GDPR Compliance

Our commitment to protecting your data under the General Data Protection Regulation

Last updated: February 23, 2026

Introduction

Scan2Order is committed to protecting the privacy and rights of individuals in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page outlines how we comply with GDPR requirements and explains your rights as a data subject.

This page supplements our Privacy Policy and provides specific information required under the GDPR.

Data Controller

The data controller responsible for your personal data is:

As a data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with GDPR.

Lawful Basis for Processing

We process your personal data based on one or more of the following lawful bases under Article 6 of the GDPR:

Lawful BasisProcessing Activity
Contract Performance (Art. 6(1)(b))Processing necessary to provide the Scan2Order service: account creation, subscription management, QR menu generation, payment processing via Stripe, and customer support
Legitimate Interests (Art. 6(1)(f))Analytics and service improvement, fraud prevention and security, platform performance monitoring
Consent (Art. 6(1)(a))Marketing communications and newsletters, non-essential cookies and tracking (analytics, preferences)
Legal Obligation (Art. 6(1)(c))Tax record retention, responding to lawful requests from authorities, maintaining billing records

Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data. We are committed to facilitating these rights in a transparent and timely manner.

Right of Access (Article 15)

You have the right to obtain confirmation as to whether we process your personal data, and if so, to access that data along with information about the purposes, categories, recipients, retention periods, and your rights.

Right to Rectification (Article 16)

You have the right to request correction of inaccurate personal data and to have incomplete data completed. You can update most account information directly through your profile settings.

Right to Erasure (Article 17)

You have the right to request deletion of your personal data ("right to be forgotten") when:

  • The data is no longer necessary for its original purpose
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Note: We may retain certain data where we have a legal obligation (e.g., billing records for tax compliance) or where processing is necessary for the establishment, exercise, or defense of legal claims.

Right to Restriction (Article 18)

You may request restriction of processing when you contest the accuracy of data, when processing is unlawful but you prefer restriction over erasure, when we no longer need the data but you require it for legal claims, or when you have objected to processing pending verification.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV). This applies to data you provided to us and that we process based on consent or contract performance.

Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes. When you object to direct marketing, we will stop processing immediately and without exception.

Right Regarding Automated Decisions (Article 22)

You have the right not to be subject to decisions based solely on automated processing that produce legal effects or significantly affect you. Scan2Order does not currently use fully automated decision-making processes.

Exercising Your Rights

To exercise any of the above rights, contact our Data Protection Officer at:

We will respond to your request within 30 days. In complex cases, this may be extended by a further 60 days, and we will inform you of any such extension. There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.

Record of Processing Activities

The following table summarizes our key data processing activities:

ActivityData ProcessedLawful BasisRetention
Account registrationName, email, business infoContractAccount lifetime + 30 days
Subscription billingPayment details (via Stripe), billing addressContract7 years (legal obligation)
Menu managementMenu content, images, translationsContractAccount lifetime + 30 days
QR code analyticsScan counts, device info, locationLegitimate interest24 months (aggregated indefinitely)
Website analyticsPage views, sessions, referrersConsent26 months
NewsletterEmail addressConsentUntil unsubscribed
Customer supportName, email, message contentContract / Legitimate interest24 months after resolution

International Data Transfers

As Scan2Order serves customers worldwide across 31 languages, personal data may be transferred outside the European Economic Area (EEA). When this occurs, we ensure adequate protection through:

  • Adequacy Decisions: Transfers to countries recognized by the European Commission as providing adequate data protection
  • Standard Contractual Clauses (SCCs): EU-approved contractual safeguards with our service providers
  • Data Processing Agreements (DPAs): Binding agreements with all sub-processors that handle personal data

Our key sub-processors and their locations:

  • Stripe (USA) — Payment processing, covered by SCCs and DPA
  • Google Analytics (USA) — Website analytics, covered by SCCs
  • Cloud Hosting Provider (EU) — Infrastructure and data storage

Data Protection Officer

Our Data Protection Officer (DPO) oversees our compliance with the GDPR and serves as the point of contact for data protection matters.

  • Email: hello@scan2order.app
  • Address: Data Protection Officer, Scan2Order, Krya Vrysi, Pella, Greece

Supervisory Authority

If you are located in the EU/EEA and believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. For Scan2Order, the lead supervisory authority is:

  • Hellenic Data Protection Authority (HDPA / APDPX)
  • Website: dpa.gr
  • Phone: +30 210 647 5600

You may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

Data Breach Notification

In the event of a personal data breach, Scan2Order will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible (as required by Article 33 of the GDPR)
  • Notify affected data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Article 34)
  • Document all breaches, including the facts, effects, and remedial actions taken

Data Protection by Design & Default

In accordance with Article 25 of the GDPR, Scan2Order implements data protection by design and by default. This means:

  • We collect only the minimum data necessary for each processing purpose
  • Privacy settings are configured to the most protective option by default
  • We conduct Data Protection Impact Assessments (DPIAs) for new features that involve significant data processing
  • Security is built into the development lifecycle of our platform
  • Access to personal data is restricted to authorized personnel on a need-to-know basis

Changes to This Page

We may update this GDPR compliance information from time to time. Significant changes will be communicated through our platform and via email to registered users.

Contact Us

For any GDPR-related inquiries, please contact:

We use cookies

Take a look at our Cookies Policy for more information.

Essential

Session, security & basic functionality. Always active.

Analytics

Google Analytics & usage statistics to improve our service.

Preferences

Theme, language & personalization settings.

Third-party

Stripe payments, embedded content & external services.