Informativa privacy
Aggiornata al 2 ottobre 2026 · Italiano · English
Italiano
1. Chi siamo
Omnyu (omnyu.it) è una piattaforma software per la gestione dei ristoranti: prenotazioni, ordini, clienti e fidelity, marketing, social, cassa e funzioni di intelligenza artificiale. Omnyu è un servizio di ZYU RESTAURANT S.R.L., Via Verdi 185, 20831 Seregno (MB), Italia, P.IVA IT07809480960 («Omnyu», «noi»). Per qualsiasi domanda sulla privacy scrivi a info@omnyu.it.
2. In quale ruolo trattiamo i dati
- Come titolare del trattamento per i dati di chi visita omnyu.it, di chi ci scrive o compila i moduli (richiesta demo, partner) e degli utenti del gestionale (titolari e personale dei ristoranti), per gestire il rapporto contrattuale e il servizio.
- Come responsabile del trattamento (art. 28 GDPR) per conto dei ristoranti che usano Omnyu, per i dati dei loro clienti (prenotazioni, ordini, tessere fedeltà, messaggi). Titolare è il singolo ristorante, che fornisce la propria informativa (per esempio su omnyu.it/<ristorante>/privacy). Per esercitare i diritti su quei dati rivolgiti al ristorante; se scrivi a noi, inoltriamo la richiesta.
3. Quali dati trattiamo
- Dati di contatto e contenuto delle richieste: nome, ristorante, email, telefono, messaggio.
- Dati degli account del gestionale: nome, email, ruolo, impostazioni, registro degli accessi e delle operazioni.
- Dati tecnici: indirizzo IP, tipo di dispositivo e browser, log di sicurezza e di errore, cookie tecnici.
- Dati ricevuti dalle piattaforme che un ristorante decide di collegare (sezione 4).
4. Dati dalle piattaforme collegate (TikTok, Instagram, Facebook, Google)
Un ristorante può collegare dal gestionale i propri account su piattaforme di terze parti. Il collegamento è sempre volontario, avviene con la procedura ufficiale della piattaforma e può essere revocato in qualsiasi momento. Riceviamo soltanto i dati per cui il ristorante dà l’autorizzazione.
TikTok. Con TikTok Login Kit, e solo dopo l’autorizzazione del titolare dell’account, riceviamo:
- informazioni del profilo: identificativo dell’account, nome visualizzato, nome utente, immagine del profilo, biografia, link al profilo, stato di verifica (user.info.basic, user.info.profile);
- statistiche dell’account: follower, account seguiti, like totali, numero di video (user.info.stats);
- l’elenco dei video pubblici dell’account con titolo, copertina, link, durata, visualizzazioni, like, commenti e condivisioni (video.list);
- il permesso di caricare e pubblicare sull’account i video che il ristorante sceglie (video.upload, video.publish);
- i token di accesso rilasciati da TikTok.
Usiamo questi dati esclusivamente per:
- mostrare al ristorante, dentro il suo gestionale, il proprio profilo, le statistiche e i propri video;
- pubblicare sul suo account TikTok i video che il ristorante seleziona e conferma esplicitamente, con la visibilità, le interazioni e l’eventuale dichiarazione di contenuto commerciale che sceglie lui ogni volta;
- mostrare l’esito e le statistiche dei video pubblicati tramite Omnyu.
Non vendiamo né cediamo i dati ricevuti da TikTok, non li usiamo per pubblicità o profilazione, non li incrociamo con dati di altri clienti e non li usiamo per addestrare modelli di intelligenza artificiale. I token sono conservati solo sui nostri server, non vengono mai mostrati nel browser e servono soltanto alle funzioni descritte sopra.
Instagram e Facebook (Meta), Google. Allo stesso modo, collegando una Pagina Facebook, un account Instagram professionale o servizi Google (per esempio il profilo dell’attività per le recensioni), riceviamo i dati e i permessi autorizzati dal ristorante e li usiamo solo per le funzioni richieste: pubblicare i contenuti scelti, leggere statistiche e recensioni, mostrarli nel gestionale.
Conservazione e revoca. I token restano memorizzati finché l’account resta collegato. Il ristorante può scollegarlo in ogni momento dal gestionale (Social → Account → Scollega): i token vengono cancellati subito dai nostri server e, per TikTok, chiediamo a TikTok di revocare l’accesso. Per le altre piattaforme, e in ogni caso, l’accesso si può revocare anche direttamente dalle loro impostazioni (su TikTok, nella sezione delle app collegate alle impostazioni di sicurezza). Le statistiche dei post pubblicati tramite Omnyu restano nello storico del ristorante finché non ne chiede la cancellazione o fino alla fine del contratto.
5. Finalità e basi giuridiche
- Fornire il servizio e gestire il contratto, compresa l’assistenza (art. 6.1.b GDPR).
- Rispondere alle richieste di informazioni e di demo (misure precontrattuali, art. 6.1.b).
- Adempiere obblighi di legge, per esempio fiscali e contabili (art. 6.1.c).
- Proteggere la sicurezza della piattaforma e prevenire abusi (legittimo interesse, art. 6.1.f).
- Inviare aggiornamenti sul servizio ai clienti; comunicazioni promozionali solo con consenso, revocabile in ogni momento (art. 6.1.a).
6. A chi comunichiamo i dati
Non vendiamo dati personali. Li trattano per nostro conto, sulla base dei rispettivi accordi sul trattamento dei dati, i fornitori che ci servono per erogare il servizio, tra cui:
- hosting e infrastruttura cloud (Vercel) e database (Supabase);
- invio di email (Brevo) e messaggistica WhatsApp Business (Meta Platforms);
- funzioni di intelligenza artificiale per testi e assistente (Anthropic, OpenAI e, solo se il ristorante lo sceglie con una propria chiave, Moonshot AI) e sintesi vocale (ElevenLabs);
- pagamenti (Stripe, Satispay), ordini da marketplace e consegne (HubRise e le piattaforme collegate dal ristorante), tessere nel telefono (Apple Wallet, Google Wallet);
- mappe e servizi Google, notifiche di servizio ai titolari (Telegram);
- le piattaforme che il ristorante collega (TikTok, Meta, Google), limitatamente a quanto serve a pubblicare o leggere ciò che il ristorante chiede.
Possiamo comunicare dati alle autorità quando la legge lo impone.
7. Trasferimenti fuori dall’Unione europea
Alcuni fornitori hanno sede o server fuori dall’UE, in particolare negli Stati Uniti. Verso gli Stati Uniti il trasferimento avviene sulla base dell’EU-U.S. Data Privacy Framework, per i fornitori che vi aderiscono, o delle Clausole Contrattuali Standard approvate dalla Commissione europea; verso gli altri paesi privi di una decisione di adeguatezza, sulla base delle Clausole Contrattuali Standard.
8. Per quanto tempo
- Account e dati del servizio: per la durata del contratto; alla fine, esportazione su richiesta entro 30 giorni e poi cancellazione.
- Documenti fiscali e contabili: 10 anni, come previsto dalla legge.
- Richieste di demo e contatti senza contratto: per il tempo necessario a gestire la richiesta e l’eventuale trattativa.
- Log tecnici e di sicurezza: per il tempo necessario alla sicurezza della piattaforma e alla diagnosi dei problemi.
- Token delle piattaforme collegate: fino allo scollegamento (sezione 4).
- Dati dei clienti dei ristoranti: secondo le istruzioni del ristorante; a fine contratto vengono restituiti o cancellati.
10. I tuoi diritti
Puoi chiedere l’accesso ai tuoi dati, la rettifica, la cancellazione, la limitazione, la portabilità, opporti al trattamento e revocare il consenso, scrivendo a info@omnyu.it. Rispondiamo entro un mese. Hai anche diritto di proporre reclamo al Garante per la protezione dei dati personali (garanteprivacy.it).
11. Sicurezza e minori
Le connessioni sono cifrate (HTTPS), l’accesso al gestionale richiede credenziali personali con ruoli distinti, e le chiavi delle piattaforme collegate restano solo sui server. Omnyu è un servizio per aziende e non è rivolto a minori di 14 anni.
12. Modifiche
Possiamo aggiornare questa informativa; la data in alto indica l’ultima versione. Delle modifiche rilevanti avvisiamo i clienti con un preavviso ragionevole.
English
1. Who we are
Omnyu (omnyu.it) is a restaurant management platform: reservations, orders, customers and loyalty, marketing, social media, point of sale and AI features. Omnyu is provided by ZYU RESTAURANT S.R.L., Via Verdi 185, 20831 Seregno (MB), Italia, VAT IT07809480960 («Omnyu», «we»). For any privacy question write to info@omnyu.it.
2. Our role
- Data controller for visitors of omnyu.it, people who contact us or fill in our forms, and users of the management software (restaurant owners and staff), to run the contract and the service.
- Data processor (Art. 28 GDPR) on behalf of the restaurants using Omnyu, for their customers’ data (reservations, orders, loyalty cards, messages). Each restaurant is the controller and provides its own privacy notice. Please contact the restaurant to exercise your rights on that data; if you write to us, we forward the request.
3. Data we process
- Contact details and the content of requests: name, restaurant, email, phone, message.
- Account data of the management software: name, email, role, settings, access and activity logs.
- Technical data: IP address, device and browser type, security and error logs, technical cookies.
- Data received from the platforms a restaurant chooses to connect (section 4).
4. Data from connected platforms (TikTok, Instagram, Facebook, Google)
A restaurant can connect its own accounts on third-party platforms from the management software. Connecting is always voluntary, uses the platform’s official authorization flow and can be revoked at any time. We only receive the data the restaurant authorizes.
TikTok. Through TikTok Login Kit, and only after the account owner’s authorization, we receive:
- profile information: account identifier, display name, username, avatar, bio, profile link, verification status (user.info.basic, user.info.profile);
- account statistics: followers, following, total likes, number of videos (user.info.stats);
- the list of the account’s public videos with title, cover, link, duration, views, likes, comments and shares (video.list);
- permission to upload and post to the account the videos the restaurant chooses (video.upload, video.publish);
- the access tokens issued by TikTok.
We use this data only to:
- show the restaurant, inside its own dashboard, its profile, statistics and videos;
- post to its TikTok account the videos the restaurant explicitly selects and confirms, with the privacy level, interaction settings and commercial content disclosure it chooses each time;
- show the outcome and statistics of the videos posted through Omnyu.
We do not sell or share data received from TikTok, we do not use it for advertising or profiling, we do not combine it with other customers’ data and we do not use it to train AI models. Tokens are stored only on our servers, are never exposed to the browser and are used only for the functions above.
Instagram and Facebook (Meta), Google. In the same way, when a restaurant connects a Facebook Page, an Instagram professional account or Google services (e.g. its Business Profile for reviews), we receive the data and permissions it authorizes and use them only for the requested features: posting the selected content, reading statistics and reviews, showing them in the dashboard.
Retention and revocation. Tokens are kept while the account stays connected. The restaurant can disconnect it at any time from the dashboard (Social → Account → Disconnect): tokens are deleted from our servers immediately and, for TikTok, we ask TikTok to revoke the access. For the other platforms, and in any case, access can also be revoked directly from their settings (on TikTok, in the connected apps section of the security settings). Statistics of posts published through Omnyu remain in the restaurant’s history until it asks for deletion or the contract ends.
5. Purposes and legal bases
- Providing the service and managing the contract, including support (Art. 6(1)(b) GDPR).
- Answering information and demo requests (pre-contractual steps, Art. 6(1)(b)).
- Complying with legal obligations, e.g. tax and accounting (Art. 6(1)(c)).
- Protecting the platform’s security and preventing abuse (legitimate interest, Art. 6(1)(f)).
- Sending service updates to customers; promotional messages only with consent, which can be withdrawn at any time (Art. 6(1)(a)).
6. Who receives the data
We do not sell personal data. It is processed on our behalf, under the respective data processing agreements, by the providers we need to run the service, including:
- hosting and cloud infrastructure (Vercel) and database (Supabase);
- email delivery (Brevo) and WhatsApp Business messaging (Meta Platforms);
- AI features for text and assistant (Anthropic, OpenAI and, only if the restaurant chooses it with its own key, Moonshot AI) and text-to-speech (ElevenLabs);
- payments (Stripe, Satispay), marketplace orders and deliveries (HubRise and the platforms the restaurant connects), mobile wallet cards (Apple Wallet, Google Wallet);
- Google maps and services, service notifications to owners (Telegram);
- the platforms the restaurant connects (TikTok, Meta, Google), only as needed to post or read what the restaurant asks for.
We may disclose data to authorities when required by law.
7. Transfers outside the European Union
Some providers are based or have servers outside the EU, in particular in the United States. Transfers to the United States rely on the EU-U.S. Data Privacy Framework, for providers certified under it, or on the Standard Contractual Clauses approved by the European Commission; transfers to other countries without an adequacy decision rely on the Standard Contractual Clauses.
8. Retention
- Accounts and service data: for the duration of the contract; afterwards, export on request within 30 days, then deletion.
- Tax and accounting records: 10 years, as required by law.
- Demo requests and contacts without a contract: as long as needed to handle the request and any negotiation.
- Technical and security logs: as long as needed for platform security and troubleshooting.
- Tokens of connected platforms: until disconnection (section 4).
- Restaurants’ customer data: as instructed by the restaurant; returned or deleted when the contract ends.
10. Your rights
You can request access, rectification, erasure, restriction, portability, object to processing and withdraw consent by writing to info@omnyu.it. We answer within one month. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
11. Security and minors
Connections are encrypted (HTTPS), access to the dashboard requires personal credentials with distinct roles, and the keys of connected platforms stay on our servers only. Omnyu is a business service and is not directed to children under 14.
12. Changes
We may update this notice; the date at the top shows the latest version. We give customers reasonable notice of material changes.