Product Privacy Policy

Last updated: 14.08.2026

This Privacy Policy concerns the processing of personal data of the business owner who registers for and uses Planivo Table as a subscribed customer (hereinafter: "Customer"), carried out by OINOS Korlátolt Felelősségű Társaság (OINOS Kft.), acting as the provider of the Planivo Table service (hereinafter: "Controller" or "we"). It is separate from the privacy notice that each restaurant customer shows to its own end guests at the time of booking, available on each restaurant's public page. This Policy has been drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Hungarian data protection law.

In the event of a legal dispute, the Hungarian-language version of this document shall prevail.

1. The Controller

Company name: OINOS Korlátolt Felelősségű Társaság (OINOS Kft.) Registered office: 1068 Budapest, Dózsa György út 86. B. ép. 3. em. 1. VAT number: 24316268-2-42 Contact for data protection matters: privacy@oinos.hu

2. Scope

This Policy governs the processing of the Customer's data as a user of the Planivo Table product: registration data, account data, billing data, dashboard usage data. For the data of end guests who make a booking with a restaurant customer, the Controller acts as a processor (Art. 28 GDPR) on behalf of the restaurant, which remains the sole controller towards its own guests. The terms of that relationship are set out in the Data Processing Agreement (DPA), which forms an integral part of the Terms of Service.

3. Categories of data processed

In connection with registering and using a Planivo Table account, we process: • first and last name of the account holder/contact person • name of the restaurant or business • email address and password (the latter stored in cryptographically protected form, never in plain text) • phone number, address, tax and legal details of the business (where provided during setup) • billing data and payment history (once a paid plan is activated) • technical usage data: IP address, device and browser type, access logs, logs of actions taken in the dashboard for security and audit purposes

4. Purposes of processing

We process the Customer's data to: • create and manage the account and subscription • deliver the service (booking management dashboard, public booking form, sending of transactional communications) • manage billing and payments • provide technical support and respond to support requests • ensure system security and prevent abuse • send service-related communications (trial expiry notices, contractual changes, technical communications essential to the service)

5. Legal basis for processing

Processing is based on: • performance of a contract (Art. 6(1)(b) GDPR) — for creating the account, delivering the service and billing • legitimate interest (Art. 6(1)(f) GDPR) — for system security, abuse prevention and technical communications essential to the operation of the service • legal obligation (Art. 6(1)(c) GDPR) — for tax and accounting requirements

6. Data retention period

Account data is retained for the duration of the contractual relationship. In the event of non-payment and the resulting blocking of the account, data is retained for 90 days from the block, after which it is permanently deleted, unless the law requires a longer retention period (e.g. accounting and tax records). In the event of voluntary account cancellation by the Customer, the same 90-day period applies before permanent deletion, unless the Customer explicitly requests immediate deletion.

7. Recipients of data and processors

The Customer's data may only be accessed by authorised staff of the Controller. The Controller uses the following processors: • Supabase (Supabase Inc., USA) — database, authentication and server function services. Data is stored within the European Union (Frankfurt, Germany). • Vercel (Vercel Inc., USA) — application hosting. • Resend (Resend Inc., USA) — sending of transactional emails. • Lemon Squeezy (payment service provider, Merchant of Record) — payment and billing management. Where data is transferred outside the European Union, such transfer takes place on the basis of the Standard Contractual Clauses approved by the European Commission, ensuring the level of protection required by the GDPR.

8. Your rights

As a data subject, you have the following rights: • right of access: you may request information about the data concerning you that we process • right to rectification: you may request correction of inaccurate data • right to erasure ("right to be forgotten"): you may request deletion of your data • right to restriction of processing • right to data portability: you may request your data in a machine-readable format • right to object • right to withdraw consent, where applicable You may exercise these rights by sending a request to privacy@oinos.hu. We will respond to your request within 30 days.

9. Right to lodge a complaint

If you believe that processing violates the GDPR or applicable Hungarian data protection law, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): Nemzeti Adatvédelmi és Információszabadság Hatóság Address: 1055 Budapest, Falk Miksa utca 9-11. Postal address: 1363 Budapest, Pf. 9. Phone: +36 1 391 1400 Email: ugyfelszolgalat@naih.hu Website: www.naih.hu You may also bring a claim before a court in the event of a breach of your rights.

10. Data security

We implement technical and organisational security measures appropriate to the state of the art: encrypted data transmission (HTTPS), passwords never stored in plain text, database-level access control (Row Level Security), separation of data between different Customers (multi-tenant architecture), regular security updates.

11. Changes to this Policy

We reserve the right to unilaterally amend this Policy. The amended version takes effect upon publication on the website. In the event of material changes, we will notify the Customer by email or dashboard notification with reasonable advance notice.