GDPR policy

Personal data and privacy policy

This policy describes how QwikEat OÜ collects, processes, stores and protects personal data as part of the operation of the QwikEat platform, in full compliance with Regulation (EU) 2016/679 (GDPR).

1.

Data controller

The controller is QwikEat OÜ, an Estonian company that defines the purposes and means of the personal data processing.

2.

Scope

This policy applies to all platform users, including end customers, partner merchants and professional users.

3.

Categories of data

The data processed may include identity details, contact information, order and billing data, transaction histories, technical data, log-in information and any details required to prevent fraud.

4.

Data origin

Data is collected directly from the data subjects when they create an account or use QwikEat services.

5.

Purposes of processing

Information is used to manage orders, customer relations, support, secure payments, prevent fraud, meet legal obligations and continually improve the platform.

6.

Legal bases

Processing is based on performance of the contract, legal obligations and QwikEat’s legitimate interest in ensuring service security and continuity.

7.

Data recipients

Personal data may be shared with the relevant partner merchants, technical providers, payment providers and competent authorities.

8.

Processors

QwikEat uses processors that provide sufficient guarantees regarding data protection. Each relationship is governed by an agreement compliant with article 28 of the GDPR.

9.

Retention period

Data is retained for a period that is proportionate to the purposes pursued, then archived or deleted according to the applicable legal obligations.

10.

Data security

QwikEat implements appropriate technical and organisational measures to guarantee confidentiality, integrity, availability and resilience of its systems.

11.

Data subject rights

Users benefit from rights of access, rectification, erasure, restriction, objection and portability regarding their data.

12.

How to exercise your rights

Any request can be sent to QwikEat using the contact details displayed on the platform. A response will be provided within the legal timeframes.

13.

Transfers outside the EU

Data is hosted within the European Union. Any potential transfer outside the EU is covered by appropriate safeguards compliant with the GDPR.

14.

Data breach

In the event of a personal data breach, QwikEat will notify the competent authority and, where necessary, the affected individuals, under the conditions set out by the GDPR.

15.

Supervisory authority

Data subjects may lodge a complaint with the competent authority in charge of personal data protection.

16.

Policy updates

QwikEat reserves the right to amend this policy to remain compliant with legal, regulatory or technical developments.

For any question related to this policy or to data protection, contact QwikEat through the information available on the platform.
Internal QwikEat document – GDPR compliant version.
QwikEat | Online ordering, click & collect, and delivery for restaurants