Lokdan
Questa pagina non è ancora tradotta in italiano; viene mostrata la versione inglese.

Privacy Policy

Ultimo aggiornamento: 16 luglio 2026

This Privacy Policy explains how Lokdan collects, uses, and protects personal data when restaurants ("Venues") use the platform and when diners order through a Venue's QR menu. It is written to comply with the EU General Data Protection Regulation (GDPR).

1. Who we are

Lokdan is a trading name — it is not a registered company. Lokdan is operated by Carlos A Perez Hernandez, an individual sole trader, who is the data controller/processor described in this policy. For data-protection matters, contact privacy@lokdan.app. A postal address is available on request and is provided to our payment processor for verification purposes. No formal Data Protection Officer has been appointed; data-protection requests are handled directly by the operator at privacy@lokdan.app.

2. GDPR still applies to EU diners' and Venues' data

The operator is based outside the European Union. That does not take Lokdan's processing outside the reach of GDPR: under Article 3(2) GDPR, processing the personal data of individuals located in the EU/EEA — including diners ordering through a Venue's digital menu, and EU-based Venues themselves — remains subject to GDPR regardless of where the operator is established, because the service is offered to, and diners' behavior is monitored within, the EU/EEA. This Privacy Policy is written on that basis: it follows the full GDPR structure (controller/processor roles, lawful basis, data-subject rights, international transfers, etc.) below.

Where Article 27 GDPR requires it, Lokdan will appoint a representative established in the EU/EEA to act as a point of contact for data subjects and supervisory authorities where required; representative details are available on request.

Separately, the operator is based in Hong Kong SAR, so the Hong Kong Personal Data (Privacy) Ordinance (PDPO) also applies to Lokdan as a data user established in Hong Kong, alongside the GDPR obligations described throughout this policy for personal data connected to the EU/EEA.

3. Controller vs. processor: two roles

Lokdan acts in two different capacities depending on whose data is involved:

  • Controller — for Venue/merchant account data: when a restaurant signs up, we decide why and how that account data is processed (e.g., billing, support, service operation), so Lokdan is the data controller for it.
  • Processor — for diner order data: when a diner scans a QR code, browses a menu, and places an order or payment, that data is processed by Lokdan on behalf of, and under the instructions of, the Venue. The Venue is the data controller for its diners' order data; Lokdan is the processor. Venues are responsible for their own lawful basis and disclosures toward their diners (e.g., a notice at the table or in the digital menu).

4. What data we collect

a) Venue / merchant account data (Lokdan as controller)

  • Account and contact details: owner/staff name, email, phone, restaurant name and address.
  • Billing data processed via Paddle (our payment provider and merchant of record) — Lokdan itself does not store full card numbers.
  • Usage data: login activity, menu/catalog configuration, support requests, and platform analytics needed to operate and improve the service.
  • Technical data: IP address, device/browser type, and similar data collected automatically when you use the console or website.

b) Diner order data (Lokdan as processor, on behalf of the Venue)

  • Order details: items ordered, table/session identifier, order timestamps.
  • Payment data for "pay at table", processed through our payment providers.
  • Optional contact details a diner may provide (e.g., for a receipt), where the Venue's flow requests them.
  • Device/session data needed to serve the digital menu and process the order (e.g., IP address, session identifier).

5. Lawful basis for processing

  • Contract (Art. 6(1)(b) GDPR): to create and administer a Venue's account, provide the subscribed service, and process orders/payments the diner initiates.
  • Legitimate interests (Art. 6(1)(f) GDPR): to secure the platform, prevent fraud and abuse, and improve the service, balanced against your rights and freedoms.
  • Legal obligation (Art. 6(1)(c) GDPR): to meet tax, accounting, and billing-record obligations (largely fulfilled via Paddle as merchant of record).
  • Consent (Art. 6(1)(a) GDPR): where required, e.g., certain marketing communications or non-essential cookies.

6. Cookies

Lokdan uses strictly necessary cookies/local storage to keep you logged in, maintain a diner's ordering session at the table, and remember basic preferences (e.g., language). We may use limited analytics cookies to understand aggregate site usage. Where non-essential cookies are used, we will request consent as required by applicable ePrivacy/cookie law before setting them.

7. Sub-processors

We share data with the following categories of service providers, acting as sub-processors, strictly to operate the platform:

  • Resend — transactional email delivery (account, receipt, and notification emails).
  • Railway — application hosting and database infrastructure for the platform and Venue instances.
  • Vercel — hosting for the Lokdan marketing website and checkout flow.
  • Paddle — payment processing, merchant of record, EU VAT handling, and invoicing for subscriptions.
  • A translation API provider — used to power multi-language menu/UI translation features.

We enter into data-processing terms with sub-processors as required by GDPR and only share the data necessary for each provider to perform its function.

8. Data retention

We retain Venue account data for as long as the account is active, plus a limited period afterward to meet legal, tax, and dispute-resolution needs. Diner order data is retained for as long as needed to complete the order, provide support, meet the Venue's and our own legal/accounting obligations, and is deleted or anonymized thereafter. Exact retention periods depend on the data category and applicable tax and accounting rules, and are available on request.

9. International transfers

Our sub-processors may process data outside the European Economic Area (EEA). Where that happens, we rely on appropriate safeguards recognized under GDPR, such as the European Commission's Standard Contractual Clauses, or the sub-processor's own adequacy/certification mechanisms (e.g., the EU-U.S. Data Privacy Framework, where applicable to that provider). Separately, because the operator itself is based outside the EU/EEA, Lokdan's own processing of EU/EEA personal data also involves a transfer outside the EU/EEA; Lokdan relies on the same category of safeguards (such as Standard Contractual Clauses) for this transfer and will provide further detail on request.

10. Your rights

If you are in the EU/EEA (or another jurisdiction granting similar rights), you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erasure ("right to be forgotten"), subject to legal retention obligations;
  • Data portability, to receive your data in a structured, machine-readable format;
  • Object to processing based on legitimate interests, including for direct marketing;
  • Restrict processing in certain circumstances;
  • Withdraw consent at any time, where processing is based on consent, without affecting prior lawful processing;
  • Lodge a complaint with your national data-protection authority — a list of EU/EEA supervisory authorities is available via the European Data Protection Board at edpb.europa.eu.

To exercise these rights, contact us at privacy@lokdan.app. If your data was submitted through a Venue's digital menu as a diner, you may also need to contact that Venue directly, since the Venue is the controller for your order data and we process it on the Venue's instructions.

11. Security

We use industry-standard technical and organizational measures — including encrypted connections, access controls, and reputable infrastructure providers — to protect personal data against unauthorized access, loss, or misuse. No system is completely secure, and we cannot guarantee absolute security.

12. Children

Lokdan is intended for use by restaurant staff (Venues) and their adult diners. It is not directed at children, and we do not knowingly collect personal data from children.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide reasonable notice.

14. Contact

Questions or requests regarding this Privacy Policy can be sent to privacy@lokdan.app. Carlos A Perez Hernandez's postal address is available on request.