Skip to content

Privacy Policy – Plattio

1. Who we are and our roles

Plattio LLC is a company registered in the State of Delaware, United States, with its registered office at 8 The Green STE B, Dover, DE 19901. We operate worldwide, providing software as a service (SaaS) for managing reservations and operations in restaurants.

When we process personal data on behalf of our customers (restaurants, cafés, bars, or other businesses), we act as the Processor, and our customers act as the Controller. For data that we process directly (e.g., customer billing, our own analytics), Plattio acts as the Controller.

2. Information we collect

  • Identification data: first name, last name.
  • Contact data: phone number, email address.
  • Reservation data: date, time, number of guests, assigned table, source channel.
  • Platform usage data: language, settings, interactions.
  • Technical data: IP address, approximate location, device and browser type.
  • Billing data: payment and invoice history (through payment processors).
  • Other data voluntarily provided by you or by the restaurant (e.g., reservation notes).

Minors and sensitive data: Plattio is not directed at minors. Our customers must not enter data of minors below the applicable minimum age (for example, 16 in the EU, 13 in the U.S.) or special categories of data without a valid legal basis and valid consents.

3. How we obtain your data

  • Directly from you when you register, make a reservation, or use the platform.
  • Through the restaurant that uses Plattio and manages your reservation.
  • Automatically through cookies and similar technologies.

4. How we use your data

  • Provide the contracted service and manage your reservations.
  • Send reservation-related confirmations, reminders, and notifications.
  • Provide technical support and assistance.
  • Improve and optimize our platform (security, fraud prevention, analytics).
  • Generate analyses, conclusions, and suggestions for the restaurant from platform data, including through artificial intelligence tools. These analyses do not involve automated decisions that produce legal effects on you (Art. 22 GDPR).
  • Comply with legal and regulatory obligations.
  • Send commercial communications when permitted by law or with your consent.
  • When we process data for marketing campaigns sent through the customer's (restaurant's) CRM, we do so solely under their instructions, and the customer is solely responsible for having the legal basis and consents required for such communications.

5. Legal basis for processing

The legal basis depends on the specific purpose of each processing activity:

  • Performance of a contract: provision of the service, management of your reservations, confirmations, reminders, and technical support.
  • Compliance with legal obligations: billing and tax and accounting obligations.
  • Legitimate interest: platform security and prevention of fraud and abuse; our legitimate interest is protecting the service and its users.
  • Your consent: analytics and marketing cookies on the website (which you can withdraw at any time from the "Cookie settings" link in the footer, as described in the Cookie Policy) and commercial communications for which Plattio is the Controller.

6. With whom we share your data (sub-processors)

We may share data with providers that act as processors to deliver the service, for example:

  • Amazon Web Services (hosting and storage).
  • Twilio (platform through which we send WhatsApp messages: reservation and waitlist confirmations, reminders, and notifications).
  • WhatsApp LLC (Meta) (delivery of those messages to their recipients through the WhatsApp Business Platform).
  • SendGrid (transactional email).
  • Stripe and PayPal (payment processing).
  • OpenAI (AI-powered data analysis; under its API terms, data is not used to train its models).

We require our providers to uphold security and confidentiality obligations equivalent to our own, and they only process data in accordance with our instructions.

The complete and up-to-date list of our main sub-processors is available upon request at [email protected].

In addition, when Plattio acts as the Controller of its own website measurement and you consent to analytics cookies, the recipient of that data is Google Ireland Ltd. (Google Tag Manager and Google Analytics 4). If you consent to marketing cookies, we use the Meta pixel: Plattio and Meta Platforms Ireland Ltd. are joint controllers (Art. 26 GDPR) for the collection and transmission of data to Meta, under Meta's joint-controllership agreement (Controller Addendum), whose essential aspects you can review at facebook.com/legal/controller_addendum; the subsequent processing that Meta carries out as an independent controller is governed by its own privacy policy.

7. International transfers

Your data may be stored and processed in the United States and other countries. The applicable safeguards depend on how the data reaches us:

  • Data you provide to us directly through the Site. Although established in the U.S., Plattio applies the GDPR directly to this processing because it directs its services to individuals in the EU (Art. 3.2 GDPR), with all the rights and safeguards described in this policy.
  • Data we process as a Processor for EU restaurants. The transfer is covered by the European Commission's Standard Contractual Clauses (2021 SCCs, module 2), incorporated into the Data Processing Agreement (DPA) that each customer accepts together with the Terms of Service. You can obtain a copy of the safeguards by writing to [email protected].
  • Data shared with our providers in the U.S. Providers such as Google, Amazon Web Services, Twilio, Meta (WhatsApp), OpenAI, or Stripe cover their transfers under their own EU–US Data Privacy Framework certifications or, failing that, under Standard Contractual Clauses.

8. Retention period and deletion

We retain your data for as long as you have an active relationship with Plattio or as necessary for the purposes described. Upon termination, contact data and reservation history may be retained for a maximum of three (3) years to maintain access to historical reports, handle claims, comply with legal obligations, or facilitate reactivation of the service. Billing data will be retained for the period required by applicable tax legislation. Backups are permanently deleted within a maximum period of 90 days from termination of the service. If you request early deletion and it is technically feasible, we will honor your request.

9. Cookies and similar technologies

Non-essential cookies (analytics and marketing) are set only with your prior consent through our cookie banner, and you can change or withdraw your decision at any time from the "Cookie settings" link in the footer. You will find full details (tools, purposes, and durations) in our Cookie Policy.

10. Your rights

  • Access your personal data.
  • Rectify inaccurate or incomplete data.
  • Request the erasure of your data.
  • Restrict or object to the processing.
  • Request the portability of your data.
  • Withdraw your consent at any time.

You can exercise these rights by writing to [email protected] with the subject line "Request to exercise rights", indicating:

  • Your full name and contact method.
  • The right you wish to exercise.
  • Any additional information needed to locate your data.

We will respond within a maximum of 30 calendar days, unless applicable legislation sets a shorter period. If your request concerns marketing communications sent by a restaurant that uses Plattio, you must contact that restaurant directly (the Controller).

If you believe that the processing of your data infringes the applicable regulations, you have the right to lodge a complaint with a supervisory authority. In Spain, the competent authority is theSpanish Data Protection Agency (AEPD) (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid); in Italy, the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it), or the authority of the Member State of your habitual residence. We would appreciate it if you first wrote to us at [email protected] so we can try to resolve the matter directly.

11. Security

We apply technical and organizational measures to protect data: TLS/AES encryption, role-based access control, multi-factor authentication for administrators, access and audit logs, encrypted backups with periodic testing, environment separation, security testing, and protection against DDoS attacks. Although we work to protect your data, no system is 100% infallible.

12. Legal precedence

In the event of a conflict between this policy and applicable legislation, the law will prevail. If a competent authority requests access to or disclosure of data, we will notify you whenever legally possible before complying.

13. Changes to this policy

We may update this policy from time to time. We will post the new version on this page and indicate the date of the last update. If the changes are substantial, we will notify you through reasonable means (for example, email or a notice within the platform).

14. Contact

Plattio LLC

Email: [email protected]

Address: 8 The Green STE B, Dover, DE 19901, United States

Last updated: August 1, 2026