Company · GDPR

GDPR framework

Roles, legal bases, providers and rights in one place.

Last updated · 9 September 2026 · Version 3.0

Cevor applies the GDPR to personal data it controls. The Privacy Policies contain the detailed notices; this page summarizes the framework.

1. Controller roles

Cevor is controller for consumer accounts, website and app discovery data, forms and prospects, communications, security and professional Business-account administration. Restaurants remain responsible for their own staff instructions and submitted content. A processor role applies only where a written arrangement and the facts establish it; aggregate platform analytics are not automatically restaurant-controlled data.

2. Legal bases

  • Contract for requested account, saved and Business services.
  • Legitimate interests for security, abuse prevention, support and proportionate product improvement.
  • Consent for optional location permission, optional marketing and non-essential tracking where required.
  • Legal obligation for accounting, regulatory and lawful authority matters.

3. Providers

Current verified categories include Lovable Cloud application backend, authentication, database and storage; hosting and content-delivery infrastructure; and Resend for transactional email and delivery events. Stripe and Billit apply only when the corresponding paid workflow is active. No current Odoo processing is claimed.

4. Transfers

Provider processing may occur inside or outside the EEA. Where GDPR requires a transfer mechanism, Cevor uses an adequacy decision, Standard Contractual Clauses or another lawful safeguard and assesses providers proportionately.

5. Minimisation and retention

Cevor seeks to collect data relevant to the active purpose and retain it only for operational, contractual, security, legal and dispute needs. The Privacy Policies describe categories; Cevor does not publish unsupported fixed retention periods as universal guarantees.

6. Rights and complaints

People may exercise GDPR rights through the public Personal Data page or legal contact. They may complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, or another competent supervisory authority.

7. Breach notification

Where Article 33 applies, Cevor notifies the competent authority without undue delay and, where feasible, within 72 hours after becoming aware. Affected people are informed where Article 34 requires it.

Contact

For questions, write to hello@cevor.app

See also