Privacy Policy

Privacy Policy

Last updated: 12 July 2026

Σύνοψη στα ελληνικά

Ποιοι είμαστε. Η edrink Ι.Κ.Ε. (Αριστοτέλους 11-13, Αθήνα 104 32, ΑΦΜ 802281720) είναι ο υπεύθυνος επεξεργασίας των προσωπικών σας δεδομένων όταν χρησιμοποιείτε την εφαρμογή και τον ιστότοπο edrink.

Τι συλλέγουμε και γιατί. Στοιχεία λογαριασμού και κρατήσεων για να εκτελούμε τις κρατήσεις σας (εκτέλεση σύμβασης)· στοιχεία πληρωμής μέσω Stripe (δεν αποθηκεύουμε τον πλήρη αριθμό της κάρτας σας)· δεδομένα χρήσης και συσκευής για αναλύσεις και ασφάλεια· τοποθεσία GPS μόνο με τη συγκατάθεσή σας. Σημειώσεις για αλλεργίες ή διατροφικές ανάγκες είναι ευαίσθητα δεδομένα: τις επεξεργαζόμαστε και τις διαβιβάζουμε στο κατάστημα μόνο με τη ρητή συγκατάθεσή σας, την οποία μπορείτε να ανακαλέσετε ανά πάσα στιγμή. Οι σημειώσεις διατηρούνται ώστε το κατάστημα να μπορεί να σας εξυπηρετεί σωστά και σε επόμενες επισκέψεις· μπορείτε να ζητήσετε τη διαγραφή τους οποτεδήποτε.

Με ποιους τα μοιραζόμαστε. Με το κατάστημα όπου κάνετε κράτηση (το οποίο γίνεται ανεξάρτητος υπεύθυνος επεξεργασίας για τα δεδομένα που λαμβάνει) και με παρόχους υπηρεσιών (φιλοξενία στη Φρανκφούρτη, πληρωμές, email/SMS, αναλύσεις). Όπου δεδομένα μεταφέρονται εκτός ΕΟΧ, εφαρμόζονται οι εγγυήσεις του ΓΚΠΔ (τυποποιημένες συμβατικές ρήτρες, Πλαίσιο Προστασίας Δεδομένων ΕΕ-ΗΠΑ, απόφαση επάρκειας).

Πόσο τα κρατάμε. Συγκεκριμένες περίοδοι ανά κατηγορία: δείτε τον πίνακα διατήρησης παρακάτω. Ορισμένα φορολογικά στοιχεία διατηρούνται έως 10 έτη βάσει ελληνικής νομοθεσίας.

Τα δικαιώματά σας. Πρόσβαση, διόρθωση, διαγραφή, περιορισμός, φορητότητα, εναντίωση (ιδίως στην εμπορική προώθηση και την εξατομίκευση) και ανάκληση συγκατάθεσης, χωρίς χρέωση και με απάντηση εντός ενός μηνός. Μπορείτε να διαγράψετε τον λογαριασμό σας μέσα από την εφαρμογή. Έχετε δικαίωμα καταγγελίας στην Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (dpa.gr, Κηφισίας 1-3, Αθήνα, contact@dpa.gr).

Επικοινωνία. support@edrink.gr

Η πλήρης πολιτική ακολουθεί στα αγγλικά.

Privacy at a glance

  • Who we are: edrink P.C., an Athens-based company. We are the controller for the edrink app and website. More
  • What we collect: account and reservation details, payment data (handled by Stripe; we never see your full card number), device and usage data, and GPS location only if you allow it. More
  • Allergies & dietary needs: health-related data. We process and share these notes with the venue only with your explicit consent; they are kept so venues can serve you correctly on future visits, and you can have them deleted at any time. More
  • Why we use it: every purpose is mapped to a legal basis in one table, with no vague “improving our services” catch-alls. More
  • Venues: when you book, we send the venue only what it needs to host you. From that moment the venue is independently responsible for its copy of your data. More
  • Who else gets it: a named list of our service providers, what they do, and where they process data. We never sell your personal data. More
  • Where it lives: our servers are in Frankfurt, Germany (EU). Transfers outside the EEA are covered by named safeguards, vendor by vendor. More
  • How long: concrete retention periods per data category; see the table. More
  • Your rights: access, correction, deletion, portability, objection, and consent withdrawal. Requests are free, answered within one month, and you can delete your account yourself in the app. More
  • Marketing: with your consent, or, for existing customers, emails about similar edrink services with an opt-out in every message. One-tap unsubscribe, and you can object to personalisation at any time. More

1. Who we are

edrink Private Company (Ι.Κ.Ε.), 11-13 Aristotelous St, Athens 104 32, Greece (Tax ID: 802281720, General Commercial Registry (GEMI) no. 173565201000) is the data controller for the personal data described in this policy, which means we decide how and why that data is processed.

For anything relating to your personal data, contact us at support@edrink.gr or by post at the address above. Our designated privacy lead handles all data protection requests.

2. What this policy covers

This policy covers personal data we process when you use the edrink mobile app, the edrink website, reservations made through Reserve with Google, and when you contact our support team or receive our communications.

It does not cover:

  • What venues do with your data after you book. Restaurants, bars and other venues on edrink are independent businesses. Section 6 explains exactly what we send them and where our responsibility ends and theirs begins.
  • Venue owners and staff. If you represent a venue that partners with edrink, contact us at support@edrink.gr for information about how we handle your business data.
  • Cookies in detail. Our Cookie Policy, available on our website, lists every cookie and similar technology we use. Section 10 below summarises how consent works.

3. The data we collect

3.1 Data you give us

  • Account data: name, email address, phone number, and password (stored hashed).
  • Reservation data: venue, date and time, party size, and the status of your booking (confirmed, seated, cancelled, no-show).
  • Special requests: free-text notes you add to a booking, for example a birthday, a stroller, or dietary needs. See the box below for how we treat allergy and dietary information.
  • Payment data: where a venue requires a deposit or prepayment, payment is processed by Stripe. Your full card details go directly to Stripe and never touch our servers; we receive only a payment confirmation, the last four digits, and the card brand.
  • Support conversations: messages you exchange with our support team (via Intercom chat or email).

3.2 Data collected automatically

  • Device and technical data: IP address, device model and OS, app version, language, and device identifiers (including the mobile advertising identifier, only where you have consented; see Section 10).
  • Usage data: screens viewed, searches, taps, and session length, collected via analytics tools subject to your cookie/SDK consent.
  • Precise location (GPS): only if you grant the app location permission, and only while you use the app, to show venues near you. This is optional: you can always search by area instead, and you can revoke the permission in your device settings at any time.

3.3 Data from third parties

  • Social login: if you sign in with Google, Apple or Facebook, we receive your name and email address (or Apple’s private relay address) from that provider.
  • Reserve with Google: if you book an edrink venue through Google, we receive your name, contact details and reservation details from Google in order to place and manage the booking. This policy applies to that data from the moment we receive it.

Allergies, dietary and religious dietary needs: special category data. Notes about allergies or intolerances are health data, and notes about halal, kosher or similar needs can reveal religious beliefs. Under EU law (GDPR Article 9) these are special categories of data that require extra protection. We handle them as follows:

  • The special request field exists so we can pass your requests to the venue you are booking. Everything you write there is shared with that venue, and only with that venue, so it can host you.
  • Include health-related or dietary information only if you want the venue to know it. By writing such information in your note and submitting the booking, you give your explicit consent for us to share it with that venue and for the note to be kept, by us with your reservation history and by that venue in its guest records, solely so that you are served correctly on this and future visits (for example, so the venue remembers an allergy even if you forget to mention it next time).
  • We never use these notes for marketing, advertising, profiling or recommendations, and venues may not use them for anything other than serving you.
  • You can have any note deleted at any time: edit or remove it on an upcoming reservation in the app, or contact us at support@edrink.gr and we will delete it and instruct the venue to do the same.

3.4 What you must provide, and what is optional

To create an account and make a booking we need your name, email address and phone number; without these we cannot provide the service, because venues need to know who is coming and how to reach you. Everything else (special requests, dietary notes, location access, marketing preferences) is optional, and declining it never affects your ability to book.

4. Why we use your data, and our legal basis for each purpose

Under the GDPR we must have a legal basis for every use of your personal data. This table is the complete list; we do not use your data for purposes that are not on it.

PurposeData usedLegal basis
Creating and managing your accountAccount dataContract (Art. 6(1)(b))
Taking, changing, cancelling and honouring your reservations, and sending you booking confirmations and reminders (email, SMS, push)Account, reservation and contact dataContract (Art. 6(1)(b))
Sending your booking details to the venue you choseName, phone, party size, date/time; booking status; non-sensitive special request notes (e.g. a birthday or a stroller)Contract (Art. 6(1)(b); the transmission is the service you asked for)
Passing allergy / dietary / other sensitive notes to the venue, and keeping them so you are served correctly on future visitsSpecial requests containing special category dataExplicit consent (Art. 9(2)(a), together with Art. 6(1)(a)), given by writing the information in your note and submitting the booking, as explained in this policy; withdrawable at any time
Processing deposits and prepaymentsPayment data (via Stripe)Contract (Art. 6(1)(b))
Answering your support requestsSupport conversations, account and reservation dataContract (Art. 6(1)(b))
Showing venues near youPrecise GPS locationConsent (Art. 6(1)(a)), via the device location permission
Personalising venue rankings, recommendations and coupons inside the appReservation history, searches, saved venuesLegitimate interests (Art. 6(1)(f)): showing you relevant venues rather than a random list. We assessed that this limited, in-app personalisation does not override your rights; it involves no sensitive data and has no legal or similarly significant effect on you. You can object at any time (see Section 5).
Marketing emails and push notifications about edrink offersContact data, marketing preferencesConsent (Art. 6(1)(a)). Additionally, where we obtained your email address in connection with a paid booking made in our own app or website (never through third-party channels such as Reserve with Google), we may email you about similar edrink services on the basis of legitimate interests (Art. 6(1)(f), Recital 47), as permitted by Greek Law 3471/2006 Art. 11(3), always with an opt-out in every message
Product analytics (understanding how the app is used)Usage and device dataConsent (Art. 6(1)(a)), collected through our cookie/tracking consent tool (see Section 10)
Measuring which app-install campaigns work (mobile attribution)Advertising identifier, install sourceConsent (Art. 6(1)(a)), via the consent tool and, on iOS, App Tracking Transparency
Preventing fraud and abuse, enforcing our no-show policy, and securing our systemsDevice data, logs, reservation historyLegitimate interests (Art. 6(1)(f)): protecting our platform, our venues and other diners from abuse. Balancing assessment available on request.
Keeping accounting and tax recordsTransaction and invoice recordsLegal obligation (Art. 6(1)(c), Greek tax and accounting law)
Establishing, exercising or defending legal claimsThe data relevant to the claimLegitimate interests (Art. 6(1)(f))

5. Personalisation, marketing and automated decisions

Personalisation. We use your reservation history and in-app activity to rank venues, suggest places you might like, and occasionally offer you coupons. This is a limited form of profiling. It does not use sensitive data, and no decision with legal or similarly significant effects is made about you this way.

Your right to object. You can object to personalisation and profiling at any time by emailing us at support@edrink.gr. If you object to personalisation for direct marketing purposes, we stop immediately and unconditionally. The app keeps working; you simply see non-personalised results.

Marketing. We send marketing emails and push notifications only as described in the table in Section 4. Every marketing email has an unsubscribe link; push notifications can be turned off in the app or your device settings; and all marketing preferences live in your account settings.

Automated decisions. We do not make any decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22).

6. edrink and venues: who is responsible for what

6.1 When you book

To fulfil your reservation, we send the venue: your first and last name, phone number, party size, the date and time, your booking status, and any special request notes. Where a note contains sensitive information (allergies, dietary needs), we send it only on the basis of your explicit consent, given as described in Section 3; the venue may keep it in its guest records solely to serve you on future visits, until you withdraw your consent or request deletion. We do not send the venue your email address, your location data, or your activity on edrink.

From the moment the venue receives this data, it processes it as an independent data controller under its own responsibility and its own privacy policy, for example to prepare your table or comply with its own legal obligations. Our agreements with venues restrict them from using data received through edrink for anything beyond hosting your reservation and their legal obligations, but we are not responsible for a venue’s own processing. Ask the venue directly about its privacy practices.

6.2 Venue marketing

Venues may not use your contact details for their own marketing unless you separately opt in to that venue’s communications. If you do opt in, the venue is solely responsible for that marketing and for honouring your opt-out.

6.3 Where we work for venues

We provide venues with reservation-management tools (their digital reservation book). When we host and maintain a venue’s guest records in those tools, we act as the venue’s processor under a data processing agreement (GDPR Art. 28): the venue decides what happens to its guest book, and we act on its instructions.

Where a venue moves to edrink from another reservation system, we may, at the venue’s request, import the venue’s existing guest and reservation records into that venue’s own records on our platform. The venue is responsible for ensuring it may lawfully transfer this data and for informing the people concerned. We act only as the venue’s processor for these records: they are never used for our own purposes, never feed your edrink account or our recommendations, are never shared with any other venue, and no marketing to you results from them.

7. Who else receives your data

We never sell your personal data. Beyond venues (Section 6), your data is handled by the providers below. Most act as processors on our instructions under GDPR Art. 28 contracts; the ones marked † act as independent controllers under their own privacy policies.

ProviderWhat it does for usProcessing locationTransfer safeguard
DigitalOceanHosting of our servers and databasesFrankfurt, Germany (EU)EU processing; Standard Contractual Clauses in our data processing agreement for any access from outside the EEA
Stripe †Payments, deposits, payouts to venues (independent controller for its own regulatory obligations, e.g. anti-fraud and financial compliance)EU / USEU-US Data Privacy Framework; SCCs
Google (Firebase, Analytics)App infrastructure, push notifications, analytics (analytics only with your consent)EU / USEU-US Data Privacy Framework
Google (Reserve with Google) †Bookings you start on Google (independent controller for your interaction with Google’s own services)EU / USEU-US Data Privacy Framework
Twilio / SendGridSMS and email delivery (confirmations, reminders)USEU-US Data Privacy Framework; SCCs
BulkerSMSSMS delivery in GreeceGreece (EU)Not applicable (EU processing)
IntercomSupport chatEU / USEU-US Data Privacy Framework; SCCs
AppsFlyerMobile install attribution (only with your consent)EU / IsraelEuropean Commission adequacy decision for Israel
Apple / Google / Meta †Social login, if you choose it (independent controllers for the sign-in service itself)USEU-US Data Privacy Framework
Accountants, auditors, lawyers †Professional services under confidentiality (independent controllers by law)Greece (EU)Not applicable (EU processing)

We may also disclose data where the law requires it (for example to tax authorities, courts, or the police on a valid legal order), and, in the event of a merger, acquisition, corporate restructuring or sale of assets, to the parties and advisers involved; see Section 13.

8. International data transfers

Your data is stored on servers in Frankfurt, Germany, inside the EU. Some of the providers listed in Section 7 process data in the United States or Israel. Where that happens, the transfer is protected by one of the GDPR’s approved mechanisms, as listed per provider in the table above: the European Commission’s adequacy decisions (including the EU-US Data Privacy Framework for certified US providers, and the adequacy decision for Israel), and/or the Commission’s Standard Contractual Clauses together with supplementary measures where needed. You can request a copy of the relevant safeguards by contacting us.

9. How long we keep your data

DataHow longWhy
Account dataWhile your account is active. If you are inactive for 3 years, we notify you and then delete the account.Providing the service
Reservation history (no payment involved)While your account is active; deleted or pseudonymised when you delete your accountProviding the service; no-show enforcement
Transaction and invoice records (deposits, prepayments)5 years, or up to 10 years where Greek tax law requires it, with identifiers accessible only on a need-to-know basisGreek tax and accounting law
Special request / dietary notesKept with your reservation history, and in the guest records of the venue(s) you shared them with, until you delete them, withdraw consent, or delete your accountYour explicit consent
Support conversations2 years after the ticket closesService quality, dispute handling
Analytics data14 monthsProduct improvement
System and security logs12 monthsSecurity, fraud prevention
BackupsRolling ~90 daysDisaster recovery
Records of consent given and withdrawn5 years after withdrawalDemonstrating compliance (Greek limitation periods)

Where we must keep transaction records for tax law after you delete your account, we pseudonymise them: your name, contact details and any notes are removed from operational systems and the retained record is accessible only for the legal purpose. We are transparent that this is pseudonymisation: the retained record remains subject to the GDPR and to the protections in this policy until it is finally deleted.

10. Cookies, SDKs and consent

We use cookies and similar technologies (including mobile SDKs) as described in our Cookie Policy, available on our website. Strictly necessary cookies run without consent. Everything else (analytics, attribution and any advertising technology) runs only after you consent through our consent banner (web) or consent screen (app), as required by Greek Law 3471/2006. You can change your choices at any time via the website footer or the app’s settings, and on iOS we additionally respect your App Tracking Transparency choice.

11. Your rights

Under the GDPR you have the right to:

  • Access your data and get a copy (Art. 15);
  • Correct inaccurate data (Art. 16); you can edit most of it yourself in account settings;
  • Delete your data (Art. 17); see Section 12 for the self-serve path;
  • Restrict processing while a dispute or verification is pending (Art. 18);
  • Portability: receive the data you gave us in a machine-readable format, or have it sent to another provider (Art. 20);
  • Object (Art. 21); see the box below;
  • Withdraw any consent at any time (Art. 7(3)), as easily as you gave it, without affecting past processing.

Right to object (Article 21 GDPR). Where we process your data on the basis of legitimate interests (personalisation, fraud prevention), you have the right to object at any time, on grounds relating to your particular situation. Where your data is used for direct marketing, you can object at any time, without giving any reason, and we will stop immediately.

How to exercise your rights: in your account settings, or by emailing support@edrink.gr. We respond within one month (extendable by two further months for complex requests; if so, we will tell you within the first month). Exercising your rights is free; we may ask you to verify your identity so we do not hand your data to someone else. We will only refuse or charge for requests that are manifestly unfounded or excessive, and we will explain why (Art. 12(5)).

Complaints. You can lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, www.dpa.gr, contact@dpa.gr, +30 210 6475600, or with the supervisory authority of the EU country where you live or work. We would appreciate the chance to resolve your concern first, but you do not have to contact us before going to the authority.

12. Deleting your account and data

You can delete your account in three ways: directly in the app (in your account settings), via the account-deletion form on our website, or by emailing us at support@edrink.gr.

When you delete your account we erase your profile, preferences, saved venues, dietary notes and support history from our live systems within 30 days; copies in encrypted backups expire automatically within roughly 90 days. Transaction records that Greek tax law obliges us to keep are pseudonymised as described in Section 9 and deleted at the end of the statutory period. If you signed in with Apple, Google or Facebook, we also revoke the connection on our side.

13. Security, age limits, and corporate changes

Security. All traffic is encrypted in transit (TLS); passwords are stored hashed; access to personal data is role-restricted and logged; our processors are bound to equivalent standards. If a personal data breach occurs, we will notify the Hellenic DPA within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to you. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.

Age limits. edrink is a service for booking venues that serve alcohol; you must be 18 or older. We do not knowingly collect data from anyone under 18, and we delete such data if we become aware of it.

Corporate changes. If edrink is involved in a merger, acquisition, corporate restructuring (including a change of the group parent company) or sale of assets, your data may be transferred to the successor entity. Any successor remains bound by this policy, and your data remains protected by the GDPR regardless of where the new controller is established. If the controller of your data changes, we will inform you prominently, in the app and by email, before the change takes effect, and remind you of your rights, including deletion.

14. Changes to this policy

When we change this policy, we will post the new version here with a new date. For material changes (new purposes, new categories of recipients, changes to your rights) we will notify you in the app or by email before the change takes effect, and where a new processing purpose requires consent, we will ask for it rather than assume it. Previous versions are available on request.

15. Contact us

edrink Private Company (Ι.Κ.Ε.)
11-13 Aristotelous St, Athens 104 32, Greece
support@edrink.gr

Supervisory authority: Hellenic Data Protection Authority, Kifissias 1-3, 115 23 Athens. Website: www.dpa.gr. Email: contact@dpa.gr. Phone: +30 210 6475600.

© 2026 edrink

Privacy Policy

Terms

Cookies

Support

Venue Support

For Businesses