← platclair.com

Privacy policy

Updated on 4 September 2026

The essentials

Five points, true and verifiable, before the detail.

  • The diner who scans the QR code leaves no personal data behind. No account, no audience measurement, no advertising tracker, and no JavaScript on those pages.
  • IP addresses are never recorded. They serve only to slow down repeated attempts, live in volatile memory and erase themselves. They are written neither to the database nor to any log.
  • The only people whose data is kept are the staff of the client establishment and the people who write in through the contact form on the sales website.
  • No data is sold, rented, or used for advertising purposes.
  • No bank card number passes through this service: payment takes place on Stripe's own pages.

Who is the data controller

The data controller is the person who decides why and how data is used. Here, that is:

  • Sergio Agustín Paredes Medina, self-employed (autónomo) in Spain
  • NIF: 49928719C
  • Address: Calle Balmes 19, 07300 Inca, Illes Balears, España
  • Contact: sergioagustinparedes@gmail.com
  • Service concerned: platclair.com

The service is sold on subscription to businesses — hotels and restaurants. The relationship is therefore a business-to-business one. The processing of data is subject to the General Data Protection Regulation (GDPR) and to Spanish law.

The publisher is a self-employed individual. The publisher is under no obligation to appoint a data protection officer, and has not appointed one. Any request is handled directly at sergioagustinparedes@gmail.com.

What data, and about whom

Two audiences must be distinguished, because they are not treated in the same way.

The diner who scans the QR code: no data

The allergen menu read by a diner is a public page. It asks for nothing and records nothing.

  • No account, no registration, no form.
  • No audience measurement, no visit statistics, no advertising tracker.
  • No JavaScript is loaded on those pages.
  • A single cookie may be set, `lang_<establishment>`, and only if the diner chooses a language themselves.

In other words: a diner can consult the menu without any personal data about them existing anywhere afterwards.

The business client and its staff

To make the service work, the following data is recorded on the server, in a database hosted in Europe.

Accounts of the establishment's staff

  • email address;
  • a hash of the password — the password itself is never kept, neither in clear text nor in any reversible form;
  • role (management or kitchen);
  • language chosen;
  • creation and update dates.

Establishment

  • trading name;
  • logo;
  • customer and subscription identifiers at Stripe.

Evidence record and log of decisions on allergen alerts

When someone confirms a menu or settles an allergen alert, their email address is frozen into the row. This is not an oversight: it is the heart of the evidence. It must remain legible even after the person has left, otherwise the record no longer proves anything to a health inspection.

Change history

The role and the action carried out. An email address sometimes appears in the text of the action, when the action concerned an account.

The people who write in through the contact form

The sales website offers a form. What is recorded: name, email, company, telephone, message, plan enquired about, language, and the browser's user agent — the text by which a browser identifies itself. This information is used to answer the enquiry and to tell an automated submission from a genuine enquiry. It is used neither for advertising nor for audience measurement.

IP addresses are never recorded

The IP address is used for one thing only: to slow down repeated attempts on login, registration and the contact form. It is held in volatile memory, for the duration of a sliding window, then disappears by itself. It is never written to the database, never written to a log, and is passed on to no one.

Why this data, and on what legal basis

What the service doesData usedLegal basis
Open and run the establishment's accountstaff accounts, trading name, logoPerformance of the contract (Article 6(1)(b) GDPR)
Collect the subscriptionemail, name of the establishment, billing dataPerformance of the contract (Article 6(1)(b) GDPR)
Keep accounting recordsbilling dataLegal obligation (Article 6(1)(c) GDPR), Spanish commercial law
Maintain the evidence record and the log of decisions on alertsfrozen email of the person who confirmed or settled, datePerformance of the contract (Article 6(1)(b) GDPR) and legitimate interests (Article 6(1)(f) GDPR)
Answer an enquiry sent through the contact formname, email, company, telephone, message, plan enquired about, languagePre-contractual steps (Article 6(1)(b) GDPR)
Trace the changes made in the panelrole, action, sometimes an email addressLegitimate interests (Article 6(1)(f) GDPR)
Slow down repeated attemptsIP address, in volatile memory onlyLegitimate interests (Article 6(1)(f) GDPR)
Remember the language chosen by the diner`lang_<establishment>` cookieExplicit request of the visitor

What “legitimate interests” means here

Legitimate interests permit a processing operation provided that it is necessary and that it does not weigh too heavily on the individual. Three cases arise in this service, and here is what they mean for the reader:

  • The evidence must outlive the person. A record in which one could erase who validated what is no longer a record. The frozen email address is the price of evidential value — it is also what protects the establishment in the event of an inspection.
  • Knowing who changed what. The change history serves to understand a mistake on an allergen menu. It is reduced to the role and the action.
  • Slowing down abuse. Without a limit by IP address, an inbox fills up with automated messages and a password ends up being guessed. This is the lightest possible processing: nothing is stored.

How long data is kept

DataRetention period
Login session30 days
Account and establishment datafor the duration of the contract, then deleted within one year
Evidence recordfor the duration of the contract; the establishment can export it as a PDF at any time and take it away
Contact form messagesone year
Accounting recordssix years, as Spanish commercial law requires
IP addressesnever recorded; they erase themselves from volatile memory
Backups30 days for local copies, 90 days for off-site copies
Cookiessee the table further down

The PDF export of the record matters for a client who leaves: the evidence is not held prisoner by the service. The establishment can keep it on its own side, even before the contract ends.

Who the data is passed on to

Nothing is sold or rented. The only third parties who receive anything are those who make the service work.

RecipientWhat it doesWhat it receivesWhere
Stripe Payments Europe, Ltd.subscription paymentemail, name of the establishment, billing dataIreland (EU)
DeepL SEtranslation of the menusnames and descriptions of dishes — no personal dataGermany (EU)
Anthropic PBCspotting missed allergensnames and descriptions of dishes — no personal dataUnited States
Brevo SASsending the service's emailsrecipient's email address and message contentFrance (EU)
The hosthosts the service and the databasethe service's dataEurope (EU)

Two points that matter:

  • No bank card number is visible to the publisher. Payment takes place on Stripe's own pages. The service receives only the fact that a subscription is active or not.
  • Translation and the check for missed allergens concern dishes alone. The text sent is the name and description of a recipe. No person's name, no email address, no account identifier appears in it.

Where the data is hosted, and the case of transfers outside the EU

The service's database is hosted in Europe. Stripe, DeepL and Brevo process the data within the European Union.

Only one processing operation leaves the Union: the spotting of missed allergens, at Anthropic PBC, in the United States. This transfer is governed by the European Commission's standard contractual clauses. What is sent is limited to names and descriptions of dishes: no personal data is concerned by this transfer.

The sending of the service's emails — today only password recovery messages — does carry personal data: the recipient's email address and the content of the message. It takes place at Brevo SAS, in France: this flow does not leave the European Union.

No automated decision-making about individuals

The service includes an automatic check that flags an allergen possibly left out of a dish. It bears on recipes, not on people. The final decision always belongs to a member of staff, and it is that human decision which is recorded.

There is no profiling, no scoring, and no automated decision producing legal effects concerning an individual.

Cookies

Here is the complete list of cookies set. There are no others.

CookieWhat it is forDurationWhere
`marmara_session`keep the session open30 daysmanagement panel
`marmara_etablissement`remember which hotel a group account is working onfor the duration of the sessionmanagement panel
`marmara_flash`display a message only oncea few secondsmanagement panel
`lang_<establishment>`remember the language chosen by the diner1 yearpublic menu

None is an advertising cookie. None measures audience. The first three are strictly necessary for the management panel to work; the fourth is set only if the visitor chooses a language themselves.

There is therefore no cookie banner, and that is a deliberate choice. Consent is required only for cookies that are neither necessary nor requested by the visitor (Article 22.2 of the Spanish LSSI, ePrivacy Directive). No cookie in this service falls into that category. Displaying a banner would amount to asking for a permission that is not needed, and to training people to click without reading.

A cookie can be deleted from the browser's settings. Deleting `marmara_session` logs the account out, nothing more.

Your rights, and how to exercise them

Anyone whose data is processed may request:

  • access — to know what data concerns them;
  • rectification — to have inaccurate data corrected;
  • erasure — to have their data deleted, within the limits described below;
  • restriction — to ask that their data be frozen while a dispute is examined;
  • objection — to object to processing based on legitimate interests;
  • portability — to receive their data in a machine-readable format.

How to do it

Write to sergioagustinparedes@gmail.com. An answer is provided within one month. If the request is complex, that period may be extended, and you are informed of this together with the reason.

For the client establishment, a good part of these rights can be exercised directly within the service: staff accounts can be modified and deleted from the management panel, and the evidence record can be exported as a PDF at any time.

What cannot be erased, and why

Three limits, stated frankly rather than discovered later:

  • The evidence record and the log of decisions. The email address of the person who confirmed a menu or settled an alert is frozen into it. Erasing it would amount to destroying the evidence that the establishment must be able to present to a health inspection. This data is kept for the duration of the contract, then deleted with the rest.
  • Accounting records. They are kept for six years because Spanish commercial law requires it. An erasure request cannot shorten that period.
  • Backups. Erased data disappears from the service immediately, but it remains in the backups until they rotate: at most 30 days for local copies, 90 days for off-site copies. Those copies serve only to bring the service back after a failure.

Outside these three cases, an erasure request is carried out.

Lodging a complaint with a supervisory authority

If an answer does not satisfy you, you may lodge a complaint with the Spanish data protection authority, to which the publisher is subject:

Agencia Española de Protección de Datos (AEPD) — www.aepd.es

You may also apply to the data protection authority of the European Union country where you live or work. In France, that is the CNIL. Addressing the request to sergioagustinparedes@gmail.com first is not compulsory, but it is often the quickest route.

Security

What concretely protects the data:

  • Passwords are never kept. Only a hash is recorded. No one, including the publisher, can read a password or reconstruct one. A forgotten password is replaced, not recovered.
  • No banking data passes through the service. Payment takes place on Stripe's own pages.
  • Repeated attempts are slowed down on login, registration and the contact form, without keeping any IP address.
  • Accounts have a role — management or kitchen — which determines what they can do.
  • Sessions expire after 30 days.
  • Data is hosted in Europe.
  • The public pages load no JavaScript, which removes a whole family of risks on the diner's side.

No system is invulnerable. In the event of a personal data breach presenting a risk to the individuals concerned, the supervisory authority is notified within the periods laid down by the GDPR, and the individuals concerned are informed where the risk is high.

Changes to this policy

This policy changes if the service changes: a new processor, a new item of data, a retention period that changes. The version published on platclair.com is always the one that applies, and the date of last update appears at the top of the page. Subscription clients are informed of a significant change by email.

Writing to us

For any question about this policy or about your data: sergioagustinparedes@gmail.com.