smaqly
Free trial
Security & GDPR Overview

Your data is in safe hands.

Smaqly is built with security and data protection at its core. Here we summarize how we protect your and your guests' data β€” technically, organizationally, and legally. All core data is hosted in the EU.

EU hosting (Frankfurt)GDPR-compliantEncryption in transit & at rest99.9% uptime SLA

Data security

Encryption

All traffic is encrypted in transit (TLS) and data is encrypted at rest with our EU hosting providers.

Separation by restaurant

Multi-tenant isolation enforced at the database level with row-level security β€” one restaurant can never see another's data.

Access control

Role-based access per employee + additional two-factor authentication (TOTP) on sensitive administrative actions.

Full audit trail

Sensitive actions are logged with user, timestamp, and details β€” so it's always traceable who did what.

Hardened surfaces

Rate limiting, server-side input validation, and XSS protection on all public and admin surfaces.

Vulnerability management

Automatic code and dependency scanning (CodeQL + Dependabot) as well as error and threat monitoring in production (Sentry).

Infrastructure & uptime

Powered by European enterprise infrastructure

EU
hosting in Frankfurt (Supabase eu-central-1 + Vercel)
99.9%
uptime target (SLA) with credit for breaches
PITR
point-in-time backup + weekly snapshots
See live status & uptime β†’

Quality & testing

GDPR & data processing

Data remains in the EU

All core data (database, hosting, email) is stored in the EU β€” Supabase eu-central-1 (Frankfurt) + Vercel + Resend (EU).

Clear role distribution

The restaurant is the data controller, Craftory is the data processor. A data processing agreement (DPA) is established during onboarding.

The rights of the data subjects

Built-in 1-click data export (JSON), deletion, and rectification β€” so you can easily comply with access and deletion requests.

Automatic data minimization

Personally identifiable customer data (phone/address) is automatically deleted after a set retention period following the last order.

Consent & cookies

Cookie banner with granular opt-in (essential/analytics/marketing separated). Marketing consent is isolated from the order.

Breach procedure

Fixed procedure for handling and reporting security breaches to the Data Protection Authority within 72 hours.

Sub-processors

SupplierPurposeRegion
SupabaseDatabase & storageEU (Frankfurt)
VercelApplication hostingEU (Frankfurt)
ResendTransactional emailEU
FrisbiiSubscription / billingEU (DK)
FlatpayCard payment (terminal)EU (DK)
OpenAI / Anthropic / falAI features (optional)EU/USA β€” under SCC
SentryError & operational monitoringEU/USA β€” under SCC

Some sub-processors (AI, operational monitoring) may process data outside the EU under the EU Commission's standard contractual clauses (SCC). AI features are optional and activated per restaurant.

Certifications & roadmap

Smaqly is GDPR-compliant today and built according to recognized security principles. Formal SOC 2 or ISO 27001 audit is available upon request for larger customers β€” our architecture (RLS, audit trail, two-factor, monitoring, automated testing) is already designed to support that process.

Questions about security or GDPR?

Contact us β€” we are happy to send the data processing agreement and answer security questions.

Contact us β†’

Security & privacy inquiries: hello@smaqly.dk

Privacy policy & terms: smaqly.dk/legal/privacy Β· smaqly.dk/legal/terms

Data Processing Agreement (DPA) available upon request.

This is an overview, not a legal contract. Specific requirements are addressed in the data processing agreement.

Security & GDPR β€” your data is in safe hands Β· Smaqly