Privacy
Privacy Notice
How PROMTIS handles account, staff, guest, order, delivery, feedback, support, and technical information, including our different roles as controller and processor.
Last updated: August 28, 2026
1. Who this notice covers
This Privacy Notice applies to visitors, account owners, staff users, support contacts, and guests who interact with PROMTIS websites, venue pages, menus, ordering, feedback, and related services.
PROMTIS is operated by TECHBRAIN d.o.o., Slovenia. Company and contact details are provided in the Legal Notice. Privacy requests may be sent to info@promtis.menu.
2. Our role
PROMTIS acts as controller for account registration, subscription administration, billing coordination, service security, legal compliance, direct support, and operation of its own website.
For guest, staff, order, delivery, feedback, supplier, and venue-operation data processed on a venue's instructions, the venue normally acts as controller and PROMTIS acts as processor. Those activities are governed by the customer agreement and, where applicable, the Data Processing Agreement.
3. Data we process
Account and commercial data may include names, business details, email addresses, phone numbers, roles, login identifiers, subscription selections, invoices, payment status, and support correspondence.
Operational data may include menus, prices, translations, staff activity, orders, tables, preparation status, delivery details, returns, feedback, warehouse movements, suppliers, and reports.
Technical data may include IP address, browser and device information, timestamps, authentication and security events, diagnostics, and the browser-storage items listed in the Cookie Policy.
4. Purposes and legal bases
We process data to perform contracts and requested pre-contract steps, provide accounts and modules, route orders, support operations, process subscriptions, answer support requests, and maintain the service.
We process data where necessary for legitimate interests such as service security, fraud prevention, reliability, support quality, and product administration, balanced against individual rights. We also process data to comply with legal, accounting, tax, and regulatory obligations.
Where consent is required, including for optional browser storage or future analytics and marketing technologies, processing remains disabled until consent is given and may be withdrawn through cookie settings.
5. AI-assisted features
When a user requests translation or image-generation features, the submitted menu text, prompt, or related content may be sent to configured AI service providers to produce the requested result. Do not submit personal data or confidential information that is unnecessary for the requested output.
6. Recipients and processors
The providers confirmed by the operator are Railway for application hosting and Stripe for payments and subscriptions where enabled. User-requested AI features send the relevant content to the provider configured for that feature. The legal entities, processing locations, other subprocessors, and transfer safeguards must be verified and listed before this notice can be treated as complete.
We do not sell personal data. Providers receive only data needed for their role and are subject to contractual and security requirements appropriate to the processing. The landing-page video is not requested until you select “Load video from YouTube”. If you choose to load it, your browser connects to YouTube, which may process technical data under its own privacy terms.
7. International transfers
Where data is transferred outside the EEA, we use an applicable adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism and assess supplementary measures where required. The final production documentation must identify provider entities, processing regions, and transfer mechanisms in the maintained subprocessor list.
8. Retention
We keep data only for as long as necessary for the stated purpose, the customer agreement, security, dispute handling, and applicable legal or accounting requirements. Account, order, log, backup, support, and deleted-data schedules may differ.
Exact retention periods for account data, venue operations, logs, backups, support records, and deleted data have not yet been confirmed for this notice. They should be documented by data category and purpose in the customer-facing retention schedule. Browser-storage durations are listed separately in the Cookie Policy.
9. Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, portability, or objection and may withdraw consent at any time. Requests concerning venue-controlled order or guest data should normally be directed to that venue first; PROMTIS will assist the venue where required.
You may complain to the competent data-protection authority in the country where you live or work, or where an alleged infringement occurred. Requests can be sent to info@promtis.menu. Identity may be verified before a request is completed.
10. Security and changes
We use access controls, authentication safeguards, encrypted transport, restricted operational access, logging, backups, dependency maintenance, and incident-handling practices appropriate to the service. No online system can guarantee absolute security.
Material changes will be published with an updated effective date. Where required, we will provide additional notice or request renewed consent.