Privacy Policy
This policy explains what data Akirivent processes, whose it is and what rights you have, wherever you are in the world.
- ANSO SOFT TECH S.R.L.
- CUI: 55368302 · Reg. Com.: J2026048166009
- Calea Mihai Viteazu, Bl. 30, Et. 4, Ap. 18, Oraș Nehoiu, jud. Buzău, România
- A product by ansosoft.ro
- contact@akirivent.com
1. Two roles, stated plainly
For the professional's account (the venue, the planner) we are the controller: we decide how account data is processed. For event data (the professional's clients and their guests) the professional is the controller, and we are the processor: we host and process the data only on their instructions, for organizing the event.
2. What data we process and why
The professional's account: e-mail, password (stored cryptographically), business profile (name, phone, locations, menus, floor plans), credit and payment history (no card data; that stays with Stripe), the company data used for verification (country, tax number, the name held in the public registry). Basis: performance of the contract.
Events: end clients' names, date, location, contacts, the invitation and the schedule, entered by the professional or their clients. Basis: the controller's instructions (the professional).
Guests: family name, composition (with children's ages), menu choices and, only if declared, dietary restrictions and allergies. Allergies can be health data: they are collected only with the consent ticked on the form, shown exclusively to the hosts and the kitchen, and never appear publicly.
We never sell or rent personal data, to anyone, and we do not “share” it within the meaning of California law. We do not use data for advertising.
3. Links, not accounts
End clients and guests access everything through links with unique random tokens, without accounts. Tokens contain no names, their pages are not indexable, and no personal data ever appears in URLs. Menu files (images, PDFs) uploaded by the professional are hosted at addresses with random names, accessible to anyone with the link, so guests can open them without an account; do not upload personal data in them.
4. Where the data lives and international transfers
Data is hosted in the European Union (Supabase database, Frankfurt region), and the platform runs on Cloudflare's global network. Payments go exclusively through Stripe. For the weather forecast we send Open-Meteo only the venue's town or address, no personal data. Account e-mails (confirmation, password reset) are sent through the provider Resend. When you use the service from outside the EU, data travels encrypted between you and our servers; our providers operate under contractual safeguards (including standard contractual clauses where applicable).
5. How long we keep it
Account data: as long as the account exists. Company data (tax number, country, and the name held in the public registry) is kept for as long as the account exists: we use it to confirm once that you are a real organiser, and for invoicing. The check is made against official public registries (ANAF for Romania, VIES for the European Union); the legal basis is our legitimate interest in preventing duplicate accounts. We never ask for or store card details: payments happen entirely at Stripe. Events archive 30 days after their date and stay available to the professional; they can delete them anytime, and closing the account deletes all their events' data. Guests' personal details (people's names, allergies, restrictions, messages) are anonymised automatically 12 months after the event date; only the figures remain (how many people, how many menus of each kind), without names. After the account is closed we keep a minimal register with the country and the verified tax number (no name, no e-mail), so the same company cannot claim the free event again with a new account; the legal basis is our legitimate interest in preventing abuse, and the register is used for no other purpose. Financial-accounting documents are kept for the periods required by law.
6. No tracking
We use no tracking cookies, marketing pixels or third-party analytics. The browser locally stores only preferences (language) and, for guests, the token of their own page. That's it. Stripe may set its own cookies on its payment page, under Stripe's policy.
7. Your rights, wherever you are
Wherever you live, we honour the same rights: access, rectification, deletion, restriction, portability, objection and withdrawal of consent. Write to our contact e-mail and we answer within 30 days, free of charge and without discrimination.
EU/EEA and the UK (GDPR/UK GDPR): you may also contact your supervisory authority; in Romania, ANSPDCP (dataprotection.ro). California (CCPA/CPRA): we do not sell or share personal information; you have the right to know, correct and delete. Brazil (LGPD), Canada (PIPEDA), Australia and other jurisdictions: the same rights, through the same channel. Guests and end clients may also exercise them directly with the event's organizer (the controller of their data). We help them respond.
8. Children
The service is not directed at children: accounts require age 18, and invited children's data (age, menu) is entered by the adults of their family, strictly for seating and catering. We do not knowingly collect data directly from children.
9. Security
Row-level access rules in the database, cryptographic tokens, encrypted connections (HTTPS/HSTS), strict content policies and abuse limits. Passwords are never stored in plain text. If an incident affects personal data, we notify authorities and affected people as applicable laws require. Files and the database are hosted in the EU; administrative access is limited to the authorised persons of ANSO SOFT TECH S.R.L.
10. Changes
We review this policy at least yearly; the current version is the one published here, and important changes are announced in the platform. The policy is published in several languages; in case of discrepancies, the Romanian version prevails.
Last updated: 2 September 2026.
