Skip to content

Legal

Privacy Policy

Version 1.0-draft

This document is a working draft published by the operator and has not yet been confirmed as reviewed by legal counsel.

Draft. This text was prepared as a professional starting point and has not yet been reviewed by legal counsel. Replace the bracketed placeholders and have it reviewed before relying on it.

1. Who we are

[Legal entity name] operates AKROUN Hospitality ERP. This policy explains how we process personal data when you visit our website or use the Service.

2. Data we process

Account data — names, work e-mail addresses, phone numbers and roles of the users your organization creates. Operational data — the business records your organization enters (suppliers, items, recipes, transactions), which may incidentally include personal data of staff or suppliers. Technical data — IP address, device and browser information, security events and audit logs. Billing data — invoices and payment status; card details are handled by our payment provider and never stored by us.

3. Why and on what basis

To provide and secure the Service (performance of contract); to bill and comply with tax and accounting law (legal obligation); to prevent fraud and abuse and to improve the Service (legitimate interests); marketing communications only with your consent.

4. Roles

For operational data entered by your organization we act as a processor on your instructions; your organization is the controller. For website visitors and account administration we act as controller.

5. Sharing and sub-processors

We share data only with providers necessary to run the Service — hosting, e-mail delivery, payment processing and, where enabled by your organization, AI providers and delivery integrations — under contracts that protect it. A current list of sub-processors is available on request.

6. International transfers

Data is hosted in [hosting region]. Where data is transferred across borders we rely on appropriate safeguards required by applicable law.

7. Retention

Account and operational data are retained for the life of the subscription and for [30] days after termination to allow export, then deleted or anonymized, except where longer retention is required by law (for example, invoices).

8. Security

Encryption in transit, row-level tenant isolation, multi-factor authentication, role-scoped permissions, audit logging and tested backups protect your data.

9. Your rights

Depending on your jurisdiction you may have rights to access, correct, delete or export your personal data and to object to or restrict processing. Contact [privacy contact e-mail]; if you are a user of a customer organization, we may refer your request to that organization.

10. Cookies

See our Cookie Policy.

11. Changes

We will publish changes to this policy here and notify account administrators of material changes.