Data Processing
Roles, purposes, sub-processors and safeguards for the data we handle.
Last updated: August 11, 2026
1. Purpose
This document describes how Isa Pankei Group, SRL, through its Simple Solutions division, processes the personal data that business customers make available when using Simple Restaurant. It complements the Privacy Policy and forms part of the Terms of Service.
2. Roles of the parties
| Scenario | Controller | Processor |
|---|---|---|
| Restaurant end-customer data (conversations, orders, loyalty) | The business customer | Isa Pankei Group, SRL |
| Portal account and user data, billing and support | Isa Pankei Group, SRL | — |
| Public website visitor data | Isa Pankei Group, SRL | — |
When we act as processor, we process data only under the business's documented instructions. The business is responsible for the lawfulness of collection and for its own customers' consent.
3. Processing purposes
- Receive, triage and answer WhatsApp orders and conversations on the business's behalf.
- Send confirmations, status notifications and post-sale follow-up authorized by the business.
- Compute menu metrics: costs, margins, turnover and per-dish profitability.
- Operate loyalty programs and repurchase campaigns defined by the business.
- Provide technical support, prevent abuse and maintain service security.
We do not use end-customer data for our own purposes, do not transfer it to third parties for commercial purposes, and do not use it for advertising unrelated to the contracted service.
4. Data and data subject categories
4.1 Data subjects
- Authorized business users (owners, managers, service staff).
- End customers who message the business on WhatsApp or place orders.
- Loyalty program participants.
4.2 Data categories
- Identity and contact: name, phone number, email address.
- Communication content: messages, attachments and timestamps.
- Transactional: items, amounts, delivery address, order status.
- Loyalty: visits, points, redeemed rewards.
- Technical: session identifiers, access logs and delivery events.
We do not request special categories of data. If an end customer volunteers them in a message, they are retained as part of the conversation under the same security measures.
5. Data obtained from the Meta platform
Data we receive from Meta is used exclusively to provide the service requested by the business: identifying the connected business account, displaying and managing customer conversations, sending and receiving messages and notifications, and following up on customer interactions.
- The connection requires explicit business authorization via Facebook Login for Business.
- Tokens and credentials are stored encrypted and revoked when the account is disconnected.
- Each business accesses only its own data; isolation is enforced at application and database level.
- We do not combine one business's data with another's, nor build cross-business profiles.
6. Sub-processors
We use infrastructure providers to operate the service. All act under contract, with confidentiality obligations and security measures equivalent to our own.
| Provider | Function | Processing location |
|---|---|---|
| Meta Platforms / WhatsApp | Message delivery and receipt | US / global |
| Hosting and database provider | Application runtime and storage | US |
| Transactional email provider | Email notifications and alerts | US / EU |
| Certified payment processor | Online payments, when the business enables them | Dominican Republic |
We will inform business customers before adding a new sub-processor that handles their end customers' personal data.
7. International transfers
Some sub-processors process information outside the Dominican Republic. These transfers rely on each provider's contractual clauses and security certifications, and are limited to what is necessary to provide the service.
8. Security measures
- Encryption in transit (TLS 1.2+) and encrypted credentials and tokens at rest.
- Role-based access control and least-privilege principle.
- Logical isolation of each business's data.
- Audit logs for access, configuration changes and sensitive actions.
- Periodic backups and tested restore procedures.
- Incident management with notification to the affected business without undue delay.
9. Retention, return and deletion
We process data for the duration of the contractual relationship. On termination, the business may request an export of its data within the following 30 days. After that period we delete or anonymize the information, except what we must retain for legal obligation, fraud prevention or defense of claims.
The detailed procedure is in Data Deletion.
10. Assistance to the controller
We assist the business customer in handling access, correction, objection or erasure requests from its end customers, and in responding to requests from competent authorities. If we receive a request directly from an end customer, we forward it to the responsible business.
11. Contact
Questions about this document: hola@waffledo.com, subject "Simple Restaurant Data Processing".
Contact Information
- Legal entity:
- Isa Pankei Group, SRL
- RNC:
- 131998151
- Email:
- hola@waffledo.com
- Phone / WhatsApp:
- 1 809-752-0045
- Address:
- Máximo Avilés Blonda 13, 102, Plaza Las Lilas, Ens. Julieta, D.N., Santo Domingo, República Dominicana
- Support hours:
- Monday to Friday, 9:00 AM - 6:00 PM (GMT-4)