ServOS Privacy Policy Data controller: Point-of-Sale Unified Partners Limited (company number 16872285), registered in England and Wales, trading as “ServOS” (“ServOS”, “we”, “us”, “our”). Registered office: [Registered Office Address] Privacy contact: [privacy@serv-os.app] | Website: https://www.serv-os.app Effective date: 7 July 2026 | Version: 1.0 Our promise ServOS was built by people who have stood behind the counter. We know your data is your business: your sales, your menu, your diners, your margins. Your data is yours. We hold it so the system can run for you. We do not mine it, sell it, rent it, or hand it to anyone who would. We do not sell ads, and we do not market to your customers on our own behalf. There is no business model hiding behind your data. This Privacy Policy explains, in plain terms and as required by UK data protection law, how we handle personal data.
1.1 This policy applies to personal data we handle in connection with the ServOS platform and our websites.
1.2 You, our business customer (the venue). When you use ServOS to run your business, you decide what customer and staff data to collect and why. For that data you are the controller and ServOS is your processor: we process it on your instructions to provide the Service. Our processing terms are set out in this policy, the Data Policy, and any data processing agreement that forms part of your contract.
1.3 Your diners and your staff. Where ServOS handles data about your customers and staff, it does so on your behalf as processor. If you are a diner or staff member with a question about your data, please contact the venue you dealt with, which is the controller. We will support that venue in responding to you.
1.4 Data we control ourselves. For some data we are the controller in our own right — for example the account and contact details of the business owners and administrators we deal with, billing data, support communications, and system and security logs we use to run and protect the platform. This policy explains that processing too.
2.1 We collect only what the platform needs to do its job: ● Account and business contact data: names, roles, email addresses, phone numbers and login credentials of the people who set up and administer your account. ● Operational data that you and your staff enter or generate: orders, items, modifiers, payments, refunds, tips, cash counts, floor plans, sessions and reports. ● Your customers’ data that your venue captures: contact details, order history, loyalty balances and points, gift-card balances and history, reviews, Wi-Fi data-capture details, and marketing preferences, consents and opt-outs. ● Staff and workforce data: staff records, scheduling, timesheets, PTO, payroll and tronc/tip information you process using the workforce tools. ● Payment data, handled through our regulated Payment Processors. Card details are tokenised and processed by the Payment Processor; ServOS does not store raw card numbers. ● System and usage data: device profiles, session activity, error logs, performance metrics and feature usage.
2.2 We do not collect data you have not given us, and we do not buy data about you or your customers from anyone.
3.1 Your business and customer data is used for one purpose: running ServOS for you. That means taking orders, processing payments, syncing devices, producing your reports, powering your CRM, loyalty, gift-card and marketing tools, and supporting you when you need help. We do not use it for anything else — not analytics we sell, not products we pitch, not insights we pass on.
3.2 Aggregated, de-identified system data — stripped of anything identifying you or your diners — is what we use to keep the platform fast, stable and secure and to improve it. This data is never tied back to your venue, never sold, and never shared with advertisers.
3.3 Where we act as controller, our lawful bases under UK GDPR are: ● Contract: to provide the Service, manage your account, process billing, and provide support. ● Legitimate interests: to secure, maintain and improve the platform, prevent fraud and misuse, and communicate with you about the Service — balanced against your rights. ● Legal obligation: to meet tax, accounting, financial-record, and other legal and regulatory duties. ● Consent: where we rely on it, for example certain optional communications — which you can withdraw at any time.
3.4 Where we act as your processor, the lawful basis for processing your customers’ and staff’s data is your responsibility as controller. You must hold the appropriate lawful basis and consents.
4.1 ServOS includes loyalty, gift-card and marketing tools so you can build repeat business with your own customers. The data stays yours, we run it for you, and we do not use it for ourselves or sell it.
4.2 Marketing reaches only your own customers. We do not pool diner data across venues. One operator can never see, borrow or market to another operator’s customers. Your customer base is walled to your organisation.
4.3 You are the sender. When you send marketing through ServOS, you are the sender and controller of that activity. You are responsible for holding the right consent, honouring opt-outs and unsubscribes, and complying with marketing law, including UK GDPR and the Privacy and Electronic Communications Regulations (PECR). We give you the tools and controls; the decision to contact a customer is yours.
4.4 We do not insert our own branding, ads or messages into the communications you send.
5.1 We never sell your data or your customers’ data, and we never share it for another party’s own purposes. To deliver the Service, your data is processed by a small, vetted set of providers acting strictly on our instructions: ● Hosting and database infrastructure to store and serve your data (for example our managed cloud and database provider). ● Payment Processors — Ryft Pay Ltd and Stripe — to process card transactions securely and within financial regulation. ● Messaging providers to deliver the marketing, loyalty and transactional communications you choose to send (for example email and SMS providers). ● Delivery and order-routing partners, where you choose to use them. ● Mapping/address and AI providers that power specific in-app features.
5.2 Every one of these providers is contractually bound to process your data only to provide their service to us, and cannot use it for their own purposes, sell it or repurpose it. We maintain a current list of these sub-processors and will provide it on request.
5.3 We may also disclose data where required by law, regulation, court order or a regulator, or to establish, exercise or defend legal claims, or in connection with a reorganisation, financing or sale of our business (subject to appropriate confidentiality).
6.1 Card payments are tokenised and processed by our regulated Payment Processors through PCI-compliant infrastructure. ServOS stores only payment references (such as transaction or session identifiers and the last four digits via the processor), not full card numbers or sensitive authentication data. The Payment Processor handles the regulated payment service under its own terms and privacy notice.
7.1 We store data in regions appropriate to your market and keep transfers within frameworks that protect it. Where personal data is transferred outside the UK, we rely on an adequacy decision or appropriate safeguards (such as the International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses). Details are available on request.
8.1 While your account is active, we keep your data for as long as you need it, plus the period required to meet legal, tax and financial-record obligations.
8.2 When you leave us. When you close your account, you take a full export with you. After that, we hold your data for a retention period of [X] days. During that window your data sits dormant — it is not accessed, used, processed or shared for any purpose, except where the law requires us to retain or produce it. This window exists so an accidental closure can be reversed and our backup cycles can roll over safely. Once it ends, we securely delete your data or irreversibly de-identify it, including as it rolls out of our backups.
8.3 Aggregated, de-identified system data, which by definition cannot identify you or your customers, may be retained to keep improving the platform.
9.1 Data is encrypted in transit and at rest. Access is restricted on a least-privilege basis to what is needed to operate and support the platform. Payment data is handled through PCI-compliant infrastructure, so raw card details never touch our own storage. The platform is built for offline resilience, so a lost connection does not mean lost data.
9.2 No system is perfect. If a personal-data breach occurs, we will act promptly, tell affected customers without undue delay where required, and notify the Information Commissioner’s Office (ICO) and others as the law requires.
10.1 Depending on your relationship with us and where you are based, you may have rights under UK GDPR to: access your personal data; have inaccurate data corrected; have data erased; restrict or object to processing; data portability; and to withdraw consent where we rely on it. Where we are the controller, you can exercise these rights by contacting us at [privacy@serv-os.app].
10.2 For our business customers, the platform also gives you self-service controls: you can export your data at any time in a usable format, correct data through the platform, and request deletion, which we honour within the retention rules above.
10.3 Where a diner or staff member exercises rights in respect of data held by a venue, the venue is the controller and we support the venue in responding.
10.4 You have the right to complain to the ICO (https://ico.org.uk, helpline 0303 123 1113). We would, however, appreciate the chance to resolve your concern first.
11.1 Our websites and applications may use cookies and similar technologies that are strictly necessary to operate the Service, and, with your consent where required, others for analytics and preferences. Where applicable, a separate cookie notice provides details and choices.
12.1 The Service is provided to businesses and is not directed at children. We do not knowingly collect personal data from children through the Service in our capacity as controller.
13.1 If we change this policy, we will not bury it. We will give clear, advance notice of any change that affects how personal data is used, and we will not weaken our core commitments without telling you directly.
14.1 Questions, requests or concerns about data: [privacy@serv-os.app], Point-of-Sale Unified Partners Limited (trading as ServOS), [Registered Office Address]. This document is provided as a draft template for Point-of-Sale Unified Partners Limited (trading as ServOS). It is not a substitute for the legally binding terms in your service agreement, and it should be reviewed by qualified counsel before publication to confirm it meets your obligations under UK GDPR, the Data Protection Act 2018, PECR and PCI-DSS.