M meni.ge
Start free
Back to Home

Privacy Policy – Cenaly / meni

Last updated: October 3, 2026

This Privacy Policy explains how Individual Entrepreneur ANDREI VERBITSKII (Identification Number 305573448) ("we", "us", "our") processes personal data in connection with the Cenaly / meni platform.

The Policy covers our services under the brands and domains meni.ge, cenaly.com, cenaly.ru, cenaly.tr, masamenu.tr and menugo.al, including their websites, administrative and customer-facing interfaces, CRM, API services and mobile applications, including Cenaly Phone for iOS and Android (together, the "Service"). Which data is processed depends on the features you or the business you interact with use. A feature described for one application or infrastructure is not necessarily available in every application or country.

We process personal data subject to applicable data-protection law, including the Law of Georgia on Personal Data Protection and, where applicable, the EU General Data Protection Regulation (GDPR). Country-specific provisions are set out in section 14.

Language and translations: This Privacy Policy is drafted in English, which is the original and legally binding version. Translations are provided for convenience. If a translation differs from the English version, the English version prevails to the extent permitted by applicable law. This does not limit mandatory rights under local law.

1. Identity, contact details and our roles

Individual Entrepreneur ANDREI VERBITSKII
Registered in the Republic of Georgia
Identification Number: 305573448
Registered address: Georgia, Tbilisi, Vake district, s. Chikovani street, N 24a, hall 2, flat N36a
Contact email for privacy matters: info@meni.ge

This privacy contact serves all the brands listed above.

When we act as controller. We determine the purposes and means of processing personal data needed to administer our relationship with users and business customers, operate platform accounts, protect the Service, manage billing, respond to support and privacy requests, and meet our own legal obligations. For those purposes, we are the data controller (or operator, where that term is used by applicable law).

When we act for a business. Businesses use the Service to manage their customers, guests, employees, orders, appointments, communications and documents. Where a business determines why and how that information is used and we process it on its documented instructions, the business is the controller and we act as its processor. This includes business call records, recordings, transcripts and call-assistant content where the business enables these features. A business's use of our software does not transfer its responsibility for choosing lawful purposes, informing individuals, obtaining any required consent or deciding appropriate access and retention to us. We remain responsible for our own obligations as a processor and for any processing we carry out for our own purposes.

If your request concerns information controlled by a business using the Service, contact that business first. You may also contact us; we will help identify the appropriate controller and assist it in handling the request. We handle requests about data we control directly.

2. Scope of this Policy

This Policy applies to owners, staff and other authorised users of business accounts; customers and guests using customer-facing services; people who communicate with a business through our tools; and visitors who contact or use our platform.

The Service supports different types of business and may include catalogues of products or services, menus, orders, reservations and appointments, customer relationship management, staff administration, websites and widgets, business telephony, mobile workplace applications, and document and AI-assisted features.

This Policy describes the platform's processing. It does not replace a business's own privacy notice about its relationship with its customers or employees, or the notices of an independent payment, communications or other provider selected by that business. The specific provisions on telephony and Cenaly Phone are in section 3.10; recipients and processing locations are in sections 6–7.

3. Personal data we collect

Depending on how you use the Service, we may collect the following categories of data.

3.1 Registration and account data

  • Email address and, where used by the relevant feature, phone number
  • Name, business contact details and business information
  • Account identifier, business and location identifiers, staff role and access permissions
  • Authentication credentials and tokens, login timestamps, and security-related session and network data
  • Records showing the version of legal documents accepted and the choices or permissions you have provided

A business may create a staff account and provide these details on a staff member's behalf. Cenaly Phone uses an existing account or an access method issued by the business; it does not provide independent account registration.

3.1a Content upload metadata

When you upload content (menu items, photos, descriptions) to the Service, we collect:

  • Upload timestamps and dates
  • User account identifier associated with each upload
  • File metadata (file name, size, format, EXIF data where applicable)
  • Modification history (who edited content and when)
  • Content identifiers and storage locations

This metadata is necessary for system operation, content management, and to comply with legal obligations, including responding to intellectual property infringement claims.

3.2 Customer, business contact and service information

When a business uses the Service to handle a customer interaction, we process the information supplied by the customer, the business or its authorised staff. Depending on the feature, this may include:

  • Customer or contact name, phone number and email address
  • Delivery or service address and instructions
  • Order, reservation or appointment details, preferences, messages and notes
  • Customer relationship records and links between an interaction and the relevant business contact
  • Staff information and business documents entered into the business account

For example, an authorised Cenaly Phone user can save a caller's name and number to the business's customer database or add a note to an existing customer record. Section 3.10 distinguishes this action from contacts kept only on the phone.

Where we process this information on a business's instructions, the business is the controller and we are its processor. The business must have a lawful basis for the information it enters, provide the required information to the people concerned, limit access appropriately and use the information only for lawful purposes. Do not enter sensitive information unless the relevant feature and your legal basis permit it.

3.3 Geolocation data

  • Device location data (GPS, Wi-Fi, Bluetooth or similar), if you grant us access in your device or browser
  • Approximate location derived from your IP address, where permitted by law

3.4 Order and transaction data

  • Items ordered, date, time and place of order
  • Table number or area (where applicable)
  • Order status and basic payment-related metadata (for example, method of payment, payment status)

As a rule, payment card data is processed by external payment providers in accordance with their own privacy policies. We do not store full card numbers or CVV/CVC codes.

3.4a Reservation and booking data

When you make a table reservation through the Service, we collect:

  • Reservation details (date, time, number of guests)
  • Special requests or notes related to your reservation
  • Reservation status and history
  • Cancellation or modification data

3.4b Copyright infringement and content moderation data

To enforce our Terms of Service and respond to intellectual property infringement claims, we may collect and process:

  • Copyright infringement notices and counter-notifications received
  • Contact information of rights holders and their authorized representatives
  • Evidence of infringement (URLs, screenshots, descriptions of allegedly infringing content)
  • Records of content removal requests and actions taken
  • History of copyright violations associated with user accounts
  • Communication between us, rights holders, and users regarding infringement claims
  • Documentation of repeat infringer status

This data is processed to:

  • Comply with intellectual property laws and legal obligations
  • Respond to valid takedown notices
  • Enforce our repeat infringer policy
  • Protect the rights of copyright owners and other rights holders
  • Defend against false or abusive infringement claims
  • Maintain records for potential legal proceedings

Legal bases:

  • Compliance with legal obligations (Art. 6(1)(c) GDPR) – to respond to valid legal notices
  • Our legitimate interests (Art. 6(1)(f) GDPR) – to protect intellectual property rights, prevent abuse, and enforce our Terms of Service
  • Establishment, exercise or defence of legal claims (Art. 9(2)(f) GDPR where applicable)

Retention: Copyright infringement records are retained for up to 5 years from the date of the incident or longer if required for ongoing legal proceedings or to comply with legal obligations.

3.5 Photo and caricature data

  • Photograph you upload or provide via your device's camera
  • Caricature image generated from your photo
  • Technical data and internal identifiers necessary to create, associate and store the caricature in your account

3.5a Dietary preferences and restrictions

If you choose to provide this information, we may collect:

  • Food preferences (for example, vegetarian, vegan)
  • Dietary restrictions or allergies (for example, gluten-free, lactose intolerance, nut allergies)
  • Special dietary requirements for religious or health reasons

This information is provided voluntarily and is used only to help venues better serve you and ensure your safety.

3.6 Device and technical data

To ensure correct display and convenient repeat orders, we collect basic technical information, such as:

  • Device type (for example, smartphone, tablet), operating system and version
  • Screen size, orientation and other display parameters
  • Browser or app version, language settings
  • IP address and other technical identifiers (for example, device or installation ID)
  • Log data about app events (for example, opening screens, button clicks, page load errors)
  • Push notification tokens (if you enable push notifications)

3.6a Push notification data

Where push notifications are available and used, we process the push token, installation or device connection identifier, relevant account or business connection, platform, app version and notification settings needed to route and maintain notifications.

Cenaly Phone uses Apple's Push Notification service (APNs / PushKit) on iOS and Firebase Cloud Messaging (FCM) on Android where configured to deliver incoming-call notifications. The call-wake payload contains technical call and connection identifiers and an expiry time; caller details are retrieved through the authorised call connection rather than included in that wake payload. Apple or Google processes the token and delivery information needed to deliver the notification.

Phone permissions and platform rules affect delivery. Disabling notifications or background operation may prevent incoming calls from being presented reliably while the app is inactive. Disconnecting a device or signing out also affects its registration, as explained in section 10.

3.7 Usage history and communication data

  • History of your orders in venues that use our platform
  • History of your interactions with different venues (for example, which venue you visited and when)
  • Messages sent to venues via the Service
  • Feedback, ratings and support requests related to venues or to the platform

3.8 Error and diagnostic data

We use our own error-telemetry system to investigate faults, protect reporting endpoints and maintain the Service. Depending on the source of a report, the information may include an error message and stack trace, application and build version, technical events leading to a problem, browser or operating-system details, device and network information, and timestamps. Web error reports use page paths without query strings or fragments and do not intentionally capture form values or the contents of orders and messages.

Staff and business-owner error reports may include pseudonymous account identifiers and a business location identifier. Pseudonymous identifiers remain personal data where they can be associated with a person; hashing is not the same as anonymisation.

The server also records the sending IP address and technical network-path information, including declared proxy information and network-provider details. We use this to prevent abuse, investigate technical problems and assess report reliability, not to build advertising profiles from diagnostic reports.

In Cenaly Phone, choosing "Send to support" submits a technical report that may include the app log, call-connection or line-check results, and device and operating-system details. You can also keep a report locally or share it through a device sharing function where offered; sharing sends it to the recipient you select. Credentials and other sensitive strings are filtered, but you should review a report before voluntarily sharing it. Routine server security and operational logging is separate from this user-triggered report.

Raw reports in our error-telemetry system are retained for 30 days. Error-group records and aggregates, which may include a limited set of network addresses, are retained for up to 400 days. A report used in a support or security investigation may be retained with that case for as long as needed to resolve it or meet a legal obligation. Hosting providers process this information as part of operating our infrastructure; using our own collection system does not mean that no cloud provider is involved.

3.9 Consent and preference data

  • Your consents and preferences (for example, consent to analytics, geolocation, camera use for photos)
  • Records of your requests regarding your data (access, deletion, etc.) and our responses

3.10 Business telephony and Cenaly Phone

Cenaly Phone is a business calling application for iOS and Android. Your business supplies or authorises your account, extension and access to its phone system. The features available to you depend on its configuration, your role, your device and the relevant infrastructure.

Account and connection information. We process your login email and account identifier, the business and location you work with, your extension, and device connection information. This includes connection or installation identifiers, the device label, relevant device/app information and push tokens. These details connect the phone to the business's phone system, authenticate it and route calls and notifications.

Calls and call records. Making or receiving a call transmits the audio needed for the call. The phone system also processes call metadata, including numbers, available caller names, date and time, direction, duration, route and outcome. Your business controls which authorised users can access its call records. Transmitting live audio to carry a call is distinct from retaining a recording or creating a transcript.

Contacts and customer records. Phone contacts or contacts saved only for your own use are handled locally by the relevant feature; Cenaly Phone does not automatically synchronise your entire device address book to the business. Dialling a number sends that number to the phone system. If you choose to save a contact for the business, the caller's number, the name and any description you provide are sent to the business's customer database. Choosing to add a customer note sends the note and the relevant customer/call reference; the record may identify the staff member who made it. This information becomes available to authorised users of that business. Choosing a local-only save does not create a business customer record.

Recordings, speech recognition and AI assistance. Where enabled by the business, a call may be recorded, transcribed, analysed or processed by a live call assistant. A permitted staff member may also request recording of a current call where that feature is available. Live transcription or AI assistance may process speech even when a retained audio recording is not requested. Resulting data may include audio files, recognised speech, summaries, call tags or assessments, and suggestions shown to staff. Audio, transcript excerpts and relevant business context may be sent to the speech-recognition and AI providers described in section 6. The provider depends on the feature, infrastructure and configuration; not every call uses every provider.

Notices and permission. The business is responsible for establishing a lawful basis, informing staff and other call participants, and obtaining consent where required, including for recording, monitoring and external AI processing. Available recording tools include a spoken announcement, an audible signal and, in supported consent-based recording flows, asking the other participant to press a key before recording starts. The applicable options depend on the call policy and phone-system configuration. A display on an employee's screen or a brief beep is not a substitute for any notice or active consent required by law. Your device's microphone permission and your business's feature setting do not by themselves constitute every participant's consent to recording or to sharing personal data with an AI provider. The business must not use a feature where the necessary notice, permission or other legal requirement has not been met.

Device permissions and your choices. Microphone access is used for calling and related voice features. Where offered, camera access supports QR sign-in and supported video features; device-contact access is requested by the contact feature. Availability differs between iOS and Android. You can manage permissions in your device settings, decline optional actions, stop an on-demand recording where you have access to that control, disconnect the phone or sign out. These actions do not automatically erase the business's existing records. Sections 8 and 10 explain retention and requests for deletion.

Cenaly Phone does not use call audio, business customer records or device contacts to serve advertising or track you across other companies' apps and websites. Its calling features do not collect precise device location or advertising identifiers. This description of Cenaly Phone is separate from the optional web analytics and marketing technologies described in section 5.

4. Purposes and legal bases for processing

Under the GDPR we must have a legal basis for each processing purpose. Depending on the situation, we rely on:

  • Performance of a contract (Article 6(1)(b) GDPR)
  • Compliance with legal obligations (Article 6(1)(c) GDPR)
  • Legitimate interests (Article 6(1)(f) GDPR)
  • Your consent (Article 6(1)(a) GDPR)

4.1 Providing and operating the Service

We process personal data to administer accounts and access, operate the business features described in section 2, route customer requests and communications, provide support, manage our commercial relationship with customers, and maintain security and service reliability.

For processing where we act as controller, we rely on performance of a contract where the processing is necessary for a contract with the individual concerned; legitimate interests in operating and protecting the Service where those interests are not overridden by the individual's rights; legal obligations where applicable; or consent for processing that requires it. A contract with a business is not automatically a contract with each of its employees or customers.

For business-controlled information, including customer and staff records, we process data on the business's documented instructions. The business is responsible for identifying the lawful basis for its purposes. Our processor agreement and this Policy do not replace that responsibility.

4.1a Content upload and management

We process content upload metadata to:

  • Track who uploaded or modified content
  • Maintain version history and audit trails
  • Enable content management and organization
  • Provide attribution for uploaded content
  • Comply with legal obligations regarding content ownership and responsibility

Legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR) – to provide content management features
  • Our legitimate interests (Art. 6(1)(f) GDPR) – to maintain system integrity and accountability
  • Compliance with legal obligations (Art. 6(1)(c) GDPR) – to respond to legal requests

4.1b Copyright infringement prevention and enforcement

We process personal data related to copyright infringement claims to:

  • Receive and evaluate copyright infringement notices and counter-notifications
  • Identify and remove content that infringes third-party intellectual property rights
  • Communicate with rights holders, users, and their representatives
  • Enforce our Terms of Service and repeat infringer policy
  • Maintain records of infringement claims and actions taken
  • Defend against false or abusive infringement claims
  • Comply with intellectual property laws and legal obligations
  • Protect the legitimate interests of copyright owners and the integrity of our platform

Legal bases:

  • Compliance with legal obligations (Art. 6(1)(c) GDPR) – to respond to valid legal notices and comply with intellectual property laws
  • Our legitimate interests (Art. 6(1)(f) GDPR) – to prevent abuse, protect intellectual property rights, enforce our Terms of Service, and maintain the integrity of our platform
  • Establishment, exercise or defence of legal claims – where processing is necessary for potential or ongoing legal proceedings

Important: When we receive a valid copyright infringement notice, we may:

  • Remove or disable access to the allegedly infringing content
  • Notify the user who uploaded the content
  • Share relevant parts of the infringement notice with the user (excluding personal details not required by law)
  • Maintain records of the incident for enforcement of our repeat infringer policy
  • Suspend or terminate accounts of repeat infringers

Your rights: If your content was removed due to a copyright claim you believe was made in error, you may submit a counter-notification as described in our Terms of Service. We will process your counter-notification and may restore the content if the original complainant does not initiate legal proceedings.

4.2 Geolocation

We use geolocation to:

  • Show you relevant venues or the correct menu for your location
  • Associate your order with the correct venue (and in some cases table)
  • Prevent fraud and misuse (for example, abnormal locations or automated requests)

Legal bases:

  • Your consent to precise location (Art. 6(1)(a) GDPR) – when you allow the browser/app to access your location
  • Our legitimate interests (Art. 6(1)(f) GDPR) in using approximate IP-based location where permitted

You can disable geolocation in your device or browser settings at any time. This does not affect processing carried out before such change but may limit some features.

4.3 Photos and caricatures

We process photos and caricatures to:

  • Create a caricature from your photograph using our algorithms or third-party tools
  • Display the caricature in your account and, where configured by a venue, to staff (for example, for a more personalized experience)

Legal basis:

  • Your consent (Art. 6(1)(a) GDPR) – you choose whether to provide a photo

You can remove your photos and caricatures via your account or via the data deletion page, or by contacting us.

4.3a Push notifications

Where supported, notifications provide order or reservation updates, service messages and incoming-call alerts. Necessary transactional notifications support the requested service; optional marketing notifications require the applicable marketing permission and a way to opt out. Enabling an operating-system notification permission does not by itself authorise marketing.

For our controller purposes, the legal basis is performance of a contract where applicable, a legitimate interest in necessary service and security communications, or consent where required. For business-controlled notifications, the business determines the lawful basis for its message.

You can manage notification permissions on your device. Disabling notifications may reduce the reliability of incoming-call alerts and other time-sensitive features. Removing a permission does not itself delete previously held business records or guarantee that a server-side token is removed immediately.

4.4 Order history and venue interaction history

We keep history of your orders and interactions with venues to:

  • Help you see previous orders and re-order faster
  • Enable venues to understand your previous interactions with them (for example, to resolve disputes, remember preferences where allowed by law)
  • Comply with accounting, tax and consumer protection obligations
  • Protect our rights and the rights of venues and users in case of disputes

Legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR)
  • Compliance with legal obligations (Art. 6(1)(c) GDPR)
  • Our legitimate interests in service quality and dispute resolution (Art. 6(1)(f) GDPR)

4.5 Device and technical data

We use device and technical data to:

  • Ensure that the Service displays correctly on your device
  • Remember basic settings to make repeat orders more convenient (for example, language or interface layout)
  • Maintain the security and stability of the platform
  • Diagnose and fix technical problems

Legal basis:

  • Our legitimate interests (Art. 6(1)(f) GDPR) – to provide a secure, stable and convenient Service

4.5a Error monitoring and support diagnostics

We process the diagnostic information described in section 3.8 to investigate faults and support requests, prevent abuse and maintain service security and reliability. For our controller purposes, this is based on our legitimate interests, assessed against the rights of the people concerned, and on responding to the support service requested. Reports handled for a business are also subject to its instructions where we act as processor.

4.6 Essential service technologies

The Service uses authentication and session technologies, local application or browser storage, hosting, content delivery, and operational diagnostics. International infrastructure uses AWS services, including Cognito for relevant account authentication; the Russian infrastructure uses its Yandex-hosted authentication and data services. Storage and processing locations vary as explained in section 7.

The data and technologies used by a web page can differ from those used by a native mobile application. Optional web analytics and marketing tools are described in section 5 and the Cookie Policy. They must not be treated as essential merely because they are available on a business software website.

4.7 Telephony, mobile connections and call assistance

We process the information in section 3.10 to authenticate authorised users, connect devices, make and receive business calls, display permitted call history and caller information, deliver incoming-call notifications, save the customer information users choose to submit, and diagnose connection problems.

Where the business enables recording, transcription, call analysis or AI assistance, we process the necessary audio and text to provide those functions on its instructions. The business must identify an appropriate legal basis for each purpose and comply with applicable communications, employment and data-protection requirements. If consent is required, it must cover the relevant processing and be obtained before that processing begins. Sensitive data may require additional conditions beyond an ordinary contract or legitimate interest.

For our own account administration, security, billing and support purposes, the controller bases described in section 4.1 apply. An operating-system permission controls access to a device capability; it is not a blanket legal basis for every subsequent use of the data.

5. Advertising, analytics and sale of data

We do not sell or rent personal data as a commercial product. Business call audio, transcripts and customer records are processed to provide the configured business features, not to create advertising audiences for our own marketing.

On web surfaces, optional analytics and marketing integrations may be used where configured for the brand and permitted by the applicable consent settings and law. These include Google Analytics, Meta Pixel and server-side registration conversion reporting, and Yandex Metrika. Depending on the integration, data may include page and interaction information, campaign identifiers, browser/device and network information, and registration conversion information. Identifiers may be used to attribute a visit or registration to an advertisement. These activities are separate from error diagnostics and must not be described as an absence of all analytics or advertising-related processing.

Where consent is required, optional processing must wait for it. You can manage available choices through the website's consent controls. Businesses may separately configure integrations on their customer-facing services and are responsible for their own notices and legal bases.

Cenaly Phone's calling functionality does not include these web advertising integrations. A link opened from the app to a website is subject to the technologies and choices applicable to that website. See the Cookie Policy for further information about web technologies.

6. Recipients of personal data

We disclose information to the people and providers needed for the relevant service, subject to the user's or business's access permissions and applicable law.

6.1 Businesses and authorised users

A business and its authorised staff receive the customer, staff and communication information they are entitled to access. For example, a customer record saved from Cenaly Phone is available within that business, and call recordings or transcripts are available according to its configured permissions. A business's independent use of that information is governed by its own responsibilities and privacy notice.

6.2 Hosting, authentication and delivery

  • Amazon Web Services (AWS): hosting, data storage, relevant account authentication, content delivery, email delivery (Amazon SES) and operational services for international infrastructure. This can involve account and business data, files, technical identifiers and request/network information.
  • Yandex Cloud: hosting, object storage, databases, email delivery (Yandex Cloud Postbox) and related operational services for Russian infrastructure. Authentication on that infrastructure is handled by our Yandex-hosted services.
  • Sign-in providers you choose: if you sign in with Google or, on cenaly.com, with Apple — or, on cenaly.ru, with Google, VK ID, Gosuslugi (ESIA), Yandex ID or Sber ID — that provider authenticates you and returns the identifiers and profile details you authorise (typically your name and email address). The provider processes your sign-in under its own terms and privacy notice.
  • Apple APNs / PushKit: delivery of incoming-call notifications on supported iOS installations; push tokens, technical routing identifiers and delivery information.
  • Google Firebase Cloud Messaging (FCM): delivery of incoming-call notifications on Android installations where configured; push tokens, technical routing identifiers and delivery information.

The operating-system notification service is distinct from advertising or analytics. The storage location of a business account does not mean that Apple or Google's notification infrastructure operates only in that country.

6.3 Speech recognition and AI providers

When a business enables a relevant feature, the following providers may receive the data needed to produce its result:

Feature and route Provider Data involved
Transcription of stored recordings on international infrastructure Amazon Transcribe; Google Cloud Speech-to-Text or Microsoft Azure Speech where that engine is selected and available Audio, language and technical job information
Live speech recognition, call-assistant or voice features on international infrastructure OpenAI or Amazon Transcribe, depending on the feature Audio or audio segments and technical context needed for recognition
Transcription and supported speech features on Russian infrastructure Yandex SpeechKit Audio or audio segments, language and technical job information
Call summaries, analysis and AI suggestions on international infrastructure OpenAI, including requests routed through the polza.ai gateway where configured Transcript excerpts, prompts, relevant business or knowledge-base context and generated responses
Supported AI text features on Russian infrastructure YandexGPT by default; an optional external route where explicitly selected, available and lawfully enabled Relevant text, prompts, business context and generated responses

The polza.ai gateway is an additional recipient where used; routing through a gateway does not remove the involvement of the selected model provider. Optional foreign routes may send data outside the account's storage country. Knowledge Base processing is described further in section 6a.

We require providers processing data on our behalf to protect it and restrict processing to the authorised purposes under applicable service and data-processing arrangements. Provider retention and any use for provider purposes depend on the applicable arrangement; the mere fact that an API is used is not a promise of zero retention or a universal exclusion from model training. Contact us for information about the providers and arrangements relevant to a feature before submitting data for which those conditions are important.

6.4 Connected services, communications and payments

Payments for our own services. When a business pays us for a subscription, a balance top-up or an add-on, the payment is made on the page of the payment provider selected at checkout — currently PayPal, Airwallex or AsiaBill — or by bank transfer against an invoice. The provider receives the amount, currency and order reference from us and the payment details you enter on its page; we do not receive full card numbers. Payment providers may act as independent controllers for their own legal, anti-fraud and accounting obligations.

Services connected by a business. A business may connect its own telephone carrier, communications channel, payment service or other integration. The information necessary to carry out the requested call, communication, payment or other action is shared with that provider. A carrier or payment provider may act as an independent controller for its own legal and operational purposes. Its own notice and terms apply to that processing.

Optional web analytics and advertising-related recipients, where enabled, are described in section 5 and the Cookie Policy. They are separate from the business telephony and diagnostic purposes described above.

6.5 Support, professional advisers and authorities

Information may also be available to authorised support personnel and service providers, or disclosed to professional advisers and competent authorities where needed for support, security, compliance with law, resolution of a claim or protection of legal rights. We limit the information to what is necessary for that purpose. Where we act for a business, disclosures remain subject to its instructions unless the law requires otherwise.

6a. AI processing of Knowledge Base content

6a.1 Information and purpose

When a business uploads or collects Knowledge Base materials, we process their contents, associated file/source information, and the queries submitted to the feature. Text or images may contain personal data. We process business-controlled content on the business's instructions to prepare, search and use its Knowledge Base and to provide the AI-assisted features it enables.

Relevant text extracts, images submitted for recognition and queries may be sent to the providers used for embeddings, optical character recognition, answer generation and other enabled AI functions. International routes use OpenAI and, for relevant guest-assistant features, Google; Yandex Cloud provides the corresponding domestic services for Russian infrastructure. Configured gateways and optional external routes are additional recipients as described in section 6.

6a.2 Storage and optional external processing

The principal infrastructure locations are described in section 7. International Knowledge Base processing may involve the United States; the Russian infrastructure stores Knowledge Base materials in Russia and uses its domestic AI route by default.

Where the Russian Knowledge Base feature offers a separate choice of an external text-generation provider, enabling it can send the text included in a request through the configured gateway to a foreign model provider. This selection does not by itself move the stored originals or change the domestic embedding and OCR routes. It is not an assurance that the text contains no personal data, and it does not replace any required notice, consent, transfer mechanism or regulatory notification.

6a.3 Retention, deletion and rights

A business can delete its Knowledge Base documents through the relevant controls or request assistance. Deleting a source document does not necessarily erase every previously generated result, training material, interaction log or cached answer that used it. Provider-held copies are subject to the relevant provider's retention arrangements.

If you need deletion of related outputs or logs, identify them in your request to the business or to the contact in section 1. We handle data we control directly and assist the business with data we process on its behalf, subject to applicable retention obligations. Sections 8–10 apply.

6b. Website compliance check tool (cenaly.ru)

The cenaly.ru website offers a free tool, available without an account, that checks a website address you enter for technical signs of risks under Russian law.

What we process. The address of the website you check (reduced to the site itself: the path and parameters of the address are discarded), the resulting report, a one-time page token, and technical data of your request: a salted hash of your IP address (the address itself is not stored), the time of the request and service data of the bot-protection check. The checked website is opened in a browser on our servers; its forms are not submitted, and we do not collect personal data of its visitors. Please do not enter addresses that contain passwords, access tokens or private links.

Purposes and legal basis. Providing the report you request; protecting the tool against abuse and automated mass requests; limiting the load our checks place on third-party websites. We rely on the performance of your request and on our legitimate interest in operating a free and secure tool.

Recipients. Yandex Cloud (hosting and storage; the YandexGPT model may receive the text of public pages of the checked website when a document is ambiguous) and Yandex SmartCaptcha (invisible bot check that processes technical data of your browser and your IP address under Yandex's terms).

Storage and retention. Data is stored in Yandex Cloud in the Russian Federation. A report is available only to the person who started the check, through a token kept in their browser, for 30 days. A "share" link is valid for 7 days and can be revoked earlier. Request counters and IP hashes are deleted after 7 days.

Disputing a finding. If you own a website that has been checked and disagree with a finding, contact us using the details in section 1. The report is an automated check of technical signs, not a legal opinion.

7. Storage locations and international transfers

The principal storage and service infrastructure depends on the brand:

Brand Principal infrastructure
meni.ge, cenaly.com, menugo.al AWS infrastructure, principally in the United States (us-east-1)
cenaly.tr, masamenu.tr AWS storage in Frankfurt, Germany (eu-central-1), with shared API and authentication services in the United States
cenaly.ru Yandex Cloud infrastructure in the Russian Federation (ru-central1)

Call media may be held in a separate archive storage tier of the relevant infrastructure. Older files may remain in the original data store. An archive tier changes storage arrangements, not the purpose of processing or the individual's rights.

Content-delivery networks, telephone carriers, notification services and the AI providers described in section 6 can process data in additional countries. Access to data by authorised personnel and providers may also constitute an international transfer. Selecting Russian storage does not by itself establish that every notification, external integration or optional AI request stays in Russia.

Where a transfer is subject to the GDPR or other restrictions on international transfers, the relevant lawful mechanism and safeguards must apply to that transfer. These may include an applicable adequacy decision or appropriate contractual safeguards, together with any additional measures required by law. An exception based on consent is not a general replacement for safeguards for ongoing processing, and acceptance of this Policy is not blanket consent to international transfers of other people's data.

You can contact us for information about the destinations, recipients and safeguards relevant to your use of the Service. Businesses remain responsible for their own controller duties; we remain responsible for the transfers and processing for which we are accountable. The additional provisions for Russian infrastructure are in section 14.2.

8. Retention of personal data

We retain personal data for the period necessary for the relevant purpose, taking account of the nature of the information, the relationship with the individual or business, applicable legal obligations and the need to resolve a specific dispute or security incident.

Account, billing and support information

Account and access information is retained while needed to provide and protect the account. Following a deletion or closure request, some billing, transaction, support, legal-acceptance and security records may need to remain for an applicable statutory period or a specific unresolved matter. The applicable period depends on the record and jurisdiction; there is no single five-year period for every category. We explain the relevant retention reason when responding to a deletion request.

Business-controlled content

A business determines retention for its customer, staff, document and communication records, subject to applicable law. We provide storage and available deletion controls on its instructions. Businesses should select periods appropriate to their purposes rather than retaining personal data indefinitely merely because storage is available.

Calls, recordings, transcripts and AI outputs

Phone-system source recordings and the records held in the Calls workspace have separate retention settings. Where a positive expiry period is configured, the relevant deletion process applies that period. A setting of zero can mean that automatic expiry is disabled. Turning off new recording is not a request to delete existing recordings and may also affect scheduled removal of phone-system source files.

Removing an audio file does not necessarily remove its transcript, call metadata, customer note or AI-generated output. Similarly, expiry of a transcript does not necessarily delete the call record. These categories may require their own retention settings or a separate deletion request. Data exported by the business or already sent to an independent provider is subject to that recipient's applicable obligations and retention arrangements.

Device and push registrations

Connection and push-registration information is kept while needed for the registered connection and related operational purposes. The app requests removal of its registration when a user signs out or disconnects the relevant phone. A device permission change or app uninstall is not itself confirmation that all server-held information has been erased.

Diagnostics and remaining copies

Error-telemetry retention is described in section 3.8: raw events for 30 days and error-group records for up to 400 days. Support cases, security investigations, backups and audit records can have different retention needs. We do not promise that deleting one visible item instantly removes all backups, derived records or copies already held by another controller. Requests should identify the related records where possible; we will explain any lawful reason for retaining information and arrange appropriate deletion or restriction when it is no longer needed.

9. Your data-protection rights

Depending on the law that applies to your data and the processing concerned, you may have rights to obtain information and access or a copy, correct inaccurate information, request erasure or restriction, receive portable data where applicable, object to certain processing, withdraw consent and complain to a competent supervisory authority. Where the GDPR applies, these include the rights under Articles 15–22, subject to their conditions and exceptions.

Withdrawing consent does not affect processing already lawfully carried out on that consent, or processing that continues on another applicable legal basis. A request for erasure may be limited by a legal retention requirement or another lawful exception; we will explain the reason when applicable.

To exercise your rights, contact info@meni.ge. Provide enough information to identify your account or the business and interaction concerned, but do not send unnecessary identity documents or sensitive information. We may seek proportionate confirmation of identity before disclosing or changing records.

For business-controlled information, we assist the business as explained in section 1. You may contact us even if you no longer work for that business or cannot access the account. We respond within the time limits applicable to the particular request and jurisdiction and explain any lawful refusal or extension. Contacting us does not prevent you from complaining to the competent authority.

10. Account access, deletion and mobile controls

Cenaly Phone does not offer independent registration: accounts or device access are supplied by the business. Its settings allow you to disconnect the phone or sign out. This stops or changes that connection and initiates removal of the relevant registration; it does not itself delete your staff account, the business account, or existing call and customer records.

To request deletion of an employer-created account or personal information associated with it, contact the business administrator or info@meni.ge. We handle requests for data we control and assist the business with data it controls. The business may be required to retain some records after employment or access ends, but ending access does not remove your data-protection rights.

Business administrators can use the available record-deletion controls and may request assistance with account closure and related data. Specify whether the request covers recordings, transcripts, call metadata, customer notes or other related information; deleting one category does not automatically request deletion of all the others. Section 8 describes retention limits and exceptions.

You can manage microphone, camera, contact and notification permissions in your operating-system settings where those permissions apply. Disabling a permission may limit a feature. Uninstalling the app, withdrawing a device permission or signing out does not erase records already held by the business or its providers.

10a. AI assistance and automated decisions

AI-assisted features can produce transcripts, summaries, tags, assessments and suggestions for business users. These outputs can be inaccurate and require human review. A business remains responsible for decisions it makes using them, including decisions about customers or employees.

The use of an AI feature is not, by itself, proof that no profiling or automated decision-making occurs. Where a business proposes to use outputs for a decision with legal or similarly significant effects, it must assess the applicable legal conditions, provide the required information and safeguards, and ensure any required human involvement. Contact the relevant business about its decision-making use, or contact us for help identifying the processing concerned.

11. Security

We use technical and organisational measures appropriate to the processing, including authentication and access controls, protected API connections, permissions for business records, and operational security monitoring. The protection of a telephone call also depends on the carrier, connected equipment and selected route. We do not describe every call as end-to-end encrypted.

No system can be completely secure. Where we become aware of a personal data breach, we assess it and make the notifications to the relevant controller, competent authority and affected individuals required by applicable law. The conditions and deadlines for notifying each recipient may differ.

11a. Cookies and local storage

Web interfaces use cookies and browser storage for authentication, security, preferences and other necessary functions. Native apps also keep local settings and connection information needed for their features.

Optional web analytics and marketing technologies, where configured, are described in section 5 and the Cookie Policy and are subject to applicable consent requirements. The presence of authentication or other essential functions does not make every technology on the same website essential. Manage available optional choices through the site's consent controls; device permissions are managed separately in operating-system settings.

12. Children's privacy

The Customer Application is not intended for children under 16 years of age.

We do not knowingly collect personal data from children under 16 without verifiable parental or guardian consent, where required by law. If you believe that a child has provided us with personal data in violation of this Policy, please contact us and we will take appropriate steps to delete such data.

12a. Newsletter (if applicable)

If you subscribe to our newsletter, we use the data you provide (email address and any other information you voluntarily provide) to send you regular email newsletters based on your consent pursuant to Art. 6(1)(a) GDPR.

You can unsubscribe from the newsletter at any time by:

  • Sending a message to us via the contact details provided in the imprint/contact section, or
  • Using the unsubscribe link provided in each newsletter

After unsubscription, we will delete your email address unless you have expressly consented to further use of your data or we reserve the right to use data beyond this scope, which is permitted by law and about which we inform you in this Policy.

11b. Social Media Presence

We maintain a presence on the following social media platforms for business representation and communication:

Facebook / Meta

Operator: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland

Privacy Policy: https://www.facebook.com/about/privacy/

Opt-Out: https://www.youronlinechoices.com

These social media platforms may process personal data outside the EU. We refer to the privacy policies of the respective social media platforms linked above.

The respective social media platforms may create usage profiles from your usage behavior and the resulting interests and actions on your part, and may store cookies on your computer in which your usage behavior is stored.

If you have an account on the respective social media platform and are logged in, your usage behavior can even be stored across devices. Your usage profile can be used to place advertisements that presumably correspond to your interests.

We process personal data exclusively for communication with you via the social media platform you have chosen and to optimize our online presence. We ensure that no interests on your part are affected that outweigh this legitimate interest on our part (Art. 6(1)(f) GDPR).

If you have already given the respective social media platform operator effective consent for the corresponding data processing, the processing of your personal data is also based on this consent (Art. 6(1)(a) GDPR).

Your rights regarding social media data

You can exercise your data protection rights (access, rectification, deletion, restriction, data portability, objection) with respect to data processed by social media platforms by contacting the respective platform operator directly.

If you have concerns about how social media platforms process your data, you can also contact the relevant data protection supervisory authority.

11c. Storage of Guest Preferences

As part of our Service, we store certain preferences and choices of guests to enable a personalized user experience and to optimize food selection.

The stored information includes, among other things:

  • Frequency of orders
  • Preferred dishes and menu items
  • Individual settings within the application
  • Previous interactions with venues
  • Dietary preferences and restrictions (if you provided them)

The processing of this data is based on our legitimate interest in improving our offering and providing a service tailored to individual needs (Art. 6(1)(f) GDPR).

You can view, modify, or delete your preferences at any time through your account settings or by contacting us at info@meni.ge.

11d. Social Media Links

We have social media pages accessible through links on this Service. By using these links, you will reach the respective third-party websites (e.g., Facebook).

To avoid unnecessary data sharing, we recommend logging out of the respective third-party service before using such a link. This prevents the third-party service from potentially creating usage profiles just by using the link.

When you click on social media links:

  • You are redirected to external third-party platforms
  • Those platforms may collect data about you according to their own privacy policies
  • We have no control over the data processing by these third parties
  • You should review the privacy policies of those platforms before using them

We are not responsible for the privacy practices of third-party social media platforms. Their data collection and use is governed by their own privacy policies, not this Privacy Policy.

13. Changes to this Policy

We may update this Policy as the Service, processing arrangements or applicable law change. The date at the beginning identifies the current revision. For material changes, including a change of controller, we will provide appropriate notice and obtain a new permission where the law requires it. Publishing a revised Policy does not by itself provide consent for new optional processing or override an individual's existing rights.

14. Country-specific provisions

The following provisions supplement the rest of this Policy where the relevant law applies. A person's nationality or residence, a website domain and an app's distribution territory do not by themselves determine every law that applies. Mandatory local rights are not reduced by this Policy. The controller and processor roles in section 1 also apply to the country-specific provisions.

14.1 For users in the United States of America

If you are a resident of the United States, the following additional provisions apply to you:

14.1.1 State privacy laws (California, Virginia, Colorado, Connecticut, Utah and other states)

Several US states have enacted comprehensive privacy laws that grant residents additional rights regarding their personal information. If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another state with similar privacy legislation, you may have the following rights in addition to those described in this Policy:

Right to know / access: You may request details about the categories and specific pieces of personal information we collect, use, disclose, and sell (if applicable).

Right to delete: You may request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, fraud prevention, security purposes).

Right to correct: You may request correction of inaccurate personal information we maintain about you.

Right to opt out of sale, sharing or targeted advertising: Where applicable state law gives you these rights, you may exercise them through the available website privacy controls or by contacting info@meni.ge. Optional web advertising and conversion tools are described in section 5 and the Cookie Policy. Their legal classification depends on the processing, not solely on whether money is paid for data. Business call recordings and the native calling features described in section 3.10 are not used for our own advertising audiences.

Right to limit use of sensitive personal information: To the extent we collect sensitive personal information (such as precise geolocation or photos, which may include biometric data if used to identify you), we only use it for purposes disclosed in this Policy and as permitted by applicable law. You can manage geolocation and photo permissions in your device settings or via the Service.

Right to non-discrimination: We will not discriminate against you for exercising any of your privacy rights.

Authorized agent: You may designate an authorized agent to make requests on your behalf. We may require verification of both your and the agent's identity and written authorization.

Appeal rights: If we deny your privacy request, you may appeal our decision by contacting us at info@meni.ge.

14.1.2 Categories, sources, purposes and recipients

Depending on the features used, the information described in section 3 includes identifiers and contact details; account, business and professional information; commercial and customer-service records; internet, device and network activity; submitted files, messages and notes; call metadata and audio; transcripts, summaries and other derived assessments; and the location or image information used by an optional feature.

Sources include the individual, the business and its authorised staff, connected services, and technical information generated when the Service is used. Purposes are set out in section 4, recipients in section 6, and retention criteria in section 8. Section 5 describes optional web advertising-related processing. Business-controlled customer and employee information is processed under the roles described in section 1; receiving it through our software does not first create the business's controller responsibilities.

14.1.3 Children's privacy under COPPA

The Customer Application is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at info@meni.ge and we will promptly delete such information.

14.1.4 Website privacy choices

Essential service technologies and optional web analytics or advertising tools are different categories. Section 5 and the Cookie Policy describe the purposes and available choices. Where applicable law requires recognition of an opt-out preference signal, that requirement applies independently of whether a browser also offers a Do Not Track setting. Contact info@meni.ge if you need help exercising a privacy choice.

14.1.5 Retention periods for US residents

Retention follows the category-specific purposes and criteria in section 8, subject to mandatory local requirements. Account information, business records, call recordings, transcripts and diagnostics can have different periods. There is no single five-year retention period for all personal data. Contact info@meni.ge for the retention criterion relevant to a particular record or request.

14.1.6 Exercising your US privacy rights

To exercise any of the rights described above, please:

We will respond to your request within the time period required by applicable state law (typically 45 days, with a possible extension).

We may need to verify your identity before processing your request. We may ask for additional information to match against our records. We will not use information provided for verification for any other purpose.

14.2 For users in the Russian Federation

Where Russian personal-data law applies, processing is subject to Federal Law No. 152-FZ on Personal Data and other applicable requirements. For the platform's own purposes, the operator is the Georgian individual entrepreneur identified in section 1. For customer, employee and communication information controlled by a business, that business is the operator and we process the information on its instructions as described in section 1.

14.2.1 Russian infrastructure and localisation

The principal account and business-data infrastructure for cenaly.ru uses Yandex Cloud in the Russian Federation. Yandex Cloud supplies infrastructure; it does not replace the operator identified above. The other brands use the infrastructure described in section 7.

Russian requirements on localisation, processing on behalf of an operator and international transfers are distinct obligations. A foreign registration or an individual's acceptance of a privacy policy does not remove applicable localisation requirements. Using a Russian storage region does not itself establish compliance for every connected service or access route.

14.2.2 Recipients and international processing

Domestic speech and AI routes use Yandex services as described in section 6. Certain optional Knowledge Base features can send request text to an external model provider through the configured gateway where that route is selected and enabled. Apple or Google notification delivery, a business's external integrations and authorised access from abroad can also involve processing outside Russia.

International processing must satisfy the requirements applicable to that transfer, including any required notice, permission, safeguard or regulatory procedure. Accepting this Policy, enabling a feature or consenting to a recording is not blanket consent to every foreign transfer. Businesses must also meet their own obligations as operators; this does not remove our obligations for the processing we carry out.

14.2.3 Rights, recording and requests

Subject to applicable law, you may request information about processing, access to your data, correction, blocking or deletion where the relevant conditions are met, withdraw consent and challenge unlawful processing. Sections 9–10 explain how to contact us and how requests concerning business-controlled information are handled. Contact info@meni.ge, including if you no longer have access to an employer-created account. We respond within the applicable statutory period and explain any lawful refusal or extension.

Audio, photographs and contact information can be personal data. Their collection does not by itself establish that they are being used as biometric identifiers. Recording and AI processing must meet the requirements applicable to the particular purpose, participants and data; the business must use the notice and consent controls required for its calls.

You may complain to the competent authority, including Roskomnadzor where it has jurisdiction: https://rkn.gov.ru, or seek judicial protection. Contacting us first does not remove those rights.

14.3 European Union and European Economic Area

Where the GDPR applies to our processing, the controller information, categories, purposes, legal bases, recipients, retention criteria and rights in sections 1–10 form part of this notice. The GDPR's territorial rules depend on the relevant establishment, offering of services or monitoring activity; availability of a mobile app in an app store is not the only factor.

14.3.1 Roles and legal bases

We act as controller for the purposes identified in section 1 and use the applicable bases described in section 4. Where we act as a business's processor, the business determines its purposes and lawful basis, and we assist it under the applicable processing arrangements. A business's contract with us does not by itself supply consent from each customer or employee. Special categories of personal data require an applicable additional condition where the GDPR requires one.

14.3.2 Storage and transfers

The Service does not promise that all data remains in the EEA. The locations and recipients depend on the brand and feature as described in sections 6–7. GDPR-restricted transfers require a lawful transfer mechanism and any necessary supplementary measures. You can request information about the safeguards relevant to your data and how to obtain a copy by contacting info@meni.ge.

14.3.3 Rights and complaints

Subject to the GDPR's conditions, you have rights of access, rectification, erasure, restriction, portability and objection, and rights concerning decisions based solely on automated processing with legal or similarly significant effects. You may withdraw consent without affecting earlier lawful processing. Section 10a describes the use of AI-assisted outputs; use of a software tool does not remove the business's duties concerning its decisions.

You may complain to a supervisory authority, in particular in the Member State of your habitual residence, place of work or the alleged infringement. A directory is available at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.

Send requests to info@meni.ge. We respond without undue delay and normally within one month of receipt. Where permitted, the period may be extended by up to two further months because of the complexity or number of requests; we will notify you within the first month and explain the reason. These rights also apply, as relevant, when access to a work account has ended.

14.4 For users in the United Kingdom

If you are a resident of the United Kingdom, the following provisions apply to you under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018:

14.4.1 UK GDPR compliance

Following Brexit, the United Kingdom has its own data protection regime based on the UK GDPR. This Privacy Policy complies with both EU GDPR and UK GDPR requirements.

The rights, legal bases, and processing principles described in Sections 1-13 apply equally under UK GDPR.

14.4.2 Data storage and international transfers

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.4.3 Your rights under UK GDPR

As a UK resident, you have the same rights as described in Section 9, including:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Right to withdraw consent
  • Right not to be subject to automated decision-making

14.4.4 UK supervisory authority

You have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO)
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Website: https://ico.org.uk
Helpline: 0303 123 1113

14.4.5 Exercising your UK rights

To make a privacy or deletion request, contact info@meni.ge as described in sections 9–10.

We will respond within one month of receipt of your request, with possible extension by two further months in complex cases.

14.5 For users in Canada

If you are a resident of Canada, the following provisions apply to you under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws:

14.5.1 PIPEDA compliance

We process your personal information in accordance with PIPEDA's Fair Information Principles and applicable provincial legislation (such as Alberta's PIPA, British Columbia's PIPA, or Quebec's Law 25).

14.5.2 Consent and purposes

We collect, use and disclose your personal information only for the purposes identified in this Policy and only with your knowledge and consent, except where otherwise required or permitted by law.

Your consent may be express (for example, when you register or upload photos) or implied (for example, when you use the Service to place orders).

You may withdraw your consent at any time by contacting us, subject to legal or contractual restrictions and reasonable notice.

14.5.3 Sensitive personal information

We handle the following sensitive personal information with additional safeguards:

  • Biometric data – photos and facial caricatures
  • Health information – dietary restrictions or allergies

We obtain meaningful consent before collecting sensitive information and use it only for the purposes disclosed.

14.5.4 International transfers

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.5.5 Your rights under PIPEDA and provincial laws

You have the right to:

  • Access your personal information – request access to your personal information in our custody or control
  • Challenge accuracy – request correction of inaccurate or incomplete information
  • Withdraw consent – withdraw consent for processing, subject to legal and contractual restrictions
  • Know how your information is used – understand the purposes for which your information is collected, used and disclosed
  • File a complaint – lodge a complaint with the Office of the Privacy Commissioner of Canada or provincial commissioners

Additional rights for Quebec residents under Law 25:

  • Right to portability – receive certain personal information in a structured, commonly used format
  • Right to de-indexing – request de-indexing of information in certain circumstances

14.5.6 Personal information of minors

We take special care when processing personal information of minors (persons under 18 in most provinces, under 19 in some provinces).

For Quebec residents: In accordance with Law 25, we obtain parental consent before collecting personal information from children aged 14 and under, except in limited circumstances.

14.5.7 Privacy incidents and breach notification

In the event of a privacy breach that poses a real risk of significant harm, we will:

  • Notify the Office of the Privacy Commissioner of Canada
  • Notify affected individuals
  • Keep records of the breach as required by law

For Quebec residents: We will also comply with Law 25's breach notification requirements, including notifying the Commission d'accès à l'information du Québec (CAI).

14.5.8 Retention and safeguards

Retention follows the category-specific purposes and criteria in section 8, subject to mandatory local requirements. Account information, business records, call recordings, transcripts and diagnostics can have different periods. There is no single five-year retention period for all personal data. Contact info@meni.ge for the retention criterion relevant to a particular record or request.

14.5.9 Privacy Commissioner of Canada

If you believe your privacy rights have been violated, you may file a complaint with:

Office of the Privacy Commissioner of Canada (OPC)
Address: 30 Victoria Street, Gatineau, Quebec, K1A 1H3, Canada
Website: https://www.priv.gc.ca
Toll-free: 1-800-282-1376
Email: info@priv.gc.ca

14.5.10 Provincial Privacy Commissioners

Depending on your province, you may also contact:

Quebec - Commission d'accès à l'information (CAI)
Website: https://www.cai.gouv.qc.ca
Toll-free: 1-888-528-7741

Alberta - Office of the Information and Privacy Commissioner
Website: https://www.oipc.ab.ca
Phone: 1-888-878-4044

British Columbia - Office of the Information and Privacy Commissioner
Website: https://www.oipc.bc.ca
Phone: 1-250-387-5629

14.5.11 Exercising your Canadian rights

To exercise your rights, please contact us at:

Email: info@meni.ge

Subject line: "Privacy Rights Request" or "Demande d'accès aux renseignements personnels"

We will respond within 30 days of receiving your request, as required by PIPEDA. For complex requests, we will notify you if we need additional time.

14.6 For users in Brazil

If you are a resident of Brazil, the following provisions apply to you under Lei Geral de Proteção de Dados (LGPD) – the Brazilian General Data Protection Law:

14.6.1 LGPD compliance

We process your personal data in accordance with LGPD (Law No. 13,709/2018). The principles and practices described in this Policy align with LGPD requirements.

14.6.2 Legal bases for processing under LGPD

We process your personal data based on the following legal bases under LGPD Article 7:

  • Consent (Article 7, I) – when you register, upload photos, or agree to analytics
  • Performance of a contract (Article 7, V) – to provide the Service and process orders
  • Legitimate interests (Article 7, IX) – to ensure security, prevent fraud, improve the Service
  • Legal or regulatory obligation (Article 7, II) – to comply with tax, accounting and consumer protection requirements

14.6.3 International data transfers

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.6.4 Your rights under LGPD

As a Brazilian data subject, you have the following rights under LGPD Article 18:

  • Confirmation and access – confirm processing and access your personal data
  • Correction – request correction of incomplete, inaccurate or outdated data
  • Anonymization, blocking or deletion – of unnecessary, excessive or unlawfully processed data
  • Portability – receive your data in structured, commonly used format
  • Information about sharing – know with which public and private entities we share your data
  • Information about consent – be informed about the possibility of not providing consent and its consequences
  • Revocation of consent – revoke consent at any time
  • Opposition – oppose processing in certain cases

14.6.5 Children's personal data

We do not knowingly process personal data of children and adolescents under 18 without parental or guardian consent, as required by LGPD and the Brazilian Child and Adolescent Statute (ECA).

14.6.6 Data protection officer

We have not appointed a Data Protection Officer (Encarregado de Proteção de Dados) at this time. For privacy matters, please contact us at info@meni.ge.

14.6.7 National Data Protection Authority (ANPD)

You have the right to lodge a complaint with the Brazilian supervisory authority:

Autoridade Nacional de Proteção de Dados (ANPD)
Website: https://www.gov.br/anpd
Email: comunicacao@anpd.gov.br

14.6.8 Exercising your LGPD rights

To make a privacy or deletion request, contact info@meni.ge as described in sections 9–10.

We will respond to your request within 15 days from receipt, in accordance with LGPD requirements.

14.7 For users in Australia

If you are a resident of Australia, the following provisions apply to you under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs):

14.7.1 Australian Privacy Principles compliance

We handle your personal information in accordance with the Australian Privacy Principles set out in the Privacy Act 1988.

14.7.2 Collection and use of personal information

We collect personal information that is reasonably necessary for our functions and activities (providing the Service). We only collect personal information by lawful and fair means, and with your knowledge and consent where required.

The types of personal information we collect and the purposes for which we use it are described in Sections 3 and 4 of this Policy.

14.7.3 Sensitive information

Photos and caricatures may constitute sensitive information under the Privacy Act. We only collect sensitive information with your consent and where reasonably necessary for our functions.

14.7.4 Disclosure of personal information

We disclose personal information to third parties as described in Section 6. We do not sell or rent personal information.

When we disclose personal information to venue operators (who may be overseas entities), we take reasonable steps to ensure they comply with the APPs or are subject to similar privacy protections.

14.7.5 Overseas disclosure

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.7.6 Your rights under Australian privacy law

You have the right to:

  • Access your personal information – request access to personal information we hold about you
  • Correction – request correction of inaccurate, out-of-date, incomplete, irrelevant or misleading information
  • Complaints – make a complaint about our handling of your personal information

14.7.7 Office of the Australian Information Commissioner

If you are not satisfied with our response to your privacy complaint, you may lodge a complaint with:

Office of the Australian Information Commissioner (OAIC)
Website: https://www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au

14.7.8 Exercising your Australian rights

To access or correct your personal information, or to make a complaint, please contact us at info@meni.ge.

We will respond to access requests within 30 days and to complaints within a reasonable period (typically 30 days).

14.8 For users in Japan

If you are a resident of Japan, the following provisions apply to you under the Act on the Protection of Personal Information (APPI):

14.8.1 APPI compliance

We handle your personal information (個人情報) in accordance with Japan's Act on the Protection of Personal Information (個人情報の保護に関する法律).

14.8.2 Purpose of use

We use your personal information only for the purposes specified in Section 4 of this Policy. We will not use personal information beyond the scope of these purposes without your consent, except as permitted by law.

14.8.3 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.8.4 Sensitive personal data (要配慮個人情報)

Photos and caricatures may include sensitive personal data under APPI. We obtain your explicit consent before collecting such information and use it only for the purposes disclosed.

14.8.5 Your rights under APPI

Under APPI, you have the right to:

  • Disclosure – request disclosure of personal information we hold about you
  • Correction – request correction, addition or deletion of inaccurate personal information
  • Suspension of use – request suspension of use or deletion of personal information obtained or used unlawfully
  • Suspension of provision to third parties – request suspension of provision to third parties if done unlawfully

We may charge a reasonable fee for disclosure requests as permitted by law.

14.8.6 Personal Information Protection Commission

You have the right to file a complaint with the Japanese supervisory authority:

Personal Information Protection Commission (個人情報保護委員会)
Website: https://www.ppc.go.jp
Phone: 03-6457-9680
Consultation line: 03-6457-9849

14.8.7 Retention period

Retention follows the category-specific purposes and criteria in section 8, subject to mandatory local requirements. Account information, business records, call recordings, transcripts and diagnostics can have different periods. There is no single five-year retention period for all personal data. Contact info@meni.ge for the retention criterion relevant to a particular record or request.

14.8.8 Exercising your Japanese rights

To exercise your rights under APPI, please contact us at info@meni.ge with sufficient details to identify you and your request.

We will respond to your request within a reasonable period in accordance with APPI requirements.

14.9 For users in Switzerland

If you are a resident of Switzerland, the following provisions apply to you under the Swiss Federal Act on Data Protection (FADP / nFADP):

14.9.1 Swiss data protection compliance

We process your personal data in accordance with the revised Swiss Federal Act on Data Protection (nFADP), which entered into force on September 1, 2023.

Switzerland is not part of the EU/EEA but has data protection standards recognized as adequate by the European Commission.

14.9.2 Data storage and transfers

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.9.3 Your rights under Swiss law

As a Swiss resident, you have the following rights:

  • Right of access – obtain confirmation of processing and a copy of your data
  • Right to rectification – request correction of inaccurate data
  • Right to erasure – request deletion of data in certain circumstances
  • Right to data portability – receive data in structured, machine-readable format
  • Right to object – object to processing based on legitimate interests
  • Right to withdraw consent – withdraw consent at any time

14.9.4 Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.

14.9.5 Federal Data Protection and Information Commissioner

You have the right to lodge a complaint with the Swiss supervisory authority:

Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Address: Feldeggweg 1, 3003 Bern, Switzerland
Website: https://www.edoeb.admin.ch
Phone: +41 58 462 43 95
Email: info@edoeb.admin.ch

14.9.6 Exercising your Swiss rights

To make a privacy or deletion request, contact info@meni.ge as described in sections 9–10.

We will respond within 30 days of receiving your request.

14.10 For users in the People's Republic of China

If you are a resident of the People's Republic of China (excluding Hong Kong, Macau and Taiwan), the following provisions apply to you under the Personal Information Protection Law (PIPL):

14.10.1 PIPL compliance

We process your personal information in accordance with the Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法), which entered into force on November 1, 2021.

14.10.2 Legal bases for processing under PIPL

We process your personal information based on the following legal bases under PIPL Article 13:

  • Consent – when you register, upload photos, grant location permissions, or agree to analytics
  • Performance of a contract – to provide the Service and fulfill our contractual obligations
  • Necessary for履行法定职责或者法定义务 – to comply with legal obligations
  • Responding to public health emergencies or protecting life/health/property – where applicable
  • Legitimate interests – where necessary for our or third parties' legitimate interests and does not have a major impact on your rights

14.10.3 Cross-border transfer of personal information

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.10.4 Sensitive personal information

Photos and facial images constitute sensitive personal information (敏感个人信息) under PIPL. We:

  • Obtain your separate consent before collecting sensitive personal information
  • Inform you of the necessity and impact on your rights
  • Use sensitive personal information only for the specific purposes disclosed
  • Allow you to delete such information at any time

14.10.5 Your rights under PIPL

As a Chinese data subject, you have the following rights under PIPL:

  • Right to know and decide – know how your personal information is processed and make decisions accordingly
  • Right to limit or refuse processing – limit or refuse processing that is unnecessary for providing the Service
  • Right of access – access your personal information
  • Right to correction – request correction of inaccurate or incomplete personal information
  • Right to deletion – request deletion in circumstances specified by law
  • Right to copy – obtain copies of your personal information
  • Right to data portability – transfer your personal information to other entities you designate
  • Right to explanation – request explanation of processing rules when automated decision-making is used
  • Right to withdraw consent – withdraw consent at any time (we do not discriminate against you for withdrawal)

14.10.6 Automated decision-making

We do not use automated decision-making to conduct price discrimination or other behaviors that materially impact your rights. If we use automated decision-making, we will inform you and provide options to refuse.

14.10.7 Personal information of minors

In accordance with PIPL, we obtain consent from parents or guardians before processing personal information of minors under 14 years old. The Service is not intended for children under 14 without parental consent.

For minors aged 14-18, we take special protection measures and limit the scope of processing to what is necessary for the Service.

14.10.8 Personal information protection officer

For privacy matters related to PIPL, please contact us at info@meni.ge. We will designate a person responsible for personal information protection when required by law.

14.10.9 Cyberspace Administration of China

While PIPL does not establish a specific complaint mechanism, you may report violations to:

Cyberspace Administration of China (国家互联网信息办公室)
Website: http://www.cac.gov.cn

Or contact local cyberspace administration authorities.

14.10.10 Exercising your PIPL rights

To make a privacy or deletion request, contact info@meni.ge as described in sections 9–10.

We will respond within 15 days of receiving your request. In cases where we cannot fulfill your request, we will explain the reasons.

14.11 For users in the Republic of Turkey

If you are a resident of the Republic of Turkey, the following provisions apply to you under the Personal Data Protection Law No. 6698 (KVKK):

14.11.1 KVKK compliance

We process your personal data in accordance with the Turkish Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu - KVKK), which entered into force on April 7, 2016.

14.11.2 Legal bases for processing under KVKK

We process your personal data based on the following legal bases under KVKK Article 5:

  • Explicit consent – when you register, upload photos, grant location permissions, or agree to processing of sensitive data
  • Necessary for performance of a contract – to provide the Service, process orders and reservations
  • Compliance with legal obligations – to comply with Turkish tax, accounting and consumer protection requirements
  • Legitimate interests – where processing is mandatory for our legitimate interests, provided that it does not harm your fundamental rights and freedoms

14.11.3 Cross-border transfer of personal data

For cenaly.tr and masamenu.tr, principal AWS storage is in Frankfurt, Germany, while shared API and authentication services are in the United States. Other providers and destinations depend on the feature, as described in sections 6–7.

Where KVKK applies, an international transfer must meet Article 9 and the applicable implementing requirements. A destination's membership in the European Union is not, by itself, a Turkish adequacy decision. Appropriate safeguards, including an applicable Turkish standard contract where used, have their own conditions and notification requirements. Simply using the Service or accepting this Policy is not explicit consent to every international transfer. Contact info@meni.ge for information about the recipient and mechanism relevant to your processing.

14.11.4 Sensitive personal data under KVKK

Under KVKK, the following categories of data we may collect are considered sensitive and require explicit consent:

  • Biometric data – photos and facial caricatures
  • Health data – dietary restrictions or allergies related to health conditions

We process sensitive personal data only with your explicit consent and for the specific purposes disclosed in this Policy.

14.11.5 Your rights under KVKK

Under KVKK Article 11, you have the right to:

  • Learn whether your personal data is processed
  • Request information about processing if your data has been processed
  • Learn the purpose of processing and whether data is used for its intended purpose
  • Know third parties to whom your data is transferred domestically or abroad
  • Request correction of incomplete or inaccurate data
  • Request deletion or destruction of your data under conditions set forth in KVKK Article 7
  • Request notification of correction, deletion or destruction to third parties to whom your data was transferred
  • Object to processing that leads to unfavorable results for you
  • Request compensation for damages arising from unlawful processing

14.11.6 Controller identity and enquiries

The platform controller is the Georgian individual entrepreneur identified in section 1; the business may separately be the controller of customer, employee and communication information. Direct enquiries about the platform controller, the applicable processing arrangement or representation to info@meni.ge. The use of a Turkish domain does not change the identity of either controller.

14.11.7 Personal Data Protection Authority

You have the right to lodge a complaint with the Turkish supervisory authority:

Personal Data Protection Authority (Kişisel Verilerin Korunması Kurumu - KVKK)
Address: Nasuh Akar Mah. Ziyabey Cad. 1407. Sok. No: 4 06520 Balgat-Çankaya/Ankara, Turkey
Website: https://www.kvkk.gov.tr
Email: kvkk@kvkk.gov.tr

14.11.8 Retention periods for Turkish residents

The category-specific criteria in section 8 apply, subject to mandatory Turkish requirements. There is no uniform five-year retention period for every account, recording, transcript or technical record.

14.11.9 Exercising your KVKK rights

To exercise your rights under KVKK, you can submit a written application:

  • By email to info@meni.ge
  • By registered mail to our address

We will respond to your request within 30 days at the latest, free of charge. If your request requires additional costs, we may charge a fee in accordance with the tariff determined by the Personal Data Protection Board.

14.12 For users in Mexico

If you are a resident of the United Mexican States (Mexico), the following provisions apply to you under the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP):

14.12.1 LFPDPPP compliance

We process your personal data in accordance with the Mexican Federal Law on Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares - LFPDPPP), which entered into force on July 6, 2010, and its Regulations.

14.12.2 Legal bases for processing under LFPDPPP

We process your personal data based on the following legal bases under LFPDPPP:

  • Consent – when you register, upload photos, grant location permissions, or agree to processing
  • Performance of a contract – to provide the Service, process orders and reservations
  • Legal obligation – to comply with Mexican tax, accounting and consumer protection requirements
  • Legitimate interests – where processing is necessary for our legitimate interests and does not override your fundamental rights

14.12.3 Privacy notice (Aviso de Privacidad)

This Privacy Policy serves as our Privacy Notice (Aviso de Privacidad) under LFPDPPP and contains:

  • Identity and address of the data controller (Section 1)
  • Personal data we collect (Section 3)
  • Purposes of processing (Section 4)
  • Sharing of personal data (Section 6)
  • Mechanisms for exercising ARCO rights (Section 14.12.6)
  • Options to limit use and disclosure of personal data (Section 14.12.7)
  • Procedures for revoking consent (Section 14.12.6)
  • How we notify changes to this Privacy Notice (Section 13)

14.12.4 Sensitive personal data (Datos personales sensibles)

Under LFPDPPP, the following categories of data we may collect are considered sensitive and require express and written consent:

  • Biometric data – photos and facial caricatures that can be used to identify you
  • Health data – dietary restrictions or allergies related to health conditions

We process sensitive personal data only with your express consent and for the specific purposes disclosed in this Policy. You have the right to refuse to provide sensitive data, though this may limit certain features of the Service.

14.12.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.12.6 Your ARCO rights

Under LFPDPPP, you have the following rights (known as "ARCO rights"):

  • Access (Acceso) – obtain confirmation of whether we process your personal data and obtain copies
  • Rectification (Rectificación) – request correction of inaccurate or incomplete personal data
  • Cancellation (Cancelación) – request deletion of your personal data when you consider it is not being processed in accordance with LFPDPPP
  • Opposition (Oposición) – oppose processing of your personal data for specific purposes

You also have the right to:

  • Revoke consent – withdraw your consent for processing at any time
  • Limit use and disclosure – request that we limit the use or disclosure of your personal data

To exercise your ARCO rights, please submit a request to info@meni.ge with the following information:

  • Your name and email or postal address for receiving responses
  • Documents proving your identity (copy of official ID)
  • Clear description of the personal data for which you seek to exercise ARCO rights
  • Any other information that facilitates locating your personal data
  • In case of rectification, include the documents supporting your request

We will respond to your ARCO request within 20 business days from the date we receive your request. Our response will indicate whether your request was accepted and, if accepted, we will make it effective within 15 business days.

We may deny your ARCO request in the following cases:

  • You are not the data subject or your legal representative is not duly accredited
  • Your personal data is not in our databases
  • Your rights are restricted by law
  • Processing is necessary for compliance with legal obligations

14.12.7 Limitation of use and disclosure

You may limit the use and disclosure of your personal data by:

  • Opting out of marketing communications (if we send any)
  • Disabling analytics cookies through cookie settings
  • Withdrawing consent for geolocation and photos through device settings
  • Contacting us at info@meni.ge to request limitation

We do not use or disclose your personal data for secondary purposes (such as advertising or marketing) without your consent.

14.12.8 Personal data of minors

In accordance with LFPDPPP, we obtain consent from parents or legal guardians (tutores) before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent. For minors aged 16-17, we may require verification of parental consent for certain features.

If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us at info@meni.ge.

14.12.9 Cookies and web beacons

The Service uses essential cookies or browser storage for requested functions and may use optional web analytics and marketing technologies where configured and lawfully enabled. Section 5 and the Cookie Policy describe those purposes and choices. Optional technologies are not made essential merely because a page is part of a business application. Device permissions for a native app are separate from website cookie choices.

14.12.10 National Institute for Transparency, Access to Information and Personal Data Protection (INAI)

You have the right to file a complaint with the Mexican supervisory authority:

Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI)
Address: Insurgentes Sur 3211, Col. Insurgentes Cuicuilco, Alcaldía Coyoacán, C.P. 04530, Ciudad de México
Website: https://home.inai.org.mx
Phone: +52 (55) 5004-2400
Email: atencion@inai.org.mx

INAI handles complaints regarding violations of LFPDPPP and can impose sanctions on data controllers who fail to comply with the law.

14.12.11 Security measures

We implement physical, technical, and administrative security measures to protect your personal data against damage, loss, alteration, destruction, unauthorized access, or use, as required by LFPDPPP and its Regulations.

These measures include:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security audits and monitoring
  • Employee training on data protection
  • Incident response procedures

14.12.12 Retention periods for Mexican residents

Retention follows the category-specific purposes and criteria in section 8, subject to mandatory local requirements. Account information, business records, call recordings, transcripts and diagnostics can have different periods. There is no single five-year retention period for all personal data. Contact info@meni.ge for the retention criterion relevant to a particular record or request.

14.12.13 Changes to this Privacy Notice

We will notify you of material changes to this Privacy Notice through:

  • Email to the address associated with your account
  • A prominent notice on our website or app
  • In-app notifications

You will have 5 business days from the notification to express any objection to the changes. If you do not object, we will consider that you accept the changes.

If you object to the changes, we may terminate your access to the Service, or you may delete your account.

14.12.14 Exercising your rights under LFPDPPP

To exercise any of your rights under LFPDPPP, please contact us at:

Email: info@meni.ge

Subject line: "ARCO Rights Request" or "Solicitud de Derechos ARCO"

We will respond within the timeframes required by LFPDPPP (20 business days for the response, 15 business days for implementation).

14.13 For users in Argentina

If you are a resident of the Argentine Republic (Argentina), the following provisions apply to you under the Personal Data Protection Act, Law No. 25.326 (PDPA):

14.13.1 PDPA compliance

We process your personal data in accordance with the Argentine Personal Data Protection Act (Ley de Protección de Datos Personales, Law No. 25.326), enacted on October 4, 2000, and its implementing regulations (Decree 1558/2001).

14.13.2 Legal bases for processing under PDPA

We process your personal data based on the following legal bases under PDPA:

  • Consent – when you register, upload photos, grant location permissions, or agree to processing
  • Performance of a contract – to provide the Service, process orders and reservations
  • Legal obligation – to comply with Argentine tax, accounting and consumer protection requirements
  • Legitimate interests – where processing is necessary for our legitimate interests and does not harm your rights

14.13.3 Information obligations

Under PDPA, we inform you of:

  • The identity and address of the data controller (Section 1)
  • The purpose of data collection (Section 4)
  • The recipients of your personal data (Section 6)
  • The existence of databases and their purpose (Section 3)
  • Your rights to access, rectify, and delete data (Section 14.13.6)
  • Whether providing data is mandatory or optional
  • The consequences of providing or refusing to provide data

14.13.4 Sensitive personal data

Under PDPA, the following categories of data we may collect are considered sensitive and require express consent:

  • Biometric data – photos and facial caricatures that can be used to identify you
  • Health data – dietary restrictions or allergies related to health conditions

We process sensitive personal data only with your express and informed consent. You have the right to refuse to provide sensitive data, though this may limit certain features of the Service.

14.13.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.13.6 Your rights under PDPA

Under PDPA, you have the following rights:

  • Right of access – obtain information about your personal data in our databases, free of charge, at intervals of not less than 6 months (unless you prove a legitimate interest)
  • Right to rectification – request correction, updating, or deletion of inaccurate, incomplete, or outdated data
  • Right to suppression (deletion) – request deletion of data that is not being processed in accordance with PDPA
  • Right to confidentiality – ensure that your data is kept confidential and used only for the purposes for which it was collected

You also have the right to:

  • Withdraw consent – revoke your consent for processing at any time
  • Object to processing – object to processing in certain cases

To exercise your rights, please submit a request to info@meni.ge with:

  • Your full name and contact information
  • Proof of identity (copy of national ID - DNI, or passport)
  • Clear description of the personal data concerned
  • Specification of the right you wish to exercise

We will respond to your request within 10 business days from the date we receive it. If we need additional time, we will notify you of the delay.

We may deny your request in cases provided by law, such as when:

  • Disclosure could obstruct judicial or administrative proceedings
  • Data is related to national defense, public security, or tax collection
  • Data is protected by professional secrecy
  • Your request is manifestly unfounded or excessive

14.13.7 Personal data of minors

In accordance with PDPA, we obtain consent from parents or legal guardians (tutores or representantes legales) before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent. For minors aged 16-17, we may require verification of parental consent for certain features.

If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us at info@meni.ge.

14.13.8 Database registration

Personal data databases must be registered with the Argentine Data Protection Authority (Agencia de Acceso a la Información Pública - AAIP) in the National Database Registry (Registro Nacional de Bases de Datos).

We comply with database registration requirements as applicable to our operations in Argentina.

14.13.9 Argentine Data Protection Authority (AAIP)

You have the right to file a complaint with the Argentine data protection supervisory authority:

Agencia de Acceso a la Información Pública (AAIP)
Address: Av. Pte. Gral. Julio A. Roca 710, Piso 3°, C1067ABC, Ciudad Autónoma de Buenos Aires, Argentina
Website: https://www.argentina.gob.ar/aaip
Phone: 0800-222-DATO (3286) / (+54 11) 2821-0047
Email: datospersonales@aaip.gob.ar

AAIP is responsible for supervising compliance with PDPA and has the authority to impose sanctions on data controllers who violate the law.

14.13.10 Security measures

We implement technical and organizational security measures to protect your personal data against unauthorized access, alteration, destruction, or disclosure, as required by PDPA and Decree 1558/2001.

These measures include:

  • Encryption of data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security audits and vulnerability assessments
  • Employee training on data protection
  • Incident detection and response procedures
  • Physical security of data storage facilities

14.13.11 Cookies and tracking technologies

The Service uses essential cookies or browser storage for requested functions and may use optional web analytics and marketing technologies where configured and lawfully enabled. Section 5 and the Cookie Policy describe those purposes and choices. Optional technologies are not made essential merely because a page is part of a business application. Device permissions for a native app are separate from website cookie choices.

14.13.12 Retention periods for Argentine residents

Retention follows the category-specific purposes and criteria in section 8, subject to mandatory local requirements. Account information, business records, call recordings, transcripts and diagnostics can have different periods. There is no single five-year retention period for all personal data. Contact info@meni.ge for the retention criterion relevant to a particular record or request.

14.13.13 Direct marketing and automated processing

We do not use your personal data for direct marketing purposes without your prior consent. If we send marketing communications, you can opt out at any time.

We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.

14.13.14 Data breach notification

In the event of a personal data breach that may significantly affect your rights, we will:

  • Notify the AAIP within the required timeframe
  • Notify affected data subjects when the breach may cause serious harm
  • Take measures to mitigate the effects of the breach

14.13.15 Exercising your rights under PDPA

To exercise any of your rights under Argentine law, please contact us at:

Email: info@meni.ge
Subject line: "PDPA Rights Request" or "Solicitud de Derechos - Ley 25.326"

We will respond within 10 business days as required by PDPA. If additional time is needed, we will notify you of the extension.

14.14 For users in Georgia

Where Georgian data-protection law applies, we process personal data under the Law of Georgia on Personal Data Protection adopted on 14 June 2023, as amended. The Georgian individual entrepreneur identified in section 1 is the controller for our own purposes. Businesses remain controllers for the processing they determine, and we act as their processor where described in this Policy.

14.14.1 Purposes, recording and safeguards

The purposes and applicable grounds are described in section 4. Consent, contractual necessity, legal obligations or legitimate interests may apply according to the processing and the law; additional conditions apply to special categories of data where required. Registration, an operating-system permission and a business's decision to enable a feature are not interchangeable with every consent required by law.

For audio monitoring, the controller must determine the purpose, scope, retention, access, storage and destruction arrangements required by law and inform the people concerned. Section 3.10 explains the available recording-notice tools. The business must select and use an appropriate lawful recording and AI-processing arrangement; the platform remains responsible for its own processor obligations.

14.14.2 Rights and time limits

Subject to the law's conditions, you may obtain information about processing, access your data and obtain a copy, request correction or completion, request termination of processing, erasure or destruction, request blocking, obtain portable data where applicable, withdraw consent and exercise rights concerning automated individual decisions.

Send requests to info@meni.ge. Information and access requests generally have a ten-working-day period under Articles 13–14; a justified extension of up to ten working days is available in the circumstances specified by law, with notice. Correction and erasure requests under Articles 15–16 also generally require action or an explained refusal within ten working days, unless another statutory period applies. Other rights may have different deadlines. We apply the period and any permitted exception specific to your request.

14.14.3 Complaints and international processing

You may apply to the State Audit Office of Georgia or a competent court in accordance with the law. Authority information is available at https://sao.ge/en/. Contacting us first is not a condition that removes your right to complain.

Our Georgian registration does not mean that all data is stored in Georgia. Sections 6–7 identify the relevant infrastructure and providers. International processing must satisfy the applicable Georgian transfer requirements as well as other laws that apply to the processing concerned.

14.15 For users in Armenia

If you are a resident of the Republic of Armenia, the following provisions apply to you under the Law on Protection of Personal Data:

14.15.1 Armenian data protection law compliance

We process your personal data in accordance with the Law of the Republic of Armenia on Protection of Personal Data (Անձնական տվյալների պահպանության մասին, Law No. HO-59-N), adopted on March 26, 2015.

14.15.2 Legal bases for processing under Armenian law

We process your personal data based on the following legal bases:

  • Consent – when you register, upload photos, grant permissions, or agree to processing
  • Performance of a contract – to provide the Service
  • Legal obligation – to comply with legal requirements
  • Legitimate interests – where necessary for our legitimate interests

14.15.3 Sensitive personal data

Under Armenian law, the following data we collect is considered sensitive and requires express consent:

  • Biometric data – photos and facial caricatures
  • Health data – dietary restrictions or allergies related to health conditions

14.15.4 Your rights under Armenian law

Under Armenian data protection law, you have the following rights:

  • Right of access – obtain information about processing of your personal data
  • Right to rectification – request correction of inaccurate data
  • Right to deletion – request deletion of data in certain cases
  • Right to object – object to processing in certain circumstances
  • Right to withdraw consent – withdraw consent at any time

14.15.5 Cross-border transfer

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.15.6 Authorized Body for Protection of Personal Data

You have the right to contact the Armenian data protection authority:

Authorized Body for Protection of Personal Data
Address: 15 M. Mkrtchyan St., 0010 Yerevan, Republic of Armenia
Website: https://www.e-gov.am/gov-decrees/item/28321/
Phone: (+374 10) 51 14 42

14.15.7 Exercising your rights

To exercise your rights, contact us at info@meni.ge. We will respond within the timeframe required by Armenian law.

14.16 For users in Azerbaijan

If you are a resident of the Republic of Azerbaijan, the following provisions apply to you under the Law on Personal Data:

14.16.1 Azerbaijani data protection law compliance

We process your personal data in accordance with the Law of the Republic of Azerbaijan on Personal Data (Fərdi məlumatlar haqqında, Law No. 998-IIIQD), adopted on May 11, 2010.

14.16.2 Legal bases for processing under Azerbaijani law

We process your personal data based on the following legal bases:

  • Consent – when you register, upload photos, grant permissions, or agree to processing
  • Performance of a contract – to provide the Service
  • Legal obligation – to comply with Azerbaijani legal requirements
  • Legitimate interests – where necessary for our legitimate interests

14.16.3 Special categories of personal data

Under Azerbaijani law, the following data we collect may be considered special categories and require express consent:

  • Biometric data – photos and facial caricatures
  • Health data – dietary restrictions or allergies

We process such data only with your express consent.

14.16.4 Your rights under Azerbaijani law

Under Azerbaijani data protection law, you have the following rights:

  • Right to information – obtain information about processing of your data
  • Right to access – access your personal data
  • Right to rectification – request correction of inaccurate data
  • Right to deletion – request deletion of data in certain cases
  • Right to object – object to processing
  • Right to withdraw consent – withdraw consent at any time

14.16.5 Cross-border transfer

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.16.6 Commissioner for Human Rights (Ombudsman)

For data protection matters in Azerbaijan, you may contact:

Commissioner for Human Rights (Ombudsman) of the Republic of Azerbaijan
Address: 16 U. Hajibeyov St., AZ1000 Baku, Azerbaijan
Website: http://www.ombudsman.az
Phone: (+994 12) 498 63 28
Email: office@ombudsman.az

14.16.7 Exercising your rights

To exercise your rights, contact us at info@meni.ge. We will respond within a reasonable timeframe.

14.17 For users in Kazakhstan

If you are a resident of the Republic of Kazakhstan, the following provisions apply to you under the Law on Personal Data and their Protection:

14.17.1 Kazakhstani data protection law compliance

We process your personal data in accordance with the Law of the Republic of Kazakhstan on Personal Data and their Protection (Дербес деректер және оларды қорғау туралы / О персональных данных и их защите, Law No. 94-V), adopted on May 21, 2013.

14.17.2 Legal bases for processing under Kazakhstani law

We process your personal data based on the following legal bases:

  • Consent – when you register, upload photos, grant permissions, or agree to processing
  • Performance of a contract – to provide the Service, process orders and reservations
  • Legal obligation – to comply with Kazakhstani legal requirements
  • Legitimate interests – where necessary for our legitimate interests and does not violate your rights

14.17.3 Biometric personal data

Under Kazakhstani law, biometric data is a special category of personal data. We collect:

  • Photos and facial caricatures – which may constitute biometric personal data

We process biometric data only with your consent and for the purposes specified in this Policy.

14.17.4 Your rights under Kazakhstani law

Under Kazakhstani data protection law, you have the following rights:

  • Right of access – obtain information about processing of your personal data
  • Right to rectification – request correction of inaccurate, incomplete, or outdated data
  • Right to deletion – request deletion of data in certain circumstances
  • Right to withdraw consent – withdraw consent at any time
  • Right to object – object to processing in certain cases
  • Right to restrict processing – request limitation of processing

14.17.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.17.6 Personal data of minors

In accordance with Kazakhstani law, we obtain consent from parents or legal representatives before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent.

14.17.7 Personal Data Protection Authority

For data protection matters in Kazakhstan, you may contact the authorized state body responsible for personal data protection.

Information is available at the official government portal: https://egov.kz

14.17.8 Exercising your rights

To exercise your rights under Kazakhstani law, please contact us at:

Email: info@meni.ge

Subject line: "Personal Data Rights Request" or "Запрос о правах на персональные данные"

We will respond within the timeframe required by Kazakhstani law (typically 30 days).

14.18 For users in Ukraine

If you are a resident of Ukraine, the following provisions apply to you under the Law of Ukraine on Protection of Personal Data:

14.18.1 Ukrainian data protection law compliance

We process your personal data in accordance with the Law of Ukraine on Protection of Personal Data (Про захист персональних даних, Law No. 2297-VI), adopted on June 1, 2010.

Ukraine is in the process of aligning its data protection legislation with EU GDPR requirements.

14.18.2 Legal bases for processing under Ukrainian law

We process your personal data based on the following legal bases:

  • Consent – when you register, upload photos, grant permissions, or agree to processing
  • Performance of a contract – to provide the Service, process orders and reservations
  • Legal obligation – to comply with Ukrainian legal requirements
  • Legitimate interests – where necessary for our legitimate interests and does not violate your rights

14.18.3 Special categories of personal data

Under Ukrainian law, the following data we collect is considered special categories and requires express consent:

  • Biometric data – photos and facial caricatures that can be used to identify you
  • Health data – dietary restrictions or allergies related to health conditions

We process special categories of personal data only with your express written consent.

14.18.4 Your rights under Ukrainian law

Under Ukrainian data protection law, you have the following rights:

  • Right to information – know about the collection, processing and use of your personal data
  • Right of access – obtain information about processing and copies of your data
  • Right to rectification – request correction of inaccurate or incomplete data
  • Right to deletion – request deletion of data in certain circumstances
  • Right to object – object to processing
  • Right to withdraw consent – withdraw consent at any time

14.18.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.18.6 Personal data of minors

In accordance with Ukrainian law, we obtain consent from parents or legal representatives before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent.

14.18.7 Ukrainian Parliament Commissioner for Human Rights (Ombudsman)

You have the right to contact the Ukrainian data protection authority:

Ukrainian Parliament Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини)
Address: 21/8 Instytutska St., 01008 Kyiv, Ukraine
Website: https://www.ombudsman.gov.ua
Phone: (+380 44) 253-80-51
Email: hotline@ombudsman.gov.ua

14.18.8 Exercising your rights

To exercise your rights under Ukrainian law, please contact us at:

Email: info@meni.ge

Subject line: "Personal Data Rights Request" or "Запит про права на персональні дані"

We will respond within the timeframe required by Ukrainian law (typically 30 days).

14.19 For users in Iran

If you are a resident of the Islamic Republic of Iran, the following provisions apply to you under Iranian data protection regulations:

14.19.1 Iranian data protection compliance

We process your personal data in accordance with Iranian laws and regulations, including provisions of the Computer Crimes Law (قانون جرایم رایانه‌ای) and regulations on protection of personal data and privacy.

14.19.2 Legal bases for processing under Iranian law

We process your personal data based on the following legal bases:

  • Consent – when you register, upload photos, grant permissions, or agree to processing
  • Performance of a contract – to provide the Service
  • Legal compliance – to comply with Iranian legal requirements
  • Legitimate purposes – where necessary for lawful business purposes

14.19.3 Sensitive personal data

Under Iranian law, we handle the following sensitive data with additional protection measures:

  • Biometric data – photos and facial caricatures
  • Health information – dietary restrictions or allergies
  • Personal identification information – that can be used to identify you

We process such data only with your consent and implement enhanced security measures.

14.19.4 Your rights under Iranian law

Under Iranian data protection regulations, you have the following rights:

  • Right to information – be informed about collection and use of your personal data
  • Right to access – access your personal data
  • Right to correction – request correction of inaccurate data
  • Right to deletion – request deletion in certain circumstances
  • Right to object – object to processing where permitted by law
  • Right to confidentiality – protection of your privacy

14.19.5 Data localization and cross-border transfer

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.19.6 Personal data of minors

In accordance with Iranian law and Islamic principles, we require consent from parents or legal guardians before processing personal data of minors (persons under 18 years old).

The Service is not intended for children without parental consent and supervision.

14.19.7 Security and confidentiality

We implement technical, physical, and administrative security measures in accordance with Iranian regulations to protect your personal data against unauthorized access, disclosure, alteration, or destruction.

These measures include:

  • Encryption of data in transit and at rest
  • Secure authentication mechanisms
  • Access controls and monitoring
  • Regular security assessments
  • Employee confidentiality obligations

14.19.8 Exercising your rights

To exercise your rights or for data protection inquiries, please contact us at:

Email: info@meni.ge

Subject line: "Personal Data Rights Request" or "درخواست حقوق داده‌های شخصی"

We will respond to your request within a reasonable timeframe in accordance with Iranian law.

14.20 For users in the United Arab Emirates

If you are a resident of the United Arab Emirates (UAE), the following provisions apply to you under the UAE Federal Data Protection Law:

14.20.1 UAE data protection law compliance

We process your personal data in accordance with the UAE Personal Data Protection Law (المرسوم بقانون اتحادي رقم 45 لسنة 2021 في شأن حماية البيانات الشخصية, Federal Decree-Law No. 45 of 2021), which came into effect on January 2, 2022.

14.20.2 Legal bases for processing under UAE law

We process your personal data based on the following legal bases under UAE law:

  • Consent – when you provide explicit consent for processing
  • Performance of a contract – to fulfill our contractual obligations to you
  • Legal obligation – to comply with UAE legal and regulatory requirements
  • Legitimate interests – where necessary for our legitimate business interests, provided this does not override your fundamental rights

14.20.3 Sensitive personal data

Under UAE law, the following data we collect is considered sensitive and requires explicit consent:

  • Biometric data – photos and facial caricatures used for identification
  • Health data – dietary restrictions, allergies, or other health-related information

We process sensitive personal data only with your explicit consent and implement additional security measures as required by UAE law.

14.20.4 Your rights under UAE law

Under UAE data protection law, you have the following rights:

  • Right to access – obtain confirmation of whether we process your personal data and receive a copy
  • Right to rectification – request correction of inaccurate or incomplete data
  • Right to erasure – request deletion of your data in certain circumstances
  • Right to restriction of processing – request limitation of processing in certain cases
  • Right to data portability – receive your data in structured, machine-readable format and transmit it to another controller
  • Right to object – object to processing based on legitimate interests
  • Right to withdraw consent – withdraw consent at any time without affecting prior processing
  • Right to lodge a complaint – file a complaint with the UAE Data Office

14.20.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.20.6 Personal data of minors

In accordance with UAE law, we obtain consent from parents or legal guardians before processing personal data of minors. In the UAE, minors are persons under 21 years old.

The Service is not intended for persons under 18 without parental consent. For persons aged 18-20, we may require verification of parental consent for certain features.

If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us at info@meni.ge.

14.20.7 UAE Data Office

You have the right to lodge a complaint with the UAE supervisory authority:

UAE Data Office (مكتب البيانات)
Ministry of Justice
Website: https://www.uaedataoffice.gov.ae
Email: dataoffice@moj.gov.ae
Phone: (+971) 600 522 222

The UAE Data Office is responsible for supervising compliance with the Personal Data Protection Law and has the authority to investigate complaints and impose penalties for violations.

14.20.8 Data breach notification

In the event of a personal data breach that may pose a risk to your rights and freedoms, we will:

  • Notify the UAE Data Office within 72 hours of becoming aware of the breach
  • Notify affected data subjects without undue delay if the breach poses a high risk
  • Take immediate measures to mitigate the effects of the breach
  • Cooperate with the UAE Data Office in investigating and resolving the breach

14.20.9 Retention periods for UAE residents

Retention follows the category-specific purposes and criteria in section 8, subject to mandatory local requirements. Account information, business records, call recordings, transcripts and diagnostics can have different periods. There is no single five-year retention period for all personal data. Contact info@meni.ge for the retention criterion relevant to a particular record or request.

14.20.10 Exercising your rights under UAE law

To exercise any of your rights under UAE law, please contact us at:

Email: info@meni.ge

Subject line: "Personal Data Rights Request" or "طلب حقوق البيانات الشخصية"

We will respond to your request within 30 days as required by UAE law. If we need additional time due to the complexity of your request, we will notify you and may extend the response time by an additional 30 days.

14.21 For users in Uruguay

If you are a resident of the Oriental Republic of Uruguay, the following provisions apply to you under the Personal Data Protection and Habeas Data Action Law:

14.21.1 Uruguayan data protection law compliance

We process your personal data in accordance with the Personal Data Protection and Habeas Data Action Law (Ley de Protección de Datos Personales y Acción de Habeas Data, Law No. 18.331), adopted on August 11, 2008, and its implementing Decree No. 414/009.

Uruguay has been recognized by the European Commission as providing adequate protection for personal data, making it the first Latin American country to receive this recognition.

14.21.2 Legal bases for processing under Uruguayan law

We process your personal data based on the following legal bases under Uruguayan law:

  • Consent – when you provide express and informed consent
  • Performance of a contract – to fulfill our contractual obligations
  • Legal obligation – to comply with Uruguayan legal requirements
  • Legitimate interests – where processing is necessary for our legitimate interests and does not harm your fundamental rights

14.21.3 Sensitive personal data

Under Uruguayan law, the following data we collect is considered sensitive (datos sensibles) and requires express written consent:

  • Biometric data – photos and facial caricatures that can be used to identify you
  • Health data – dietary restrictions or allergies related to health conditions

We process sensitive data only with your express written consent and for the purposes explicitly disclosed.

14.21.4 Your rights under Uruguayan law

Under Uruguayan data protection law, you have the following rights:

  • Right of access (acceso) – obtain confirmation of whether we process your data and receive copies
  • Right to update (actualización) – request updating of incomplete or outdated data
  • Right to rectification (rectificación) – request correction of inaccurate data
  • Right to inclusion (inclusión) – request addition of data that should be part of the database
  • Right to deletion (supresión) – request deletion of data that is unlawfully processed or no longer necessary
  • Right to confidentiality (confidencialidad) – ensure your data is kept confidential
  • Right to information (información) – be informed about the existence of databases and their purpose
  • Right to object (oposición) – object to processing in certain circumstances

14.21.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.21.6 Personal data of minors

In accordance with Uruguayan law, we obtain consent from parents or legal representatives (padres o representantes legales) before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent.

14.21.7 Data Protection Unit (URCDP)

You have the right to lodge a complaint with the Uruguayan data protection authority:

Unidad Reguladora y de Control de Datos Personales (URCDP)
Address: Andes 1365, Piso 10, 11100 Montevideo, Uruguay
Website: https://www.gub.uy/unidad-reguladora-control-datos-personales
Phone: (+598) 2901 2929
Email: urcdp@agesic.gub.uy

14.21.8 Habeas Data action

In addition to administrative remedies, Uruguayan law provides a constitutional action called Habeas Data (Acción de Habeas Data), which allows you to seek judicial protection of your personal data rights.

14.21.9 Exercising your rights

To exercise your rights under Uruguayan law, please contact us at:

Email: info@meni.ge
Subject line: "Solicitud de Derechos - Ley 18.331" or "Data Rights Request"

We will respond to your request within the timeframes required by Uruguayan law (typically 5 working days for access requests, longer for complex requests).

14.22 For users in Peru

If you are a resident of the Republic of Peru, the following provisions apply to you under the Personal Data Protection Law:

14.22.1 Peruvian data protection law compliance

We process your personal data in accordance with the Personal Data Protection Law (Ley de Protección de Datos Personales, Law No. 29733), enacted on July 3, 2011, and its implementing regulations (Supreme Decree No. 003-2013-JUS).

14.22.2 Legal bases for processing under Peruvian law

We process your personal data based on the following legal bases under Peruvian law:

  • Consent – when you provide free, prior, express, informed and unequivocal consent
  • Performance of a contract – to fulfill contractual obligations
  • Legal obligation – to comply with Peruvian legal requirements
  • Legitimate interests – where processing is necessary for legitimate purposes, provided it does not violate your fundamental rights

14.22.3 Sensitive personal data

Under Peruvian law, the following data we collect is considered sensitive (datos sensibles) and requires express, written and prior consent:

  • Biometric data – photos and facial caricatures used for identification
  • Health data – dietary restrictions or allergies related to health conditions

We process sensitive data only with your express written consent, obtained prior to processing, and for the specific purposes disclosed.

14.22.4 Your rights under Peruvian law (ARCO rights)

Under Peruvian law, you have the following ARCO rights:

  • Right of access (Acceso) – know what personal data is being processed and obtain copies
  • Right to rectification (Rectificación) – request correction of inaccurate, incomplete or outdated data
  • Right to cancellation (Cancelación) – request deletion or blocking of data that is excessive, unnecessary, or processed in violation of law
  • Right to opposition (Oposición) – object to processing when you have legitimate reasons

You also have the right to:

  • Revoke consent – withdraw your consent at any time
  • Information – be informed about the processing of your data
  • Objection to automated decisions – object to decisions based solely on automated processing

To exercise your ARCO rights, please submit a request to info@meni.ge with:

  • Your full name and contact information
  • Copy of your national ID (DNI) or passport
  • Clear description of the right you wish to exercise
  • Any supporting documentation

We will respond to your ARCO request within 10 business days. If we need additional time, we may extend the response period by 5 business days and will notify you of the extension.

14.22.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.22.6 Personal data of minors

In accordance with Peruvian law, we obtain consent from parents or legal guardians (padres o tutores legales) before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent.

14.22.7 National Authority for the Protection of Personal Data

You have the right to lodge a complaint with the Peruvian data protection authority:

Autoridad Nacional de Protección de Datos Personales
Dirección General de Transparencia, Acceso a la Información Pública y Protección de Datos Personales
Ministry of Justice and Human Rights
Address: Calle Scipión Llona 350, Miraflores, Lima, Peru
Website: https://www.minjus.gob.pe/proteccion-de-datos-personales/
Email: protecciondedatospersonales@minjus.gob.pe

14.22.8 Exercising your rights

Email: info@meni.ge
Subject line: "Solicitud de Derechos ARCO - Ley 29733" or "ARCO Rights Request"

14.23 For users in Chile

If you are a resident of the Republic of Chile, the following provisions apply to you under the Law on Protection of Private Life:

14.23.1 Chilean data protection law compliance

We process your personal data in accordance with the Law on Protection of Private Life (Ley sobre Protección de la Vida Privada, Law No. 19.628), enacted on August 28, 1999.

Chile is in the process of modernizing its data protection legislation to align with international standards including GDPR.

14.23.2 Legal bases for processing under Chilean law

We process your personal data based on the following legal bases under Chilean law:

  • Consent – when you provide express consent
  • Authorization by law – when processing is authorized by legal provisions
  • Sources accessible to the public – for publicly available data
  • Performance of a contract – to fulfill contractual obligations

14.23.3 Sensitive personal data

Under Chilean law, the following data we collect is considered sensitive (datos sensibles) and requires express written consent:

  • Biometric data – photos and facial caricatures
  • Health data – dietary restrictions or allergies
  • Physical characteristics – information about your appearance or physical attributes

We process sensitive data only with your express written consent.

14.23.4 Your rights under Chilean law

Under Chilean data protection law, you have the following rights:

  • Right of access (información) – know what personal data is stored in databases
  • Right to rectification (modificación) – request correction of inaccurate or incomplete data
  • Right to deletion (eliminación) – request deletion of data when processing is unlawful or no longer necessary
  • Right to blocking (bloqueo) – request blocking of data in certain circumstances
  • Right to object (oposición) – object to processing
  • Right to revoke consent – withdraw your consent at any time

14.23.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.23.6 Personal data of minors

In accordance with Chilean law and general principles of protection of minors, we obtain consent from parents or legal guardians (padres o representantes legales) before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent.

14.23.7 National Consumer Service (SERNAC)

For data protection matters, you may contact:

Servicio Nacional del Consumidor (SERNAC)
Website: https://www.sernac.cl
Phone: 800 700 100
Address: Teatinos 120, Santiago, Chile

You may also file a habeas data action (acción de protección or recurso de amparo) in Chilean courts to protect your personal data rights.

14.23.8 Exercising your rights

To exercise your rights under Chilean law, please contact us at:

Email: info@meni.ge
Subject line: "Solicitud de Derechos - Ley 19.628" or "Data Rights Request"

We will respond to your request within a reasonable timeframe.

14.24 For users in Colombia

If you are a resident of the Republic of Colombia, the following provisions apply to you under the Statutory Law on Personal Data Protection:

14.24.1 Colombian data protection law compliance

We process your personal data in accordance with the Statutory Law on Personal Data Protection (Ley Estatutaria de Protección de Datos Personales, Law No. 1581), enacted on October 17, 2012, and its implementing regulations (Decree 1377 of 2013).

14.24.2 Legal bases for processing under Colombian law

We process your personal data based on the following legal bases under Colombian law:

  • Prior, express and informed consent – when you provide consent that is free, specific, informed and unequivocal
  • Performance of a contract – to fulfill contractual obligations
  • Legal or judicial mandate – to comply with legal requirements
  • Vital interests – to protect vital interests of the data subject

14.24.3 Sensitive personal data

Under Colombian law, the following data we collect is considered sensitive (datos sensibles) and requires prior, express and informed consent:

  • Biometric data – photos and facial caricatures used for identification
  • Health data – dietary restrictions or allergies related to health conditions

We process sensitive data only with your prior, express and informed consent. You have the right to refuse to provide sensitive data without negative consequences, though this may limit certain features of the Service.

14.24.4 Your rights under Colombian law

Under Colombian data protection law, you have the following rights:

  • Right to know (conocer) – know, update and rectify your personal data
  • Right to access (acceder) – access your personal data free of charge
  • Right to update (actualizar) – request updating of incomplete or outdated data
  • Right to rectification (rectificar) – request correction of inaccurate data
  • Right to deletion (suprimir) – request deletion when processing is unlawful or consent is revoked
  • Right to revoke consent (revocar) – revoke authorization at any time
  • Right to file complaints (presentar quejas) – lodge complaints with the Superintendence for violations of the law

To exercise your rights, please submit a request to info@meni.ge with:

  • Full name and contact information
  • Copy of your national ID (cédula de ciudadanía) or passport
  • Clear description of the right you wish to exercise and the data concerned
  • Contact address for receiving responses

We will respond to your request within 10 business days informing you whether we accept or reject it. If accepted, we will implement your request within 15 business days.

14.24.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.24.6 Personal data of minors

In accordance with Colombian law, we obtain authorization from parents or legal guardians (padres o representantes legales) before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent.

Colombian law provides special protection for personal data of children and adolescents, requiring that processing respect their prevalence and superiority of rights.

14.24.7 Superintendence of Industry and Commerce (SIC)

You have the right to lodge a complaint with the Colombian data protection authority:

Superintendencia de Industria y Comercio (SIC)
Dirección de Investigación de Protección de Datos Personales
Address: Carrera 13 No. 27-00, Pisos 1 y 3, Bogotá D.C., Colombia
Website: https://www.sic.gov.co
Phone: (+57 1) 587 0000
Email: contactenos@sic.gov.co

14.24.8 Database registration

In compliance with Colombian law, personal data databases must be registered with the National Registry of Databases (Registro Nacional de Bases de Datos - RNBD) administered by the Superintendence of Industry and Commerce.

We comply with database registration requirements as applicable to our operations in Colombia.

14.24.9 Exercising your rights

To exercise your rights under Colombian law, please contact us at:

Email: info@meni.ge
Subject line: "Solicitud de Derechos - Ley 1581" or "Data Rights Request"

14.25 For users in Indonesia

If you are a resident of the Republic of Indonesia, the following provisions apply to you under the Personal Data Protection Law:

14.25.1 Indonesian data protection law compliance

We process your personal data in accordance with the Personal Data Protection Law (Undang-Undang Perlindungan Data Pribadi, Law No. 27 of 2022), enacted on October 17, 2022.

The law has a 2-year transition period for full implementation, during which we are working to ensure full compliance.

14.25.2 Legal bases for processing under Indonesian law

We process your personal data based on the following legal bases under Indonesian law:

  • Consent – when you provide explicit consent for processing
  • Performance of a contract – to fulfill our contractual obligations
  • Legal obligation – to comply with Indonesian legal requirements
  • Vital interests – to protect your vital interests or those of another person
  • Public interest – for tasks carried out in the public interest
  • Legitimate interests – where necessary for our legitimate interests, provided this does not override your fundamental rights

14.25.3 Sensitive personal data

Under Indonesian law, the following data we collect is considered specific personal data (data pribadi yang bersifat spesifik) and requires explicit consent:

  • Biometric data – photos and facial caricatures used for identification
  • Health data – dietary restrictions or allergies related to health conditions
  • Children's data – personal data of persons under 18 years old

We process specific personal data only with your explicit consent and implement additional security measures.

14.25.4 Your rights under Indonesian law

Under Indonesian data protection law, you have the following rights:

  • Right to information – be informed about the processing of your personal data
  • Right of access – obtain confirmation and copies of your personal data
  • Right to rectification – request correction of inaccurate or incomplete data
  • Right to erasure – request deletion of your data in certain circumstances
  • Right to restriction – request limitation of processing in certain cases
  • Right to data portability – receive your data in structured, machine-readable format
  • Right to object – object to processing based on legitimate interests
  • Right to withdraw consent – withdraw consent at any time
  • Right to complain – lodge a complaint with the supervisory authority

14.25.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.25.6 Personal data of children

In accordance with Indonesian law, we obtain consent from parents or legal guardians (orang tua atau wali) before processing personal data of children under 18 years old.

The Service is not intended for children under 16 without parental consent.

14.25.7 Data breach notification

In the event of a personal data breach, we will:

  • Notify the Indonesian data protection authority within 72 hours
  • Notify affected individuals if the breach poses a high risk
  • Take immediate measures to mitigate the effects of the breach
  • Document the breach and our response

14.25.8 Ministry of Communication and Informatics

For data protection matters in Indonesia, the supervisory authority is:

Ministry of Communication and Informatics (Kementerian Komunikasi dan Informatika / Kominfo)
Website: https://www.kominfo.go.id
Email: humas@mail.kominfo.go.id

The government is establishing a dedicated Personal Data Protection Agency as required by the law.

14.25.9 Exercising your rights

To exercise your rights under Indonesian law, please contact us at:

Email: info@meni.ge

Subject line: "Personal Data Rights Request" or "Permintaan Hak Perlindungan Data Pribadi"

We will respond to your request within a reasonable timeframe as required by Indonesian law.

14.26 For users in the Philippines

If you are a resident of the Republic of the Philippines, the following provisions apply to you under the Data Privacy Act:

14.26.1 Philippine data protection law compliance

We process your personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173), enacted on August 15, 2012, and its Implementing Rules and Regulations.

The Philippines has one of the most comprehensive data privacy frameworks in Southeast Asia.

14.26.2 Legal bases for processing under Philippine law

We process your personal data based on the following legal bases under Philippine law:

  • Consent – when you provide consent freely, specifically and informed manner
  • Performance of a contract – to fulfill contractual obligations
  • Compliance with legal obligation – to comply with Philippine legal requirements
  • Protection of vital interests – to protect your vital interests
  • Legitimate interests – where processing is necessary for our legitimate interests, provided this does not override your rights and freedoms

14.26.3 Sensitive personal information

Under Philippine law, the following data we collect is considered sensitive personal information and requires additional consent:

  • Biometric data – photos and facial caricatures that can identify you
  • Health information – dietary restrictions or allergies related to health conditions
  • Age – when collected for specific purposes

We process sensitive personal information only with your consent, and we implement strict security measures to protect it.

14.26.4 Your rights under Philippine law

Under the Data Privacy Act, you have the following rights:

  • Right to be informed – be informed about the collection and processing of your personal data
  • Right to access – obtain reasonable access to your personal data
  • Right to object – object to processing, including direct marketing and automated decision-making
  • Right to erasure or blocking – request suspension, withdrawal or removal of your data
  • Right to rectification – request correction of inaccurate or outdated data
  • Right to data portability – receive your data in electronic or structured format and transmit to another controller
  • Right to file a complaint – lodge a complaint with the National Privacy Commission
  • Right to damages – seek damages for violations of your rights

14.26.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.26.6 Personal data of minors

In accordance with Philippine law, we obtain consent from parents or legal guardians before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent. We take special measures to protect children's privacy and comply with Philippine laws on child protection.

14.26.7 Data breach notification

In the event of a personal data breach, we will:

  • Notify the National Privacy Commission (NPC) within 72 hours of becoming aware of the breach
  • Notify affected individuals if the breach is likely to give rise to a real risk of serious harm
  • Document the breach and our response as required by NPC regulations
  • Take measures to mitigate harm and prevent future breaches

14.26.8 National Privacy Commission (NPC)

You have the right to lodge a complaint with the Philippine data protection authority:

National Privacy Commission (NPC / Pambansang Komisyon sa Pagkapribado)
Address: 5th Floor, Delegation Building, PICC Complex, Pasay City, Metro Manila, Philippines
Website: https://www.privacy.gov.ph
Email: info@privacy.gov.ph
Hotline: (+632) 8234-2228

The NPC has the authority to investigate complaints, impose penalties, and issue compliance orders for violations of the Data Privacy Act.

14.26.9 Registration with NPC

We comply with registration requirements under the Data Privacy Act as applicable to our operations in the Philippines.

14.26.10 Exercising your rights

To exercise your rights under Philippine law, please contact us at:

Email: info@meni.ge

Subject line: "Data Rights Request" or "Kahilingan para sa Karapatan sa Datos"

We will respond to your request within 15 days for access requests, or within a reasonable period for other requests, as required by Philippine law and NPC guidelines.

14.27 For users in Vietnam

If you are a resident of the Socialist Republic of Vietnam, the following provisions apply to you under Vietnamese data protection regulations:

14.27.1 Vietnamese data protection law compliance

We process your personal data in accordance with Vietnamese laws and regulations, including the Law on Cybersecurity (Luật An ninh mạng, Law No. 24/2018/QH14) and the Decree on Personal Data Protection (Nghị định về Bảo vệ dữ liệu cá nhân, Decree No. 13/2023/NĐ-CP), which came into effect on July 1, 2023.

14.27.2 Legal bases for processing under Vietnamese law

We process your personal data based on the following legal bases under Vietnamese law:

  • Consent – when you provide consent freely, specifically and informed
  • Performance of a contract – to fulfill contractual obligations
  • Legal obligation – to comply with Vietnamese legal requirements
  • Vital interests – to protect your vital interests or public health
  • Public interest – for tasks carried out in the public interest
  • Legitimate interests – where necessary for our legitimate interests

14.27.3 Sensitive personal data

Under Vietnamese law, the following data we collect is considered sensitive personal data and requires explicit consent:

  • Biometric data – photos and facial caricatures used for personal identification
  • Health data – dietary restrictions or allergies related to health conditions
  • Data of minors – personal data of persons under 16 years old

We process sensitive personal data only with your explicit consent and implement enhanced security measures.

14.27.4 Your rights under Vietnamese law

Under Vietnamese data protection regulations, you have the following rights:

  • Right to be informed – be informed about the processing of your personal data
  • Right of access – access your personal data
  • Right to rectification – request correction of inaccurate or incomplete data
  • Right to erasure – request deletion of your data in certain circumstances
  • Right to restriction – request limitation of processing
  • Right to data portability – receive your data in structured format
  • Right to object – object to processing
  • Right to withdraw consent – withdraw consent at any time
  • Right to complain – lodge a complaint with the supervisory authority

14.27.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.27.6 Personal data of children

In accordance with Vietnamese law, we obtain consent from parents or legal guardians (cha mẹ hoặc người giám hộ hợp pháp) before processing personal data of children under 16 years old.

The Service is not intended for children under 16 without parental consent.

14.27.7 Data breach notification

In the event of a personal data breach, we will:

  • Notify the competent Vietnamese authority as required by law
  • Notify affected individuals if the breach may cause serious harm
  • Take measures to mitigate the effects of the breach
  • Document the breach and our response

14.27.8 Ministry of Public Security - Department of Cybersecurity and Hi-Tech Crime Prevention

For data protection matters in Vietnam, the supervisory authority is:

Ministry of Public Security - Department of Cybersecurity and Hi-Tech Crime Prevention
Bộ Công an - Cục An ninh mạng và Phòng chống tội phạm sử dụng công nghệ cao
Website: https://www.bocongan.gov.vn

14.27.9 Exercising your rights

To exercise your rights under Vietnamese law, please contact us at:

Email: info@meni.ge

Subject line: "Personal Data Rights Request" or "Yêu cầu quyền về dữ liệu cá nhân"

We will respond to your request within a reasonable timeframe as required by Vietnamese law.

14.28 For users in Thailand

If you are a resident of the Kingdom of Thailand, the following provisions apply to you under the Personal Data Protection Act:

14.28.1 Thai data protection law compliance

We process your personal data in accordance with the Personal Data Protection Act (พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562, B.E. 2562 / 2019), which came into full effect on June 1, 2022.

Thailand's PDPA is based on EU GDPR principles and provides comprehensive data protection rights.

14.28.2 Legal bases for processing under Thai law

We process your personal data based on the following legal bases under Thai law:

  • Consent – when you provide consent freely, specifically, informed and unambiguous
  • Performance of a contract – to fulfill contractual obligations
  • Legal obligation – to comply with Thai legal requirements
  • Vital interests – to protect your vital interests or those of another person
  • Public interest or official authority – for tasks carried out in the public interest
  • Legitimate interests – where necessary for our legitimate interests, provided this does not override your rights and freedoms

14.28.3 Sensitive personal data

Under Thai law, the following data we collect is considered sensitive personal data (ข้อมูลส่วนบุคคลที่มีความอ่อนไหว) and requires explicit consent:

  • Biometric data – photos and facial caricatures used for identification
  • Health data – dietary restrictions or allergies related to health conditions

We process sensitive personal data only with your explicit consent. You have the right to refuse consent for sensitive data processing without negative consequences, though this may limit certain features.

14.28.4 Your rights under Thai law

Under Thai PDPA, you have the following rights:

  • Right to be informed – be informed about the collection and processing of your personal data
  • Right of access – access your personal data and request copies
  • Right to data portability – receive your data in structured, commonly used format and transmit to another controller
  • Right to object – object to processing including for direct marketing
  • Right to erasure – request deletion of your data in certain circumstances
  • Right to restriction – request restriction of processing
  • Right to rectification – request correction of inaccurate or incomplete data
  • Right to complain – lodge a complaint with the Personal Data Protection Committee
  • Right to withdraw consent – withdraw consent at any time

14.28.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.28.6 Personal data of children

In accordance with Thai law, we obtain consent from parents or legal guardians (พ่อแม่หรือผู้ปกครอง) before processing personal data of minors.

Important: In Thailand, persons under 20 years old are considered minors. The Service is not intended for persons under 18 without parental consent.

14.28.7 Data Protection Officer (DPO)

As our operations in Thailand develop, we will appoint a Data Protection Officer (เจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล) if required by law.

14.28.8 Personal Data Protection Committee (PDPC)

You have the right to lodge a complaint with the Thai data protection authority:

Personal Data Protection Committee (PDPC / คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล)
Office of the Personal Data Protection Committee
Ministry of Digital Economy and Society
Website: https://www.mdes.go.th
Email: pdpc@mdes.go.th

14.28.9 Exercising your rights

To exercise your rights under Thai law, please contact us at:

Email: info@meni.ge

Subject line: "Personal Data Rights Request" or "คำขอใช้สิทธิข้อมูลส่วนบุคคล"

We will respond to your request within 30 days as required by Thai law.

14.29 For users in Myanmar

If you are a resident of the Republic of the Union of Myanmar, the following provisions apply to you under Myanmar law and regulations:

14.29.1 Myanmar data protection compliance

We process your personal data in accordance with Myanmar laws and regulations, including the Privacy and Security Law (2013), the Electronic Transactions Law (2004), and relevant regulations.

Myanmar is in the process of developing more comprehensive data protection legislation.

14.29.2 Legal bases for processing under Myanmar law

We process your personal data based on the following principles:

  • Consent – when you provide consent for processing
  • Contractual necessity – to provide the Service you requested
  • Legal compliance – to comply with Myanmar legal requirements
  • Legitimate purposes – where necessary for lawful business purposes

14.29.3 Sensitive personal information

We handle the following sensitive information with additional care and security:

  • Biometric data – photos and facial caricatures
  • Health information – dietary restrictions or allergies
  • Personal identification information

We process such data only with your consent and implement appropriate security measures.

14.29.4 Your rights under Myanmar law

Under Myanmar law and international best practices, you have the following rights:

  • Right to information – be informed about the processing of your personal data
  • Right to access – access your personal data
  • Right to correction – request correction of inaccurate data
  • Right to deletion – request deletion of data in certain circumstances
  • Right to object – object to processing
  • Right to withdraw consent – withdraw consent at any time

14.29.5 Cross-border transfer of personal data

The recipients and processing locations depend on the brand and feature, as described in sections 6–7. Principal infrastructure may be in the United States, Germany or the Russian Federation; a provider or authorised access route may involve another country. We do not promise that every user's information is stored in Germany or remains in the EEA.

Where local law imposes localisation or international-transfer requirements, those requirements must be met for the relevant processing. A privacy-policy acceptance or a feature setting is not blanket consent to all international transfers. Contact info@meni.ge for information about the destinations, recipients and safeguards applicable to your data. Mandatory local requirements and rights continue to apply.

14.29.6 Personal data of minors

In accordance with Myanmar law and international best practices, we obtain consent from parents or legal guardians before processing personal data of minors under 18 years old.

The Service is not intended for children under 16 without parental consent.

14.29.7 Security measures

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security assessments
  • Employee training on data protection
  • Incident response procedures

14.29.8 Data protection inquiries

For data protection matters in Myanmar, you may contact relevant authorities or industry bodies such as:

Ministry of Transport and Communications
Website: https://www.motc.gov.mm

As Myanmar develops its data protection framework, dedicated supervisory authorities may be established.

14.29.9 Exercising your rights

To exercise your rights or for data protection inquiries, please contact us at:

Email: info@meni.ge

Subject line: "Personal Data Rights Request"

We will respond to your request within a reasonable timeframe.

15. How to contact us

For privacy questions or requests about any brand covered by this Policy, contact:

Individual Entrepreneur ANDREI VERBITSKII
Registered in the Republic of Georgia
Identification Number: 305573448
Registered address: Georgia, Tbilisi, Vake district, s. Chikovani street, N 24a, hall 2, flat N36a
Email: info@meni.ge

If the information is controlled by a business using the Service, identify that business where possible so that we can direct the request and assist it. You may contact us even after your access to a business account has ended.