This Privacy Policy explains how Kratisis (the "Provider", "we") processes personal data in connection with the Kratisis SaaS platform. It applies to (a) staff of venues that use Kratisis and (b) guest records entered by those venues.
1. Controller / processor
For staff accounts (name, email, role), the Provider acts as data controller. For guest records entered by a venue (name, phone, reservation history, notes), the venue is the data controller and the Provider is the processor. Processing by the Provider is governed by the Data Processing Agreement.
2. What we collect
- Account data โ email, name, hashed password (managed by our authentication provider), role, venue association.
- Venue data โ venue name, address, opening hours, branding/logo, tables and subscription tier.
- Guest records โ entered by venue staff (name, phone, tags, notes, reservation and visit history).
- Operational data โ audit log of tier changes, deleted-reservation archive, email delivery log (recipient, template, status).
- Usage data โ server logs, timestamps, IP address and browser/device metadata for security and reliability.
3. Purposes & legal bases
- Providing the Service โ performance of contract.
- Security, abuse prevention, backups, audit logging โ legitimate interests.
- Service emails โ authentication emails (sign-up confirmation, magic link, password recovery, email change, reauthentication, invitations), password-reset confirmations, weekly reports (when the venue has them enabled), on-demand report exports you request, and messages you send us through the in-app Contact form โ performance of contract / legitimate interests.
- Compliance with legal obligations.
4. Retention
Deleted reservations are recoverable for 7, 30 or 90 days depending on the venue's plan and are then permanently removed. Account data is kept while the account is active and for a reasonable period afterwards for security and legal claims.
5. Sub-processors
We rely on infrastructure providers to operate Kratisis (hosting, database, email delivery). A current list of sub-processors is available on request at info@kratisis.com.
6. International transfers
Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
7. Your rights
Under the GDPR you may access, rectify, erase, restrict or port your personal data, and object to certain processing. For staff accounts, contact us directly. For guest records, contact the venue that entered them (they are the controller).
8. Security
We rely on our infrastructure provider for TLS in transit, encryption at rest and managed backups. Access is controlled with row-level security in the database, role-based access inside the app (super-admin, admin, manager, staff), and least-privilege service credentials. Tier changes are recorded in an internal audit log.
9. Cookies & local storage
Kratisis uses only strictly-necessary cookies and browser local storage for authentication (session), and user preferences (theme, language, active venue). No advertising, analytics or cross-site tracking cookies. A service worker is used to keep the app up to date offline; it stores no personal data.
10. Contact
Data-protection requests: info@kratisis.com. You may also lodge a complaint with your local supervisory authority.