Privacy policy
Updated on 4 September 2026
The essentials
Five points, true and verifiable, before the detail.
- The diner who scans the QR code leaves no personal data behind. No account, no audience measurement, no advertising tracker, and no JavaScript on those pages.
- IP addresses are never recorded. They serve only to slow down repeated attempts, live in volatile memory and erase themselves. They are written neither to the database nor to any log.
- The only people whose data is kept are the staff of the client establishment and the people who write in through the contact form on the sales website.
- No data is sold, rented, or used for advertising purposes.
- No bank card number passes through this service: payment takes place on Stripe's own pages.
Who is the data controller
The data controller is the person who decides why and how data is used. Here, that is:
- Sergio Agustín Paredes Medina, self-employed (autónomo) in Spain
- NIF: 49928719C
- Address: Calle Balmes 19, 07300 Inca, Illes Balears, España
- Contact: sergioagustinparedes@gmail.com
- Service concerned: platclair.com
The service is sold on subscription to businesses — hotels and restaurants. The relationship is therefore a business-to-business one. The processing of data is subject to the General Data Protection Regulation (GDPR) and to Spanish law.
The publisher is a self-employed individual. The publisher is under no obligation to appoint a data protection officer, and has not appointed one. Any request is handled directly at sergioagustinparedes@gmail.com.
What data, and about whom
Two audiences must be distinguished, because they are not treated in the same way.
The diner who scans the QR code: no data
The allergen menu read by a diner is a public page. It asks for nothing and records nothing.
- No account, no registration, no form.
- No audience measurement, no visit statistics, no advertising tracker.
- No JavaScript is loaded on those pages.
- A single cookie may be set, `lang_<establishment>`, and only if the diner chooses a language themselves.
In other words: a diner can consult the menu without any personal data about them existing anywhere afterwards.
The business client and its staff
To make the service work, the following data is recorded on the server, in a database hosted in Europe.
Accounts of the establishment's staff
- email address;
- a hash of the password — the password itself is never kept, neither in clear text nor in any reversible form;
- role (management or kitchen);
- language chosen;
- creation and update dates.
Establishment
- trading name;
- logo;
- customer and subscription identifiers at Stripe.
Evidence record and log of decisions on allergen alerts
When someone confirms a menu or settles an allergen alert, their email address is frozen into the row. This is not an oversight: it is the heart of the evidence. It must remain legible even after the person has left, otherwise the record no longer proves anything to a health inspection.
Change history
The role and the action carried out. An email address sometimes appears in the text of the action, when the action concerned an account.
The people who write in through the contact form
The sales website offers a form. What is recorded: name, email, company, telephone, message, plan enquired about, language, and the browser's user agent — the text by which a browser identifies itself. This information is used to answer the enquiry and to tell an automated submission from a genuine enquiry. It is used neither for advertising nor for audience measurement.
IP addresses are never recorded
The IP address is used for one thing only: to slow down repeated attempts on login, registration and the contact form. It is held in volatile memory, for the duration of a sliding window, then disappears by itself. It is never written to the database, never written to a log, and is passed on to no one.
Why this data, and on what legal basis
| What the service does | Data used | Legal basis |
|---|---|---|
| Open and run the establishment's account | staff accounts, trading name, logo | Performance of the contract (Article 6(1)(b) GDPR) |
| Collect the subscription | email, name of the establishment, billing data | Performance of the contract (Article 6(1)(b) GDPR) |
| Keep accounting records | billing data | Legal obligation (Article 6(1)(c) GDPR), Spanish commercial law |
| Maintain the evidence record and the log of decisions on alerts | frozen email of the person who confirmed or settled, date | Performance of the contract (Article 6(1)(b) GDPR) and legitimate interests (Article 6(1)(f) GDPR) |
| Answer an enquiry sent through the contact form | name, email, company, telephone, message, plan enquired about, language | Pre-contractual steps (Article 6(1)(b) GDPR) |
| Trace the changes made in the panel | role, action, sometimes an email address | Legitimate interests (Article 6(1)(f) GDPR) |
| Slow down repeated attempts | IP address, in volatile memory only | Legitimate interests (Article 6(1)(f) GDPR) |
| Remember the language chosen by the diner | `lang_<establishment>` cookie | Explicit request of the visitor |
What “legitimate interests” means here
Legitimate interests permit a processing operation provided that it is necessary and that it does not weigh too heavily on the individual. Three cases arise in this service, and here is what they mean for the reader:
- The evidence must outlive the person. A record in which one could erase who validated what is no longer a record. The frozen email address is the price of evidential value — it is also what protects the establishment in the event of an inspection.
- Knowing who changed what. The change history serves to understand a mistake on an allergen menu. It is reduced to the role and the action.
- Slowing down abuse. Without a limit by IP address, an inbox fills up with automated messages and a password ends up being guessed. This is the lightest possible processing: nothing is stored.
How long data is kept
| Data | Retention period |
|---|---|
| Login session | 30 days |
| Account and establishment data | for the duration of the contract, then deleted within one year |
| Evidence record | for the duration of the contract; the establishment can export it as a PDF at any time and take it away |
| Contact form messages | one year |
| Accounting records | six years, as Spanish commercial law requires |
| IP addresses | never recorded; they erase themselves from volatile memory |
| Backups | 30 days for local copies, 90 days for off-site copies |
| Cookies | see the table further down |
The PDF export of the record matters for a client who leaves: the evidence is not held prisoner by the service. The establishment can keep it on its own side, even before the contract ends.
Who the data is passed on to
Nothing is sold or rented. The only third parties who receive anything are those who make the service work.
| Recipient | What it does | What it receives | Where |
|---|---|---|---|
| Stripe Payments Europe, Ltd. | subscription payment | email, name of the establishment, billing data | Ireland (EU) |
| DeepL SE | translation of the menus | names and descriptions of dishes — no personal data | Germany (EU) |
| Anthropic PBC | spotting missed allergens | names and descriptions of dishes — no personal data | United States |
| Brevo SAS | sending the service's emails | recipient's email address and message content | France (EU) |
| The host | hosts the service and the database | the service's data | Europe (EU) |
Two points that matter:
- No bank card number is visible to the publisher. Payment takes place on Stripe's own pages. The service receives only the fact that a subscription is active or not.
- Translation and the check for missed allergens concern dishes alone. The text sent is the name and description of a recipe. No person's name, no email address, no account identifier appears in it.
Where the data is hosted, and the case of transfers outside the EU
The service's database is hosted in Europe. Stripe, DeepL and Brevo process the data within the European Union.
Only one processing operation leaves the Union: the spotting of missed allergens, at Anthropic PBC, in the United States. This transfer is governed by the European Commission's standard contractual clauses. What is sent is limited to names and descriptions of dishes: no personal data is concerned by this transfer.
The sending of the service's emails — today only password recovery messages — does carry personal data: the recipient's email address and the content of the message. It takes place at Brevo SAS, in France: this flow does not leave the European Union.
No automated decision-making about individuals
The service includes an automatic check that flags an allergen possibly left out of a dish. It bears on recipes, not on people. The final decision always belongs to a member of staff, and it is that human decision which is recorded.
There is no profiling, no scoring, and no automated decision producing legal effects concerning an individual.
Cookies
Here is the complete list of cookies set. There are no others.
| Cookie | What it is for | Duration | Where |
|---|---|---|---|
| `marmara_session` | keep the session open | 30 days | management panel |
| `marmara_etablissement` | remember which hotel a group account is working on | for the duration of the session | management panel |
| `marmara_flash` | display a message only once | a few seconds | management panel |
| `lang_<establishment>` | remember the language chosen by the diner | 1 year | public menu |
None is an advertising cookie. None measures audience. The first three are strictly necessary for the management panel to work; the fourth is set only if the visitor chooses a language themselves.
There is therefore no cookie banner, and that is a deliberate choice. Consent is required only for cookies that are neither necessary nor requested by the visitor (Article 22.2 of the Spanish LSSI, ePrivacy Directive). No cookie in this service falls into that category. Displaying a banner would amount to asking for a permission that is not needed, and to training people to click without reading.
A cookie can be deleted from the browser's settings. Deleting `marmara_session` logs the account out, nothing more.
Your rights, and how to exercise them
Anyone whose data is processed may request:
- access — to know what data concerns them;
- rectification — to have inaccurate data corrected;
- erasure — to have their data deleted, within the limits described below;
- restriction — to ask that their data be frozen while a dispute is examined;
- objection — to object to processing based on legitimate interests;
- portability — to receive their data in a machine-readable format.
How to do it
Write to sergioagustinparedes@gmail.com. An answer is provided within one month. If the request is complex, that period may be extended, and you are informed of this together with the reason.
For the client establishment, a good part of these rights can be exercised directly within the service: staff accounts can be modified and deleted from the management panel, and the evidence record can be exported as a PDF at any time.
What cannot be erased, and why
Three limits, stated frankly rather than discovered later:
- The evidence record and the log of decisions. The email address of the person who confirmed a menu or settled an alert is frozen into it. Erasing it would amount to destroying the evidence that the establishment must be able to present to a health inspection. This data is kept for the duration of the contract, then deleted with the rest.
- Accounting records. They are kept for six years because Spanish commercial law requires it. An erasure request cannot shorten that period.
- Backups. Erased data disappears from the service immediately, but it remains in the backups until they rotate: at most 30 days for local copies, 90 days for off-site copies. Those copies serve only to bring the service back after a failure.
Outside these three cases, an erasure request is carried out.
Lodging a complaint with a supervisory authority
If an answer does not satisfy you, you may lodge a complaint with the Spanish data protection authority, to which the publisher is subject:
Agencia Española de Protección de Datos (AEPD) — www.aepd.es
You may also apply to the data protection authority of the European Union country where you live or work. In France, that is the CNIL. Addressing the request to sergioagustinparedes@gmail.com first is not compulsory, but it is often the quickest route.
Security
What concretely protects the data:
- Passwords are never kept. Only a hash is recorded. No one, including the publisher, can read a password or reconstruct one. A forgotten password is replaced, not recovered.
- No banking data passes through the service. Payment takes place on Stripe's own pages.
- Repeated attempts are slowed down on login, registration and the contact form, without keeping any IP address.
- Accounts have a role — management or kitchen — which determines what they can do.
- Sessions expire after 30 days.
- Data is hosted in Europe.
- The public pages load no JavaScript, which removes a whole family of risks on the diner's side.
No system is invulnerable. In the event of a personal data breach presenting a risk to the individuals concerned, the supervisory authority is notified within the periods laid down by the GDPR, and the individuals concerned are informed where the risk is high.
Changes to this policy
This policy changes if the service changes: a new processor, a new item of data, a retention period that changes. The version published on platclair.com is always the one that applies, and the date of last update appears at the top of the page. Subscription clients are informed of a significant change by email.
Writing to us
For any question about this policy or about your data: sergioagustinparedes@gmail.com.