1. Controller
- Axiom Atlas, LLC, EIN 30-1446189, 131 Continental Dr, Suite 305, Newark, DE 19713, USA.
- Data protection contact: hola@neo.menu.
- Representative in the European Union (GDPR art. 27): Dmitry Molchanov, Carrer de Josep Pla, 27, Sant Martí, 08019 Barcelona, España, support@neo.menu.
2. What data we process, why, and on what legal basis
- Restaurant account (name, email, phone, venue details): to provide the contracted service — performance of a contract.
- Billing (tax and payment details handled by Stripe): to charge and invoice — performance of a contract and legal obligation.
- Security and errors (technical logs, daily-hashed IP address, error reports): to protect the service — legitimate interest.
- Page performance measurement: to improve the site — consent, which you can withdraw in “Cookie settings”.
- Public business data (name, address, phone and menu published in open sources) to prepare a menu preview the restaurant can claim: legitimate interest; the restaurant can object at any time.
- Rights and support requests: to handle them — legal obligation and legitimate interest.
Diner data that a restaurant processes through neo.menu is processed by us on behalf of that restaurant, which is its controller; see the restaurant's own policy or contact it.
3. Cookies
We use necessary cookies (language, session, security) and, only with your consent, performance measurement. Error detection sets no cookies. You can accept, reject or change your choice at any time from “Cookie settings”.
4. Recipients and international transfers
- Supabase Inc. (AWS) — Database, authentication and file storage (US (AWS us-west-1); outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
- Vercel Inc. — Web hosting and performance measurement (with consent) (US / global edge; outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
- Fly.io Inc. — WhatsApp messaging, AI waiter and assistant services (US (iad, sjc) and FR (cdg); outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
- WhatsApp (Meta Platforms) — Delivery of verification codes and requested notifications (US / global; outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
- Functional Software Inc. (Sentry) — Error detection and diagnostics (US; outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
- Stripe — Subscription payments and invoicing (EU / US; outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
- Google LLC — Maps and public business data, translation and AI menu processing (US / global; outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
- Anthropic PBC — AI assistant for menu management (US; outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
- OpenAI — Menu extraction from web pages (US; outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
- Email delivery (Nerve Email Cloud / SMTP provider) — Transactional email delivery (US / EU; outside the EEA: EU-US Data Privacy Framework or standard contractual clauses)
These providers process data on our behalf under data processing agreements. Where processing takes place outside the European Economic Area, the transfer relies on the provider's EU-US Data Privacy Framework certification or on the European Commission's standard contractual clauses.
5. Retention
- Account data: while the account is active and then for up to 6 years to meet legal obligations and possible claims.
- Technical logs and error reports: up to 90 days.
- Consent records: up to 3 years.
- Rights requests: up to 3 years after closure.
- Public data of unclaimed venues: deleted when the restaurant objects or when no longer needed for the preview.
6. Your rights
You can exercise your rights of access, rectification, erasure, restriction, portability and objection, and withdraw consent, at /privacy/request?lang=en or by writing to hola@neo.menu. We will verify your identity and reply within one month (extendable by two further months for complex requests, with notice). If you are not satisfied, you can complain to the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es.