Tout Compris is a trade name of Macher B.V., a company registered in the Netherlands, which operates this Service.
KVK number: 92995551
VAT number: NL866242958B01
Address: Herengracht 320, 1016 CE Amsterdam
Website: www.toutcompris.nl
Privacy contact: info@toutcompris.nl
This policy applies to:
Legal basis: Performance of contract (Article 6(1)(b) GDPR)
Legal basis: Legitimate interest (Article 6(1)(f) GDPR) and compliance with employment law obligations. The restaurant operator is the Data Controller for their staff data. We act as Data Processor.
Allergy and dietary information constitutes health data under Article 9 GDPR. It is processed solely to deliver safe and appropriate service to guests, on behalf of the restaurant operator who acts as Data Controller for this data.
Online booking requests are used solely to deliver the request to the restaurant, where it becomes part of that restaurant's reservation records. To protect the public booking page against abuse, a salted, truncated hash derived from the sender's network address is stored alongside the request for rate-limiting; it cannot be reversed into the address and is deleted together with the request record. Delivered booking requests are removed from the transfer inbox within 90 days.
Legal basis: Processed on behalf of the restaurant operator as Data Controller. Where the restaurant operator relies on consent, they are responsible for obtaining and recording that consent.
Legal basis: Performance of contract and legitimate interest (Article 6(1)(b) and (f) GDPR)
When a user interacts with the built-in AI Assistant, two different things are sent to Anthropic PBC, and the difference matters:
For that reason the app displays a notice beside the chat box asking users not to type guest or staff names. What personal data, if any, reaches Anthropic through the AI Assistant is therefore determined by what your users type.
The same applies in reverse to the AI daily brief: it is generated from aggregated operational figures only and contains no free text entered by anyone.
We do not store AI Assistant conversations. They exist in the browser's memory for the length of the session and are not written to our database. Anthropic processes this data as a sub-processor under a Data Processing Agreement and Standard Contractual Clauses, and Anthropic's own data retention policies apply to it.
Legal basis: Legitimate interest in providing a functional and intelligent operational tool (Article 6(1)(f) GDPR)
This data is pseudonymised, not anonymous, and we prefer to say so precisely rather than claim more than is true. Analytics events are tagged with your account's internal identifier — a random code that means nothing outside our systems, but which is stable, so events from the same account can be linked together over time. That is what makes it pseudonymous rather than anonymous.
We do not send staff names, guest names, or the content of anything typed into the app to either service. Specifically:
It is used solely to maintain and improve the service.
Legal basis: Legitimate interest in maintaining a reliable and improving service (Article 6(1)(f) GDPR)
| Data type | Service | Location |
|---|---|---|
| All restaurant operational data | Supabase (PostgreSQL) | EU — Ireland (AWS eu-west-1) |
| Authentication | Supabase Auth | EU — Ireland |
| Error monitoring | Sentry | EU — Germany (de.sentry.io) |
| Usage analytics | PostHog | EU — EU Cloud (eu.posthog.com) |
| AI Assistant queries and invoice scanning (when used) | Anthropic PBC | United States — transferred under Standard Contractual Clauses (SCCs) |
| Subscription billing (when active) | Stripe Inc. | United States — transferred under Standard Contractual Clauses (SCCs) |
| Account emails (address confirmation, password reset) and operational notification emails (when enabled) | Resend Inc. | EU — Ireland (eu-west-1 sending region); Resend Inc. is US-based, SCCs in place |
| Hosting of the application and these legal pages | Netlify, Inc. | United States, global CDN — SCCs in place |
| Support mailbox (info@toutcompris.nl) | Antagonist B.V. | EU — Netherlands |
Everything you enter into the app is stored in Europe. Your restaurant's operational data — staff, guests, reservations, recipes, temperatures, invoices, sales — lives in a database in Ireland and is never copied anywhere else. Below is every case in which any personal data leaves the European Economic Area. We would rather list them plainly than make a shorter promise we cannot keep.
Email is not in this list: account emails and notification emails are sent from Resend's EU (Ireland) infrastructure. Resend Inc. is a United States company, so Standard Contractual Clauses cover any access from there. Notification emails go to your own account address, and depending on the notification can contain a guest's name and booking details, or the names of the staff members concerned (leave and TOIL decisions, shift swaps, certificate expiry).
Anthropic, Stripe, Resend and Netlify operate under Standard Contractual Clauses approved by the European Commission, providing an adequate level of data protection.
If you are based in the EU or UK, you have the right to:
Netherlands: Autoriteit Persoonsgegevens
UK: Information Commissioner's Office (ICO)
To exercise any of these rights, contact us at info@toutcompris.nl. We will respond within 30 days.
We engage the following third-party sub-processors to deliver the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database storage and authentication | EU (Ireland) |
| Sentry | Error monitoring and crash reporting | EU (Germany) |
| PostHog Inc. | Product analytics (pseudonymised — see section 3f) | EU Cloud |
| Anthropic PBC | AI Assistant processing and invoice OCR — only when these features are used | United States (SCCs in place) |
| Stripe Inc. | Subscription billing and payment processing — only when a paid subscription is active | United States (SCCs in place) |
| Resend Inc. | Delivery of email notifications — only when email notifications are enabled by the account holder | EU (Ireland) sending region — US parent company, SCCs in place |
| Netlify, Inc. | Web hosting and content delivery of the application and legal pages | United States, global CDN (SCCs in place) |
| Antagonist B.V. | Support mailbox hosting (info@toutcompris.nl) | EU (Netherlands) |
Our Data Processing Agreement (DPA) forms part of the Terms of Service for all business customers and takes effect automatically — no signature or separate request is required. Questions: info@toutcompris.nl.
We do not use advertising cookies or third-party tracking cookies. The application uses browser local storage to maintain your authenticated session. This is not a cookie but operates in a similar way — it persists your login across page reloads and browser restarts until you explicitly log out.
Analytics data collected via PostHog does not link usage events to individual names or email addresses. It is, however, tied to your account’s internal identifier, which makes it pseudonymised rather than anonymous — see section 3f. Error reports collected via Sentry include technical context (browser type, page URL, error message), with name-shaped text removed before the report leaves your browser.
We implement appropriate technical and organisational measures including:
Tout Compris is a business operations tool intended for use by adults in a professional context. We do not knowingly collect personal data from individuals under the age of 16. If you become aware that a minor's personal data has been submitted to the application without appropriate authorisation, please contact us at info@toutcompris.nl and we will delete it promptly.
Restaurant operators who employ staff under the age of 16 are responsible for ensuring they have the appropriate legal basis to process that staff member's data under their national employment law.
This policy is written primarily in reference to the GDPR (EU) and UK GDPR. If you are based outside the EU or UK, the following additional information applies:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale (we do not sell personal data). To exercise your CCPA rights, contact us at info@toutcompris.nl.
We apply the standards set out in this policy to all users regardless of location. If local laws in your jurisdiction provide additional rights or impose additional obligations, we will comply with those requirements to the extent applicable.
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority (Autoriteit Persoonsgegevens in the Netherlands) within 72 hours of becoming aware of the breach, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly without undue delay, in accordance with Article 34 GDPR.
If you become aware of a potential security issue affecting your data, please contact us immediately at info@toutcompris.nl.
We will notify registered customers by email of any material changes at least 14 days before they take effect. The "last updated" date and version number at the top of this page will always reflect the current version.
Macher B.V.
Herengracht 320, 1016 CE Amsterdam
Website: www.toutcompris.nl
info@toutcompris.nl