GDPR — General Data Protection Regulation
Last updatedMay 29, 2026
1. Controller and Representatives
Synaltix LLC (1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA — operating the Thmenu platform) acts as the Data Controller for personal data of platform users (restaurant owners, staff, affiliates). For end-customers of restaurants, the restaurant operator acts as the Data Controller and Synaltix LLC acts as the Data Processor under the written Data Processing Addendum published at /legal/dpa, which is incorporated into the Terms of Service by reference.
EU / UK Representative (GDPR Art. 27): Synaltix LLC has not appointed an EU or UK Article 27 representative. It relies on the Art. 27(2)(a) exemption for occasional processing — the same assessment set out in §11 of our Privacy Policy, which is the canonical statement of this position.
EU/EEA and UK data subjects can exercise every right under Articles 15–22 directly, without a representative, at contact@synaltix.io.
Privacy contact: contact@synaltix.io. Synaltix LLC has not designated a formal Data Protection Officer under GDPR Art. 37; this address is the single point of contact for all privacy matters.
EU / UK Representative (GDPR Art. 27): Synaltix LLC has not appointed an EU or UK Article 27 representative. It relies on the Art. 27(2)(a) exemption for occasional processing — the same assessment set out in §11 of our Privacy Policy, which is the canonical statement of this position.
EU/EEA and UK data subjects can exercise every right under Articles 15–22 directly, without a representative, at contact@synaltix.io.
Privacy contact: contact@synaltix.io. Synaltix LLC has not designated a formal Data Protection Officer under GDPR Art. 37; this address is the single point of contact for all privacy matters.
2. Legal Basis for Processing
• Contract (Art. 6(1)(b)): account creation, billing, support, order/reservation processing.
• Legal obligation (Art. 6(1)(c)): tax records, IRS 1099, AML.
• Legitimate interests (Art. 6(1)(f)): platform security, fraud prevention, aggregate analytics — balancing test on file.
• Consent (Art. 6(1)(a)): non-essential cookies + marketing emails + newsletter (double opt-in).
AI-assisted processing (Art. 13(2)(f) + Art. 22): Cloudflare Workers AI (Llama 3.1 8B for short text, Llama 3.3 70B for menu digitisation, plus a bge embedding model) generates product descriptions, surfaces menu recommendations, and produces business insights. Inference is stateless; we do NOT train third-party AI models on your data. AI-generated outputs are flagged in admin (
• Legal obligation (Art. 6(1)(c)): tax records, IRS 1099, AML.
• Legitimate interests (Art. 6(1)(f)): platform security, fraud prevention, aggregate analytics — balancing test on file.
• Consent (Art. 6(1)(a)): non-essential cookies + marketing emails + newsletter (double opt-in).
AI-assisted processing (Art. 13(2)(f) + Art. 22): Cloudflare Workers AI (Llama 3.1 8B for short text, Llama 3.3 70B for menu digitisation, plus a bge embedding model) generates product descriptions, surfaces menu recommendations, and produces business insights. Inference is stateless; we do NOT train third-party AI models on your data. AI-generated outputs are flagged in admin (
ai_generated=1). You may request human review of any AI-assisted decision (see §3).3. Data Subject Rights
EU/EEA residents have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), not to be subject to automated decision-making (Art. 22), withdraw consent (Art. 7(3)), lodge a complaint (Art. 77 — directory at edpb.europa.eu). Send requests to contact@synaltix.io; we reply within 30 days (Art. 12(3)), extendable by two months.
4. International Data Transfers (Chapter V)
Sub-processors located outside the EEA receive personal data under EU Standard Contractual Clauses 2021/914 (Module 2/3) plus supplementary measures per EDPB Recommendations 01/2020 (encryption in transit + at rest, network access controls, RBAC). EU–US Data Privacy Framework relied on where the provider is self-certified.
• Cloudflare Inc. — infrastructure, CDN, R2, D1, KV, Vectorize, Workers AI
• Supabase Inc. — authentication and primary Postgres database. Transfers of EEA/UK personal data are covered by the SCCs / UK IDTA referenced above; if you need the current hosting region in writing for your own records, ask at contact@synaltix.io.
• Stripe Inc. — payments (DPA + SCCs)
• Resend Inc. — transactional email
• PostHog Inc. — analytics (cookie-gated)
• Sentry — error monitoring (PII-scrubbed)
• Wise Payments Ltd. — affiliate payouts (opt-in)
• Google Ireland Ltd. — Google Tag Manager container (marketing site, consent-gated)
Updates: at least 30 days' notice; full list on the Compliance page.
• Cloudflare Inc. — infrastructure, CDN, R2, D1, KV, Vectorize, Workers AI
• Supabase Inc. — authentication and primary Postgres database. Transfers of EEA/UK personal data are covered by the SCCs / UK IDTA referenced above; if you need the current hosting region in writing for your own records, ask at contact@synaltix.io.
• Stripe Inc. — payments (DPA + SCCs)
• Resend Inc. — transactional email
• PostHog Inc. — analytics (cookie-gated)
• Sentry — error monitoring (PII-scrubbed)
• Wise Payments Ltd. — affiliate payouts (opt-in)
• Google Ireland Ltd. — Google Tag Manager container (marketing site, consent-gated)
Updates: at least 30 days' notice; full list on the Compliance page.
5. Retention
| Category | Retention | Basis |
|---|---|---|
| Account profile | Lifetime + 30 days | Art. 6(1)(b) |
| Invoices & payments | 7y US IRS / 10y EU VAT / 10y TR TTK — longest applicable | Art. 6(1)(c) |
| Order/transaction (end-customer) | 6m active + anonymised aggregates | Legitimate interest |
| Cookie consent | 13 months | Art. 7(1) |
| Support / email | 3 years | Statute of limitations |
| Push subscription token | 90d inactive or invalidated | Storage limitation |
| Staff audit log | 24 months, then deleted | Art. 32 |
| Affiliate KYC (pgcrypto) | 7y post closure | IRS 1099 + AML |
| AI inference cache | 7 days | Storage limitation |
6. Data Breach Notification
On detection of a personal data breach (Art. 4(12)) we will: notify the lead supervisory authority within 72 hours (Art. 33); notify affected data subjects without undue delay where the breach is likely to result in high risk (Art. 34); document every breach (Art. 33(5), which requires documentation but sets no fixed period — our own policy is to retain it for 5 years); coordinate with Cloudflare, Supabase, Stripe and other sub-processors.
7. DPO and Complaints
Privacy contact: contact@synaltix.io (no formal DPO or Art. 27 representative is appointed — see §1). You may complain to your member-state DPA (ICO, CNIL, BfDI, Garante, Datatilsynet etc.). Full directory: edpb.europa.eu/about-edpb/about-edpb/members_en.