Overview & commitment
TechVerdi SA (Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland) operates the Kappino platform (the “Service”) and is committed to processing personal data lawfully, fairly, and transparently.
This statement summarises how the Service supports the requirements of the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP, SR 235.1) and its Ordinance. It complements, and should be read with, our Privacy Policy and Data Processing Agreement.
Roles & legal frameworks
The GDPR applies where we process the personal data of individuals in the EU/EEA in scope of Art. 3 GDPR; the FADP applies to our processing in Switzerland. Both frameworks rest on similar principles: lawfulness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and accountability.
Roles. For account, billing, website, and security data, TechVerdi is the controller. For the operational data our business customers enter about their own diners, staff, and riders, the business customer is the controller and TechVerdi is the processor, governed by our Data Processing Agreement (DPA).
The mechanisms below are provided either directly, where we are controller, or as processor support to help our customers meet their obligations.
Data export
We provide mechanisms to export personal and account data:
- In-account export of your data and records, such as customers, orders, reservations, menus, and reports, in common formats where available in the Service;
- API access via scoped API keys, allowing you to retrieve your data programmatically; and
- Export on request — if you cannot export what you need yourself, contact us and we will make your data available for export within a reasonable period.
Exports support both the GDPR right of access under Art. 15 and the FADP right of access under Art. 25, and help our customers respond to their own data subjects.
Right to erasure
We support the right to erasure / to be forgotten under Art. 17 GDPR and deletion under the FADP:
- Record-level deletion — authorised users can delete individual records, such as a customer or rider record, within the Service;
- Account deletion — on termination or request, account data is deleted within 30 days, and residual copies are removed from backups within the rolling backup cycle, up to 90 days; and
- Erasure requests — requests can be sent to our Data Protection Contact and, where we act as processor, are actioned on the controller’s instruction.
Erasure is subject to legal exceptions, for example data we must retain under statutory obligations, such as accounting records for 10 years under Art. 958f of the Swiss Code of Obligations. Such data is securely archived, access-restricted, and deleted at the end of the retention period.
Consent management
Cookie consent. Our website presents a cookie consent banner with an “Accept” option and an “Essential-only” option, so that non-essential cookies are set only with consent.
Marketing consent. Where consent is the basis for marketing communications, we record it, and every marketing message includes an easy opt-out.
Withdrawal. Consent can be withdrawn at any time, as easily as it was given, without affecting the lawfulness of prior processing.
Customer-side consent. Where our customers collect consent from their own diners or staff, for example for loyalty or messaging, the customer is responsible for obtaining and recording that consent; the Service provides features to support this.
Data portability
We support the right to data portability under Art. 20 GDPR and Art. 28 FADP, the right to the handing over or transfer of data.
On request or via the export mechanisms in Section 3, we provide the relevant personal data that was provided to us, processed by automated means and based on consent or a contract, in a structured, commonly used, machine-readable format, such as CSV or JSON, so it can be reused or transmitted to another provider.
Where technically feasible, data can be transmitted directly to another controller.
Records of processing activities
We maintain records of our processing activities in line with Art. 30 GDPR and Art. 12 FADP. These records describe the categories of processing carried out as controller and as processor, the purposes, the categories of data and data subjects, recipients and sub-processors, international transfers and their safeguards, retention periods, and a general description of our security measures.
We keep these records current and make them available to the competent supervisory authority on request.
Breach notifications
We maintain an incident-response procedure with detection, escalation, mitigation, and post-incident review. In the event of a personal data breach:
- Under the GDPR, where we are controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, where the breach is likely to result in a risk to individuals. We notify affected individuals where there is a high risk.
- Under the FADP, we notify the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible where the breach is likely to result in a high risk to the personality or fundamental rights of data subjects, and inform affected persons where necessary or on request.
- As a processor, we notify the affected business customer, the controller, without undue delay after becoming aware, and assist them with their own notification obligations.
Privacy by design & by default
We apply data protection by design and by default under Art. 25 GDPR and Art. 7 FADP throughout the Service, including:
- Data minimisation — collecting and processing only what is needed for the relevant purpose;
- Tenant isolation — logically separating each customer’s data in our multi-tenant environment;
- Access controls — role-based access (RBAC) on a least-privilege basis and scoped API keys;
- Security measures — encryption in transit, AES-256-GCM for sensitive tokens, bcrypt password hashing, audit logging, and tested backups;
- AI controls — profiling designed to support human decisions, with the option to disable AI processing on request; and
- Secure development — privacy and security considered during design and review, with penetration testing and internal audits.
International transfers
The core platform and database are hosted in Switzerland by Infomaniak SA. Some features rely on providers that process data outside Switzerland and the EU/EEA, such as OpenAI, Google, and Meta.
Such transfers are protected by appropriate safeguards — adequacy recognition, applicable data-transfer frameworks, or the EU Standard Contractual Clauses with the Swiss FDPIC addendum — supplemented by additional measures where necessary. See the Privacy Policy and DPA for details.
Sub-processors
We engage vetted sub-processors under written agreements imposing data-protection obligations substantially equivalent to our own, and we remain responsible for their performance.
A current list of sub-processors is maintained and available on request, and is set out in our DPA. We inform customers of intended changes and provide an opportunity to object on reasonable grounds.
Exercising rights & contact
Individuals can exercise their rights — access, rectification, erasure, restriction, objection, portability, and withdrawal of consent — by contacting our Data Protection Contact below.
Where the request relates to data held by a business customer as controller, we will forward it to that customer and assist them in responding. We respond within the timeframes required by applicable law, generally within one month under the GDPR, and may need to verify identity.
Supervisory authorities. You may lodge a complaint with the FDPIC (Feldeggweg 1, 3003 Bern, Switzerland) or, where the GDPR applies, with the supervisory authority of your EU/EEA country of residence or workplace.
Changes & governing law
We may update this statement to reflect changes in our practices or the law; material changes will be notified and the “Last updated” date revised.
This statement is governed by Swiss law; where the GDPR applies, it applies in addition. The competent courts of the Canton of Vaud, Switzerland — place of jurisdiction: Pully / Lausanne — have jurisdiction, subject to any mandatory place of jurisdiction and the rights of EU data subjects under the GDPR.