Privacy Policy

Notice provided under arts. 13 and 14 of Regulation (EU) 2016/679. Article 9 sets out United States privacy rights.

Last updated: September 25, 2026
NB Studio processes personal data in two distinct capacities. In respect of the data of restaurateurs, being its own customers, it acts as data controller; in respect of the data of guests which the restaurant collects through the platform — bookings and orders — it acts as processor on behalf of that restaurant. The distinction, which governs how rights are exercised, is set out in article 4.

1The controller

1.1. The controller is NB Studio di Nico Boccia, a sole proprietorship established in Italy, VAT number IT03154820645, entered in the Avellino company register under no. REA AV-302763, with registered office in Montella (AV), Italy; certified email nico.boccia@pec.it. The full postal address is provided on request from the address in clause 1.2.

1.2. Requests concerning personal data are to be addressed to privacy@useaurel.com; operational correspondence to info@useaurel.com.

1.3. No data protection officer has been designated, none of the circumstances requiring designation under art. 37 of the Regulation being present.

2Categories of data processed

2.1. Restaurateur data. Collected on registration and in the course of use of the service, comprising first and last name, role, business name, login email address, telephone and mobile numbers, WhatsApp number, certified email address, tax and VAT identifiers, electronic invoicing code, venue address and billing address. The password is stored solely in hashed form and is at no time accessible to the controller.

2.2. Venue content. Comprising menus, dish descriptions and photographs, allergens, prices, opening hours, logo and any other material published by the restaurateur.

2.3. Guest data. Collected through and on behalf of the restaurant, comprising, for bookings, name, telephone number, WhatsApp number, email address, party size and any notes; and, for takeaway or delivery orders, name, telephone number, email address, delivery address and items ordered.

2.4. Technical and navigation data. Comprising server logs, aggregate usage statistics — page views, device type, language —, IP address, processed for security and abuse prevention, and cookies, for which reference is made to the Cookie Policy.

2.5. No special categories of data within the meaning of art. 9 of the Regulation are collected, nor data relating to criminal convictions and offences. In particular, the controller does not collect social security or driving licence numbers, precise geolocation, biometric data, health data, or data revealing racial or ethnic origin, religious belief, sexual orientation or trade union membership. Payment card data is processed exclusively by Stripe and neither passes through nor is stored on the controller’s systems.

3Purposes and legal bases

3.1. Data is processed for the purposes and on the legal bases set out below.

PurposeLegal basis
Provision and management of the service: account, menu, bookings, ordersPerformance of a contract, art. 6.1.b
Invoicing and tax and accounting obligationsLegal obligation, art. 6.1.c
Processing of guest dataOn behalf of the restaurant, as processor (art. 4)
Usage statisticsConsent, art. 6.1.a, or legitimate interest, art. 6.1.f
Marketing communicationsConsent, art. 6.1.a
Security and prevention of abuse and fraudLegitimate interest, art. 6.1.f

4The controller’s dual capacity

4.1. NB Studio acts as controller in respect of restaurateur data relating to the account, invoicing and contact details, determining the purposes and means of processing independently.

4.2. NB Studio acts as processor, within the meaning of art. 28 of the Regulation and as service provider for the purposes of United States state privacy laws, in respect of guest data collected by each restaurant through the platform. In that case the restaurant is the controller and NB Studio processes the data solely on its documented instructions, for the sole purpose of providing the service. The relationship is governed by the Data Processing Agreement.

4.3. It follows that a guest wishing to exercise rights in relation to a booking or an order must address the restaurant at which the booking or order was placed. Requests received by NB Studio are forwarded to the restaurant, which is assisted in responding.

5Recipients

5.1. Personal data is not sold. For the provision of the service the controller engages the providers set out below, which act as processors or sub-processors and process the data solely for the purpose of the services rendered to the controller.

ProviderServiceLocationSafeguard
Supabase, Inc.Database and authentication; data hosted on Amazon Web Services infrastructure, London region (eu-west-2)Data: United Kingdom. Entity: SingaporeUK adequacy and Standard Contractual Clauses
Amazon Web ServicesCloud infrastructure on which Supabase operatesEntity: United States. Data: United KingdomStandard Contractual Clauses and UK adequacy
CloudflareHosting, content delivery, bot protection and image storageUnited StatesStandard Contractual Clauses
StripeSubscription payments and booking card holdsUnited States and IrelandStandard Contractual Clauses
ResendTransactional emailUnited StatesStandard Contractual Clauses
OpenAIMenu optical character recognition, assistant, translationsUnited StatesStandard Contractual Clauses

5.2. Data may be disclosed to public authorities and professional advisers where required by law.

6Selling and sharing

6.1. The controller does not sell personal information for monetary or other valuable consideration, does not share it for cross-context behavioural advertising, and does not use or disclose sensitive personal information beyond the provision of the service. None of the foregoing has occurred in the preceding twelve months, including in relation to persons under 16 years of age.

6.2. No mechanism to opt out of selling or sharing is accordingly required. Further particulars are set out in Your Privacy Choices.

7Retention

7.1. Data is retained for the periods set out below, on the expiry of which it is deleted or rendered anonymous.

Category of dataRetention period
Restaurateur account and menu configurationTerm of the contract; deletion within 30 days of termination
Invoicing and tax records10 years, by operation of law
Guest bookings and orders12 months from the date, then deleted
Page view statistics90 days
Security logsNot exceeding 12 months

8Security

8.1. The controller applies technical and organisational measures appropriate under art. 32 of the Regulation, and in particular encryption of communications by means of HTTPS/TLS, storage of passwords by means of a strong hashing algorithm, isolation of each restaurant’s data from that of every other by rules applied at database level, access to data through controlled procedures, and rate limiting and protection against automated access.

9United States privacy rights

9.1. The rights set out in this article arise under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under the comparable laws of other states. The controller extends them to residents of every state of the United States, irrespective of whether that state has enacted such a law.

9.2. The data subject has the right to know the categories of personal information collected, the sources from which it was obtained, the purposes for which it is processed and the recipients to which it has been disclosed; to obtain a copy in a portable format; to obtain deletion, save where retention is required by law; to obtain correction of inaccurate information; and not to be discriminated against for exercising any of those rights, whether by denial of service, difference in price or reduction in quality.

9.3. The rights to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information do not fall to be exercised, for the reasons set out in article 6.

9.4. Requests are made by email to privacy@useaurel.com, sent from the address associated with the account. Receipt is acknowledged within 10 business days and a substantive response is provided within 45 days, extendable once by a further 45 days upon notice of the extension and the reasons for it. Verification of identity may be required. The creation of an account is not a condition of making a request.

9.5. An authorised agent may submit a request on production of written authorisation signed by the data subject, from whom direct confirmation may be sought.

9.6. A decision may be appealed by reply to the same address. The appeal is determined by a person other than the original decision-maker within 45 days. Residents of states conferring a right of appeal may thereafter contact the Attorney General of their state; residents of California may contact the California Privacy Protection Agency.

10Children

10.1. The service is directed at businesses. The controller does not knowingly collect the personal data of persons under 16 years of age. Any such collection may be reported to privacy@useaurel.com and the data will be deleted.

11Location of data and international transfers

11.1. The database is physically hosted in the United Kingdom, London region, a country in respect of which the European Commission has adopted an adequacy decision. Certain providers are established outside the European Union, as set out in clause 5.1; transfers to those providers are governed by the Standard Contractual Clauses adopted by the European Commission or by equivalent mechanisms.

12Rights of data subjects in the European Union and the United Kingdom

12.1. Data subjects in the European Union or the United Kingdom hold, in addition to the rights set out in article 9, the rights to restrict and to object to processing, to withdraw consent at any time without prejudice to the lawfulness of processing carried out before withdrawal, and to lodge a complaint with a supervisory authority, in Italy the Garante per la protezione dei dati personali.

12.2. The Italian text of this notice is published at aureltable.com/privacy and prevails in the event of discrepancy.

13Amendments

13.1. The version in force is the one published on this page, bearing the date of last amendment shown above. Material amendments are notified in advance by appropriate means.