercise their GDPR rights (access, correction, deletion, portability, objection) through the Support page in the Gastavo dashboard. We respond within 30 days. Complaints can be lodged with the Autoriteit Persoonsgegevens.
Incident response
In the unlikely event of a personal data breach, we notify affected customers and, where required, the supervisory authority within 72 hours of becoming aware, in line with Articles 33–34 GDPR.