Privacy Policy
Updated:
Who we are
RUVO is a point-of-sale system for restaurants, made and sold by TT DAILY KITCHEN DOO, Tax ID (PIB) 113820680, Cara Uroša 19, 11000 Beograd, Serbia (“we”). Questions about privacy: hello@ruvo.ac.
Two roles
Restaurants that use RUVO (our clients) decide what data about their staff and guests goes into it. For that data the restaurant is the controller and we are its processor: we process it only to provide RUVO to that restaurant, under our contract with it.
For the data of people who contact us and of our clients’ account holders, we are the controller.
What RUVO processes
- A restaurant’s staff: name, role, the venues they work in, a personal PIN (stored only as a keyed cryptographic hash, never as the PIN itself), an email address for back-office access, shifts and pay rates if the restaurant uses the shifts module, and the actions they take (the action log: discounts, cancellations, refunds).
- Guests, only if the restaurant runs a loyalty program and the guest agrees: name, phone number, card number, points, discounts and purchase history.
- Orders and payments: items, prices, totals and the payment method. For card payments we receive only the amount and the bank terminal’s approval, never the card number.
- Devices: an identifier of each connected iPad, iPhone, kitchen screen or kiosk, and technical records (time of access, errors) needed to keep the service secure and working.
- Supplier invoices from SEF (the Serbian e-invoicing system): the data on the invoices of the restaurant’s suppliers, mostly company data. The SEF API key is stored only on our server, encrypted, and is never shown again.
- Messages you send us: your email address and what you write.
Why and on what basis
To provide RUVO under the contract with the restaurant; to meet legal obligations (accounting, tax); for our legitimate interest in keeping the service secure and preventing abuse; guests’ loyalty data on the basis of the consent the restaurant obtains.
Where the data is kept and how it is protected
On servers in the European Union (Germany). Connections are encrypted (TLS). Each restaurant’s data is separated from other clients’ data in the database itself. Access is limited to people who need it to run and support the service.
Who else processes data
- A hosting provider in the EU — stores the data and runs the service.
- An email provider — for our correspondence.
- Anthropic (USA) — the AI assistant in reports and in moving data from another POS. It receives the question and the figures needed for the answer; we do not send guests’ phone numbers or email addresses. Transfers outside Serbia and the EU are made with the safeguards the law requires.
- Apple — distributes the RUVO app (App Store, TestFlight) under its own privacy policy.
- Google Fonts — this website loads its fonts from that service; Google receives the visitor’s IP address.
We do not sell data, show ads or track users across other apps and websites.
How long
As long as the contract with the restaurant lasts. When it ends, we return or delete the restaurant’s data within 30 days, except what the law requires us to keep. Technical records are kept for up to 90 days.
Your rights
Under the Law on Personal Data Protection of the Republic of Serbia (“Official Gazette of RS”, No. 87/2018) and, where it applies, the EU General Data Protection Regulation (GDPR), you may ask for access to your data, correction, deletion, restriction of processing and portability, and you may object to processing. You can withdraw consent at any time.
Staff and guests of a restaurant should first contact that restaurant, as the controller; we help it answer. Write to us at hello@ruvo.ac. You may also complain to the Commissioner for Information of Public Importance and Personal Data Protection (www.poverenik.rs).
Children
RUVO is a business tool and is not meant for children.
Changes
We publish changes on this page with a new date.