QRelia
Home Interface tour Terms Privacy Start trial
QRelia privacy framework

Privacy Policy

How QRelia handles account, Venue, Guest-order, subscription, technical and connected-Device information across the current platform.

Effective date31 July 2026
FrameworkUK GDPR and DPA 2018
Privacy contactsupport@qrelia.uk
QRelia is primarily a processor for a Venue’s Guest and operational data, while acting as a controller for its own account administration, subscription billing, security, support and service-management activities.
Contents 18 sections
Contents
1. Scope and identity 2. Controller and processor roles 3. Information we process 4. Where information comes from 5. Purposes and lawful bases 6. Sensitive information 7. QR, cookies and browser storage 8. Sharing and providers 9. International transfers 10. Retention and deletion 11. Security 12. Your rights 13. Requests and complaints 14. Analytics and automation 15. Children and age checks 16. Venue privacy duties 17. Changes 18. Contact

1. Scope and identity

This Privacy Policy explains how the QRelia hospitality software service processes personal information when people visit qrelia.uk, create or use a Venue account, administer menus and operations, subscribe, contact support, scan a QRelia QR code, submit a Guest order or use an optional connected Device.

QRelia is operated by Lukas Slivka under the QRelia name from the United Kingdom. The privacy contact is support@qrelia.uk.

This Policy covers QRelia’s own processing. A Venue may also provide its own privacy notice covering how it uses Guest, staff, payment, CCTV, booking, loyalty or other information outside QRelia.

2. Controller and processor roles

QRelia as controller

QRelia is normally the controller for information used to manage its website, enquiries, Venue-account relationship, authentication and security, subscription billing, service communications, support, diagnostics, abuse prevention, legal obligations and product administration.

QRelia as processor

For personal information entered or generated through a Venue’s Customer App, Receiver, staff accounts, operational reports and Devices, the Venue is normally the controller and QRelia is normally its processor. This includes Guest order details, location references, service notes, course assignments and staff operational activity.

Order-specific requests: A Guest should normally contact the Venue first because the Venue decides why the order information is used, how the hospitality service is delivered and how long its operational records are needed. QRelia will assist the Venue where required.

3. Information we process

Venue account and staff information

  • name, email address, business contact details and Venue affiliation;
  • account identifier, role, permissions, confirmation status, login and security information;
  • subscription plan, trial status, invoices, payment status, Stripe customer/payment-method references and billing history;
  • support messages, feedback, onboarding information and administrative actions.

Venue configuration and content

  • Venue name, address, timezone, branding, logo, social links and booking links;
  • areas, rooms, tables or other locations and their QR-code references;
  • menus, categories, items, modifiers, images, prices, availability, allergens, preparation stations and service courses;
  • Receiver, analytics, QR Print Studio and Device settings.

Guest, basket and order information

  • the Venue, area and exact location associated with a QR scan or manually selected ordering journey;
  • basket items, quantities, modifiers, wine size, prices, requests and item notes;
  • serving mode, service course, guest number and any first name or label entered for item assignment;
  • order identifier, status, estimated waiting time, timestamps and course-progress information;
  • browser/session information needed to maintain the basket, ordering window and live status.

Device and technical information

  • Device identifier, name, setup/provisioning status, firmware version, claim time and last-seen/heartbeat information;
  • operational status, selected profiles, animations and order-state signals sent to the Device;
  • IP address, browser type, operating-system information, request timestamps, error details, security logs and diagnostic events;
  • cookie and local-storage values used for authentication, security, basket continuity, preferences and consent records.

QRelia does not ordinarily receive full Venue subscription card numbers. Stripe processes card and payment-authentication details under its own privacy practices. QRelia does not process Guest-order payments as part of the standard ordering service unless a separate payment feature is expressly enabled.

4. Where information comes from

Information may come from:

  • you, when you register, configure a Venue, place an order, enter a request or contact support;
  • the Venue and its authorised owners, administrators and staff;
  • your browser or Device when it communicates with QRelia;
  • Stripe, Brevo and other providers used for billing, transactional communication, hosting, security or support;
  • integrations or data imports authorised by a Venue; and
  • public business sources where reasonably needed to verify or contact a Venue.

5. Purposes and lawful bases

PurposeTypical informationLawful basis where QRelia is controller
Provide and administer the Venue serviceAccount, role, Venue, subscription and support dataContract; steps requested before contract
Authenticate users and protect tenantsLogin, session, IP, role, anti-forgery and security eventsLegitimate interests in secure, reliable service; legal obligation where applicable
Bill the Venue and keep financial recordsPlan, invoice, payment status and Stripe referencesContract; legal obligation; legitimate interests in debt and dispute management
Send transactional service communicationsEmail, account, subscription, security and support informationContract; legitimate interests; legal obligation
Diagnose, maintain and improve QReliaLogs, errors, feature usage, performance and de-identified statisticsLegitimate interests in operating and improving the service
Prevent misuse and establish legal claimsSecurity, account, payment, support and audit informationLegitimate interests; legal obligation; establishment, exercise or defence of legal claims
Optional marketingBusiness contact and communication preferencesConsent where required, or legitimate interests where permitted with an opt-out

Where QRelia acts as processor, the Venue determines the lawful basis for Guest and staff processing and instructs QRelia through its authorised use of the Platform.

Where we rely on legitimate interests, those interests include running a secure multi-tenant SaaS service, preventing fraud and abuse, supporting Venues, maintaining records, understanding service performance and improving hospitality workflows. We consider the necessity and impact on individuals before relying on this basis.

6. Dietary, allergy and other sensitive information

A Guest or Venue may enter dietary, allergy, health, religious or other information in a request, note or guest-assignment field. Some of this may be special-category personal data and requires additional protection.

Venues should collect only what is genuinely needed for the immediate hospitality service, avoid detailed medical histories, restrict staff access and identify both an Article 6 lawful basis and an Article 9 condition where required. QRelia processes this information on the Venue’s instructions and does not use it for advertising or unrelated profiling.

Do not rely on a text field for safety: Guests with allergies or medical requirements should speak directly to Venue staff. The Venue remains responsible for allergen controls, staff communication and safe fulfilment.

7. QR access, cookies and browser storage

QRelia uses cookies, sessions and browser storage where necessary to operate its websites and applications. Depending on the surface and user journey, these technologies may:

  • authenticate Venue users and protect forms and sessions;
  • remember the correct tenant, area and location opened from a QR code;
  • maintain a Guest basket, live order continuity and the time-limited ordering window;
  • remember a theme or display preference;
  • record whether the essential-storage notice has been acknowledged; and
  • support security, load management, diagnostics and fraud prevention.

The current QRelia Guest ordering experience is designed not to use advertising or cross-site behavioural-tracking cookies. If QRelia or a Venue introduces optional storage or similar technology that legally requires consent, it should not be activated before valid consent is obtained.

On the public QRelia marketing website, Google Analytics 4 may be loaded only after the visitor selects “Accept all”. It is used to understand page usage and navigation patterns, not to provide guest-order advertising. The visitor can choose “Essential only”, reopen Cookie settings later and withdraw the analytics choice. Google may process analytics identifiers, browser and device information, approximate location derived from network information, page paths, referral information and interaction events according to Google’s service terms.

Browser controls can remove or block storage, but doing so may sign a user out, clear the basket, lose preferences or prevent ordering from working correctly.

8. Sharing and service providers

Personal information may be shared with:

  • the relevant Venue and its authorised staff, so they can receive, prepare, serve, manage and report on orders;
  • Stripe for Venue subscription billing and payment-method services;
  • Brevo or another configured communication provider for transactional email;
  • Google Analytics, only where the visitor has consented on the public marketing website;
  • hosting, database, backup, domain, security, monitoring and technical-support providers;
  • professional advisers, insurers, accountants or auditors where reasonably required;
  • courts, regulators, law enforcement or public authorities where disclosure is required or lawfully justified;
  • a purchaser, investor or successor in a genuine restructuring, incorporation, financing or sale, subject to appropriate confidentiality and data-protection safeguards.

QRelia does not sell personal information. QRelia does not allow a Venue to access another Venue’s tenant data except where explicitly authorised for support or legally required.

9. International transfers

Some service providers may process or make information accessible outside the United Kingdom. Before QRelia initiates a restricted transfer, it will use an applicable UK adequacy regulation, appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism. A transfer-risk assessment and supplementary measures will be used where required.

More information about a material transfer or safeguard can be requested at support@qrelia.uk, subject to security and commercial confidentiality.

10. Retention and deletion

QRelia keeps personal information only for as long as reasonably necessary for the purpose collected, the Venue’s instructions, security, backups, legal obligations, accounting, dispute management and establishment or defence of claims.

  • Venue accounts and subscriptions: for the active relationship and afterwards for the period needed for tax, accounting, security and legal records.
  • Guest and operational data: according to the Venue’s service needs, configuration and instructions, subject to legal and technical requirements.
  • Browser baskets and sessions: for the operational period set by the application or until the user clears browser data.
  • Security and diagnostic logs: for a limited period proportionate to investigation, service reliability and abuse-prevention needs.
  • Backups: until overwritten or securely removed through normal backup cycles.
  • Support and complaints: for as long as needed to resolve the matter and maintain an appropriate record.

When information is no longer needed, it is deleted, anonymised or made inaccessible. Deletion from active systems may not immediately remove every backup copy, but retained backup data remains protected and is not restored for ordinary use.

11. Security

QRelia uses reasonable technical and organisational measures appropriate to the Platform’s risks. These may include tenant-aware data access, authentication and roles, encrypted network transport, anti-forgery protections, access restrictions, logging, backups, subscription and provisioning controls, software maintenance and incident response.

No internet service is completely secure. Venues and users must protect credentials, local networks, browsers, exports, QR materials and Devices; grant minimum necessary access; and promptly report suspected unauthorised access or data loss.

12. Your data-protection rights

Subject to the law and circumstances, you may have the right to:

  • be informed about processing;
  • request access to your personal information;
  • correct inaccurate or incomplete information;
  • request erasure;
  • request restriction of processing;
  • receive certain information in a portable format;
  • object to processing based on legitimate interests or direct marketing;
  • withdraw consent at any time where consent is the basis, without affecting earlier lawful processing; and
  • raise concerns about solely automated decisions producing legal or similarly significant effects.
Right to object: You may object at any time to direct marketing. You may also object to processing based on legitimate interests; we will stop unless there are compelling legitimate grounds or the processing is needed for legal claims.

Rights are not absolute. We may need to verify identity, clarify the request, protect another person’s rights or retain information where law permits or requires it. We will not charge a fee unless a request is manifestly unfounded or excessive and the law allows a reasonable fee.

13. Requests and data-protection complaints

How to make a request

Email support@qrelia.uk with enough information to identify the relevant Venue, account, order or interaction. For Guest-order data, contacting the Venue first is usually the fastest route because the Venue is normally the controller.

How to make a complaint

Put “Data protection complaint” in the subject line and explain what happened, the relevant dates, the Venue or account involved and the outcome sought. QRelia will provide a clear complaints route, acknowledge the complaint within 30 days, investigate it appropriately and communicate the outcome without undue delay.

You may also complain to the UK Information Commissioner’s Office. Its current contact and complaint information is available at ico.org.uk. We would appreciate the opportunity to address the concern first, but this does not restrict your right to contact the ICO.

14. Analytics, forecasts and automated processing

QRelia may automatically calculate operational statistics, best sellers, completion rates, service-time measures, preparation-station results, weather overlays and forecasts. These outputs assist Venue management and do not by themselves make decisions producing legal or similarly significant effects about a person.

QRelia may use aggregated or de-identified usage information to understand performance and improve the Platform. Information is not treated as anonymous if a person can still reasonably be identified from it.

15. Children and age-restricted service

Venue administration and subscriptions are not intended for children. The Guest ordering interface may be encountered by families or younger guests, but QRelia does not knowingly require a child to create a personal account for ordinary QR ordering.

The Venue is responsible for age checks and lawful service of alcohol or other age-restricted products. QRelia’s interface, QR scan or order submission is not proof of age or authority to purchase.

16. Venue privacy responsibilities

A Venue using QRelia should:

  • provide an accurate privacy notice to Guests and staff;
  • identify lawful bases and, where applicable, special-category conditions;
  • collect only necessary information and avoid using free-text fields for excessive personal data;
  • control staff roles, exports, Receiver visibility and access to order history;
  • set and document appropriate retention and deletion practices;
  • respond to rights requests and complaints and involve QRelia where processor assistance is needed;
  • maintain appropriate operational and device security; and
  • notify QRelia promptly of suspected cross-tenant access, compromise or personal-data breach involving the Platform.

17. Changes to this Policy

We may update this Policy when QRelia’s features, providers, data uses or legal obligations change. The effective date at the top will be updated. Material changes may also be notified through the Platform or account email where appropriate.

A new use of personal information that is incompatible with the original purpose will not be introduced merely by changing this page; QRelia will identify an appropriate lawful basis and provide any additional notice or consent required by law.

18. Contact details

Service: QRelia

Operator and privacy contact: Lukas Slivka

Country of establishment: United Kingdom

Email: support@qrelia.uk

Website: qrelia.uk

Formal business correspondence details, controller/processor documentation and current core-subprocessor information are available on reasonable request.
© 2026 QRelia. All rights reserved.
Home Terms Privacy Contact
Your cookie choice QRelia uses essential cookies for site operation and security. With your permission, Google Analytics helps us understand how the public site is used. Privacy and cookies