Skip to document content

Legal

Privacy Policy

Effective
Effective date: 16 August 2026
Updated
Last updated: 3 September 2026
Version
Version 1.4

This Policy describes how personal data is processed on dineslate.com, in the DineSlate platform and on the public booking pages operated through it.

1. Processing roles: controller and processor

DineSlate acts as an independent controller for: website visitors, contact-form inquiries, prospective restaurant customers, restaurant user accounts, authentication, user account licensing, billing, support, security, audit records and legal compliance.

The restaurant acts as controller and DineSlate as processor for: guest reservation data, waitlist, CRM, preferences, allergies and dietary information, internal notes, visit history, evaluations, restaurant-directed guest messages and recorded visit bills.

The processor relationship is governed by the Data Processing Addendum (/en/dpa).

2. Categories of data subjects

  • visitors to dineslate.com
  • people submitting a contact inquiry
  • representatives and staff of partner restaurants
  • guests submitting a reservation request to a restaurant

3. Data categories

  • Identity and contact data: name, email, phone, city/country, restaurant name.
  • Reservation data: date, time, party size, zone, special requests, reservation status.
  • CRM data: preferences, tags, visit history, notes, recorded visit bill.
  • Evaluations: post-visit ratings and comments.
  • Account data: user identifiers, role, device installations, sign-in times.
  • Technical data: IP address, basic device and browser information, security logs, email-delivery metadata.
  • Billing data: counts of confirmed online reservations and the restaurant’s invoicing details.

4. Sources

  • directly from you (booking form, contact form, evaluation form)
  • from the restaurant (phone reservations, walk-ins, staff notes)
  • automatically from use of the platform (technical logs)

5. Purposes and legal bases

5. Purposes and legal bases
PurposeLegal basis
Handling a reservation request and a confirmed reservationPerformance of a contract or pre-contractual steps, on the restaurant’s instructions
Operational emails (confirmation, reminder, cancellation)Performance of a contract and legitimate interest in operating the reservation correctly
Contact-form inquirySteps taken at your request prior to entering into a contract, and legitimate interest in responding to a business inquiry
CRM, preferences and service qualityLegitimate interest of the restaurant, and consent where sensitive data is involved
Post-visit evaluationLegitimate interest of the restaurant in internal quality control
Accounts, authentication, user account licensing, securityPerformance of a contract and legitimate interest in security
Billing and accounting/tax recordsLegal obligation and performance of a contract
Optional cookie technologiesConsent

6. Special-category data

Information about allergies or medical dietary restrictions may constitute sensitive health data within the meaning of Article 9 GDPR.

The restaurant, as controller, is responsible for having an appropriate legal basis and Article 9 condition where required, typically the guest’s explicit consent.

Access to such information must be limited to staff who need it, and irrelevant sensitive data must not be recorded.

DineSlate processes such data strictly in accordance with its role and the restaurant’s documented instructions.

7. Evaluation data

The evaluation invitation is sent after the visit on the restaurant’s instructions. Completing the evaluation form is optional and the content is not automatically published publicly.

8. Aggregate operational statistics

The platform produces aggregate operational statistics for each restaurant (for example occupancy, service periods, booking sources). No advertising networks are used and no cross-site tracking takes place.

9. Automated decision-making

DineSlate does not make the final automated decision to accept or decline a reservation. That decision is made by the Restaurant.

The platform may suggest available tables or apply the availability rules configured by the restaurant, but the final acceptance or refusal is a human decision made by the restaurant.

10. Recipients

  • the restaurant the reservation is addressed to
  • technology infrastructure providers acting as subprocessors
  • accounting and legal advisers, where necessary
  • competent authorities, where legally required

Personal data is never sold.

11. Third-party providers and subprocessors

DineSlate uses third-party technology providers, including Supabase for database, authentication, storage and related cloud functionality, Resend for operational email delivery, and Twilio for transactional SMS delivery where a restaurant enables it. Processing locations, authorised subprocessors and international-transfer mechanisms are described in the providers’ current official legal and technical documentation and, where required, in the contractual safeguards applicable to DineSlate’s use of their services.

The current subprocessor list is published at /en/subprocessors.

12. International transfers

  • Personal data may be processed inside the European Economic Area (EEA) and in third countries.
  • DineSlate does not guarantee EEA-only processing unless this has been verified for the relevant service.
  • The applicable transfer safeguards depend on the provider, the processing context and the current contractual documentation, such as Standard Contractual Clauses or another Chapter V GDPR mechanism.
  • Provider subprocessor lists and processing locations may change.
  • DineSlate updates its Subprocessor List when a material change affects its own processing.

13. Data migration source files

When a restaurant requests data migration from a previous system, it provides a CSV or Excel export file that may contain guest personal data and reservation history. DineSlate acts as processor and handles the file solely on the restaurant’s documented instructions.

The file is inspected for its structure, quality and technical compatibility before any import. Access is restricted to the personnel performing the review and the import.

The source file is stored temporarily, only for as long as the review, import and verification require, and is then securely deleted. Deletion is suspended where a legal retention obligation applies, for as long as that obligation remains in force.

14. Retention

No arbitrary periods are applied. Data is retained according to the following objective criteria:

14. Retention
CategoryRetention criterion
Reservation and waitlist dataFor the duration of the restaurant’s relationship with the platform and for as long as required by the restaurant’s accounting and legal obligations; then deleted or anonymised on the restaurant’s instruction.
CRM data, preferences, notesFor as long as the restaurant keeps them active for the customer relationship; deleted on instruction or on exercise of a right.
EvaluationsFor as long as they serve the restaurant’s internal quality control.
Contact-form inquiriesFor as long as the inquiry is being assessed and discussed, and up to 24 months from the last contact.
User accounts and device installationsFor as long as the user account exists; deactivating the account releases the licence. Devices are unlimited.
Billing records and tax documentsFor the statutory tax-record retention period in Greece.
Data migration source filesFor as long as required for the review, import and verification; securely deleted afterwards, unless a legal retention obligation applies.
Technical and security logsFor a limited period necessary to investigate security incidents.
BackupsAccording to the managed infrastructure’s backup cycle; deleted data disappears as the corresponding cycle expires.

While the service is active, the restaurant can export its supported reservation and CRM data at any time, itself. No additional export window is provided after the service ends. Customer data is then deleted or anonymised in line with the criteria above, while billing, tax and accounting records may be retained where required by law.

15. Security

  • encryption in transit
  • role-based and per-restaurant access control
  • database-level access restrictions
  • user account licensing and visibility of active installations
  • action logging and audit records
  • private storage for internal files

16. Rights of data subjects

  • access to your data
  • rectification of inaccurate data
  • erasure, where the conditions are met
  • restriction of processing
  • objection, where processing relies on legitimate interest
  • portability, where applicable
  • withdrawal of consent, without retroactive effect

For reservation data, contact the restaurant first as controller. You can also write to reservations@dineslate.com and we will forward or support the request in line with our role.

17. Right to lodge a complaint

You have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or with the supervisory authority where you live.

18. Cookies and storage technologies

The storage technologies in use are described in detail in the Cookie Policy (/en/cookies). Optional technologies are not loaded before you consent.

19. Updates to this Policy

This Policy is updated when processing changes materially. The last-updated date is shown at the top of the page.

20. Data-protection contact

For data-protection requests to DineSlate, acting as controller or processor as applicable, contact reservations@dineslate.com. Full legal name and registered address are listed under “Provider details” at the end of this page.

21. Transactional SMS

Where the business enables transactional SMS, DineSlate transmits to the messaging provider the destination number, the content of the transactional message, and the technical identifiers, routing metadata and delivery-status metadata required to send the message and evidence its delivery attempt.

Delivering an SMS requires telecommunications providers and destination-country networks and may involve international routing. DineSlate makes no statement that the delivery path remains within a particular jurisdiction.

No data beyond what is required to send the message is transmitted to the messaging provider.

Legal name
ΔΗΜΗΤΡΙΟΣ ΦΑΡΣΕΔΑΚΗΣ
Legal form
sole proprietorship established in Greece
Trading name
DineSlate
VAT number
079009366
Tax office
ΚΕΦΟΔΕ ΑΤΤΙΚΗΣ
Registered address
151 Makrygianni Street, Moschato 18346, Greece
Governing law
the laws of Greece
Courts
the competent courts of Athens, Greece

Legal and data-protection contact: reservations@dineslate.com