EU General Data Protection Regulation

GDPR Compliance

Commitment to European & Global Data Privacy Standards

Our Commitment to GDPR

TestyGrid is fully compliant with Regulation (EU) 2016/679 (GDPR). We adhere to stringent technical and organizational data protection measures to ensure the integrity, confidentiality, and availability of personal data across our European and global operations.

Data Controller vs. Data Processor Roles

TestyGrid as Data Controller: We act as the Data Controller for our direct customers (restaurant owners and billing contacts) for account management, authentication, and invoicing purposes.

TestyGrid as Data Processor: When restaurant operators use TestyGrid to process dining orders, guest phone numbers for digital receipts, or staff shift records, TestyGrid acts as the Data Processor on behalf of the venue operator (the Data Controller).

Your Data Subject Rights

Right to Access (Article 15)

You may request a copy of all personal records and operational logs we store concerning your account or venue.

Right to Rectification (Article 16)

You have the right to modify or update inaccurate billing, business registry, or employee profile information.

Right to Erasure / "To Be Forgotten" (Article 17)

You may request permanent deletion of guest contact records, customer loyalty histories, and inactive staff accounts.

Right to Data Portability (Article 20)

Export all recipe catalogs, sales transaction archives, and customer cohorts in standardized JSON/CSV formats.

Data Protection Officer (DPO) Contact

For formal GDPR requests, Standard Contractual Clauses (SCCs), or Data Processing Agreements (DPAs):

dpo@testygrid.com