Mezenta
Products
  • Interactive menu A QR menu on your guest’s phone, with allergens and filters.
  • Menu insights Scans, peak hours and the dishes that pull attention.
  • Reservations Table requests you approve yourself, with no commission.
  • Restaurant website A fast website ready for Google, with your menu built in.
30 DAYS FREE Everything your restaurant needs in one platform
  • ✓0% commission on every booking
  • ✓Live in a day
  • ✓No technical skills needed
Request access →
Pricing Contact
Ελληνικά Dashboard Sign in Request access →

Products

  • Interactive menuA QR menu on your guest’s phone, with allergens and filters.
  • Menu insightsScans, peak hours and the dishes that pull attention.
  • ReservationsTable requests you approve yourself, with no commission.
  • Restaurant websiteA fast website ready for Google, with your menu built in.

More

Pricing Contact Ελληνικά
Dashboard
Request access → Sign in

Privacy

Privacy policy

Last updated: 9 October 2026

This policy explains how Mezenta processes personal data when you visit our website, when you use the platform as a restaurant business or a member of its team, and when, as a restaurant's guest, you make a reservation, leave a review or use a rewards card. It is written under Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), Greek Law 4624/2019 and Greek Law 3471/2006.

The operating company's details (legal name, registered seat, VAT and GEMI numbers, and contact details) have not been published yet and will be added to this page.

Who we are

In this policy, “Mezenta”, “we” and “us” mean the company that operates the Mezenta platform. Mezenta gives restaurants digital menus, reservations, a guest list, reviews, a rewards card, analytics and a website.

For any data-protection matter, or to exercise your rights, contact us through our contact form. We have not appointed a Data Protection Officer (DPO).

When we are the controller and when we are a processor

We are the controller (GDPR Article 4(7)) for:

  • our website (mezenta.gr) and its contact form;
  • the accounts of our restaurant customers and their team members;
  • billing and subscriptions;
  • service emails and the weekly summary sent to restaurants;
  • platform security and logs;
  • usage statistics that do not identify anyone.

For each restaurant's guest data we are a processor (GDPR Article 28) acting on the restaurant's behalf: reservations, guest profiles and the guest list (including the tags staff add), reviews, the rewards card, newsletter lists, and guest sign-in with Google or Facebook on the restaurant's pages. The restaurant is the controller of this data: it decides what it records, how long it keeps it and how it contacts you. We process it only on the restaurant's instructions and under the data-processing terms in our Terms of service, never for our own purposes.

Each restaurant has its own privacy policy on the platform page /privacy/<restaurant>/, linked from the reservation form in its menu and from its rewards card page. For your data as a guest, contact the restaurant first; if you contact us, we will pass your request on to the restaurant and help it reply.

What we process as controller, why, and on what legal basis

Visiting the website. To show you our pages and protect the service, our server receives your IP address, the page you request, your browser (user-agent) and the time of the request. Legal basis: our legitimate interest in running the website securely (GDPR Article 6(1)(f)). Google Analytics traffic statistics are used only with your consent (Article 6(1)(a)); see “Cookies and browser storage”.

Contact form. Your name, email, phone and message, so that we can reply. Legal basis: steps you ask us to take before entering into a contract (Article 6(1)(b)) and our legitimate interest in answering enquiries (Article 6(1)(f)). The message is emailed to our inbox and is not stored in the platform database.

Restaurant and staff accounts. Name, email, password (stored only as a hash), role and restaurant, and, if you use them, Google or Facebook sign-in (we receive your name, email and profile photo from the provider) and two-step verification. For sign-in sessions we record the IP address and user-agent. Team invitations contain the email the owner entered and are valid for 7 days. Staff actions in the management area are recorded in an activity log. For support or security reasons, authorised Mezenta staff can temporarily sign in to your account; every such access is logged. Legal basis: performance of the contract (Article 6(1)(b)) and our legitimate interest in account security (Article 6(1)(f)).

Restaurant details. Display and legal name, email, phone, address, Google review link, WiFi details, reservation settings, menus and images. These are mainly business details; where they relate to an individual (for example a sole trader), we process them to perform the contract (Article 6(1)(b)). Whatever the restaurant chooses to publish appears on its menu and pages.

Billing and subscriptions. Payments run through Stripe, which collects your name or company name, billing address, email, VAT number (if you provide one) and card details; we do not store card numbers. We keep Stripe's customer and subscription identifiers, your plan and the subscription status. Legal basis: performance of the contract (Article 6(1)(b)) and our legal obligation to keep accounting and tax records (Article 6(1)(c), Greek Law 4308/2014).

Service emails and the weekly summary. We send staff the emails the service needs, such as email confirmation, password reset and invitations, and a weekly summary of scans, popular dishes and the review average. The summary is on by default and you can stop it with the link in each summary email. We keep the summary's recipient and content in our email send queue. Legal basis: performance of the contract (Article 6(1)(b)); for the summary, our legitimate interest in keeping you informed about the service you use (Article 6(1)(f)).

Security and abuse prevention. We use your IP address to rate-limit requests. Cloudflare Turnstile protects the sign-up, sign-in, password-reset, contact, reservation and rewards-card save forms from automated use, and receives your IP address and technical characteristics of your browser. Requests and errors are recorded in logs (Cloudflare Workers Logs), which may contain the IP address, the page address and the user-agent. Legal basis: our legitimate interest in the security and integrity of the service (Article 6(1)(f)).

Usage statistics that do not identify anyone. On menus we record events such as viewing, adding or sharing a dish, with the event type, the dish, the device type (mobile or desktop) and the time; these records contain no IP address or guest identity. To count at most one QR scan per visitor, restaurant and day, we keep a SHA-256 hash of the IP address for up to 24 hours in the cache of the Cloudflare data centre that served the scan, not in a database. The restaurant sees these statistics in its dashboard. Legal basis: our legitimate interest in measuring and improving the service (Article 6(1)(f)).

Automatic menu translation. To translate a menu we send Google Gemini, through Cloudflare AI Gateway, only the menu text and the restaurant name; no guest or staff data.

Do you have to give us this data? Account and billing details are needed to enter into and perform the contract, and some are required by tax law; without them we cannot provide the service. Consent to Google Analytics is optional.

Where data comes from. Some data does not come from you directly: a team member's email is entered by the owner who invites them, your name, email and profile photo come from Google or Facebook when you sign in with them, and payment status comes from Stripe.

Guest data we process on behalf of restaurants

For each restaurant, and only on its instructions, the platform keeps:

  • Reservations: name, email, phone, party size, date and time, note, occasion (for example a birthday) and its note, dietary restrictions the guest enters, a staff note, preferred language, table, reservation status (including no-show), whether the email or phone was verified, the sign-in provider (Google or Facebook) and profile photo if the guest signed in with one, and, if given, newsletter consent with the time it was given. Pending requests also keep a hashed email-verification token.
  • Guest profiles (the guest list), per restaurant and email: name, phone, number of bookings, first and last visit, dietary information, profile photo, occasions, newsletter consent with the time it was given, and tags staff add (VIP, loves wine, always late, high or low spender, frequent visitor, vegan, vegetarian, gluten-free, nut allergy, lactose intolerant, pescatarian, halal, organic).
  • Emails to guests: the recipient, subject and content of the emails the platform sends about a reservation, including messages staff write about your reservation.
  • Reviews: a 1–5 rating, an optional comment and the source you pick (Google, Instagram, a friend or other). Reviews are anonymous: no identity is asked for or stored, and the IP address is used only to rate-limit requests.
  • Newsletter lists: only guests who gave consent. If a restaurant asks us to send a newsletter, we pass those guests' email and first name to Resend, which sends it. Every such message contains an unsubscribe link that withdraws consent.
  • Google or Facebook sign-in on the restaurant's pages: if you choose to sign in this way, we receive your name, email and profile photo from the provider and a user account is created for you on the platform.
  • Rewards card: see the next section.

The restaurant is responsible for the legal basis of this processing, for informing you and for your newsletter consent. Dietary information and some tags (for example allergies or halal) can reveal health data or religious beliefs, which are special categories of data (GDPR Article 9); we recommend that restaurants record them only with your explicit consent.

We do not use guest data for our own purposes, we do not send you our own marketing, and we do not build profiles that combine data from different restaurants.

Rewards card

The rewards card is a digital points card on the platform page /l/<restaurant>. It needs no app or account, and no Apple Wallet or Google Wallet pass is issued. The programme is run by the restaurant, which sets the points and rewards; we process the card data on its behalf. The legal basis is normally performance of the programme contract (Article 6(1)(b)) and, for newsletters, your consent (Article 6(1)(a)).

Your device is recognised by the mezenta_loyalty cookie, which holds a random code and lasts 400 days from its last use. The same cookie is used for every restaurant on the platform, but the database stores only a different hash (SHA-256) of the code for each restaurant, so your cards at different restaurants are not linked to each other. For each device we keep the dates of its first and last use.

For the card we keep the points balance and lifetime points, rewards redeemed, the dates it was created and last used, the preferred language, and a history of every earn, redemption, adjustment or merge, with the staff member who made it and an optional staff note of up to 200 characters.

Your email is optional. If you save the card, we email you a six-digit code, valid for 10 minutes with up to 5 attempts, and the email is stored only once you confirm it; the code is kept only as a cryptographic fingerprint (HMAC). The message is sent through Cloudflare Email and replies to it go to the restaurant. With a saved email you can recover the card on another device; cards with the same email at the same restaurant are merged. Staff can search members by email.

Newsletters from the restaurant: opting in is optional, the box is not pre-ticked and the card works without it. Only your choice (yes or no) is kept, without a date. On a saved card you can change it at any time on the card page.

The card page is protected by Cloudflare Turnstile when you save a card and by per-IP rate limiting. Staff use a counter screen to add and redeem points. Scan tokens are deleted 30 days after they expire.

Deletion: “Delete my card” on the card page permanently deletes the card, its devices, history and codes. “Remove from this phone” only unlinks your device; a card with no saved email that no other device holds is then deleted along with its points. The restaurant can also delete a member. Cards and their history do not expire automatically; they are kept until you or the restaurant delete them, or until the restaurant's account ends (see “How long we keep data”).

Cookies and browser storage

We use only what is listed below. Essential cookies need no consent (Article 4(5) of Greek Law 3471/2006); Google Analytics cookies are set only if you click “Accept”. We use no advertising cookies and no advertising tracking.

Essential cookies (over HTTPS the better-auth.* cookies carry the __Secure- prefix):

  • better-auth.session_token: your sign-in to the management area; up to 7 days, renewed while you use your account.
  • better-auth.session_data: a signed, short-lived copy of the session for faster page loads; 5 minutes.
  • mezenta_session_refresh: a technical marker that the session must be re-read; 5 minutes.
  • mezenta_signed_in: a hint that you are signed in, so the header links to your dashboard; it holds no credentials; 30 days.
  • mezenta_lang: the language you picked on the menu; 1 year.
  • mezenta_loyalty: your device's random code for the rewards card; 400 days from its last use.
  • Signing in with Google or Facebook, or with two-step verification, may set further technical cookies lasting a few minutes, only to complete the sign-in.

Statistics cookies, only with your consent:

  • _ga and _ga_<id>: Google Analytics, to measure traffic to our website; 2 years.

Google Analytics is used only on the public pages of our website, not in the management area or on restaurants' menus and pages, and runs in Google's Consent Mode with consent denied by default. This means Google's script loads before you choose and, until you click “Accept” or if you click “Reject”, it sends Google cookieless signals (such as that a page loaded and the consent state) without storing or reading identifiers on your device; according to Google, these signals are used only for aggregated, modelled statistics. As with any connection, Google receives your IP address.

Your choice is stored in your browser. To withdraw consent, clear the cookies and site data for mezenta.gr in your browser settings; the choice banner will then appear again.

Browser storage (localStorage and sessionStorage), which stays on your device and is not sent to us:

  • mezenta:consent (localStorage): your choice in the consent banner, until you clear it.
  • On menus (sessionStorage): the dishes you shortlist and a note that you dismissed a suggestion; cleared when the tab closes.
  • On the rewards card: mezenta-loyalty-redeem:<restaurant> (sessionStorage) for a redemption in progress until the tab closes, and mezenta-loyalty-home-hint (localStorage) so that a tip you have already seen is not shown again.
  • In the management area, on the staff member's device: the navigation menu state (dashboardNavCollapsed), an unsaved menu draft until it is saved or discarded, and the screen chosen for the rewards-card counter (localStorage); the reservations board you viewed last (reservations.board) and short confirmation messages (sessionStorage).

Recipients and processors

We share data only as far as needed, with these recipients:

  • Cloudflare: hosting and running the application (Workers), logs (Workers Logs), databases (D1), file storage and image processing (R2, Images), caching (KV), statistics (Analytics Engine), rate limiting (Rate Limiting), sending email (Email Sending), form protection (Turnstile), routing translation requests (AI Gateway) and restaurants' custom domains (Cloudflare for SaaS).
  • Stripe: payments and subscriptions. For some processing, such as fraud prevention and compliance with payments law, Stripe acts as an independent controller.
  • Google (Gemini API): automatic menu translation; it receives only the menu text and the restaurant name.
  • Google and Meta (Facebook): sign-in with a Google or Facebook account, only if you choose it; for their own sign-in services they act as independent controllers.
  • Google (Google Analytics): traffic statistics for our website, with your consent (and the cookieless signals described above).
  • Resend: sending newsletters a restaurant asks for, only to guests who gave consent; it receives email and first name.
  • Restaurants receive the data of their own guests.
  • Public authorities and courts, and our legal, accounting and tax advisers, who are bound by confidentiality, where the law requires it or it is needed to establish, exercise or defend legal claims.

These providers are also our sub-processors for guest data; we announce any change to them to restaurants 30 days in advance, as our Terms of service set out. We do not sell personal data or use it for advertising.

Transfers outside the EEA

Cloudflare serves requests from data centres worldwide, and some providers (Cloudflare, Stripe, Google, Meta and Resend) are based in, or process data in, the USA. Transfers outside the European Economic Area rely on the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) where the recipient is certified under it, and otherwise on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with supplementary measures where needed.

You can get information about these safeguards, or a copy of them, by contacting us through our contact form.

How long we keep data

  • Accounts, restaurant details, sessions, the activity log and service emails: for the term of the contract and 5 years after it ends, to establish, exercise or defend legal claims.
  • Invoices and billing records: 5 years from the end of the financial year they relate to (Article 7 of Greek Law 4308/2014), or longer where tax law requires.
  • Request and error logs: for the short period Cloudflare keeps them (currently up to 7 days), after which they are deleted automatically. The IP hash used to count QR scans: up to 24 hours.
  • Contact-form messages: not stored in the platform database; we keep the emails in our mailbox as long as needed to deal with the request and any business that follows from it.
  • Google Analytics: cookies up to 2 years; data in Google Analytics for the period set in its settings, at most 14 months.
  • Short-lived data: temporary table holds during a reservation expire after 15 minutes, rewards-card email codes after 10 minutes, and team invitations after 7 days.
  • Guest data (reservations, profiles, emails to guests, reviews, rewards cards, lists): as long as the restaurant keeps it; the restaurant can delete guests and cards at any time, and you can delete your rewards card yourself. The platform does not delete it automatically while the restaurant is a customer. After the restaurant's account ends, we delete it or return it to the restaurant within 90 days.
  • A user account created by signing in with Google or Facebook on a restaurant's page: until you ask us to delete it.

Your rights

Under Articles 15 to 22 GDPR, you have the right:

  • to access your data and get a copy (Article 15);
  • to have inaccurate or incomplete data corrected (Article 16);
  • to erasure (Article 17);
  • to restriction of processing (Article 18);
  • to portability of the data you gave us, where processing is based on contract or consent and carried out by automated means (Article 20);
  • to object to processing based on legitimate interest (Article 21);
  • not to be subject to a decision based solely on automated processing (Article 22).

Where processing is based on consent, you can withdraw it at any time, without affecting the lawfulness of processing before the withdrawal.

To exercise your rights, contact us through our contact form. Exporting or deleting an account is done on request, not from within the platform. We may ask for information to confirm your identity. We reply without undue delay and within one month at the latest; for complex or numerous requests this can be extended by two further months, in which case we will tell you. Exercising your rights is free of charge.

For data we process on behalf of a restaurant, contact the restaurant; if your request reaches us, we pass it on without delay and help the restaurant reply. You can delete your rewards card yourself on its page, and stop newsletters with the unsubscribe link.

Complaints to the Data Protection Authority

If you believe the processing of your data breaks the law, you have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, Kifisias Ave 1-3, 115 23 Athens, Greece, tel. +30 210 6475600, contact@dpa.gr, www.dpa.gr), which also offers an online complaint form, or with the supervisory authority of the Member State where you live or work. If you wish, contact us first so that we can try to resolve the matter.

Children

Our services are aimed at businesses and are not intended for children under 15. Guests under 15 should not create a rewards card or consent to newsletters (Article 21 of Greek Law 4624/2019). If you find that a child has given us data, contact us through our contact form and we will delete it.

Automated decisions

We make no decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects for you. The Turnstile check and rate limiting may temporarily block a request that looks automated; you can then try again or contact us.

Security

We apply technical and organisational measures appropriate to the risk (GDPR Article 32), including:

  • encryption of all connections (HTTPS);
  • passwords stored only as hashes, and optional two-step verification;
  • role-based access for each restaurant's team members, and an activity log;
  • separate storage of each restaurant's guest data;
  • rate limiting and protection of forms against automated use;
  • one-time codes with a limited lifetime and number of attempts.

If a personal data breach is likely to put your rights at risk, we will notify the Hellenic Data Protection Authority within 72 hours and, where required, tell you without undue delay.

Changes to this policy

We may update this policy when the service or the law changes; the date of the last update is shown at the top of this page. We tell account holders about material changes by email or in the platform before they take effect.

For questions about this policy, contact us through our contact form.

© 2026 Mezenta
Interactive menu Menu insights Reservations Restaurant website
Privacy Terms