Privacy Policy
Version 2.0 — 20 July 2026
Privacy Policy
Last updated: [PUBLICATION DATE] Version: 2.0
1. Data Controller
The controller of the personal data collected through the ALaCarte.Direct Service is:
DGK Group, SASU with share capital of €10,000 RCS Paris 901 219 352 Registered office: 25 rue de Ponthieu, 75008 Paris, France VAT: FR 57 901 219 352
Data Protection Officer (DPO): Damien GOSSARD Contact: [email protected]
2. Data Collected and Purposes
2.1 — Customer Data (restaurant operators)
| Data collected | Purpose | Legal basis |
|---|---|---|
| Identity (surname, first name, company name, SIRET) | Account creation and management, invoicing | Performance of contract |
| Contact details (email, phone, address) | Communication, support, invoicing | Performance of contract |
| Banking data (IBAN, card information via Stripe/GoCardless) | Collection of subscriptions and commissions | Performance of contract |
| Login data (credentials, access logs, IP address) | Service security, traceability | Legitimate interest |
| Usage data (activated features, usage statistics) | Service improvement, support | Legitimate interest |
| Invoicing data (invoice history, amounts) | Accounting and tax obligations | Legal obligation |
2.2 — End Customer Data (consumers)
End Customer data is collected when they interact with the Service features activated by the Customer (restaurant):
| Data collected | Feature concerned | Purpose | Legal basis |
|---|---|---|---|
| Name, email, phone | Gift cards, Click & Collect, Loyalty, Group Benefits | Order/service fulfilment | Performance of contract (with the restaurant) |
| Order history | Click & Collect, Table ordering | Order tracking, claims | Performance of contract |
| Loyalty points / stamps | Loyalty | Management of the loyalty programme | Performance of contract |
| Payment data (handled exclusively by Stripe) | Pay-at-table, Click & Collect, Gift cards | Payment processing | Performance of contract |
| Business email address | Group Benefits | Eligibility verification | Performance of contract |
ALCD processes this data as a processor within the meaning of the GDPR, on behalf of the Customer (restaurant) who remains the controller vis-à-vis its End Customers. ALCD provides the Customer with the tools necessary to comply with its obligations regarding personal data (access, rectification, deletion).
2.3 — Browsing Data
| Data collected | Purpose | Legal basis |
|---|---|---|
| Essential cookies (session, authentication, CSRF) | Service operation | Legitimate interest |
| Analytics cookies (Google Analytics 4) | Audience measurement, Service improvement | Consent |
| IP address, browser type, operating system | Security, technical compatibility | Legitimate interest |
3. Sub-processors
ALCD uses the following sub-processors for the processing of personal data:
| Sub-processor | Location | Role | Data processed | Transfer outside EU | Safeguards |
|---|---|---|---|---|---|
| OVH SAS | Roubaix, France | Server and data hosting | All data | No | — |
| Stripe Payments Europe Ltd | Dublin, Ireland | Payment processing (Stripe Connect) | Payment data, identity | Yes (USA) | EU-US Data Privacy Framework |
| GoCardless Ltd | London, United Kingdom | SEPA direct debits | IBAN, Customer identity | No | UK adequacy decision |
| Brevo (Sendinblue SAS) | Paris, France | Sending of transactional and marketing emails | Email, surname, first name | No | — |
| HubSpot Inc. | Cambridge, USA | CRM — sales relationship management | Identity, contact details, sales history | Yes (USA) | EU-US Data Privacy Framework |
| Google Ireland Ltd | Dublin, Ireland | Analytics (Google Analytics 4) | Anonymised browsing data, truncated IP address | Yes (USA) | EU-US Data Privacy Framework |
| Anthropic PBC | San Francisco, USA | Artificial intelligence — assistance and automation | Contextual processing data | Yes (USA) | Standard contractual clauses |
ALCD ensures that each sub-processor provides sufficient guarantees as to the implementation of appropriate technical and organisational measures, in accordance with Article 28 of the GDPR.
4. Data Transfers Outside the European Union
Some data may be transferred to the United States in connection with the services provided by Stripe, HubSpot, Google and Anthropic. These transfers are governed by:
- the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) for Stripe, Google and HubSpot, which are certified under this framework
- the standard contractual clauses adopted by the European Commission (decision of 4 June 2021) for Anthropic
ALCD regularly verifies the validity of these transfer mechanisms and will take the necessary measures in the event of invalidation.
5. Retention Periods
| Data category | Retention period | Justification |
|---|---|---|
| Active Customer (restaurant operator) account data | Term of contract | Performance of contract |
| Customer account data after termination | 3 years | Civil limitation period (Article 2224 of the French Civil Code) |
| Invoicing data | 10 years | Accounting obligation (Article L.123-22 of the French Commercial Code) |
| End Customer data (loyalty) | 24 months after last activity | Proportionality |
| End Customer data (orders) | 5 years after last order | Contractual limitation period |
| End Customer data (gift cards) | Card validity + 12 months | Claim management |
| Data regarding acceptance of legal documents | Unlimited | Proof of contractual acceptance |
| Connection logs | 12 months | Legal obligation (LCEN) |
| Session cookies | Session duration | Technical operation |
| Analytics cookies | 13 months maximum | CNIL recommendation |
| Commercial prospecting data (HubSpot) | 3 years after last contact | CNIL recommendation |
Upon expiry of these periods, data is deleted or anonymised irreversibly.
6. Rights of Data Subjects
In accordance with the GDPR (Articles 15 to 22), any person whose data is processed has the following rights:
- Right of access (Article 15): obtain confirmation that data is being processed and receive a copy
- Right to rectification (Article 16): correct inaccurate or incomplete data
- Right to erasure (Article 17): request deletion of data, subject to legal retention obligations
- Right to restriction of processing (Article 18): temporarily restrict processing
- Right to portability (Article 20): receive your data in a structured, commonly used and machine-readable format
- Right to object (Article 21): object to processing based on legitimate interest, in particular for commercial prospecting purposes
- Right to withdraw consent at any time, where processing is based on consent
How to Exercise Your Rights
To exercise any of these rights, send your request to:
- Email: [email protected]
- Post: DGK Group — DPO, 25 rue de Ponthieu, 75008 Paris, France
ALCD undertakes to respond within thirty (30) days of receipt of the request. This period may be extended by two months in the event of complexity or a high number of requests, in which case the requester is informed of this extension within the initial 30-day period.
Proof of identity may be requested in the event of reasonable doubt about the identity of the requester.
End Customers (consumers)
End Customers whose data is processed through the Service should first contact the relevant restaurant (controller). ALCD may process requests directly where the restaurant is no longer active or does not respond within a reasonable period.
Complaint to the CNIL
In the event of a persistent disagreement regarding the processing of your data, you have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL — the French Data Protection Authority):
- Online: https://www.cnil.fr/en/plaintes
- By post: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
7. Cookies and Trackers
7.1 — Essential Cookies (without consent)
These cookies are strictly necessary for the operation of the Service. They cannot be disabled:
| Cookie | Purpose | Duration |
|---|---|---|
| Laravel session | User session maintenance | Session duration |
| XSRF-TOKEN | Protection against CSRF attacks | Session duration |
| Cookie preference cookie | Remembering your cookie choice | 13 months |
7.2 — Analytics Cookies (with consent)
These cookies are only placed with your prior consent:
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| _ga, ga* | Google Analytics 4 | Anonymised audience measurement | 13 months |
Google Analytics 4 is configured with IP address anonymisation enabled. Data is hosted in the European Union by default. The consent parameter (Google Consent Mode v2) is used to collect data only after explicit consent.
7.3 — Managing Your Preferences
On your first visit, a banner offers you the option of accepting or refusing non-essential cookies. You can change your choice at any time by clicking the "Manage cookies" link in the footer of the site.
Refusing analytics cookies has no impact on the use of the Service.
8. Data Security
ALCD implements the following technical and organisational measures to protect personal data:
- Encryption in transit: all communications between the browser and our servers are encrypted via TLS/SSL (HTTPS)
- Encryption at rest: sensitive data (credentials, banking data) is encrypted in the database
- Access control: access to data restricted to authorised personnel, with strong authentication
- Backups: daily encrypted backups retained for 7 days
- Security updates: regular application of security patches across the infrastructure
- Security testing: code reviews and regular testing
9. Data Breach
In the event of a personal data breach within the meaning of Article 33 of the GDPR, ALCD undertakes to:
- Notify the CNIL within 72 hours of becoming aware of the breach, if the breach is likely to give rise to a risk to the rights and freedoms of data subjects
- Inform the data subjects as soon as possible if the breach is likely to give rise to a high risk to their rights and freedoms
- Document any breach in an internal register, in accordance with Article 33.5 of the GDPR
- Inform the Customer (restaurant) concerned so that they can fulfil their own notification obligations as controller
10. Changes to this Policy
ALCD may modify this Privacy Policy at any time. Substantial changes are communicated by email or by in-Service notification at least thirty (30) days before they take effect.
The date of the last update appears at the top of this document. The most recent version is always accessible at https://alacarte.direct/en/legals/confidentialite.
11. Contact
For any questions regarding the protection of your personal data:
- Email: [email protected]
- Post: DGK Group — DPO, 25 rue de Ponthieu, 75008 Paris, France
- Phone: +33 (0)7 82 82 00 27