GDPR in the ordering system: servers in Germany, DPA, retention periods and access requests

Your restaurant orders, your guest data and the email dispatch are processed on servers in Germany or the EEA. For the processing carried out on behalf of your business, a ready-made data processing agreement (AV-Vertrag / DPA) is available, which you confirm in the panel; the version, the time and the email address are stored as proof. Order data is then cleaned up automatically after fixed periods, and for access or erasure requests from individual guests there is a dedicated route in the DSGVO-Bereich of the Bestellzentrale with export, anonymisation and a log.

Where the data is held

Website, orders, guest data and email dispatch run through a hosting processor with processing in Germany or the EEA. No external analytics service is used for usage measurement in the panel, and no evaluation of individual staff members is made available to the restaurant. Which providers are involved, for what purpose, on what legal basis and in which country, is set out in the privacy policy.

Who is responsible for what?

For the ordering operation your restaurant is the controller and the platform is the processor: it processes your guest data on your behalf and on your instructions. That is precisely what the DPA governs. Orders run directly through your own website, without an external portal in between – see Ordering system without commission.

Confirming the DPA and checking the status

You read the ready-made agreement and accept it in the panel. As proof, the version, the time and the email address used for acceptance are recorded. In the DSGVO-Bereich of the Bestellzentrale a status indicator shows whether your DPA is confirmed or whether something is missing (warning). If the confirmed agreement is missing, ordering operations may be restricted. Step by step: AV-Vertrag (DPA) & GDPR status.

Fixed retention periods run automatically

By default the system cleans up order data without any action from you:

  • Customer notes on an order are deleted after 30 days.
  • Completed orders are anonymised after 365 days.
  • Cancelled orders are deleted after 90 days.

Once notes have been cleaned up, the order shows the remark Keine Hinweise (retention abgelaufen). Completed orders are anonymised rather than deleted: the personal reference is removed, the order record itself remains. All periods in detail: Data retention & periods.

When a guest asks: access, erasure, anonymisation

  1. In the DSGVO-Bereich, search for that guest orders – by email, phone, order number or date.
  2. Export the overview as a file (JSON); that is the access information under Art. 15 GDPR.
  3. On the same search result, choose Anonymisieren or Stornierte löschen und den Rest anonymisieren.
  4. For safety, enter your password again.

Every operation is logged: a log records each access, anonymisation and erasure with the time and the number of records. If a guest or an authority asks later, you have dated proof. Instructions: Access (Art. 15), erasure & anonymisation.

Clearing archives is not erasure

Clearing the archive lists in the Bestellzentrale only tidies up the display and is not an erasure under data protection law. Genuine erasure or anonymisation happens only through the DSGVO-Bereich. The difference is explained under Tidying up archives.

Maps and addresses only with consent

Any function that would transmit a delivery address or coordinates to an external map, geocoding or routing service first requires the explicit consent of the guest. Without consent, the distance-based price and the map display run in an internal substitute mode: no address leaves the server, and the ordering process remains fully usable.

Services outside Germany

Some optional functions – such as message dispatch, online payment or AI functions – are provided by companies not based in Germany. They are only contacted if you switch them on or your guest consents. Push notifications about new orders to your team devices run through a delivery service based in the USA. Provider, purpose and country are named in the privacy policy.

Who is this worth it for?

For every business that accepts orders through its own website and thereby processes names, phone numbers and delivery addresses – so in practice every restaurant offering delivery or pre-orders. It is particularly helpful without a data protection department of your own: the DPA is ready to hand, the retention periods run without a reminder, and the answer to an access request is an export instead of a search through emails and notes. What your guests see in terms of mandatory information and labelling is described under Legally compliant menu.

What the system does not take off your hands

You have to confirm the DPA – the platform cannot do that for you. You also decide which optional services you switch on, and you answer your guest requests yourself; the system provides search, export, anonymisation, erasure and the log for that. This page describes what the platform provides – it does not replace legal advice for your business.

Frequently asked questions

Where is the data of my ordering system held?

The data of the ordering system – website, orders, guest data and email dispatch – is processed through a hosting processor in Germany or the EEA. Optional services with providers outside Germany are named in the privacy policy together with purpose and country.

Do I need a data processing agreement as a restaurant?

Yes: anyone who has guest data processed by a service provider needs a data processing agreement for it. The DPA is ready in the panel and is confirmed there; version, time and email address are stored as proof. If the confirmation is missing, ordering operations may be restricted.

How long is order data stored?

Customer notes on an order are deleted after 30 days, completed orders are anonymised after 365 days and cancelled orders are deleted after 90 days. These retention periods run automatically in the background, without you having to trigger anything.

How do I answer an access request under Art. 15 GDPR?

In the DSGVO-Bereich of the Bestellzentrale you search for that guest orders by email, phone, order number or date and export the overview as a JSON file. You hand this file to the guest as the access information under Art. 15 GDPR; the operation is recorded in the log.

Is clearing the archive lists a GDPR erasure?

No. Clearing the archive lists only tidies up the display in the Bestellzentrale. An erasure or anonymisation under data protection law happens exclusively through the DSGVO-Bereich, and each of these operations is logged.

Are my guest addresses transmitted to a map service?

Only after the explicit consent of the guest. Without consent, the map display and the distance calculation run in an internal substitute mode in which no address leaves the server – the guest can still order.

Am I automatically GDPR compliant with the ordering system?

No. The ordering system provides the building blocks: processing in Germany, a ready-made DPA, automatic retention periods and access, anonymisation and erasure with a log. Confirming the DPA, deciding on optional services and answering your guest requests remain your own tasks.


More on this: Legally compliant menu · Ordering system without commission · Online ordering system

How to set this up

Hear about new features first

We keep building on this capability and on the rest of the platform. Sign up and learn about every change before it shows up in your panel — short, concrete, and only when there is something to say.

Your choice about cookies and optional services

Technically necessary functions are always active. We only use optional services – such as measuring our ads – if you agree. You can change your choice at any time.