Sirvely
EN

Privacy policy

Sirvely is a QR ordering system for restaurants, bars and cafés. On this page we explain, in language you can understand, which data we process, why we process them, who else sees them and what you can ask of us at any time.

Last updated: 10 September 2026

1. Data controller

Sirvely is a trading name of a Dutch company. That company is the controller of the data described in this policy and decides, within the limits explained here, what they are used for.

Trading nameSirvely
Chamber of Commerce (KvK)86964178
VAT numberNL004333820B72
Registered addressZandzuigerstraat 70, 1333 HD Almere, the Netherlands
Emailinfo@sirvely.com
Telephone+31 85 060 4404
Information sitehttps://www.sirvely.com
The servicehttps://app.sirvely.com

To exercise any of the rights explained below, or simply to ask us something about this policy, email info@sirvely.com or call us on +31 85 060 4404. We have not appointed a data protection officer, so everything to do with your data goes through that email address. The company's identification details are also in the legal notice.

2. Who this policy is for

Around Sirvely there are three groups of people, and they are not all in the same position, so it helps to tell them apart from the start.

You, as the owners of the restaurant, are our customer. About your business and the person who signs the set-up we process the data needed to provide the service to you and to charge for it. For that part we are the data controller.

Your staff use the application to work. You enter their details yourselves, and they are processed so that each person can sign in with their PIN, see what concerns them and clock in and out.

The customers who sit at your tables scan the QR code and order from their own phone, without installing any app and without registering. We do not ask them for a name, a phone number or anything else in order to place an order. Only if they book a table from the menu do they give us their name, email and phone number; we explain that in section 5.

For the data of your staff and of the customers at your tables, you are the data controller: it is your business that decides which menu is published, which employees exist and what is done with the orders. We act as a data processor on your behalf, we process those data solely to provide the service to you and following your instructions, and we do not use them for any purpose of our own. It is you who must inform your team and your customers that you work with a digital ordering system. The obligations we take on as a processor, which article 28 of the General Data Protection Regulation requires, are set out in section 11 of the terms and conditions, which form part of the contract between your restaurant and us.

3. Data about the restaurant and its owner

About the business we keep the trading name, the address, the phone number and the email address. About the owner we keep their name and their email address, which is also the one used to sign in to the panel. Your VAT number is not in the application: we use it only on the invoice and in our accounts.

The monthly fee is paid with a credit card that you link yourselves from the panel. That link is processed through Pay.nl and leaves a recurring payment authorisation on the card. We do not send Pay.nl your name or your email address: we only pass on the amount, our own internal references and the address of the service. You can check the payments made and the state of the subscription at any time in the panel, at https://app.sirvely.com. If you cancel the subscription, the authorisation on the card is removed and there are no further charges.

To invoice you we need your VAT number. If you are established in Spain and the number is valid, the transaction goes without Dutch VAT and the tax is settled in Spain under the reverse charge; if you are established in the Netherlands, the invoice carries Dutch VAT. That detail is processed for invoicing and for accounting, and for nothing else. The financial terms are in the terms and conditions.

4. Staff data

For each person on your team we keep their name, their role, the permissions you have given them, the venue they work at, the times they sign in to the application and the clock-in and clock-out times they record. Those data exist because without them the work on the floor cannot be shared out and nobody would know who served which table.

About the PIN we want to be clear, because it affects your team. The PIN with which each person signs in on the tablet is stored encrypted and not as an irreversible hash, and this is deliberate: the manager must be able to show the PIN again to someone who has forgotten it, and that would not be possible with a hash. It means that the PIN can be read again inside the system by anyone with permission to do so. That is why we ask that nobody on your team uses as a PIN a number they also use for their bank, their phone or anything else in their private life.

5. Data about the restaurant's customers

A customer can order without giving us any details: there is no registration, no account and no form with their name. Even so, three things arise from normal use of the menu that you should know about.

The first is a device identifier. When someone opens the menu, their browser stores a random code that says nothing about the person and that lets you see how many phones are ordering at the same table and who ordered what within that table. That code is not linked to any name, any phone number or any account.

The second is the note the customer can write next to an item. It is a free-text field, meant for things like 'no onion' or 'rare', and whatever is written there reaches the kitchen and is stored with the order. There is no need to write health data or any personal data in that note, and we recommend that your staff do not ask for them there either: if a customer writes down an allergy, that text is stored like the rest of the order and is seen by anyone with access to the order ticket.

The third is the email address, and it only appears if the customer themselves asks us to send them the receipt. That address is used solely to send that particular receipt, is not stored in the database, is never used to write to them again and is not shared with you or with anyone. For each visit we only record how many receipts have been sent, with a maximum of three, so that nobody can use that function to send email to third parties.

There is a fourth situation, and it is the only one in which a customer gives us their name: the booking. Anyone looking at your menu through the shareable link, without sitting at a table, can book a table from there. To do so they enter their name, email address and phone number, the day, the time, how many people they are and how long they plan to stay, and a remark if they wish. Those details are stored with the booking so that you can see it in the panel and confirm or cancel it, and the customer receives the confirmation by email, in the language of their phone. They are your restaurant's data and we process them on your behalf, like the rest.

If you link your own Mollie or SumUp account so that the customer can pay online from the menu, the payment takes place on that provider's page and the money goes directly to your account with them. We do not see the customer's card details and we do not receive the money; we only know whether the payment went through. In that relationship Mollie or SumUp is your provider, not ours, and it is their terms and their privacy policy that apply to the customer.

6. Technical data

Every time someone signs in, the IP address they signed in from and the details of the browser they use are stored alongside that session. They serve to spot an unusual sign-in and to be able to close a particular session, and they disappear when the session expires or is closed. The IP address is also held for a few moments in the server's memory to limit the number of requests and slow down attempts at abuse, and it is very likely to end up in the server's technical logs, as with any internet service.

In the admin panel a log of important actions is kept, such as creating a user or resetting a password, and that log records the email address of the person concerned. It is what lets us reconstruct afterwards who did what.

This information website, https://www.sirvely.com, sets no cookies of its own or of third parties, does not measure visits, carries no advertising pixel and loads no fonts, videos or maps from outside. In your browser it stores only that you have read the information notice in the footer, the language you chose and, if you came through a partner's link, their code; that code is the only thing that reaches our API from this website, once, to count the visit. The sessions that do exist are those of the application, and they are strictly necessary to keep you signed in. This is explained in detail on the cookies page.

7. Purposes and legal basis

We do not process any data 'just in case'. Each purpose has its legal basis, and this is the full list.

PurposeLegal basis
Giving you access to the panel, publishing your menu, receiving the orders from the tables and letting you know that a table is asking for the billThe performance of the contract we have with your restaurant
Building and maintaining the menu, including reading a photo of your paper menu and writing the descriptions and the photos of the itemsThe performance of the contract we have with your restaurant
Charging the monthly fee to the card you have linkedThe performance of the contract we have with your restaurant
Issuing invoices and keeping the accountsA legal obligation that rests on us
Keeping you signed in, limiting the number of requests and slowing down attempts at abuseOur legitimate interest in keeping the service running and preventing it from being misused
Recording in the admin panel who does whatOur legitimate interest in being able to reconstruct a change and respond to an incident
Sending the receipt to the address the customer enters themselvesThe consent of that customer, who gives us their email address precisely to receive the receipt and is free not to
Processing the data of your staff and their clock-insOn your behalf and following your instructions, since it is you who determine the purpose and the legal basis for those data
Storing a customer's booking and sending them the confirmation by emailOn your behalf and following your instructions: the booking is with your restaurant

8. Who else processes these data

To provide the service we rely on a small number of suppliers. All of them act as processors, that is, they process the data on our behalf, only for what is stated here and without being able to use them for anything of their own. We do not sell data, we do not pass them to third parties for advertising purposes and there is no other company watching what happens at your tables.

SupplierWhat for
ResendSending all the service's email, including the receipt a customer asks for at the table and the confirmation of a booking
AnthropicReading the photo of your paper menu and writing the descriptions of the items
HiggsfieldGenerating photos of items for the menu
Pay.nlCharging the subscription to a credit card
Our own server, managed with CoolifyThe service's database and files, with a disk reserved for the menu photos

Resend, Anthropic and Higgsfield are companies in the United States, so part of this processing involves a transfer of data outside the European Economic Area. Those transfers rely on the standard contractual clauses adopted by the European Commission and, where the provider is certified under the EU-US Data Privacy Framework, on that adequacy decision. Pay.nl is a Dutch company. If you need to know in detail where a particular piece of data is processed, ask us in writing at info@sirvely.com and we will tell you.

9. How long they are kept

We would rather tell you how things are than promise a period that is not met today. Orders, table visits, bookings, the order log and staff clock-ins are not deleted automatically: they are kept for as long as you are a Sirvely customer, because they form the history of your business and it is you who consult them. When the relationship ends, those data are deleted at your request, and for that it is enough to email us at info@sirvely.com.

Clock-in and clock-out records are kept deliberately, even when a person no longer works for you, because they are your restaurant's record of hours and they belong to you. We only delete them if you ask us to.

Sessions expire on their own, and with them the IP address and the browser details attached to them disappear. The email address to which a receipt is sent is never stored: all that remains of the visit is the number of receipts sent. Invoicing data are kept for seven years, the period that Dutch tax law, article 52 of the Algemene wet inzake rijksbelastingen, imposes on the company, even after you have stopped being a customer.

10. Your rights

Anyone whose data we process can ask us to access them, to correct them if they are wrong, to delete them, to restrict their processing, to object to processing based on our legitimate interest and to receive their data in a format that can be taken to another system. Where processing is based on consent, that consent can be withdrawn at any time, without affecting what was done before.

To exercise them, email info@sirvely.com stating what you want and which restaurant you are writing from. If the request comes from an employee or from a customer at the table, the controller of those data is the restaurant, so the request is addressed to it; we, as processor, give the restaurant the technical support it needs to deal with it and pass on any request that reaches us by mistake.

If you believe we have not handled your request properly, you can lodge a complaint with the supervisory authority. In Spain that is the Agencia Española de Protección de Datos, at www.aepd.es. In the Netherlands, where the company is established, it is the Autoriteit Persoonsgegevens, at www.autoriteitpersoonsgegevens.nl. We would appreciate it if you wrote to us first: it is almost always resolved without going that far.

11. Security

All traffic between phones, tablets and our servers travels over an encrypted connection, and the session cookies only travel over that connection, cannot be read from the page's code and contain no data: they are a random code from which nothing can be deduced. Sessions have a limited validity, twelve hours in the admin panel and on the staff tablet and seven days in the restaurant panel, after which you have to sign in again.

Within the restaurant, each person has the permissions you have given them and sees only what corresponds to their role and their venue. To build your menu or to help you with an incident, our team can enter your account from the admin panel. That session lasts four hours at most and is logged, so it is always possible to check who signed in and when.

12. Changes to this policy

The service changes, and this policy will change with it. The version that applies is always the one published at https://www.sirvely.com/privacy/, and the date of the last update appears at the very top, just below the title, so that you can see at a glance whether anything has moved since you last read it. If a change genuinely affects how we process your data, you will see it reflected in that date and in the text of the relevant section. If in doubt, email us at info@sirvely.com.