Privacy Policy EN


Web apps for restaurants

Privacy Policy

This policy is drawn up by Lavigna SRL located at 261 avenue de Broqueville, 1200 Brussels, registered under the number 0799364924 (hereinafter referred to as the “data controller”), owner of the “dinnertogether” brand.

The purpose of this policy is to inform visitors to the website hosted at http://www.dinnertogether.io (hereinafter referred to as the “website”) of the manner in which data is collected and processed by the controller.

This policy is part of the controller’s desire to act transparently, in compliance with its national provisions and with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the “General Data Protection Regulation”).

The data controller pays particular attention to protecting the privacy of its users and therefore undertakes to take the reasonable precautions required to protect the personal data collected against loss, theft, disclosure or unauthorised use.

Personal data” is defined as all personal data concerning the user. In other words, any information that enables the user to be identified directly or indirectly as a natural person. If the user wishes to react to any of the practices described below, he/she may contact the data controller at the postal address or e-mail address specified in the “contact details” section of this policy.

What data do we collect?

The data controllers collect and process the following personal data in accordance with the methods and principles described below:

Its domain (automatically detected by the data controller’s server), including the dynamic IP address.

All information concerning the pages that the user has consulted on the website.

Any information that the user has given voluntarily, for example by completing the contact form.

The data controller may also collect non-personal data. This data is considered to be non-personal because it does not directly or indirectly identify a specific individual. It may therefore be used for any purpose whatsoever, for example to improve the website, the products and services offered or the advertising of the data controller.

In the event that non-personal data is combined with personal data in such a way that it is possible to identify the persons concerned, this data will be treated as personal data until such time as it is impossible to link it with a specific person.

Collection methods

The data controller collects personal data when the user fills in the contact form.

Purpose of processing

Personal data is collected and processed solely for the purposes set out below:

To manage and control the performance of the services offered.

Sending and monitoring orders and invoices.

Sending promotional information about the products and services of the controller.

Sending promotional material.

Answering users’ questions.

To compile statistics.

To improve the quality of the website and the products and services of the data controller.

To send information about new products and services from the data controller.

With a view to commercial prospecting.

The data controller may carry out processing operations that are not yet provided for in this policy. In this case, it will contact the user before re-using his/her personal data in order to inform him/her of the changes and give him/her the opportunity, where appropriate, to refuse such re-use.

Legitimate interests

Certain processing operations carried out by the data controller are founded on the legal basis of its legitimate interests. These legitimate interests are proportionate to respect for the user’s rights and freedoms. If the user wishes to be informed of the details of the purposes founded on the legal basis of legitimate interests, he/she is recommended to contact the data controller (see point relating to “contact details”).

Retention period

As a general rule, the data controller only keeps personal data for as long as is reasonably necessary for the purposes for which it is to be used and in accordance with legal and regulatory requirements.

A customer’s personal data is kept for a maximum of 10 years after the end of the contractual relationship between the customer and the data controller.

At the end of the retention period, the data controller shall take all necessary steps to ensure that the personal data has been made unavailable and inaccessible.

Application of rights

For all the rights listed below, the data controller reserves the right to verify the identity of the user for the application of the rights listed below.

This request for additional information will be made within one month of the user submitting the request.

Access to data and copying

Users may obtain written communication or a copy of their personal data collected free of charge.

The data controller may charge a reasonable fee based on administrative costs for any additional copies requested by the user. Where the user makes such a request electronically, the information shall be provided in a commonly used electronic form unless the user requests otherwise.

Unless an exception is provided for in the General Data Protection Regulation, the user will be sent a copy of his/her data no later than one month after receipt of the request.

Right of rectification

The user may obtain, free of charge, as soon as possible and at the latest within a period of one month, the rectification of any personal data that is inaccurate, incomplete or irrelevant, and may complete the data if it proves to be incomplete.

Unless an exception is provided for in the General Data Protection Regulation, the request for application of the right to rectification will be processed within one month of the request being made.

Right to object to processing

Users may at any time, for reasons relating to their particular situation, object free of charge to the processing of their personal data when :

The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, unless the interests or fundamental rights and freedoms of the data subject which require the protection of personal data prevail.

The data controller may refuse to implement the user’s right to object if it establishes the existence of compelling and legitimate grounds for the processing, which override the interests or the rights and freedoms of the user, or for the establishment, exercise or defence of legal claims. In the event of a dispute, the user may lodge a complaint in accordance with the “Complaints” section of this policy.

Users may also, at any time, object, without justification and free of charge, to the processing of personal data concerning them when their data is collected for the purposes of commercial canvassing.

Where personal data is processed for scientific or historical research purposes or for statistical purposes in accordance with the General Data Protection Regulation, the user has the right to object, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out in the public interest.

Subject to the exceptions provided for in the General Data Protection Regulation, the data controller is required to respond to the user’s request as soon as possible and within one month at the latest, and to give reasons for its response if it intends not to comply with such a request.

Right to limit processing

The user may obtain a restriction on the processing of his/her personal data in the cases listed below:

When the user disputes the accuracy of the data and only for as long as it takes the controller to check it.

When the processing is unlawful and the user prefers the limitation of processing to erasure.

When, although it is no longer necessary for the purposes of the processing, the user needs it for the establishment, exercise or defence of legal claims.

For the time required to examine the merits of a request for opposition made by the user, in other words for the time required for the controller to check the balance of interests between the legitimate interests of the controller and those of the user.

 The data controller will inform the user when the processing restriction is lifted.

Right to erasure (right to be forgotten)

Users may obtain the deletion of their personal data if one of the following reasons applies:

The data is no longer necessary for the purposes of processing.

The user has withdrawn his/her consent to his/her data being processed and there is no other legal basis for the processing.

The user objects to the processing and there are no compelling legitimate grounds for the processing and/or the user exercises his/her specific right to object in relation to direct marketing.

The personal data has been processed unlawfully.

The personal data must be erased in order to comply with a legal obligation (under EU or Member State law) to which the controller is subject.

Personal data have been collected in the context of offering information society services to children.

However, data may not be erased in the following cases:

Where processing is necessary for the exercise of the right to freedom of expression and information.

Where processing is necessary for compliance with a legal obligation which requires processing under Union law or the law of the Member State to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Where processing is necessary for reasons of public interest in the field of public health.

Where processing is necessary for archival purposes in the public interest, for scientific or historical research purposes or for statistical purposes and provided that the right to erasure is likely to make impossible or seriously compromise the achievement of the purposes of the processing in question.

Where processing is necessary for the establishment, exercise or defence of legal claims.

Subject to the exceptions provided for in the General Data Protection Regulation, the data controller is required to respond to the user’s request as soon as possible and within one month at the latest, and to give reasons for its response if it intends to take no further action on such a request.

Right to “data portability”

The user may, at any time, request to receive, free of charge, his/her personal data in a structured, commonly used and machine-readable format, with a view, in particular, to transmitting it to another data controller when the data processing is carried out using automated processes and when the processing is based on the user’s consent or on a contract concluded between the user and the data controller.

Under the same conditions and according to the same procedures, the user has the right to obtain from the data controller that personal data concerning him or her be transmitted directly to another data controller, insofar as this is technically possible.

The right to data portability does not apply to processing that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Recipients of data and disclosure to third parties

The recipients of the data collected and processed are, in addition to the data controller itself, its employees or other subcontractors, its carefully selected commercial partners located in the European Union who collaborate with the data controller in the marketing of products or the provision of services.

In the event that data is disclosed to third parties for the purposes of direct marketing or commercial prospecting, the user will be informed in advance so that he/she can choose to accept the transfer of his/her data to third parties.

Where this transfer is based on the user’s consent, the user may withdraw his or her consent for this specific purpose at any time.

The data controller complies with the legal and regulatory provisions in force and will ensure in all cases that its partners, employees, subcontractors or other third parties with access to this personal data comply with this policy.

The data controller discloses the user’s personal data in the event that a law, legal proceedings or an order from a public authority makes such disclosure necessary.

The data controller does not transfer personal data outside the European Union.

Security

The data controller shall implement appropriate technical and organisational measures to guarantee a level of security of the processing and of the data collected that is appropriate to the risks presented by the processing and the nature of the data to be protected. It shall take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks to the rights and freedoms of users.

The data controller always uses encryption technologies that are recognised as industry standards within the IT sector when transferring or receiving data on the website.

The data controller has put in place appropriate security measures to protect and prevent the loss, misuse or alteration of information received on the website.

In the event that personal data under the control of the data controller is compromised, the data controller will act promptly to identify the cause of the breach and take appropriate remedial action.

The data controller will inform the user of this incident if required to do so by law.

Complaints

If the user wishes to react to any of the practices described in this policy, he/she is advised to contact the data controller directly.

Users may also lodge a complaint with their national supervisory authority, whose contact details can be found on the European Commission’s official website: https://www.edps.europa.eu/data-protection/our-role-supervisor/complaints_en

In addition, the user may lodge a complaint with the competent national courts.

Contact details

For any questions and/or complaints relating to this policy, the user may contact the data controller:

E mail: info@dinnertogether.io

By post :
Lavigna SRL,
261, av. de Broqueville at 1200 Brussels

Modification

The data controller reserves the right toe modifier à tout moment les dispositions de la présente politique. Les modifications seront publiées directement sur le site web du responsable de traitement.

Applicable law and competent jurisdiction

This policy is governed by the national law of the place where the data controller has its principal place of business.

Any dispute relating to the interpretation or execution of this policy will be subject to the jurisdiction of this national law.

This version of the policy is dated 1 January 2023.