Effective on November 8, 2025
INTRODUCTION
This Privacy Policy, hereinafter referred to as the “Privacy Policy”, sets forth the rules for using the Portal.
All capitalized terms used in this Privacy Policy shall have the same meanings ascribed to them in the GoodResto Portal - Terms of Service, unless expressly stated otherwise.
DATA CONTROLLER AND CONTACT INFORMATION
The controller of your personal data is:
Goodresto sp. z o.o.ul. Williama Heerleina Lindleya 1602-013 Warsaw, Poland
KRS: 0001124926
NIP: 7011221145
You can contact us via:
• Postal mail: Goodresto sp. z o.o., ul. Williama Heerleina Lindleya 16, 02-013 Warszawa, lub
• E-mail: [email protected]
SCOPE OF APPLICATION
This Privacy Policy applies to processing of Personal Data of:
This policy applies only to the Portal.
Separate Privacy Policies apply to GoodResto App & Website (End Users).
TYPES OF PERSONAL DATA PROCESSED
We process Personal Data provided during account registration and use of the Portal, including:
For invoicing purposes, we process
Data collected automatically:
When you use the Portal we may collect:
Referral or incentive programs:
If Venue Representative are participating in incentive or referral programs offered by the Service Provider, GoodResto may collect and process Personal Data such as bank account details for the purpose of administering payments in accordance with applicable data protection laws.
Reservation customer Personal Data:
The Portal may contain Personal Data of customers who made a reservation at the Venue.
Such data may originate from:
Depending on the origin of data:
For online reservations: GoodResto and the Venue are each independent data controllers.
For manually entered customer data: the Venue is the data controller, and GoodResto processes such data solely as a data processor providing the reservation management system.
If a customer voluntarily provides dietary or allergy-related information during reservation, this information is only transmitted to the Venue. GoodResto does not verify, interpret, or act upon such information.
PURPOSES AND LEGAL BASES FOR PROCESSING
We process Personal Data to:
Legal bases for processing include:
OPERATIONAL RESERVATION MESSAGES
The Portal may send transactional communications to End Users on behalf of the Venue, including reservation confirmations, reminders, updates, cancellation messages, and post-visit review requests. These communications are not marketing and do not require Marketing Consent. They are necessary to perform the Reservation and are sent based on Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in preventing no-shows and ensuring reservation management).
The Venue may manually enter customer information into the Portal.
By doing so, the Venue represents and warrants that:
For manually entered data:
Any segmentation, notes, tags, or internal labels applied to customers are performed by the Venue and are not reviewed or validated by GoodResto.
If a manually entered customer later submits a reservation independently through GoodResto Services, GoodResto becomes an independent Data Controller for Personal Data related to that independent interaction.
OBLIGATION TO PROVIDE DATA
Providing personal data is voluntary but necessary to use the Services. Without this data, we will not be able to create or manage your account or provide functionalities.
DATA SHARING
We may share your Personal Data with:
• Trusted service providers such as IT companies, accounting firms, marketing agencies, analytics providers, or payment processors, but only to the extent necessary for the delivery of our services;
• Advisors such as legal, accounting or tax;
• Entities affiliated with Goodresto, if necessary for internal administrative purposes;
• Public authorities or regulatory bodies when required by applicable laws or legitimate legal requests
• Communication providers (SMS / email sending),
Data is hosted in the European Union.
In principle, we do not transfer your personal data outside the European Economic Area (EEA). If such transfer becomes necessary, it will only be done in accordance with applicable legal requirements and with the use of appropriate safeguards, such as standard contractual clauses approved by the European Commission.
We apply organizational and technical safeguards, including:
Personal Data is retained only as long as necessary to fulfill the purposes described above, unless longer retention is required by law.
Account data is kept while the account is active and for a limited period afterward to manage legal claims and compliance.
RIGHTS OF DATA SUBJECT
You may request:
To exercise your rights, contact us at: [email protected]
If we make material changes to this Privacy Policy, and you are not accepting changes, then you should cease using the Services.