Skip to content
FunkcijosKainosPartneriaiPagalbaApie musKontaktai
PradėtiPrisijungti
This page is available in:English— You are viewing the English version.

GDPR — General Data Protection Regulation

Last updatedMay 29, 2026

1. Controller and Representatives

Synaltix LLC (1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA — operating the Thmenu platform) acts as the Data Controller for personal data of platform users (restaurant owners, staff, affiliates). For end-customers of restaurants, the restaurant operator acts as the Data Controller and Synaltix LLC acts as the Data Processor under the written Data Processing Addendum published at /legal/dpa, which is incorporated into the Terms of Service by reference.

EU / UK Representative (GDPR Art. 27): Synaltix LLC has not appointed an EU or UK Article 27 representative. It relies on the Art. 27(2)(a) exemption for occasional processing — the same assessment set out in §11 of our Privacy Policy, which is the canonical statement of this position.
  EU/EEA and UK data subjects can exercise every right under Articles 15–22 directly, without a representative, at contact@synaltix.io.

Privacy contact: contact@synaltix.io. Synaltix LLC has not designated a formal Data Protection Officer under GDPR Art. 37; this address is the single point of contact for all privacy matters.

2. Legal Basis for Processing

Contract (Art. 6(1)(b)): account creation, billing, support, order/reservation processing.
Legal obligation (Art. 6(1)(c)): tax records, IRS 1099, AML.
Legitimate interests (Art. 6(1)(f)): platform security, fraud prevention, aggregate analytics — balancing test on file.
Consent (Art. 6(1)(a)): non-essential cookies + marketing emails + newsletter (double opt-in).

AI-assisted processing (Art. 13(2)(f) + Art. 22): Cloudflare Workers AI (Llama 3.1 8B for short text, Llama 3.3 70B for menu digitisation, plus a bge embedding model) generates product descriptions, surfaces menu recommendations, and produces business insights. Inference is stateless; we do NOT train third-party AI models on your data. AI-generated outputs are flagged in admin (ai_generated=1). You may request human review of any AI-assisted decision (see §3).

3. Data Subject Rights

EU/EEA residents have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), not to be subject to automated decision-making (Art. 22), withdraw consent (Art. 7(3)), lodge a complaint (Art. 77 — directory at edpb.europa.eu). Send requests to contact@synaltix.io; we reply within 30 days (Art. 12(3)), extendable by two months.

4. International Data Transfers (Chapter V)

Sub-processors located outside the EEA receive personal data under EU Standard Contractual Clauses 2021/914 (Module 2/3) plus supplementary measures per EDPB Recommendations 01/2020 (encryption in transit + at rest, network access controls, RBAC). EU–US Data Privacy Framework relied on where the provider is self-certified.

• Cloudflare Inc. — infrastructure, CDN, R2, D1, KV, Vectorize, Workers AI
• Supabase Inc. — authentication and primary Postgres database. Transfers of EEA/UK personal data are covered by the SCCs / UK IDTA referenced above; if you need the current hosting region in writing for your own records, ask at contact@synaltix.io.
• Stripe Inc. — payments (DPA + SCCs)
• Resend Inc. — transactional email
• PostHog Inc. — analytics (cookie-gated)
• Sentry — error monitoring (PII-scrubbed)
• Wise Payments Ltd. — affiliate payouts (opt-in)
• Google Ireland Ltd. — Google Tag Manager container (marketing site, consent-gated)

Updates: at least 30 days' notice; full list on the Compliance page.

5. Retention

CategoryRetentionBasis
Account profileLifetime + 30 daysArt. 6(1)(b)
Invoices & payments7y US IRS / 10y EU VAT / 10y TR TTK — longest applicableArt. 6(1)(c)
Order/transaction (end-customer)6m active + anonymised aggregatesLegitimate interest
Cookie consent13 monthsArt. 7(1)
Support / email3 yearsStatute of limitations
Push subscription token90d inactive or invalidatedStorage limitation
Staff audit log24 months, then deletedArt. 32
Affiliate KYC (pgcrypto)7y post closureIRS 1099 + AML
AI inference cache7 daysStorage limitation

6. Data Breach Notification

On detection of a personal data breach (Art. 4(12)) we will: notify the lead supervisory authority within 72 hours (Art. 33); notify affected data subjects without undue delay where the breach is likely to result in high risk (Art. 34); document every breach (Art. 33(5), which requires documentation but sets no fixed period — our own policy is to retain it for 5 years); coordinate with Cloudflare, Supabase, Stripe and other sub-processors.

7. DPO and Complaints

Privacy contact: contact@synaltix.io (no formal DPO or Art. 27 representative is appointed — see §1). You may complain to your member-state DPA (ICO, CNIL, BfDI, Garante, Datatilsynet etc.). Full directory: edpb.europa.eu/about-edpb/about-edpb/members_en.