RestoAudit.ai is a product of SIA «IT Hospitality» (Katrīnas iela 5, LV-1045 Rīga, Latvia; registration number 40203196322). This document explains what data we process, on what legal basis, how long we keep it and what your rights are.
Two distinct roles
We act in different roles for different data, and this determines who makes the decisions.
We are the controller for your account data, enquiries and correspondence with us. Here we determine the purposes of processing.
We are the processor for the content of your invoices and the related reference data. Here you are the controller: this is your commercial data, and we process it on your instructions and under the contract, not at our own discretion.
What data we process
- Account data: name, work email, phone, company, role, sign-in log and actions on sign-in methods (enabling and disabling the second factor), the device public key for quick sign-in - if you turned it on. When you sign in with Google - the name and email from your Google account.
- Enquiries and correspondence: whatever you entered in a form or sent us by email.
- Document content: invoices, bills, credit notes and their attachments - line items, quantities, prices, VAT rates, supplier details.
- Reference data: products, warehouses, recipes, suppliers - to the extent needed to match line items.
- Technical data: request address, time, browser type - in server logs.
- Identity check: the check status, the method and the date of the decision. The check is required when you work with your own data from 20 documents or connect a back office system; for now we carry it out manually.
What we use it for
- Recognising documents and matching line items to your product catalogue.
- Monitoring purchase prices and raising signals when a figure moves out of range.
- Calculating food cost and reconciling with your accountant's export.
- Pushing documents into your back office - after confirmation or automatically, under a rule you enabled for the supplier.
- Running your account, support and answering your requests.
- Checking the identity of the account owner - protection against abuse of the free period and against working with someone else's data under your name.
- Improving the product - see the separate section below.
Legal bases
- Performance of a contract (Art. 6(1)(b) GDPR) - everything required to deliver the service: account, document processing, support.
- Controller's instructions (Art. 28 GDPR) - the content of your documents is processed on your instructions, set out in the contract.
- Legal obligation (Art. 6(1)(c) GDPR) - accounting and tax records of our relationship with you.
- Legitimate interests (Art. 6(1)(f) GDPR) - service security, protection against abuse, and product improvement on anonymised data.
How long we keep it
- Document content and reference data - 3 years after the service ends. On your request we delete or return it earlier, within 14 days: that decision is yours, not ours.
- Account and correspondence - 3 years after the service ends. On your request we delete it within 14 days, except what we are required by law to keep.
- Enquiries that did not become a contract - 12 months.
- Our invoices to you and the related accounting records - for the period required by Latvian law. This is a legal obligation and a deletion request does not override it.
Where the data is stored
The database and document files are hosted on Supabase in the London region, United Kingdom. The document processing worker runs on a dedicated Contabo server in Nuremberg, Germany. The website and the application are hosted on Vercel in the London region. Data is encrypted in transit and at rest. The United Kingdom is recognised by the European Commission as providing an adequate level of data protection, so transfers there require no separate contractual clauses.
Who we share data with
We do not sell data and do not pass it to third parties for their own purposes. The providers below process data on our instructions:
- Anthropic (USA) - recognition of document content. The document image or file is transferred. Transfer to a third country is based on the European Commission's Standard Contractual Clauses.
- Google (USA) - interpreting the wording of a question in the assistant. Only the text of your question is transferred: no invoices, prices, suppliers or stock figures. The access key is separate from the one used for document recognition. Transfer to a third country is based on Standard Contractual Clauses.
- Supabase (United Kingdom, London) - database and file storage.
- Contabo (EU, Nuremberg) - document processing server.
- Vercel (United Kingdom, London) - hosting for the website and the application.
- Telegram - delivery of alerts and intake of documents, if you use that channel.
- Cloudflare - protection of forms against automated submissions.
- Stripe Payments Europe (Ireland) - card payment processing. The billing contact and a card identifier are transferred; the card details themselves are held by Stripe, not by us. Transfers within the Stripe group to the US rely on the European Commission's standard contractual clauses.
- Resend (USA) - sending email: sign-in, confirmations, notifications. The recipient address and the message text are transferred. Transfers to a third country rely on standard contractual clauses.
- NEXX - only if you enabled the integration: the supplier list and product catalogue needed for orders are transferred. The transfer is made on your instruction and within the scope of the integration.
Product improvement
We use data to improve the product - and that is the only additional purpose beyond delivering the service. We work with anonymised aggregates: shares, distributions, frequencies. We do not publish or disclose company names, purchase amounts, or any data that would identify a particular restaurant or supplier.
If you would rather your data was not used this way, write to hello@restoaudit.ai and we will exclude it, with no effect on your service.
Cookies
The website uses one functional cookie, which remembers the language you selected. Inside the application there are additionally authentication cookies and Cloudflare Turnstile form protection. All of these are strictly necessary or functional; there are no advertising or analytics cookies.
Your rights
You may request access to your data, its correction, erasure or restriction of processing, object to processing, and receive your data in a portable format. Write to hello@restoaudit.ai and we will respond within the period set by the GDPR.
If our response does not satisfy you, you have the right to lodge a complaint with a supervisory authority - in Latvia this is the State Data Inspectorate (Datu valsts inspekcija), or with the authority where you live.
Data processing agreement
For business customers we enter into a data processing agreement (DPA) under Art. 28 GDPR: subject matter and purposes of processing, the list of sub-processors, security measures and what happens when the service ends. The text of the agreement is published. If your compliance process needs a signed copy, request it at hello@restoaudit.ai.
Contact
SIA «IT Hospitality»
Katrīnas iela 5, LV-1045 Rīga, Latvia
Email: hello@restoaudit.ai