Effective version 1.0 · Last updated June 2026
1. Roles
For restaurant customer and order data, the Restaurant is generally the Controller and MZG TECH is the Processor, except where MZG TECH acts as Controller for platform account data.
2. Processing instructions
We process personal data only on documented instructions from the Controller, including via account configuration and feature use, unless required by law.
3. Security measures
Encryption in transit, access controls, tenant isolation, audit logging, incident response procedures, and staff confidentiality obligations.
4. Subprocessors
Controllers authorize use of subprocessors for hosting, messaging, payments, and support tools. An up-to-date list is available on request at contact@qr2eat.com.
5. International transfers
Appropriate safeguards are applied for cross-border processing consistent with applicable data protection law.
6. Assistance and deletion
We assist with data subject requests where applicable and delete or return personal data upon termination subject to legal retention requirements.
Operator: Mohamed Zouaa Group Technology (MZG TECH) · Platform: QR2EAT · Contact: contact@qr2eat.com
