Privacy Policy
This policy explains how ai-support.scan-order.eu processes personal data when presenting eNaroči, handling demonstration enquiries and operating the AI Waiter.
Data controller
The controller is the company identified below. Send privacy questions to the stated privacy contact.
Data we process
Necessary technical data includes a random session identifier, CSRF token, activity timestamps and a daily pseudonymous security token derived from the IP address.
When you submit the demo form, we may process the restaurant name, contact person, telephone number, email address, city, number of locations, restaurant type, current ordering method, selected plan, features of interest, preferred demonstration date, time and format, and an optional message.
For AI chat, the question and answer are processed only to prepare the response. Chat content is not saved in a local application database.
Purposes and legal bases
Form data is processed to respond to the requested demonstration or enquiry and to take requested steps before a possible contract.
Technical data is processed for our legitimate interests in security, abuse prevention, troubleshooting and reliable operation. We also collect aggregate page and event counters to improve the website; these counters contain no IP address, session identifier or form content.
Demonstration form
Form content is stored in a private enquiry-management system and may also be delivered to the configured business email address used to handle enquiries.
The data is kept until the enquiry is completed and for a reasonable follow-up period. Closed, lost or spam enquiries are normally removed after the configured sales-lead retention period; contract and accounting information may be retained longer when required by law.
Artificial intelligence
The OpenAI feature is enabled. Obvious contact details are minimised or removed before transmission, and requests are sent with store=false. The AI provider may generally retain content for abuse monitoring for up to 30 days unless stricter account controls apply.
AI answers are informational. The system does not make decisions producing legal or similarly significant effects. A person confirms formal quotes, discounts, deadlines, integrations and contract terms.
Recipients and transfers
Data may be accessible to authorised personnel, the hosting provider, the business email provider and, when enabled, OpenAI and its subprocessors. Appropriate safeguards are used for transfers outside the EEA where required.
Retention
Sessions are removed after about 30 minutes of inactivity. Rate-limit records are kept for no more than 7 days and sanitised technical logs for no more than 30 days. Aggregate usage counters are normally kept for no more than 400 days or the shorter period configured in the system. Local AI chat content is not archived. Form data is stored in a private enquiry-management system with restricted access.
Security
We use HTTPS, secure session cookies, CSRF protection, origin checks, rate limiting, IP pseudonymisation, log redaction, private storage and automatic deletion. Do not send passwords, payment-card details, health information or identity documents.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction or portability and may object to processing. You may also complain to the Information Commissioner of the Republic of Slovenia.
Policy changes
We may update this policy when features, providers or legal requirements change. The current version and date will be published on this page.
Contact
- Mao Hua Trade d.o.o.
- Ulica Ilije gregoriča 12, 2000 Maribor
- info@scan-order.eu
- Registration / VAT
- 5966710 / 61634271