Privacy Notice

Effective date: 18 November 2025
Governing law: Greece and EU (GDPR)

1. Who we are (Data Controller)

This Privacy Notice explains how we collect, use, share and protect personal data when:

  • you visit our public website / landing pages (for example to learn about the Service),

  • you create and manage a venue account on the Scan and Dine platform,

  • you subscribe and pay for the Service, and

  • your customers view your QR code menu.

The Service is operated by Petro Dudi, a sole proprietorship (ατομική επιχείρηση) established in Greece (“Company”, “we”, “us”, “our”). As a Greek sole proprietorship, the business is carried out by one natural person who is personally responsible for the business and its obligations.

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the “controller” is the person or entity that decides why and how personal data are processed. We act as the data controller for most of the data described in this Privacy Notice.

Contact details of the controller:
• Business name: Petro Dudi
• Registered seat: 4 Marathonomachon str., Argyroupoli 16452, Greece
• Tax ID (ΑΦΜ): EL105770219
• Email: support@scan-and-dine.com

If you are an End User (for example, a diner scanning a QR code at a venue), you should also review the venue’s own privacy / data protection notice, because the venue itself may be a separate controller for some data it processes about you.

2. What this Notice covers

This Privacy Notice covers:

  • Venue owner / subscriber data (account, billing, login, usage).

  • Data created by venues about their menus (menu items, descriptions, allergens, prices, announcements, “Pet Friendly” badge, translations, etc.).

  • Basic technical data from End Users who view a menu by scanning a QR code, including limited interaction features such as “Like” and the temporary “List”.

  • Payment and invoicing data handled via Stripe (payments) and Elorus (invoicing / tax-compliant invoices in Greece, including transmission to AADE/myDATA where required).

This Notice does not cover personal data you independently collect from your own customers outside the platform (for example, if you ask them for a phone number to take a reservation).

3. Personal data we collect

3.1 Venue / subscriber data

When you create and manage an account in the “My Account” area, we collect:

  • Business email and password (and any password reset tokens we send you).

  • Business display name shown on the QR menu (this can differ from the legal billing name you use for subscription payments).

  • Social media handles and website links you choose to publish in your menu.

  • Settings you choose to enable (for example, Pet Friendly badge, translations, currency display, color theme, availability of Like / List buttons, job alert announcements).

  • Activity logs related to changes you make (for example, enabling/disabling features, changing your menu name, exporting/importing backups, cancelling the subscription).

  • Billing details needed for payment and invoicing, such as billing address, VAT/ΑΦΜ, and payment method.

3.2 Payment data

When you pay for a subscription, Stripe collects and processes your card/billing information on our behalf in order to charge you for recurring subscription fees and applicable taxes. Stripe may also store limited billing details (such as card type and expiry) for future renewals.

We receive from Stripe high-level payment status information (e.g. “paid”, “failed”) so we can activate or suspend service.

3.3 Invoicing data

We issue and send your invoices through Elorus. To generate tax-compliant invoices in Greece, Elorus processes information such as your business name, address, VAT number (ΑΦΜ), invoice amount, invoice date, and subscription description.

Under Greek e-invoicing / e-bookkeeping rules and AADE’s myDATA reporting framework, invoice and transaction data can be transmitted electronically to the Greek tax authority for audit, bookkeeping and VAT reporting purposes.

3.4 End User (customer scanning the QR menu)

When an End User scans a venue’s QR code or opens the menu URL:

  • We deliver the menu content (categories, items, prices, allergens, announcements, translations, Pet Friendly badge, etc.) that the venue configured.

  • We may collect basic technical data from the End User’s browser/device (such as IP address, device type, and language preference) to operate, secure and display the menu and to apply the correct language/translation view.

  • If the venue has enabled the Like button, End Users can tap “Like” on menu items. We record that a menu item received a “like” so the venue can view aggregated like statistics per item and per category. We do not display individual identities to the venue; they only see counts.

  • If the venue has enabled the List feature, the End User can add menu items to a temporary list (“what I plan to order”). This list exists only in that browser session; it disappears if they refresh, close the page, or rescan the QR code.

  • If the venue has published announcements (including “Job alert”), we show those announcements. We don’t collect application data; applicants must contact the venue directly, using the contact details the venue provides.

  • If the venue temporarily disables its menu, End Users will see an overlay (“The menu is temporarily unavailable”) and cannot interact with it.

We do not ask End Users for names, phone numbers, emails or payment info. The platform is not a table-ordering, reservation, or payment system; it is a digital menu display with optional engagement features.

4. Why we process personal data (purposes and legal bases)

Under the GDPR, we must identify a lawful basis for each type of processing. The GDPR allows processing when, for example, it is necessary to perform a contract, comply with a legal obligation, pursue a legitimate interest that is not overridden by data subject rights, or when consent has been given.

4.1 To provide and operate the Service (contract necessity – GDPR Art. 6(1)(b))

We process your account data, menu configuration, and subscription status to:

  • let you sign in securely and manage your “My Account” settings, including changing email and password and recovering access if you forget your password, where we may send a token to your new email.

  • let you build and update your QR-based menu, including translations, announcements, allergen labels, and pricing.

  • generate and display your QR code and public menu URL so End Users can see your menu.

  • show you engagement metrics such as “likes” per item, grouped by category.

  • allow you to export/import your menu and restore backups (noting that imports overwrite the live menu).

4.2 To take payment and issue invoices (contract necessity + legal obligation – GDPR Art. 6(1)(b) and 6(1)(c))

We use Stripe to collect subscription payments securely and on a recurring basis. Stripe processes your card/billing details to charge you each billing cycle.

We use Elorus to generate and send invoices that meet Greek tax and e-invoicing / myDATA requirements, and Elorus may transmit invoice data to the Greek tax authority (AADE) as required by Greek bookkeeping and VAT reporting rules.

We must keep proper accounting records and invoices to comply with Greek commercial, tax and VAT law.

4.3 To maintain security and prevent abuse (legitimate interests – GDPR Art. 6(1)(f))

We may log technical details (such as IP address, device type and activity) to:

  • keep the Service secure;

  • detect, investigate and prevent misuse (for example, attempts to access another venue’s account, or automated scraping);

  • troubleshoot outages or bugs.
    We believe these uses are necessary for the stability and safety of the Service and align with our legitimate interest in operating a reliable platform.

4.4 To communicate with you (legitimate interests / contract necessity)

We may email you about:

  • service or security issues (for example, password reset tokens);

  • subscription status, renewal date (“Renews on”), payment failures, or price changes;

  • important updates to our Terms or Privacy Notice.

Where required by law, we will ask for your consent before sending marketing communications.

4.5 To comply with law (legal obligation – GDPR Art. 6(1)(c))

We process and may retain certain information to:

  • meet tax, invoice, bookkeeping and VAT-reporting obligations in Greece, including obligations connected to AADE’s myDATA system and structured e-invoicing.

  • respond to lawful requests from competent authorities, such as the Hellenic Data Protection Authority (HDPA) or tax authorities. The HDPA is the independent supervisory authority in Greece responsible for enforcing data protection law and overseeing GDPR compliance.

5. Cookies, analytics and similar technologies

We may use strictly necessary cookies / local storage or similar browser technologies so that:

  • You stay signed in to your dashboard securely.

  • We remember certain configuration choices during a session (for example, language selection in the customer menu). When a customer chooses a translation, the interface and menu items can appear in that language; supported languages include English, Greek, French, Spanish and Portuguese, and the interface elements such as category names, List counter, Pet Friendly badge, etc., appear localized.

On our public website / landing pages, we also use analytics cookies and similar technologies to understand how visitors use the site and to improve it over time. For this, we use Google Analytics (provided by Google LLC / Google Ireland Ltd.), which collects information such as your truncated IP address, device and browser information, pages visited and actions taken on the site. These analytics are used in aggregated form for statistics and to improve our website and Service, not to show you personalised ads through our own website. Google may process this information on servers located inside and outside the European Economic Area (EEA); where such transfers occur, they are subject to appropriate safeguards as required by applicable data protection law.

We load Google Analytics and other non-essential services only after you give consent through our cookie banner, which is powered by the tarteaucitron.js consent management platform. You can accept or reject analytics cookies at any time through the banner or your cookie settings, and you can withdraw your consent just as easily as you gave it.

Within the Scan and Dine platform itself, we may also collect basic analytics (for example, which menu items received the most “likes”). These analytics are provided to the venue owner in aggregated form.

Where non-essential cookies / analytics are used, we rely on your consent as the legal basis and we will seek that consent through our cookie banner when required by applicable e-privacy / cookie rules.

6. Who we share data with

We share personal data only with:

  1. Stripe (payments). Stripe acts as our payment processor, handling your payment method to complete subscription charges and recurring renewals, and providing us with payment status. Stripe may transfer data internationally (for example, to the U.S.) using approved GDPR transfer mechanisms such as the EU Commission’s Standard Contractual Clauses (SCCs).

  2. Elorus (invoicing). Elorus issues subscription invoices, manages recurring billing records, and can transmit invoice data to AADE/myDATA in line with Greek e-invoicing / e-bookkeeping rules, including the framework for certified e-invoicing service providers (Υ.ΠΑ.Η.Ε.Σ.) recognized by the Greek tax authority.

  3. Hosting, infrastructure, and security providers. We use service providers to host the platform, store backups, deliver content quickly, and detect abuse. These providers act under contracts that require appropriate confidentiality, security, and (where applicable) GDPR processor terms.

  4. Professional advisers and authorities. We may disclose data to auditors, accountants, tax consultants, or legal advisers where needed to protect our legitimate interests or comply with Greek tax/accounting law, and to lawful authorities (e.g. AADE, courts, HDPA) if required.

We do not sell or rent personal data.

7. International data transfers

Some of our service providers (for example, Stripe) may store or access personal data outside the European Economic Area. Under the GDPR, personal data can only be transferred outside the EEA if certain safeguards are in place to ensure essentially equivalent protection.

Stripe states that it uses the European Commission’s Standard Contractual Clauses (SCCs), which are legally approved contract terms for protecting EU personal data when it is transferred internationally.

Elorus is based in Greece and issues invoices locally, including forwarding invoice data to the Greek Independent Authority for Public Revenue (AADE) and the national myDATA e-bookkeeping system, as required under Greek tax rules for electronic invoicing and reporting.

8. Data retention

We keep personal data only for as long as necessary for the purposes described in this Notice, including:

  • Account data: we keep your account and menu data while your subscription is active and for a short grace period if there is a payment problem. If you cancel, your QR menu and your account are permanently deleted immediately, and the QR code becomes unusable. If we cancel your subscription for non-payment (for example, because a renewal payment remains unpaid), your subscription is automatically canceled and your account — including menu data — is normally permanently deleted within fifteen (15) days from the failed payment, and your QR code becomes unusable. We may still retain invoices, billing details and limited logs as described below where we are required to do so by Greek tax, accounting or other legal obligations.

  • Backups / menu exports: you can export your entire menu, and you can import it later, but importing permanently overwrites the current live menu.

  • Invoices, billing and tax records: we keep invoices and related billing details for as long as required by Greek tax and accounting law. Greece’s e-invoicing / myDATA framework requires businesses to report and keep accounting and VAT records so authorities can audit and reconcile VAT and corporate tax, and invoicing data may need to be archived for at least 5 years and sometimes longer (for example, in case of extended audit windows or disputes).

  • Security logs: we may keep limited security and access logs for a reasonable period to detect, investigate, and prevent fraud or abuse, and to comply with legal obligations.

When data is no longer needed, we will delete or irreversibly anonymize it unless we are legally required to keep it (for example, pending a tax audit or legal claim).

9. How we protect personal data

We apply technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, alteration or disclosure, taking into account the nature, scope, context and purposes of processing, consistent with GDPR security obligations.

Examples include: requiring current password entry to change account email, sending verification tokens to the new email, recommending strong 8+ character passwords with a mix of upper/lowercase letters, numbers and symbols, and warning you to change temporary passwords after reset.

10. Your data protection rights

Under the GDPR and Greek data protection law (Law 4624/2019), you have rights over your personal data, including:

  • Right of access – to ask if we process your personal data and to receive a copy.

  • Right to rectification – to correct inaccurate or incomplete data.

  • Right to erasure (“right to be forgotten”) – to request deletion of your personal data in certain cases.

  • Right to restriction of processing – to request that we limit how we use your data in certain cases.

  • Right to data portability – to receive your data in a structured, commonly used format and ask us to transfer it to another controller where technically feasible.

  • Right to object – to object, in certain cases, to processing based on our legitimate interests.

  • Right to withdraw consent – where we rely on consent (for example, for optional marketing), you can withdraw it at any time.

These rights exist under the GDPR, which has applied directly across all EU Member States since 25 May 2018, and are supplemented in Greece by Law 4624/2019, which also establishes the Hellenic Data Protection Authority and its powers.

If you exercise these rights, we may need to verify your identity before acting on the request.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA), which supervises data protection law in Greece. The HDPA’s contact details are:

Hellenic Data Protection Authority
Kifissias 1-3, 115 23 Athens, Greece
Tel. +30 210 6475600
Email: contact@dpa.gr. (dpa.gr)

11. Contact us

For any questions about this Privacy Notice, data protection, or to exercise your rights, you can contact us at:

Petro Dudi
4 Marathonomachon str., Argyroupoli 16452, Greece
Email: support@scan-and-dine.com

When you contact us, please include enough information so we can identify you and respond (for example, the email you use for your account).

12. Changes to this Privacy Notice

We may update this Privacy Notice from time to time (for example, if we add new features such as additional analytics, or if Greek tax/e-invoicing rules change and require different invoicing or data retention). Greece is in the process of expanding structured e-invoicing and real-time reporting via certified providers and AADE’s myDATA system, including plans to make near real-time B2B e-invoicing broadly mandatory.

If we make material changes, we will let you know (for example, by email or via your dashboard). If you keep using the Service after the effective date of an updated Privacy Notice, that means you accept the updated version.