GDPR policy
This policy describes how QwikEat OÜ collects, processes, stores and protects personal data as part of the operation of the QwikEat platform, in full compliance with Regulation (EU) 2016/679 (GDPR).
The controller is QwikEat OÜ, an Estonian company that defines the purposes and means of the personal data processing.
This policy applies to all platform users, including end customers, partner merchants and professional users.
The data processed may include identity details, contact information, order and billing data, transaction histories, technical data, log-in information and any details required to prevent fraud.
Data is collected directly from the data subjects when they create an account or use QwikEat services.
Information is used to manage orders, customer relations, support, secure payments, prevent fraud, meet legal obligations and continually improve the platform.
Processing is based on performance of the contract, legal obligations and QwikEat’s legitimate interest in ensuring service security and continuity.
Personal data may be shared with the relevant partner merchants, technical providers, payment providers and competent authorities.
QwikEat uses processors that provide sufficient guarantees regarding data protection. Each relationship is governed by an agreement compliant with article 28 of the GDPR.
Data is retained for a period that is proportionate to the purposes pursued, then archived or deleted according to the applicable legal obligations.
QwikEat implements appropriate technical and organisational measures to guarantee confidentiality, integrity, availability and resilience of its systems.
Users benefit from rights of access, rectification, erasure, restriction, objection and portability regarding their data.
Any request can be sent to QwikEat using the contact details displayed on the platform. A response will be provided within the legal timeframes.
Data is hosted within the European Union. Any potential transfer outside the EU is covered by appropriate safeguards compliant with the GDPR.
In the event of a personal data breach, QwikEat will notify the competent authority and, where necessary, the affected individuals, under the conditions set out by the GDPR.
Data subjects may lodge a complaint with the competent authority in charge of personal data protection.
QwikEat reserves the right to amend this policy to remain compliant with legal, regulatory or technical developments.