Who is responsible for what
WorkTable is the provider of worktable.nl and the QR ordering platform. WorkTable itself is responsible for data that you provide directly to us—for example with a pilot request, account, support question or business agreement.
When placing an order, the catering business or leisure location is usually the controller. That location determines why order, guest and payment information is needed. WorkTable then processes this data on behalf of the location. The location is therefore usually your first point of contact for questions about one specific order.
The formal name and registration details of the contracting party are stated on the quotation, order confirmation or invoice. WorkTable is located in Rotterdam and can be reached via info@worktable.nl.
What data we process
We do not process everything about everyone as standard. The data presented depends on how you use WorkTable.
A free order note or question to the menu assistant can contain information about allergies or health. Do not share a name or medical details that are not necessary. Always ask staff for confirmation if you have a serious allergy.
Why we use data
We use data to review a request, prepare an approved business portal and account invitation, publish a menu, start a guest session, process an order, track a payment, provide support and prevent abuse. A public request does not automatically create an account or paid subscription.
- Agreement or preparation therefor: for accounts, pilot requests, orders, payments and support necessary to provide the service.
- Legitimate interest: for security, fraud prevention, error investigation and business follow-up where reasonable. We weigh this against the privacy of those involved.
- Legal obligation: for example for administration or when a competent authority lawfully requests data.
- Consent: only where permission is really necessary. You can withdraw that permission.
When WorkTable is a processor, WorkTable also follows the documented instructions of the connected location.
AI: when something is forwarded
AI doesn't sit quietly everywhere. There are three concrete applications:
- Menu import: an entrepreneur can consciously have a menu file, photo, text or URL read out. The chosen source is then sent to the AI provider with relevant business context.
- Menu assistant for guests: If a guest uses this feature and the question cannot be answered locally from the map, the question, brief chat history and relevant parts of the menu can go to the AI provider. The question and answer are also logged in WorkTable to monitor limits, security and operation.
- Internal editorial: Authorized WorkTable administrators can have source notes converted into marketing or blog text, SEO fields and an appropriate blog image. The entered text and image instructions are sent to the AI provider. This is not a feature that automatically analyzes guest orders.
WorkTable uses OpenAI for this, directly or via Netlify AI Gateway. A menu assistant can make mistakes and is not a substitute for checking the location, especially for allergens. A successfully processed import file is deleted from temporary private storage. If the import fails, the file can be left there to try again.
With whom data is shared
We do not sell or share personal data for advertising profiles. Data may end up with parties that are necessary to provide the chosen function:
- the affiliated catering business or leisure location and authorized employees;
- Netlify for hosting, server functions and contact forms;
- Supabase for database, authentication and private file storage;
- Mollie when the location has activated online payment via Mollie;
- unTill when the location uses the cash register connection;
- OpenAI, possibly via Netlify AI Gateway, when an AI function is deliberately used;
- Google when a user chooses to log in with Google.
Some suppliers are located outside the European Economic Area or may process data there. In that case, a valid transfer ground must be used, such as an adequacy decision or standard contractual clauses approved by the European Commission.
Cookies and local storage
At the time of this release, WorkTable does not use advertising or analytics cookies. That's why we don't show a consent banner that has no choice. We do use functional storage that is necessary to make the site and ordering process work.
- Guest session cookie: a secure, non-JavaScript readable cookie links the browser to the correct table session. The set maximum lifespan is 16 hours.
- Login session: Supabase stores session information so that a business user can remain logged in and access can be controlled by role.
- Session storage: shopping cart and a technical reference against duplicate orders are normally only saved during the browser session.
- Local preferences: a demo ID or screen preference can remain on the device until the user clears browser data.
- Cache: the service worker can cache public pages and static files locally for speed. Order APIs are not stored by this cache.
If we add unnecessary analytics or marketing tracking later, we'll request a real choice upfront and update this statement.
How long data remains
We don't pretend that there is one retention period for everything. These are the criteria that currently apply:
- Business accounts and setup: as long as the account or agreement is active. After termination, data will be deleted or returned according to the agreements with the company, except what remains demonstrably necessary for a legal obligation or dispute.
- Guest orders, reviews and AI questions: as long as the affiliated location needs this information for service, administration or a dispute. The location determines this period; WorkTable removes them on its instructions or at the end of the service in accordance with the processing agreements.
- Financial administration: data that are part of the administration can be kept for seven years if the tax retention obligation requires this.
- Import files: after a successful AI import, the temporary source files are deleted. A failed resource can be left in private storage to restart the import.
- Technical logs: for as long as necessary for security, fault investigation and the log period set by the hosting service.
The current software does not have an automatic cleanup timer for every data category. Deletion can therefore also take place after a request or upon termination. We mention this deliberately, because otherwise “automatically removed” would be an incorrect promise.
How we protect data
WorkTable uses, among other things, encrypted connections, protected server secrets, access rights per company and role, secure session cookies and database policies that separate companies. POS login details are stored encrypted and not returned to the browser.
No online system is error-free or impenetrable. In the event of a security incident, we investigate what happened and inform the parties involved or the supervisory authority when required by law.
Your privacy rights
Depending on the situation, you can request access, correction, deletion, restriction, transfer or objection. You can also withdraw consent. Some rights have legal exceptions, for example when data is needed for financial administration or legal proceedings.
Is your request about an order at a specific location? Please contact that location first. WorkTable helps the location with the handling. For data for which WorkTable is responsible, please email info@worktable.nl. We may ask for additional information to check that the data really belongs to you.
You may also file a complaint with the Dutch Data Protection Authority.
Children and guest use
WorkTable focuses on catering and leisure locations and does not ask guests for an account. In practice, a child can view a QR menu together with a parent or supervisor. Locations that want to collect data from children must provide an appropriate basis and a clear structure. Do not enter information about a child in free fields that is not necessary for the order.
Changes and contact
We will adjust this statement if the service, suppliers or legal requirements change. The date and version are always at the top. In the event of an important change for account users, we will notify this via an appropriate route, for example by email or in the dashboard.
Privacy question, correction or seen something that is incorrect? Mail info@worktable.nl. You can also use the general terms and conditions Read for the business agreements about the use of WorkTable.