Privacy Policy

Complete transparency about how we protect and use your personal data in compliance with GDPR and LGPD

Last updated: October 24, 2025
GDPR
LGPD
EU Storage
1
Introduction

Karu Software is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our restaurant management platform.

This policy complies with the European Union's General Data Protection Regulation (GDPR) and Brazil's General Data Protection Law (LGPD), ensuring the highest standards of data protection.

2
Data Controller
Data ControllerKaru Software
JurisdictionPortugal (European Union)
Data StorageGermany (European Union)
Data Protection OfficerAvailable through contact form

As a company based in the European Union, we strictly follow GDPR guidelines for data protection.

3
Data We Collect

We only collect data necessary to provide and improve our services. All data is processed with appropriate legal basis:

CategoryExamplesPurposeLegal Basis
Account DataName, email, phone, companyAccount creation and management, communicationContract performance
Operational DataRecipes, staff, salesPlatform functionality, reportingContract performance
Payment DataBilling information, transaction historyPayment processing, billingContract performance
Technical DataIP address, access logs, usage dataSecurity, optimization, technical supportLegitimate interest
4
Third-Party Services

We use trusted providers to ensure the best experience and security. All have compliance certifications:

ServicePurposeLocationCompliance
SupabasePrimary database and authenticationGermany (EU)GDPR
StripeSecure payment processingUnited StatesSCC
Google AnalyticsUsage analysis and optimizationUnited StatesSCC
ClerkAuthentication and user managementUnited StatesSCC
SentryError monitoring and performanceUnited StatesSCC

Strict Policy: We never sell, rent, or share your personal data with third parties for commercial purposes.

6
Your Rights (GDPR/LGPD)

You have comprehensive rights over your personal data. You can exercise these rights at any time:

RightDescription
AccessRequest a copy of all personal data we process about you
RectificationCorrect inaccurate or incomplete personal data
ErasureRequest deletion of your personal data ('right to be forgotten')
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing of your data for direct marketing purposes
Withdraw ConsentWithdraw consent at any time when processing is based on consent
8
Data Security

We implement strict technical and organizational security measures to protect your data against unauthorized access, alteration, disclosure, or destruction:

AES-256 Encryption
Role-based access control
Firewalls and 24/7 monitoring
Modern security practices
Contact

To exercise your rights or clarify questions about this policy, contact us through our secure contact form.

Secure and encrypted contact form