Skip to main content
Kymiro

Privacy policy

This privacy policy explains which personal data Kymiro processes, for which purposes and on which legal basis — for guests who scan a QR code, for venues and their staff, and for visitors of kymiro.com.

Last updated: 20 August 2026

1. Scope

This policy covers three parts of the service: the guest view that opens after scanning a venue QR code, the back office used by venues, their staff and sales partners, and the public website kymiro.com including its cookie banner.

2. Controller and contact

NT Investments UG (haftungsbeschränkt), Katzbachstraße 8, 40231 Düsseldorf, Germany. Managing Director: Nikolaos Charalampidis. Commercial register: Amtsgericht Düsseldorf, HRB 83079. VAT ID pursuant to § 27a UStG: DE321423608. Email: info@kymiro.com. No data protection officer is required by law for our organisation; please use the email address above for all data protection matters.

3. Who is responsible for which data

The roles are split, and this matters for your rights:

  • Guest data created inside a venue's digital menu — selections, item notes, table sessions, guest display names, waiter calls — is processed by Kymiro strictly on behalf of that venue. The venue is the controller (Art. 4(7) GDPR), Kymiro is the processor (Art. 28 GDPR) under a data processing agreement that forms part of our terms.
  • Account, contract, billing and website data of venues, staff members and sales partners is processed by Kymiro as its own controller.
  • We never sell personal data, we do not use it for advertising profiles, and no automated decision-making with legal effect under Art. 22 GDPR takes place.

4. Guest data: categories, purposes, legal bases

Guests use the menu without an account and without registering. We process only what the venue needs to serve the request:

  • Request content: selected products, quantities, options, item notes, preliminary amounts, service requests and waiter calls. Purpose: transmitting the request to the venue. Legal basis: Art. 6(1)(b) GDPR (steps at the guest's request) and Art. 6(1)(f) GDPR (the venue's legitimate interest in running its service).
  • Session data: venue, area, spot or table code, session identifier, an optional self-chosen guest name shown to the other guests at the same table, and the fee snapshot applied to the session. Purpose: keeping one shared session per spot correct. Legal basis: Art. 6(1)(b) and (f) GDPR.
  • Device settings: language and appearance preference, cart identifier. Purpose: showing the menu in the right language and keeping the cart during the visit. Legal basis: § 25(2) TDDDG (strictly necessary) together with Art. 6(1)(f) GDPR.
  • Technical log data: IP address, request time, browser and operating system version, error reports. Purpose: delivering the page, security and troubleshooting. Legal basis: Art. 6(1)(f) GDPR.
  • Guests never have to enter a name, phone number, email address or payment card in Kymiro.

5. Venue, staff and partner data

For everyone who signs in to the back office we process:

  • Account data: email address, name, password hash or Google sign-in identifier, role, assigned venues and stations, invitation status. Legal basis: Art. 6(1)(b) GDPR (user agreement).
  • Venue master data: business name, address, contact details, opening hours, branding, menu content, tariffs and plan. Legal basis: Art. 6(1)(b) GDPR.
  • Operational records: audit log entries for sensitive actions such as goodwill discounts, voided items, plan or role changes. Purpose: traceability and abuse prevention. Legal basis: Art. 6(1)(f) GDPR.
  • Billing data for the annual subscription. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR in connection with commercial and tax retention duties.

6. Cookies and local storage

Kymiro works with a small set of strictly necessary browser storage entries and asks for consent before anything else is set. Strictly necessary entries — sign-in session, cart and table session, language, appearance and your cookie decision itself — are stored under § 25(2) TDDDG without consent because the service cannot work without them. Optional categories (preferences, analytics, marketing) are only activated after you opt in under § 25(1) TDDDG and Art. 6(1)(a) GDPR. You can change or withdraw your decision at any time with the button below or on the cookie policy page; withdrawal does not affect processing that happened before. The guest menu contains no advertising trackers.

7. AI features

Venues can have menu texts translated automatically, import a menu from a photo of a printed card, and generate or tag product images. For these features menu content of the venue — text and uploaded pictures — is sent to our AI provider through an AI gateway. No guest request data is used for AI features and no data from these features is used to train third-party models on our instruction. Images created by AI are marked as such in the guest menu.

8. Recipients and processors

We only pass data to service providers who are contractually bound under Art. 28 GDPR:

  • Hosting, database, file storage and authentication (Lovable Cloud, built on Supabase infrastructure) — stores venue, menu, session and account data.
  • AI gateway provider for menu translation, menu import from photos and product image generation.
  • Email delivery provider for sign-in, password and staff invitation emails.
  • Stripe Payments Europe for the venue subscription — this is prepared but not active yet; it will only process venue billing data, never guest payments.
  • The venue you send a request to receives that request. Beyond that, data is only disclosed to public authorities where we are legally obliged to do so.

9. Transfers outside the EU/EEA

Our infrastructure is operated in the European Union wherever possible. Some AI and infrastructure providers may process data in third countries, in particular the United States. Such transfers are safeguarded by an adequacy decision of the European Commission or by the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR together with additional technical and organisational measures. You can request a copy of the safeguards at info@kymiro.com.

10. Retention periods

We keep data no longer than necessary:

  • Table sessions and their requests: automatically deleted 30 days after the session is closed; venues can delete them earlier at any time. Only anonymous daily totals are kept for up to 90 days for the venue's own statistics.
  • Support requests: deleted 24 months after submission. Back-office audit log entries: deleted 12 months after the action.
  • Account and contract data: for the duration of the agreement, then deleted unless retention duties apply.
  • Invoices and accounting records: 10 years under § 147 AO and § 257 HGB; commercial letters 6 years.
  • Cookie consent proof: for the duration of the consent cycle plus the period needed to demonstrate it.
  • Technical log data: normally deleted or anonymised after a short period, unless required for a security investigation.
  • After an account deletion: we keep pseudonymised proof only — acceptance of the agreements and accounting records for 10 years, the record of the deletion itself for 3 years. It contains no name, email address or phone number.
  • Legal hold: while a matter is pending (open invoice, dispute, request by an authority) deletion is suspended, the data is restricted and removed as soon as the matter ends.

11. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21) and withdrawal of consent at any time (Art. 7(3)). Guests should address requests about their orders to the venue, which is the controller for that data; if you contact us instead we forward your request to the venue without undue delay and support them in answering it. For account and contract data, contact info@kymiro.com directly.

12. Right to lodge a complaint

You can lodge a complaint with a supervisory authority, in particular in the member state of your residence or place of the alleged infringement:

  • Greece: Hellenic Data Protection Authority (HDPA), Kifissias 1-3, 115 23 Athens, www.dpa.gr
  • Germany: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2-4, 40213 Düsseldorf, www.ldi.nrw.de

13. Security

Data is transmitted over encrypted TLS connections. Access is protected by authentication, role-based permissions and row-level security rules in the database, so a venue's staff can only reach that venue's data. Sensitive actions are written to an audit log. We review these measures regularly; no online service can, however, guarantee absolute security.

14. Children

The service is directed at hospitality businesses and their adult guests. It is not intended for children under the age of 16, and we do not knowingly process their data beyond an ordinary request placed at a table.

15. Changes to this policy

We update this policy when the service or the legal situation changes. The current version always applies, with the date shown at the top of this page.

Manage your choice

You can change or withdraw your consent at any time, with no effect on the lawfulness of processing before the withdrawal. We ask again after 12 months at the latest.

Related pages

This policy describes how the Kymiro platform works. Venues remain responsible for their own information duties towards their guests.