Privacy Policy

    Last updated: August 17, 2026 Version: 1.1

    This Privacy Policy explains how personal data is processed when you use Food22 surfaces intended for restaurants and diners, including digital menus, reservations, orders, diner accounts, artificial intelligence assistants, calls, SMS and WhatsApp.

    This policy does not cover Food22 Discovery, which will have its own Privacy Policy.

    1. Who we are

    Food22 is a technology platform for restaurants.

    Where Food22 determines for itself why and how certain personal data is used, the controller is:

    Juan Carlos Valencia Hernandez, trading as Food22 Address: Rychtalska 22, 50-304, Wrocław, Poland Privacy contact: hello@food22.club

    We have not currently appointed a Data Protection Officer (DPO). We will review whether this is required from time to time, taking into account the scale and nature of the processing carried out.

    2. Who is responsible for what

    Food22 may act as a controller or as a processor, depending on the specific purpose.

    ActivityMain controllerFood22 role
    Viewing a menu and using Food22's own featuresFood22Controller
    Booking a tableRestaurantProcessor
    Managing reservations and the restaurant CRMRestaurantProcessor
    Placing an order with the restaurantRestaurantProcessor
    Customer history within that restaurant's CRMRestaurantProcessor
    Creating and maintaining a Food22 diner accountFood22Controller
    Personalizing the Food22 experience within the restaurantFood22Controller
    Saving dietary preferences in the Food22 accountFood22Controller
    Advertising activated by the restaurantRestaurantProcessor or technology provider, depending on the integration
    Security, abuse prevention and technical administration of Food22Food22Controller

    2.1 Reservations, orders and CRM

    The restaurant is responsible for the data used to manage its reservations, orders and relationship with its own customers.

    Food22 provides the technical infrastructure and processes that data following the restaurant's instructions.

    A restaurant does not automatically gain access to a diner's activity at other restaurants.

    2.2 Food22 account

    When you create a diner account, Food22 acts as controller because it provides and administers that account so that you can view and manage your information, history and preferences within Food22.

    3. Data we process

    3.1 When you visit a menu

    We may process:

    • IP address;
    • basic browser and device information;
    • language and visual preferences;
    • technical session identifiers;
    • security and abuse-prevention data.

    With your consent, we may also process analytics data such as pages viewed, dishes viewed, searches, usage time and other navigation events.

    Information about cookies, localStorage, analytics identifiers and similar technologies is explained in our Cookie Policy.

    3.2 When you make a reservation

    The restaurant may request:

    • name;
    • phone number;
    • email address;
    • date and time;
    • number of guests;
    • comments or special requests.

    Controller: the restaurant. Food22 role: processor.

    The purpose is to create, manage, confirm, modify or cancel the reservation and enable the restaurant to handle it.

    3.3 When you place an order

    We may process, on behalf of the restaurant:

    • name;
    • phone number;
    • email address;
    • products ordered;
    • amount;
    • delivery address or location data where necessary;
    • order instructions;
    • order status.

    The restaurant is the seller and the main controller of the order data.

    Food22 does not store your full card number. Payment data is processed by Stripe.

    3.4 Food22 diner account

    If you create an account, Food22 may process:

    • name;
    • email address;
    • phone number;
    • account identifiers;
    • visible order and reservation history;
    • profile preferences;
    • personalization settings.

    Legal basis: performance of the requested service and, where applicable, consent.

    The account exists so that you can manage your experience within Food22. It does not automatically allow a restaurant to view your activity at other restaurants.

    3.5 Allergies and dietary preferences

    Allergies, intolerances and certain dietary information may constitute health data.

    Food22 processes this data for personalization only where we obtain your explicit consent.

    The flow may include:

    • local detection in your browser;
    • intelligent analysis of the text you authorize;
    • checking compatibility with dishes;
    • storing preferences on your device;
    • storing them in your Food22 account if you choose to save them.

    When you authorize intelligent analysis, the text you enter may be sent to an artificial intelligence service provider to extract allergies, foods you wish to avoid and dietary preferences.

    Food22 does not retain the original text in the technical logs of the extraction endpoint after the request is completed, unless you expressly choose to save it as part of your profile.

    Food22 does not store lists of allergies or health preferences within analytics events.

    You may withdraw this consent and delete saved preferences.

    Dish labeling is an informational aid and does not replace direct confirmation with the restaurant. If you have a severe allergy, always confirm ingredients and possible cross-contamination with staff.

    4. Artificial intelligence assistants

    Food22 uses artificial intelligence systems to provide chat, voice, preference interpretation and other functions.

    Depending on the function, we may process:

    • written text;
    • transcripts;
    • audio;
    • language;
    • menu context;
    • information needed to answer a query or manage a reservation/order.

    Food22 uses specialized artificial intelligence service providers for certain analysis, response-generation and voice-processing functions.

    When we use these providers, data is sent only to the extent necessary to provide the relevant function and is subject to applicable contractual and data-protection obligations.

    5. Voice in the browser

    When you use the voice assistant in the browser:

    • we ask for your consent before activating the microphone;
    • audio may be transmitted directly to a voice-processing and artificial intelligence provider for real-time processing;
    • you can use other Food22 functions without activating voice.

    If we enable recording for quality control or improvement, we will request separate explicit consent before recording begins.

    6. Phone calls, SMS and WhatsApp

    Restaurants may use Food22 to manage communications through specialized telephony and messaging providers.

    6.1 Phone calls

    Food22 may use communication services to:

    • receive calls directed to the restaurant;
    • handle them through a voice assistant;
    • transfer calls to staff;
    • place calls to restaurants when a user requests assistance with a reservation.

    During a call, the following may be processed:

    • phone number;
    • call identifier;
    • audio;
    • duration;
    • reservation data;
    • transcript;
    • requests or comments provided during the conversation.

    Audio from certain calls may be processed by communication providers and, where the assistant function is active, by artificial intelligence and voice-processing providers for recognition and response generation.

    6.2 Call recording

    A call will only be recorded after informing the caller and obtaining any authorization required by applicable law.

    Where recording is enabled:

    • the communications provider may store the audio where recording is enabled;
    • Food22 may retain the transcript needed to provide the service;
    • the retention periods set out in this policy or the instructions of the restaurant controller will apply.

    If you do not authorize recording where it is optional, we will use the available non-recording flow or offer another contact channel.

    6.3 SMS

    Messaging providers may be used to send or receive reservation-related messages, for example:

    • confirmations;
    • reminders;
    • modifications;
    • cancellations;
    • requests for information.

    The messaging provider processes the phone number and the message content needed to provide the service.

    6.4 WhatsApp

    Food22 may integrate WhatsApp Business through messaging providers where a restaurant activates this channel.

    The following may be processed:

    • phone number;
    • WhatsApp profile name;
    • message content;
    • assistant responses;
    • reservation or order data included in the conversation.

    The messaging provider and the provider of the messaging platform itself may be involved in providing WhatsApp.

    The conversation content needed for the service may be sent to an artificial intelligence provider to generate assistant responses.

    7. Emails

    Food22 uses transactional email providers to send confirmations, reservation notices, order notices and other service communications.

    These providers may process:

    • name;
    • email address;
    • phone number where included in the content;
    • reservation or order information;
    • technical delivery metadata.

    Certain metadata or service-related data may be processed outside the European Economic Area in accordance with applicable international-transfer mechanisms.

    8. Payments and subscriptions

    8.1 Order payments

    When a diner pays for an order:

    • the restaurant is the seller;
    • Food22 provides the integration;
    • Stripe processes the payment.

    Food22 does not store your full card details.

    8.2 Restaurant subscription to Food22

    Food22 also uses Stripe to allow restaurants to subscribe to, upgrade, downgrade or manage their Food22 subscription.

    In that case, Food22 acts as controller of the data needed to:

    • manage the contractual relationship;
    • process the subscription;
    • administer payments;
    • comply with accounting and tax obligations.

    Full card details are processed directly by Stripe.

    9. Categories of providers and recipients

    Food22 uses specialized providers to deliver, protect and operate the service. Depending on the function used, these may include:

    • cloud infrastructure, hosting, database, authentication and storage providers;
    • network security, content-delivery and traffic-protection providers;
    • artificial intelligence and text- or voice-processing providers;
    • communications, telephony and messaging providers;
    • transactional email providers;
    • payment and billing providers;
    • mapping, location and technical-integration providers;
    • providers of remote resources or content used on certain surfaces.

    These providers may process personal data only to the extent necessary to provide their services and are subject to applicable contractual and data-protection obligations.

    Where a function involves a direct relationship with a clearly identified third party — for example, a payment provider during the payment process — we may identify that provider expressly in the relevant section or interface.

    Providers may use their own subprocessors in accordance with their agreements and data-protection obligations.

    10. International transfers

    Some providers or their subprocessors may process data outside the European Economic Area or the country where you are located.

    Where the GDPR applies, international transfers are carried out using mechanisms recognized under Chapter V of the GDPR, including:

    • adequacy decisions of the European Commission;
    • the EU-U.S. Data Privacy Framework, where applicable;
    • the Standard Contractual Clauses of the European Commission;
    • or other legally valid mechanisms.

    The specific mechanism depends on the recipient or category of recipients, the country and the service used.

    11. Retention

    We apply the principle of retaining data only for as long as necessary.

    CategoryRetention criterion
    Food22 analyticsMaximum 14 months
    Food22 accountWhile active; inactive accounts may be deleted after 24 months, with prior notice
    Dietary preferencesUntil you delete them or withdraw consent
    Text sent to the preference-extraction endpointNot retained by Food22 after the request is completed unless you choose to save it in your profile
    Reservation, order and CRM dataAccording to the instructions and obligations of the restaurant controller
    Call recordingsMaximum 90 days where Food22 manages retention, unless a legal obligation or valid instruction requires a different period
    Transcripts and communications managed for the restaurantAccording to the purpose, restaurant instructions and retention periods implemented in the service
    Restaurant subscription and billing dataDuring the contractual relationship and afterwards for the period required by applicable tax and accounting law
    Technical and security logsFor the period reasonably necessary for security, diagnostics and abuse prevention, with minimization of personal data

    Data that must be retained to comply with a legal obligation, resolve claims or establish, exercise or defend legal rights may be kept blocked or access-restricted for the applicable period.

    12. Your rights

    Where Food22 acts as controller, you may exercise the rights available to you under applicable law.

    In the European Economic Area these include:

    • access;
    • rectification;
    • erasure;
    • objection;
    • restriction;
    • portability;
    • withdrawal of consent;
    • the right not to be subject to certain decisions based solely on automated processing where they produce legal or similarly significant effects.

    In Mexico, you may exercise your Access, Rectification, Cancellation and Objection (ARCO) rights, as well as withdraw consent where applicable.

    To exercise your rights, contact:

    hello@food22.club

    We may request reasonable information to verify your identity.

    Where the request concerns data for which a restaurant is the controller, Food22 will cooperate with the restaurant and handle the request in accordance with the controller's instructions.

    Authorities

    • Poland: Prezes Urzędu Ochrony Danych Osobowych (UODO).
    • Mexico: the competent federal authority for the protection of personal data held by private parties is the Secretaría Anticorrupción y Buen Gobierno, under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares.

    13. Account deletion and withdrawal of consent

    Food22 allows you to request deletion of your account and associated personal data for which it acts as controller.

    When you request deletion:

    • we will delete or anonymize data that is no longer necessary;
    • we will remove preferences based on consent;
    • we will delete health data stored by Food22 where applicable;
    • we will delete locally stored data through available controls;
    • we will propagate the request to providers where necessary and appropriate.

    We may temporarily retain data where there is a legal obligation, a pending claim or a need to establish, exercise or defend legal rights.

    Where Food22 acts as processor for a restaurant, deletion will be handled in accordance with the instructions of the restaurant controller.

    14. Portability and export

    Where applicable law recognizes the right to data portability, Food22 will provide a mechanism to obtain personal data provided to Food22 in a structured, commonly used and machine-readable format where technically appropriate.

    15. Automated decisions and recommendations

    Food22 may use automated systems to:

    • suggest dishes;
    • check compatibility with dietary preferences;
    • help assign tables;
    • generate assistant responses;
    • personalize certain functions.

    These functions are not designed to produce decisions with legal or similarly significant effects on the user.

    You can disable optional personalization functions where they rely on consent.

    16. Minors

    Food22 is not directed at children under 16 years of age.

    Children under 16 must not create an account or provide consent-based personal data without authorization from a parent or legal guardian.

    This does not prevent an adult from including children in the number of guests for a reservation or order where no personal data about the child is collected.

    If we become aware that we have received data from a child without the required authorization, we will take reasonable steps to delete it.

    17. Security

    We apply technical and organizational measures intended to protect personal data, including, depending on the service:

    • encryption in transit;
    • access controls;
    • isolation between restaurants;
    • authentication;
    • database-level permissions;
    • infrastructure protection;
    • technical logs and security controls;
    • minimization of personal data in logs;
    • deletion procedures and request-response processes.

    No system is completely infallible. Where a security breach must be notified under applicable law, we will make the required communications.

    18. Changes to this policy

    We may update this Privacy Policy when our services, purposes, categories of recipients, processing activities or legal requirements change.

    If a change materially affects processing based on consent, we will request consent again where necessary.

    The current date and version appear at the beginning of this document.