ASERIA - Restaurant Management System
  • Features
  • Modules
  • Security
  • Privacy
  • Terms
Sign In
Legal

Privacy Policy

How ASERIA collects, uses, shares, secures, and retains personal data across the admin dashboard, POS terminals, kitchen displays, e-kiosks, queue screens, and reporting tools.

Effective 10 July 2026 Last updated 10 July 2026 GDPR & Swiss FADP aligned
On this page
  • 1. Scope of this policy
  • 2. Who we are
  • 3. Controller and processor roles
  • 4. Data we collect
  • 5. Where the data comes from
  • 6. Purposes and legal bases
  • 7. Cookies and local storage
  • 8. Sharing and sub-processors
  • 9. International transfers
  • 10. Data retention
  • 11. How we protect data
  • 12. Your privacy rights
  • 13. Restaurant operator duties
  • 14. Automated decision-making
  • 15. Children's data
  • 16. Incident and breach handling
  • 17. Changes to this policy
  • 18. How to contact us

ASERIA is a restaurant management system. It runs the admin dashboard, point-of-sale terminals, kitchen displays, self-service e-kiosks, queue screens, and the reporting engine that sits behind them. Operating that platform means handling personal data — of the restaurant staff who log in, of the devices they log in from, and of the guests whose orders pass through the system.

This policy explains exactly what we collect, why we collect it, who else sees it, how long we keep it, and what you can ask us to do with it. It applies to the ASERIA platform, the ASERIA websites, our mobile and desktop applications, and the device-facing APIs used by POS, kitchen, kiosk, and queue hardware.

Section 01

Scope of this policy

This Privacy Policy covers all personal data processed in connection with the ASERIA platform, including:

  • The admin dashboard — the web application used by owners, managers, and back-office staff to manage locations, menus, users, roles, orders, and reports.
  • Operational device interfaces — POS terminals, kitchen display screens, e-kiosk tablets, queue displays, and cash register sessions.
  • Companion applications — Android, desktop (Electron), and browser-based clients that connect to the same backend.
  • Public websites — the ASERIA marketing site and this legal documentation.
  • Support and communications — email, phone, and ticket exchanges with our support team.

It does not cover third-party services that a restaurant chooses to connect independently of ASERIA, nor the privacy practices of any external website linked from our platform. Those are governed by their own policies.

Section 02

Who we are

ASERIA is operated by two affiliated entities. Unless stated otherwise, the Swiss entity is the data controller for platform-level personal data, and the Kosovo entity acts on its behalf as an internal processor for engineering, support, and operational functions.

Switzerland
ASERIA SA
Rue du Pre-de-la-fontaine 13
1242 Satigny, Switzerland
  • privacy@aseria.ch
  • +41 76 699 59 99
Kosovo
ASERIA LTD
Rr. Beqir Musliu 6/161
60000 Gjilan, Kosovo
  • privacy@aseria.ch
  • +383 45 81 99 99
Section 03

Controller and processor roles

The same platform handles two different categories of personal data, and our legal role differs between them. Getting this distinction right matters, because it determines who you contact to exercise your rights.

Where ASERIA is the controller

We decide the purposes and means of processing for data relating to our own commercial relationship: the account details of the restaurant business that subscribes to ASERIA, the identity of the administrator who signed up, billing records, support correspondence, security logs, and website analytics. For this data, ASERIA SA is the controller.

Where ASERIA is the processor

When a restaurant uses ASERIA to run its operations, the restaurant decides what data goes into the system. Orders, guest names attached to a ticket, loyalty records, table assignments, staff shift activity, and receipt content are all entered or generated under the restaurant's instructions. For this data, the restaurant is the controller and ASERIA is the processor, acting only on documented instructions.

If you are a restaurant guest or an employee

Your first point of contact is the restaurant that holds your data, not ASERIA. We will forward any request we receive directly to the relevant restaurant and assist them in responding within the statutory deadline.

Section 04

Data we collect

We collect only what the platform needs to function, to stay secure, and to meet our legal obligations. We do not sell personal data, and we do not use it to build advertising profiles.

Account and identity data

  • Name, email address, and phone number of the account administrator and each staff user created within the system.
  • Hashed authentication credentials. Passwords are stored as one-way hashes and are never recoverable in plain text, by us or by anyone else.
  • Assigned role, granular permission set, kitchen station assignment, and the locations a user is scoped to.
  • Account status, creation date, last sign-in, and password reset history.

Business and operational data

  • Restaurant details: legal name, trading name, addresses of each location, currency, tax configuration, and operating settings.
  • Menu and catalogue data: categories, items, meals, modifiers, modifier groups, ingredients, and multilingual translations.
  • Order records: line items, modifiers, quantities, prices, order type (dine-in, takeaway, delivery), table or queue number, status transitions, and timestamps.
  • Payment records: payment method used, amounts, tax breakdown, refund events, and cash register session data. We do not store full card numbers, CVV codes, or PIN data — card payments are processed by the terminal or payment provider you connect.
  • Shift and reconciliation data: opening balances, cash floats, Z-report figures, and closure audit trails.
  • Stock and ingredient thresholds, and the alerts they generate.

Guest data processed on behalf of restaurants

  • Customer name, phone number, and email address, where a restaurant chooses to capture them for orders, receipts, or loyalty programmes.
  • Delivery address, where delivery orders are enabled.
  • Order history linked to a customer record.
  • Data entered by a guest at an e-kiosk terminal during self-service ordering.

Device and technical data

  • Device identifiers and device tokens issued to POS terminals, kitchen displays, kiosks, and queue screens for authentication.
  • IP address, browser type and version, operating system, screen resolution, and application version.
  • Server and application logs, including request paths, response codes, error traces, background job outcomes, and broadcast events.
  • Session identifiers and API access tokens.

Communications data

  • Emails, phone calls, and support messages exchanged with our team, and their attachments.
  • Delivery status of scheduled email reports and system notifications.
Special category data

ASERIA is not designed to process special categories of personal data, such as health information, biometric identifiers, religious beliefs, or trade union membership. Do not enter such data into free-text fields, order notes, or customer records.

Section 05

Where the data comes from

  • Directly from you — when you register an account, configure a location, create a staff user, or contact support.
  • From the restaurant that employs you — staff accounts are typically created by an owner or manager rather than by the staff member.
  • Automatically from your device — technical and log data generated as the platform is used.
  • From guests at the point of sale — data entered at a POS terminal by staff, or by the guest themselves at an e-kiosk.
  • From connected hardware — printers, cash drawers, payment terminals, and display devices that report status back to the platform.
Section 06

Purposes and legal bases

Under the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP), every processing activity needs a lawful basis. Ours are set out below.

Purpose What this involves Legal basis
Providing the platform Authenticating users and devices, processing orders, routing tickets to kitchens, running queue displays, generating receipts and reports. Performance of a contract
Account administration Creating accounts, managing roles and permissions, scoping data by location, handling password resets. Performance of a contract
Billing and collection Invoicing subscription fees, recording payments, pursuing overdue amounts. Performance of a contract; legal obligation
Support and troubleshooting Responding to enquiries, reproducing reported faults, inspecting logs and error traces. Performance of a contract; legitimate interests
Security and abuse prevention Detecting intrusion attempts, rate-limiting, auditing privileged actions, monitoring failed jobs and anomalies. Legitimate interests; legal obligation
Backups and continuity Running daily automated database and server backups, verifying restore capability. Legitimate interests; legal obligation
Tax and accounting compliance Retaining Z-reports, tax reports, and transaction records for the statutory period. Legal obligation
Product improvement Analysing aggregated, non-identifying usage patterns to prioritise features and fix performance issues. Legitimate interests
Service communications Sending scheduled reports, stock alerts, maintenance notices, and security advisories. Performance of a contract; legitimate interests
Marketing communications Sending product news or promotional material where you have opted in. Consent

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that the processing is necessary, proportionate, and not overridden by the rights of the individuals concerned. You may object to such processing at any time — see Section 12.

Section 07

Cookies and local storage

ASERIA uses a deliberately small set of cookies and browser storage keys. We do not use advertising cookies, cross-site trackers, or third-party marketing pixels anywhere in the platform.

Type Purpose Consent needed
Session cookie Keeps you signed in as you move between pages of the admin dashboard. No — strictly necessary
CSRF token Protects forms and requests against cross-site request forgery. No — strictly necessary
API access token Authenticates POS, kitchen, kiosk, and queue clients against the backend. No — strictly necessary
Device identifier Identifies a physical terminal so it can be assigned to a location and station. No — strictly necessary
Interface preferences Remembers language selection, selected location, and layout choices. No — strictly necessary

Blocking strictly necessary cookies will prevent sign-in and prevent devices from authenticating. Web fonts on our public pages are served from Google Fonts, which may receive your IP address as part of the request; no cookie is set by that request.

Section 08

Sharing and sub-processors

We never sell personal data. We share it only in the circumstances below, and only to the extent necessary.

Categories of recipients

  • Hosting and infrastructure providers — to run application servers, databases, queues, and file storage.
  • Backup storage providers — to hold encrypted daily database and server backups.
  • Email delivery providers — to send transactional messages, scheduled reports, alerts, and password resets.
  • Realtime broadcasting infrastructure — to push live order events to kitchen, POS, kiosk, and queue devices.
  • Error and issue tracking — where a restaurant enables GitHub issue logging, technical error context is written to the repository it configures. Restaurants control that repository and its access.
  • Payment terminal and processor providers — where a restaurant connects card payments. Card data flows to the provider, not through ASERIA.
  • Professional advisers — auditors, accountants, and lawyers, under confidentiality obligations.
  • Authorities — where disclosure is required by a valid legal order, and after we have assessed its lawfulness.
  • Acquirers — in a merger, acquisition, or asset sale, subject to equivalent protections and prior notice.

Every sub-processor is bound by a written agreement imposing confidentiality, security, and purpose-limitation obligations no weaker than those in this policy. An up-to-date list of sub-processors is available on request from privacy@aseria.ch. Restaurants under a data processing agreement receive advance notice of new sub-processors and may object.

Section 09

International transfers

ASERIA operates from Switzerland and Kosovo, and some of our sub-processors operate outside those jurisdictions.

  • Switzerland benefits from an adequacy decision from the European Commission, so transfers from the EEA to Switzerland require no additional safeguard.
  • Transfers to Kosovo and to any other country without an adequacy decision are covered by the European Commission's Standard Contractual Clauses, supplemented where necessary by the Swiss addendum recognised by the Federal Data Protection and Information Commissioner.
  • Where a transfer risk assessment identifies gaps, we apply supplementary technical measures — including encryption in transit and at rest, and strict access controls — before any transfer takes place.

You may request a copy of the relevant safeguards by writing to privacy@aseria.ch.

Section 10

Data retention

We keep personal data only for as long as it serves the purpose it was collected for, or for as long as the law requires us to keep it — whichever is longer.

Data category Retention period Reason
Active account data For the life of the subscription Needed to operate the service
Deactivated staff accounts Retained while audit trails reference them Order and shift attribution integrity
Order, payment, and Z-report records 10 years from the end of the financial year Swiss commercial and tax bookkeeping obligations
Guest and customer records As instructed by the restaurant; deleted on request The restaurant is the controller
Application and security logs Up to 12 months Security investigation and abuse prevention
Automated backups Per the configured retention window Disaster recovery and continuity
Support correspondence 3 years from last contact Service quality and dispute defence
Marketing consent records Until withdrawn, plus 3 years Evidence of consent

When a subscription ends, active operational data is deleted or returned within 90 days of termination, except where a statutory retention obligation applies. Data that persists in backups is deleted as those backups age out of their retention window; it is not restored into production in the interim.

Section 11

How we protect data

Security is engineered into the platform, not bolted on afterwards. Our technical and organisational measures include:

  • Encryption in transit — all traffic between clients, devices, and our servers is protected with TLS 1.3.
  • Encryption at rest — stored data and backups are encrypted using AES-256.
  • Credential hashing — passwords are stored as salted one-way hashes and are never logged or transmitted in plain text.
  • Token-based authentication — API and device access use scoped, revocable tokens rather than shared credentials.
  • Role-based access control — every module and action is gated by a granular permission, and permissions are scoped per location.
  • Device authentication — kitchen, POS, kiosk, and queue devices authenticate independently and can be revoked individually.
  • Audit trails — privileged actions, shift closures, and cash sessions are recorded with the acting user and timestamp.
  • Automated daily backups — with health monitoring, retention control, and tested restore procedures.
  • Continuous monitoring — server logs, failed background jobs, and operational anomalies are surfaced daily to our engineering team.
  • Least privilege internally — staff access to production data is limited to what a role requires and is logged.

No system can be guaranteed perfectly secure. We commit to industry-standard measures and to prompt, transparent handling of any incident — see Section 16.

Section 12

Your privacy rights

Subject to the conditions and exemptions in the applicable law, you have the following rights over your personal data.

  1. Access. Obtain confirmation of whether we process your data, and receive a copy of it together with information about how it is used.
  2. Rectification. Have inaccurate data corrected and incomplete data completed.
  3. Erasure. Have your data deleted where it is no longer necessary, where consent is withdrawn, or where processing is unlawful — unless a statutory retention duty applies.
  4. Restriction. Require us to pause processing while an accuracy dispute or objection is resolved.
  5. Portability. Receive the data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  6. Objection. Object to processing based on legitimate interests, including profiling, on grounds relating to your particular situation.
  7. Withdraw consent. Withdraw any consent you have given, at any time, without affecting processing carried out before withdrawal.
  8. Complain. Lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EEA, the authority of your country of residence or place of work.

To exercise a right, write to privacy@aseria.ch. We will verify your identity before acting, and we will respond within 30 days. If a request is complex we may extend that period by a further two months and will tell you why. Requests are free unless they are manifestly unfounded or excessive.

Requests about restaurant-held data

If your request concerns data a restaurant entered into ASERIA — an order, a customer record, a loyalty entry — we act as processor. We will pass the request to the restaurant without undue delay and support them in fulfilling it.

Section 13

Restaurant operator duties

If you operate a restaurant on ASERIA, you are the controller for the data you put into the system. That carries obligations that only you can discharge:

  • Establish a lawful basis before collecting guest names, phone numbers, email addresses, or delivery addresses.
  • Provide your own privacy notice to guests and staff, describing what you collect and why.
  • Configure roles and permissions so that each staff member can access only the data their job requires.
  • Deactivate accounts and revoke device tokens promptly when a staff member leaves.
  • Keep free-text fields — order notes, customer comments — free of special category or excessive personal data.
  • Respond to guest and staff data subject requests within the statutory deadline, using the export and deletion tools the platform provides.
  • Notify us without undue delay if you become aware of a breach affecting data held in ASERIA.

Restaurants processing personal data of individuals in the EEA or Switzerland should have a data processing agreement in place with us. Contact privacy@aseria.ch to request one.

Section 14

Automated decision-making

ASERIA does not make decisions producing legal or similarly significant effects about individuals on the basis of automated processing alone, and it does not perform profiling for that purpose.

The platform does apply automated rules of an operational nature — routing an order to a kitchen station based on its category, raising a stock alert when an ingredient crosses a configured threshold, generating a queue number, or flagging an anomaly for engineering review. None of these evaluate personal characteristics or affect an individual's rights.

Section 15

Children's data

ASERIA is a business tool. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. Staff accounts may only be created for individuals lawfully permitted to work in the relevant jurisdiction.

A guest at an e-kiosk may be any age, but the kiosk collects no personal data beyond what is needed to fulfil an order. If you believe a child's personal data has been entered into ASERIA without a lawful basis, contact privacy@aseria.ch and we will work with the relevant restaurant to remove it.

Section 16

Incident and breach handling

We maintain an incident response procedure covering detection, containment, assessment, notification, and remediation.

  • Where we are the controller and a breach is likely to result in a risk to individuals' rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it.
  • Where the risk is high, we notify the affected individuals directly and without undue delay.
  • Where we are the processor, we notify the affected restaurant without undue delay so that it can meet its own notification duties, and we provide the information it needs to do so.
  • Every incident is documented, including its facts, effects, and the remedial action taken.

Security concerns and suspected vulnerabilities can be reported confidentially to security@aseria.ch. We do not pursue legal action against good-faith researchers who report responsibly and avoid privacy violations or service disruption.

Section 17

Changes to this policy

We may update this policy to reflect changes in the platform, in our sub-processors, or in the law. The effective date and last-updated date at the top of this page always reflect the current version.

Where a change materially affects how we handle your data, we will notify account administrators by email, or by an in-product notice, at least 30 days before it takes effect. Continuing to use ASERIA after a change takes effect means you accept the updated policy. Where the change requires your consent, we will ask for it separately.

Section 18

How to contact us

For any question about this policy, about how your data is handled, or to exercise a privacy right:

  • Privacy enquiries and data subject requests — privacy@aseria.ch
  • Security reports — security@aseria.ch
  • General and commercial enquiries — hello@aseria.ch
  • Platform support — support@aseria.ch

Written correspondence may be addressed to ASERIA SA, Rue du Pre-de-la-fontaine 13, 1242 Satigny, Switzerland. If you are not satisfied with our response, you may complain to the Federal Data Protection and Information Commissioner in Bern, or to the supervisory authority in your EEA country of residence.

Read the Terms of Service Contact us
ASERIA - Restaurant Management System

The restaurant operating system for teams that need live orders, kitchen flow, POS, kiosk, reporting, and backups in one dependable dashboard.

Multi-location ready 99.9% uptime Daily backups
Switzerland
ASERIA SA

Rue du Pre-de-la-fontaine 13
1242 Satigny, Switzerland

  • hello@aseria.ch
  • +41 76 699 59 99
  • +41 22 559 50 99
Kosovo
ASERIA LTD

Rr. Beqir Musliu 6/161
60000 Gjilan, Kosovo

  • hello@aseria.ch
  • +383 45 81 99 99
  • www.aseria.ch
Explore Platform
  • Core Features
  • All Modules
  • Workflow
  • Reporting
  • Infrastructure
  • Onboarding
  • How It Works
  • Multi-location
  • Built for Roles
  • Security
Legal & Account
  • Privacy Policy
  • Terms of Service
  • Case Study
  • Sign In
  • Support
  • FAQ

Built for restaurant operators. Keep every order, terminal, kitchen station, queue screen, and report connected across every location.

ASERIA - Restaurant Management System

© 2026 ASERIA - Restaurant Management System. All rights reserved.

Privacy Policy Terms of Service Case Study aseria.ch