Who we are
§George Adrian Gabor Olteanu, tax ID 18536955J, registered at C/ Jocs Olímpics de Barcelona 35, 17003 Girona, España, develops and operates the Comanda service.
For anything relating to data protection, write to ggabor@outlook.es.
Controller and processor
§Comanda is a work tool that a restaurant licenses for its staff. That distinction decides who you should approach:
- The restaurant that gives you access is the data controller for your employee data and for the operational data you generate (orders, tables, payments). It decides who has an account, with which role, and for how long.
- George Adrian Gabor Olteanu acts as data processor: we handle that data solely to provide the service, on the restaurant's instructions, and never for our own purposes.
- George Adrian Gabor Olteanu is the controller for the commercial relationship with the restaurant — contracting, invoicing and support.
If you are restaurant staff and want to exercise your rights, approach your employer first. We will assist them with whatever is needed.
What data we process
§The waiter app handles only the data needed to take orders. Specifically:
| Data | Contents | Where it lives |
|---|---|---|
| Account identity | Name, username, role and organization identifier | Server and device |
| Sign-in credentials | The password or PIN entered at login | Transmitted to the server for verification; never stored on the device |
| Session tokens | Refresh token and access token | The refresh token on the device; the access token in memory only, lost when the app closes |
| Device identifier | A random UUID generated on the device itself the first time the app opens | Device; sent to the server to attribute order locks |
| Linked restaurant | Identifier, name, language and currency of the restaurant this device serves | Device |
| Usage preferences | Start screen, sounds, haptics, send confirmation | Device only: never synced, never sent to the server |
| Operational data | Orders, tables, items, kitchen notes and payments | Server |
The device identifier is a random number belonging to this installation. It is not an advertising identifier, it is not derived from the hardware, and it cannot be used to follow you outside Comanda. Uninstalling the app deletes it.
What we do not do
§Worth stating plainly, because it is unusual:
- We show no advertising and use no advertising identifiers.
- We embed no analytics, measurement or third-party tracking SDKs. The app contains none.
- We do not access your location, contacts, camera, microphone, calendar or photos.
- The only permission the Android app declares is internet access.
- We do not sell or share personal data with third parties for commercial purposes.
- We do not profile you or make automated decisions with legal effects concerning you.
Purposes and legal bases
§| Purpose | Legal basis |
|---|---|
| Authenticating the user and keeping the session open | Performance of the contract between the restaurant and us, plus legitimate interest in service security |
| Providing the service: taking orders, sending them to kitchen and bar, managing tables and payments | Performance of the contract |
| Attributing order locks to the right device so two terminals cannot edit the same order | Legitimate interest in the service working correctly |
| Diagnosing incidents and providing support | Legitimate interest, and the restaurant’s instructions |
| Meeting legal obligations, including tax obligations | Legal obligation |
Data stored on your device
§The app keeps these in the device’s local storage — not in tracking cookies:
- comanda.session — who is signed in, so credentials are not requested after every reload.
- comanda.refresh — the token that renews the session.
- comanda.deviceId — the random identifier for this installation.
- comanda.terminal — the restaurant this device is linked to.
- comanda.prefs — your usage preferences, which never leave the device.
Signing out removes the session and the refresh token. Uninstalling the app removes all of the above.
Security and transmission
§- All communication with our servers is encrypted with HTTPS/TLS.
- Production builds of the Android app refuse unencrypted traffic: the operating system itself blocks a cleartext connection.
- Data access is segmented by organization and by restaurant, so one restaurant cannot see another’s data.
- Passwords are stored hashed using key-derivation functions, never in plain text.
No system is infallible. Should a breach occur that poses a risk to your rights, we will inform the controlling restaurant and the supervisory authority within the deadlines the GDPR requires.
Retention
§- Account data is retained while the restaurant keeps your access active.
- Operational data is retained for the duration of the contract with the restaurant and thereafter for the applicable statutory limitation periods.
- Tax records are retained for the period Spanish tax law requires.
- Data stored on the device disappears when the app is uninstalled.
Recipients and processors
§We do not disclose personal data to third parties unless it is essential to provide the service or required by law. Our suppliers act as processors and are bound by contract.
- Hosting and infrastructure: Clouding.io, with servers in España (Barcelona).
- Public authorities, where a legal obligation requires it — for example the Spanish tax agency in relation to invoicing.
The app is distributed through Apple’s App Store and Google Play. Neither of them receives from us the data processed inside the app.
International transfers
§Data is hosted in España (Barcelona). We make no international transfers of data outside the European Economic Area. Were that ever to become necessary, it would be done with the safeguards set out in Chapter V of the GDPR, and this policy would be updated first.
The demo form on this website
§If you fill in the demo form on this website, we collect your name, your venue’s name, your phone number and whatever message you write. We do not ask for your email address, and this site uses no analytics or advertising cookies.
The purpose is single: to contact you and arrange the demo. The legal basis is your consent, given when you submit the form. We do not use this data to send you marketing.
The notification reaches us by email through Mailtrap (Railsware Products Studio), which acts as a processor for that delivery only. We keep the notification while we handle your request and for at most twelve months from the last contact, then delete it.
You can exercise your rights of access, rectification and erasure by writing to ggabor@outlook.es, as for the rest of this document.
Your rights
§The GDPR grants you the following rights over your personal data:
- Access: to know what data we process and obtain a copy.
- Rectification: to correct inaccurate or incomplete data.
- Erasure: to request deletion once the data is no longer necessary.
- Restriction: to have processing suspended while a complaint is resolved.
- Portability: to receive your data in a structured, commonly used format.
- Objection: to object to processing based on legitimate interest.
If you are restaurant staff, address your request to your employer, who is the controller. If the request is ours to answer, write to ggabor@outlook.es; we will respond within one month.
You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you believe your rights have not been respected.
Children
§Comanda is a professional tool aimed at restaurant staff. It is not intended for anyone under 16, and we do not knowingly collect children’s data.
Changes to this policy
§If we change this policy we will update the date shown at the top and publish the new version at https://comanda.re-ark.es/privacy. Where the change is substantial, we will also notify the restaurants we work with.
Contact
§- Data protection: ggabor@outlook.es
- General contact: ggabor@outlook.es
- Telephone: +34 642 956 773
- Postal address: George Adrian Gabor Olteanu, C/ Jocs Olímpics de Barcelona 35, 17003 Girona, España