Privacy notice for the FoodGenius SaaS platform
1. Controller
About this translation: This English version is a translation of the German original. In the event of discrepancies, the German version prevails to the extent permitted by law. The statutory rights of data subjects remain unaffected.
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
FoodGenius Labs GmbH
Tholeyer Str. 3A, 66606 St. Wendel
Managing Director: Christian Farr
Email: support@foodgenius.de
Tel.: 06858 9797-0
Data Protection Officer:
Thomas Hergl
Email: datenschutz@foodgenius.de
Tel.: 06858 9797-400
2. Scope
This privacy notice applies to the use of the FoodGenius SaaS platform at foodgenius.ai by restaurant operators and their employees (hereinafter “users”). It does not apply to the marketing website of FoodGenius Labs GmbH, the white-label online shops of restaurant customers or other standalone products.
Where FoodGenius Labs GmbH processes data on behalf of restaurant operators in connection with platform use (e.g. order data or customer master data), FoodGenius Labs GmbH acts as a processor. The respective restaurant operator is responsible for these data under data protection law. The details are governed by the data processing agreement (DPA).
3. Hosting and technical infrastructure
The FoodGenius platform is hosted on servers within the European Union. Data are transmitted using SSL/TLS encryption.
Whenever the platform is accessed, technical connection data (including IP address, browser type and time of access) are automatically recorded in server log files. These data are used solely to ensure technical operation and are deleted after a short period.
Legal basis Article 6(1)(f) GDPR (legitimate interest)
4. What data we process and why
4.1 Registration and user management
To provide and manage your platform access, we process your name, email address, company name and details of the modules you have subscribed to.
Legal basis Article 6(1)(b) GDPR (performance of a contract)
Deletion period After the contract ends, data are blocked and then fully deleted after a reactivation period. Details are governed by the deletion policy.
4.2 Payment processing and KYC verification
Activating payment features requires identity and business verification as required by law (Know Your Customer, KYC). For this purpose, we process business and identification data relating to the owner or managing director, as well as the required supporting documents. Payment data are processed to handle cashless payments and to bill for subscribed modules.
Legal basis Article 6(1)(b) and (c) GDPR (performance of a contract + statutory anti-money laundering obligation)
Recipients Adyen N.V. (payment service provider, Netherlands)
Deletion period After the contract ends; the statutory retention obligation (section 147 of the German Fiscal Code, AO) rests with the restaurant operator
4.3 Cash register security (TSE)
To meet legal requirements, cash register transactions are signed in a tamper-proof manner and the cash register is registered with the competent tax office. After the contract ends, tax-relevant data are made available for export. The statutory retention obligation rests with the restaurant operator.
Legal basis Article 6(1)(c) GDPR (legal obligation)
Recipients Fiskaly GmbH (TSE service provider, Germany); tax office (public authority recipient)
Deletion period After the contract ends; the statutory retention obligation (section 147 AO) rests with the restaurant operator
4.4 AI-assisted features
FoodGenius provides AI-assisted features (including text generation and a review assistant). Inputs are transmitted to an external AI service provider for processing. Inputs are not used to train AI models.
Legal basis Article 6(1)(b) GDPR (performance of a contract)
Recipients AI service provider (USA); transfer mechanism: EU-U.S. Data Privacy Framework
Deletion period Up to 30 days at the service provider, followed by automatic deletion
4.5 Email communications
To send transactional emails (e.g. onboarding or contract-related notices), names and email addresses are transmitted to an email service provider.
Legal basis Article 6(1)(b) GDPR (performance of a contract)
Recipients Email service provider (EU/USA); transfer mechanism: EU-U.S. Data Privacy Framework
Deletion period After the contract ends
4.6 Accounting export (DATEV)
Restaurant operators may choose to transmit end-of-day reports directly to DATEV. Data are transmitted only at the user's express request.
Legal basis Article 6(1)(b) and (c) GDPR
Recipients DATEV eG (Germany)
Deletion period After the contract ends; the statutory retention obligation (section 147 AO) rests with the restaurant operator
4.7 Support and customer communications
When you contact our support team, we process your name, email address and the content of your enquiry. Different communication channels are available depending on your selected plan.
Legal basis Article 6(1)(b) GDPR (performance of a contract)
Recipients Support tools (EU/USA); transfer mechanism for US service providers: EU-U.S. Data Privacy Framework
Deletion period 3 years after the matter has been closed
4.8 Technical monitoring and IT security
We use monitoring and security services to ensure technical stability, protect against unauthorised access and recognise trusted devices. Technical diagnostic data and device characteristics (including device fingerprints) are processed for these purposes. Payment and transaction data are excluded from transmission to these services.
Legal basis Article 6(1)(f) GDPR (legitimate interest in system security)
Recipients Monitoring and security service providers (EU/USA); data processing within the EU wherever possible
Deletion period Up to 30 days, followed by automatic deletion
Notice of your right to object (Article 21 GDPR): You may object at any time to processing based on legitimate interests (section 4.8). To do so, please contact us using our data protection contact details (see section 1).
5. Recipients and international transfers
We use service providers, some of which are based in the USA. For transfers to the USA, we rely on the EU-U.S. Data Privacy Framework (DPF) under Article 45 GDPR. Where necessary, standard contractual clauses (SCCs) under Article 46 GDPR are also agreed.
We provide an up-to-date list of the service providers we use (sub-processors) upon request.
6. Retention period
We store personal data only for as long as necessary for the relevant purpose or as required by statutory retention obligations. Tax-relevant data are subject to statutory retention periods (in particular, section 147 AO: 10 years; section 257 of the German Commercial Code, HGB: 6 years). The restaurant operator is responsible for retaining cash register data; FoodGenius makes these data available for export and subsequently deletes them from the platform.
7. Your rights as a data subject
You have the following rights:
- Access (Article 15 GDPR)
- Rectification (Article 16 GDPR)
- Erasure (Article 17 GDPR)
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Objection (Article 21 GDPR), particularly to processing based on legitimate interests
- Withdrawal of consent (Article 7(3) GDPR), with effect for the future
To exercise your rights, please contact: datenschutz@foodgenius.de
We respond to requests within one month (Article 12(3) GDPR).
8. Right to lodge a complaint
You have the right to lodge a complaint with the competent data protection supervisory authority:
Unabhängiges Datenschutzzentrum Saarland (UDSaar)
Fritz-Dobisch-Straße 12, 66111 Saarbrücken
Tel.: 0681 94181-0
Email: poststelle@datenschutz.saarland.de
www.datenschutz.saarland.de
9. Automated decision-making
We do not use automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
10. Updates to this privacy notice
This privacy notice is dated September 2026. We will inform registered users by email of material changes. The current version is available within the platform at login.foodgenius.ai.