Last updated: 4 September 2026 · Draft pending legal review.
Oveliks ("Oveliks", "we") provides digital menus, table ordering and websites to hospitality businesses. The controller for data about our customers (restaurant owners and staff) is Oveliks, [legal name, VAT number, address], email info@oveliks.com.
For data created when guests scan a menu or order (for example the content of an order or a remark), the restaurant is the controller and Oveliks acts as processor under the Data Processing Agreement.
No account, name, phone or email is needed to view a menu or to order from the table.
When you scan a QR/NFC stand a "table session" is created: a random identifier stored in a functional cookie (ovl_ts) that links your orders to the table for up to 3 hours. It does not identify you personally.
We store the content of orders (items, options, remarks you type), requests to staff, and any rating and comment you leave. Please do not write personal details in remarks.
For the restaurant's statistics we record anonymous events: stand scan, menu open, item view, add to basket, language and device class (iOS/Android/desktop). We do not store IP addresses, full user agents or tracking cookies, and we use no third-party advertising services.
The IP address is used transiently and in hashed form only for abuse protection (rate limits) and is not kept in our records.
To run your account we process: email, name, phone, business details (legal name, VAT number, address), the menus and photos you upload, opening hours, the WiFi network you choose to display, settings, the orders and statistics of your locations, and an audit log kept for security.
Staff devices (tablets) pair with a device code and need no personal details.
We use login cookies (Supabase Auth) and one language-preference cookie. We use no advertising cookies.
Performance of a contract (providing the service), legitimate interest (security, abuse prevention, anonymous statistics), legal obligation (tax and accounting records) and, where requested, consent.
Detailed orders: 90 days, then anonymised (remarks and notes removed). Anonymous daily statistics: 2 years. Raw scan events: 35 days. Audit log: 2 years. Table sessions: 90 days. Data of cancelled accounts: 12 months, then permanently deleted.
All data is stored in the European Union. Processors: Supabase (database, authentication, file storage, Frankfurt), Cloudflare (hosting and network, EU jurisdiction), Resend (email delivery), DeepL and Google Cloud Translation (menu text only, when translation is requested). We do not sell data.
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr). Contact info@oveliks.com. Owners can export their data from the account Settings.
Menu guests: because we collect no identifying details we usually cannot link an order to a person. For requests about remarks you wrote, contact the restaurant or us.
Encryption in transit (HTTPS) and at rest, per-account data isolation enforced in the database, mandatory two-step verification for Oveliks administration, daily backups, audit logging.
We update this page when our processing changes. Material changes are communicated to customers by email or in the dashboard.



