Legal
Privacy Policy
- Effective
- Effective date: 2 August 2026
- Updated
- Last updated: 2 August 2026
- Version
- Version 1.0
Service provider: ΔΗΜΗΤΡΙΟΣ ΦΑΡΣΕΔΑΚΗΣ, a sole proprietorship established in Greece, trading as “DineSlate”. Registered address: 151 Makrygianni Street, Moschato 18346, Greece. VAT number: 079009366, ΚΕΦΟΔΕ ΑΤΤΙΚΗΣ. Legal and data-protection contact: reservations@dineslate.com.
This Policy describes how personal data is processed on dineslate.com, in the DineSlate platform and on the public booking pages operated through it.
1. Roles — when we are controller and when we are processor
DineSlate acts as an independent controller for: website visitors, contact-form inquiries, prospective restaurant customers, restaurant user accounts, authentication, device licensing, billing, support, security, audit records and legal compliance.
The restaurant acts as controller and DineSlate as processor for: guest reservation data, waitlist, CRM, preferences, allergies and dietary information, internal notes, visit history, evaluations, restaurant-directed guest messages and recorded visit bills.
The processor relationship is governed by the Data Processing Addendum (/en/dpa).
2. Categories of people
- visitors to dineslate.com
- people submitting a contact inquiry
- representatives and staff of partner restaurants
- guests submitting a reservation request to a restaurant
3. Data categories
- Identity and contact data: name, email, phone, city/country, restaurant name.
- Reservation data: date, time, party size, zone, special requests, reservation status.
- CRM data: preferences, tags, visit history, notes, recorded visit bill.
- Evaluations: post-visit ratings and comments.
- Account data: user identifiers, role, device installations, sign-in times.
- Technical data: IP address, basic device and browser information, security logs, email-delivery metadata.
- Billing data: counts of confirmed online reservations and the restaurant’s invoicing details.
4. Sources
- directly from you (booking form, contact form, evaluation form)
- from the restaurant (phone reservations, walk-ins, staff notes)
- automatically from use of the platform (technical logs)
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Handling a reservation request and a confirmed reservation | Performance of a contract or pre-contractual steps, on the restaurant’s instructions |
| Operational emails (confirmation, reminder, cancellation) | Performance of a contract and legitimate interest in operating the reservation correctly |
| Contact-form inquiry | Steps taken at your request prior to entering into a contract, and legitimate interest in responding to a business inquiry |
| CRM, preferences and service quality | Legitimate interest of the restaurant, and consent where sensitive data is involved |
| Post-visit evaluation | Legitimate interest of the restaurant in internal quality control |
| Accounts, authentication, device licensing, security | Performance of a contract and legitimate interest in security |
| Billing and accounting/tax records | Legal obligation and performance of a contract |
| Optional cookie technologies | Consent |
6. Special-category data
Information about allergies or medical dietary restrictions may constitute sensitive health data within the meaning of Article 9 GDPR.
The restaurant, as controller, is responsible for having an appropriate legal basis and Article 9 condition where required, typically the guest’s explicit consent.
Access to such information must be limited to staff who need it, and irrelevant sensitive data must not be recorded.
DineSlate processes such data strictly in accordance with its role and the restaurant’s documented instructions.
7. Evaluation data
The evaluation invitation is sent after the visit on the restaurant’s instructions. Completing the evaluation form is optional and the content is not automatically published publicly.
8. Aggregate analytics
The platform produces aggregate operational statistics for each restaurant (for example occupancy, service periods, booking sources). No advertising networks are used and no cross-site tracking takes place.
9. Automated decision-making
DineSlate does not make the final automated decision to accept or decline a reservation. That decision is made by the Restaurant.
The platform may suggest available tables or apply the availability rules configured by the restaurant, but the final acceptance or refusal is a human decision made by the restaurant.
10. Recipients
- the restaurant the reservation is addressed to
- technology infrastructure providers acting as subprocessors
- accounting and legal advisers, where necessary
- competent authorities, where legally required
Personal data is never sold.
11. Third-party providers and subprocessors
DineSlate uses third-party technology providers, including Supabase for database, authentication, storage and related cloud functionality, and Resend for operational email delivery. Processing locations, authorised subprocessors and international-transfer mechanisms are described in the providers’ current official legal and technical documentation and, where required, in the contractual safeguards applicable to DineSlate’s use of their services.
The current subprocessor list is published at /en/subprocessors.
12. International transfers
- Personal data may be processed inside the European Economic Area (EEA) and in third countries.
- DineSlate does not guarantee EEA-only processing unless this has been verified for the relevant service.
- The applicable transfer safeguards depend on the provider, the processing context and the current contractual documentation, such as Standard Contractual Clauses or another Chapter V GDPR mechanism.
- Provider subprocessor lists and processing locations may change.
- DineSlate updates its Subprocessor List when a material change affects its own processing.
13. Data migration source files
When a restaurant requests data migration from a previous system, it provides a CSV or Excel export file that may contain guest personal data and reservation history. DineSlate acts as processor and handles the file solely on the restaurant’s documented instructions.
The file is inspected for its structure, quality and technical compatibility before any import. Access is restricted to the personnel performing the review and the import.
The source file is stored temporarily, only for as long as the review, import and verification require, and is then securely deleted. Deletion is suspended where a legal retention obligation applies, for as long as that obligation remains in force.
14. Retention
No arbitrary periods are applied. Data is retained according to the following objective criteria:
| Category | Retention criterion |
|---|---|
| Reservation and waitlist data | For the duration of the restaurant’s relationship with the platform and for as long as required by the restaurant’s accounting and legal obligations; then deleted or anonymised on the restaurant’s instruction. |
| CRM data, preferences, notes | For as long as the restaurant keeps them active for the customer relationship; deleted on instruction or on exercise of a right. |
| Evaluations | For as long as they serve the restaurant’s internal quality control. |
| Contact-form inquiries | For as long as the inquiry is being assessed and discussed, and up to 24 months from the last contact. |
| User accounts and device installations | For as long as the account or device licence exists; removing an installation releases the licence. |
| Billing records and tax documents | For the statutory tax-record retention period in Greece. |
| Data migration source files | For as long as required for the review, import and verification; securely deleted afterwards, unless a legal retention obligation applies. |
| Technical and security logs | For a limited period necessary to investigate security incidents. |
| Backups | According to the managed infrastructure’s backup cycle; deleted data disappears as the corresponding cycle expires. |
15. Security
- encryption in transit
- role-based and per-restaurant access control
- database-level access restrictions
- device licensing and control of active installations
- action logging and audit records
- private storage for internal files
16. Your rights
- access to your data
- rectification of inaccurate data
- erasure, where the conditions are met
- restriction of processing
- objection, where processing relies on legitimate interest
- portability, where applicable
- withdrawal of consent, without retroactive effect
For reservation data, contact the restaurant first as controller. You can also write to reservations@dineslate.com and we will forward or support the request in line with our role.
17. Right to complain
You have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or with the supervisory authority where you live.
19. Policy updates
This Policy is updated when processing changes materially. The last-updated date is shown at the top of the page.
20. Contact
ΔΗΜΗΤΡΙΟΣ ΦΑΡΣΕΔΑΚΗΣ, a sole proprietorship established in Greece, 151 Makrygianni Street, Moschato 18346, Greece. Data-protection email: reservations@dineslate.com.
Provider details
- Legal name
- ΔΗΜΗΤΡΙΟΣ ΦΑΡΣΕΔΑΚΗΣ
- Legal form
- sole proprietorship established in Greece
- Trading name
- DineSlate
- VAT number
- 079009366
- Tax office
- ΚΕΦΟΔΕ ΑΤΤΙΚΗΣ
- Registered address
- 151 Makrygianni Street, Moschato 18346, Greece
- Governing law
- the laws of Greece
- Courts
- the competent courts of Athens, Greece
Contact: reservations@dineslate.com