Privacy Policy
Last updated: 10 October 2026
This Privacy Policy explains what personal data Fresto (the “Platform”) collects, why we collect it, who receives it, how long we keep it, and what rights you have.
It applies to diners, restaurant owners and staff who use the Platform, and website visitors. We aim to comply with applicable data-protection laws, including the EU General Data Protection Regulation (GDPR) and applicable ePrivacy rules where they apply.
1. Who is responsible for your data
The controller responsible for the relevant personal data processing is:
- Company: EURL Techpos
- Privacy contact: eurltechpos@gmail.com
- Website: https://frestopos.com
Restaurants. When you place an order or make a reservation, we may pass the information needed to fulfil your request to the relevant restaurant. The restaurant generally acts as a separate controller for its own use of that information, including preparing orders, managing reservations and maintaining legally required records. The restaurant’s own privacy practices apply to that processing.
Some restaurants use Fresto to manage their restaurants and related operations. Depending on the feature and arrangement, EURL Techpos may process personal data on a restaurant’s behalf. Where applicable, this relationship is governed by the relevant agreement and data-protection law.
Restaurant owners. The Platform includes a profile area where restaurant owners can manage their account and restaurants. Information associated with that profile is processed to provide these management features and related services.
2. The data we process
The information we process depends on which features you use and what information you choose to provide.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and profile | Name, email address, phone number, login credentials, preferences and account information, where collected | You |
| Orders | Customer contact details, delivery address and instructions, items, quantities, order notes, order type, selected payment method, order number and status history | You; the restaurant |
| Reservations | Name, contact details, date, time, party size and reservation notes | You; the restaurant |
| Table orders | Table identifier, selected items, order notes and order status, where this feature is used | You; the restaurant |
| Reviews | Rating, comment, display name and related review information, where reviews are enabled | You |
| Restaurant management | Restaurant details, menus, prices, opening hours, business contact information and activity associated with the owner profile | You; the restaurant |
| Software activation and licensing | Business contact details, activation requests, relevant software or device identifiers, and communications relating to licence discussions | You |
| Technical and security data | IP address, browser and device information, timestamps, security events and diagnostic information, where collected | Your device; our service providers |
| Cookie preferences | Your choice of essential cookies or all available cookie categories | You; your browser |
| Support | Messages, complaints and contact information you provide when contacting us | You |
| Integration data | Information necessary to provide a connection between Fresto and an external service through the MCP server, depending on the integration and permissions used | You; the connected service |
Where your data is stored
The Fresto website at frestopos.com is hosted on a VPS provided by Infomaniak.
The Fresto application is used on customers’ PCs and phones, and its database is stored locally on the device where the application is installed, as applicable to the feature. Data stored locally may therefore be subject to the security, access permissions, backups and other controls of that device.
Information submitted to the website, an online activation service, or an external integration may also be processed on a server or by the relevant service as needed to provide that function. Local storage does not mean that every interaction with Fresto remains exclusively on the device.
We do not intentionally request special categories of personal data as part of ordinary Platform use. If you voluntarily include information about an allergy or health condition in an order note, that information may be passed to the restaurant to help it respond to your request. Such information may constitute special-category data under the GDPR. Please include only information necessary for your request. Where explicit consent or another specific legal condition is required, we will apply the relevant requirements.
3. Why we use your data and our legal bases
Where the GDPR applies, we process personal data on one or more of the following legal bases:
| Purpose | Legal basis under the GDPR |
|---|---|
| Provide account and restaurant profile features | Performance of a contract, Article 6(1)(b), where applicable |
| Submit orders and reservations and communicate their status through the Platform | Performance of a contract or steps taken at your request before entering into a contract, Article 6(1)(b) |
| Manage restaurant information and software activation requests | Steps taken before entering into a contract and/or performance of a contract, Article 6(1)(b), where applicable |
| Provide customer support and handle complaints | Performance of a contract, Article 6(1)(b), and/or legitimate interests, Article 6(1)(f) |
| Publish and manage reviews, where available | Legitimate interests in maintaining useful and trustworthy reviews, Article 6(1)(f), subject to your rights |
| Protect the Platform and prevent fraud, fake orders, spam and abuse | Legitimate interests in security and service integrity, Article 6(1)(f) |
| Operate the website and maintain necessary technical records | Legitimate interests and/or compliance with a legal obligation, depending on the processing |
| Store legally required business, accounting or tax records | Compliance with a legal obligation, Article 6(1)(c) |
| Use non-essential cookies or similar technologies where consent is required | Consent, Article 6(1)(a) |
| Process health-related information in an order note where explicit consent is the applicable condition | Explicit consent, Article 9(2)(a), where applicable |
| Provide an MCP integration requested by a user | Performance of a contract or steps taken at the user’s request, and/or another applicable legal basis depending on the integration |
Where we rely on legitimate interests, you may have the right to object. See Section 7.
Information necessary to complete an order, reservation, account operation or requested integration must be provided where the relevant feature cannot work without it. Optional information can generally be left blank.
We do not send marketing messages unless we have a lawful basis to do so and obtain consent where required by law.
4. Who receives your data
We may disclose personal data to the following recipients when necessary to provide the Platform, comply with law or fulfil a request.
- The restaurant you order from or book at: information needed to handle your order, reservation or other request.
- Restaurant owners and authorised staff: information needed to manage restaurants and their operations through Fresto.
- Infomaniak: our VPS hosting provider for frestopos.com. Information processed by the hosted website may be stored or handled within the hosting service as necessary to operate it.
- Cloudflare Turnstile: we use Cloudflare Turnstile for bot protection. Its operation may involve processing technical information, such as information about your browser, device and network, to help distinguish legitimate users from automated traffic. Cloudflare’s applicable privacy terms also apply to its processing.
- External services connected through the MCP server: if you choose to connect Fresto to a service such as ChatGPT or another supported service, information may be exchanged with that service according to the integration, the permissions granted and the actions you request. The external service may process information under its own terms and privacy policy.
- Professional advisers and authorities: where necessary to comply with law, respond to lawful requests, or establish, exercise or defend legal claims.
- A successor or buyer: if EURL Techpos or the relevant part of its business is sold, merged or reorganised, subject to appropriate safeguards and applicable law.
We do not currently identify messaging services, map providers or third-party meal-payment processors as part of the Platform’s data-processing arrangements described in this Policy.
Payments. Customers pay restaurants directly for food orders. Fresto does not currently collect payments for those orders. Restaurant software activation requests may lead to separate licensing discussions and an agreement. Any licence fees or payment arrangements are governed by the terms disclosed during the licensing process or in a separate agreement.
We do not sell your personal data.
5. Transfers outside the EEA
EURL Techpos is established in Algeria, and Fresto may expand into Spain and other markets. Depending on the service, hosting arrangements, connected integrations and locations of service providers, personal data may be accessed or processed outside the European Economic Area (EEA).
Where the GDPR applies, restricted international transfers will rely on an appropriate legal transfer mechanism, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where required.
You may contact eurltechpos@gmail.com to request further information about applicable transfer safeguards, subject to legal restrictions.
Our website hosting provider is Infomaniak. The location of the relevant hosting infrastructure and the locations used by external integrations should be confirmed against the applicable service arrangements.
6. How long we keep data
We retain personal data only for as long as necessary for the purposes described in this Policy, including providing services, maintaining security, resolving disputes and complying with legal obligations.
- Account and profile data: while the account remains active and for a reasonable period afterwards, unless earlier deletion is required or permitted by law.
- Orders and reservations: for as long as necessary to fulfil the transaction, handle complaints or disputes, and comply with applicable accounting and tax requirements.
- Locally stored application data: until it is deleted from the relevant device or application, subject to any copies, exports or backups the user or restaurant has created. Deleting local data may not delete information previously transmitted to another user, restaurant, server or connected service.
- Reviews: while published, unless removed or restricted in accordance with applicable law and our moderation rules.
- Technical and security logs: for the period necessary for security, troubleshooting and legal purposes. The precise period depends on the system and log type.
- Support requests: for as long as necessary to respond to the request and manage related follow-up, disputes or legal claims.
- Restaurant owner and business data: for the duration of the relevant business relationship and any additional period required by law or necessary to resolve claims.
- Software activation and licensing records: for as long as necessary to evaluate activation requests, negotiate and administer licences, and meet applicable legal or contractual obligations.
- Data held independently by restaurants or external services: under their own applicable retention practices and legal obligations.
When personal data is no longer necessary, we will delete it, anonymise it or securely restrict it, as appropriate and as permitted by law.
Closing an account or deleting data from one device does not necessarily delete every copy. Information may remain in legally required records, backups, exports or systems operated by recipients who have independently received it, subject to applicable law.
7. Your rights
Where the GDPR applies, you may have the right to:
- Access your personal data and receive a copy (Article 15).
- Rectify inaccurate or incomplete information (Article 16).
- Erase your personal data in circumstances provided by law (Article 17).
- Restrict processing in certain circumstances (Article 18).
- Data portability: receive certain data you provided in a structured, commonly used and machine-readable format (Article 20).
- Object to processing based on legitimate interests (Article 21).
- Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of earlier processing (Article 7(3)).
- Challenge certain automated decisions where Article 22 or other applicable law provides that right.
- Lodge a complaint with a competent data-protection supervisory authority.
These rights are subject to the conditions and exceptions provided by applicable law.
How to exercise your rights
Email eurltechpos@gmail.com with the subject line “Privacy Request.” Explain what you are requesting and, where possible, identify the relevant account, order, reservation or other interaction.
We may ask for information reasonably necessary to verify your identity before responding.
Where the GDPR applies, we generally respond within one month. If a request is complex or we receive multiple requests, the response period may be extended by up to two further months where permitted. We will inform you of the extension and the reasons within the initial month.
Requests are generally free of charge. We may charge a reasonable fee or refuse to act where the law permits this because a request is manifestly unfounded or excessive.
For information held independently by a restaurant or an external service, you may need to contact that organisation directly. If you send us a request concerning processing by a restaurant, we will direct or forward it as appropriate, subject to our legal obligations.
Complaints
You may lodge a complaint with a competent data-protection supervisory authority, particularly in the EU or EEA country where you live, work or believe an infringement occurred.
In Spain, the supervisory authority is the Agencia Española de Protección de Datos (AEPD). The appropriate authority for a particular complaint depends on the circumstances and applicable law.
You do not have to contact us before lodging a complaint with a supervisory authority.
8. Automated decisions and profiling
Fresto may use technical tools to protect the Platform against automated abuse and to organise information.
We do not intend to make decisions about individual users based solely on automated processing that produce legal effects or similarly significant effects within the meaning of Article 22 GDPR.
Where an MCP integration connects Fresto to an external AI service, the external service may process information according to the instructions, permissions and features used. This Policy does not mean that every integration performs automated decision-making about users.
If our processing changes in a way that requires additional disclosures or rights, we will update this Policy and provide the information required by law.
9. Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure or destruction.
Protection depends on where the data is stored. Website data hosted on the VPS is subject to the security measures applicable to that infrastructure and the website. Data stored in the local Fresto application is also affected by the security of the device on which it resides.
Users and restaurant owners should protect their devices, restrict access to authorised people, use appropriate account credentials and keep their software and operating systems updated.
No system can be guaranteed to be completely secure. If a personal data breach occurs, we will notify the relevant supervisory authority and affected individuals where and as required by applicable law.
If you suspect unauthorised access to your account or personal data, contact eurltechpos@gmail.com.
10. Children
Fresto is not specifically designed for children to create independent accounts or provide personal data without appropriate authorisation.
Where applicable law requires parental or guardian consent, age verification or other safeguards, those requirements must be met.
We do not knowingly collect children’s personal data in circumstances where doing so would be unlawful. If you believe a child has provided personal data in such circumstances, contact eurltechpos@gmail.com so we can investigate and take appropriate action.
Applicable age requirements may differ between countries and services.
11. Cookies
Fresto uses a cookie banner that allows users to choose between Essential Cookies and All Cookies.
- Essential Cookies: cookies or similar technologies needed for the website to function, provide a service you request, maintain security or support other legally exempt essential purposes.
- All Cookies: allows the additional cookie categories made available by the website, alongside essential cookies.
Essential cookies may be used without consent where permitted by law. Non-essential cookies and similar technologies will only be activated where the required consent has been obtained.
You can change your cookie choice through the available cookie controls, where provided. Withdrawing consent does not affect processing that took place lawfully before withdrawal.
For more information, please see Cookies & GDPR: /pages/cookies.
12. Changes to this Policy
We may update this Privacy Policy when our services, data-processing practices, integrations, service providers or legal obligations change.
The date at the top of this page indicates when the Policy was last updated. We will provide additional notice or obtain consent where required by applicable law.
We encourage you to review this page periodically.
13. Contact
For questions, complaints or requests relating to personal data, contact:
- Company: EURL Techpos
- Email: eurltechpos@gmail.com
- Website: https://frestopos.com
Related pages:
- Customer Service: /pages/customer-service
- Terms of Use: /pages/terms
- Cookies & GDPR: /pages/cookies