A3 Package A — interactionfqm.com
Privacy Policy
Privacy Policy · interactionfqm.com/articles/privacy-policy
IT Dynamic Systems GmbH · v1.3 · 07 August 2026
__________________________________________________________________________________
1. Data Controller
IT Dynamic Systems GmbH, Theresienstraße 41, 80333 München, Germany (HRB 289348). Managing Director: Yevhen Klep.
Data protection contact: ceo@itdynamicsystems.com
Supervisory Authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), www.lda.bayern.de
2. Website visitors (interactionfqm.com)
Data collected:
-
Technical data: IP address, browser, OS, visit time — automatically in log files
-
Analytics: Google Analytics 4 (only with consent via cookie banner)
-
Contact forms: name, email, message content
Legal basis & retention:
-
Technical data — legitimate interest (Art. 6(1)(f) GDPR) — 30 days
-
Analytics — consent (Art. 6(1)(a) GDPR)
-
Contact forms — contract performance (Art. 6(1)(b) GDPR)
3. Platform clients (restaurants, hotels, cafés)
Data collected:
-
Company registration data, representatives and beneficial owners (UBO 25%+)
-
Bank account details for Adyen payouts
-
Transaction data: amounts, dates, statuses, fees, payment IDs
-
Records of acceptance of Adyen and Platform terms
-
For Clients using POS integration via HubRise: order data transmitted through HubRise to the connected POS system
-
For Clients in Germany using SIGN DE through the Platform: cash register and transaction data transmitted to fiskaly Deutschland GmbH for fiscal purposes (§146a AO)
Payment provider — Adyen N.V.
Payment processing and KYC is carried out by Adyen N.V. as an independent data controller. The Platform's fee of €0.10 is deducted via Split Payment — we only receive the transaction result, not card data. Adyen Privacy Policy: adyen.com/privacy-policy.
POS integration middleware — HubRise SASU (optional, where activated):
For Clients who have activated POS connectivity through the Platform, order data (items, amounts, quantities, statuses) is transmitted via HubRise SASU (630 Route des Dolines, Valbonne, France) to the Client's connected POS system (e.g. Lightspeed Restaurant). HubRise acts as a data processor on the Platform's behalf. Data is used exclusively for order relay purposes. HubRise Privacy Policy: hubrise.com/privacy-policy.
Fiscal compliance provider — fiskaly Deutschland GmbH (Germany only, optional, where activated):
For Clients in Germany who have activated the technical fiscal compliance service, transaction data (amounts, timestamps, identifiers) is transmitted to fiskaly Deutschland GmbH (Prinzregentenstraße 54, 80538 München) — a certified TSS provider under §146a AO. fiskaly acts as a data processor on the Platform's behalf, exclusively for fiscal signing purposes. fiskaly Privacy Policy: fiskaly.com/privacy-policy.
Legal basis & retention:
-
Contract performance — Art. 6(1)(b) GDPR
-
KYC/AML — legal obligation — Art. 6(1)(c) GDPR
-
Tax records — 10 years (§147 AO, §257 HGB)
-
Fiscal data (SIGN DE) — 10 years after last transaction (§147 AO) — only where activated
-
Consent records — minimum 5 years (Adyen agreement requirement)
Multi-country note:
If the Client operates in a country where local data protection requirements apply in addition to GDPR, the Client is solely responsible for compliance with such requirements with respect to their guests' data. The Platform complies with GDPR (EU Regulation 2016/679) as the applicable standard for all Clients in the EEA.
4. Restaurant guests (Shoppers)
Card data is entered directly into the Adyen payment form — we do not receive card details (PCI DSS compliant). We only receive: transaction amount, status and ID. The restaurant is the data controller for their guests; we act as a technical processor.
5. Recipients of data
-
Adyen N.V. — payment processing and KYC (Netherlands / EEA)
-
HubRise SASU — order relay to POS systems (France / EEA) — only where POS integration is activated
-
fiskaly Deutschland GmbH — fiscal transaction signing (Germany / EEA) — only where SIGN DE is activated
-
Bis-Soft (Ukraine) — technical processor for platform maintenance (under Data Processing Agreement with SCCs under GDPR Chapter V)
-
Google LLC — analytics (only with consent, Consent Mode v2)
-
Public authorities — upon lawful request
All recipients operate within the EEA or have adequate data transfer safeguards in place (SCCs). Data transfers to Bis-Soft (Ukraine) are secured by Standard Contractual Clauses (SCCs) pursuant to GDPR Chapter V, Section 3.
6. Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21). Requests: ceo@itdynamicsystems.com. Response within 30 days. Complaints: BayLDA, www.lda.bayern.de.
Publication date: 07 August 2026
IT Dynamic Systems GmbH · Theresienstraße 41, 80333 München · ceo@itdynamicsystems.com