Skip to content
Tembrel.Back to the homepage

Privacy Policy

How Tembrel handles personal data across its website, business relationships and customer guest experiences.

Last updated 25 September 2026

On this page

  1. Who we are and when this policy applies
  2. Information we handle
  3. The website and demo requests
  4. Purposes and lawful bases
  5. Cookies, storage and voice input
  6. AI-assisted answers
  7. Providers and other disclosures
  8. International processing
  9. Retention and deletion
  10. Security
  11. Your rights and choices
  12. Children, changes and contact

Who we are and when this policy applies

Tembrel is operated by Zadok Enterprise, Netherlands ("Tembrel", "we" or "us"). You can contact us at [email protected].

This policy explains how we handle personal data when you visit our website, contact us, discuss a demo, administer a business account or use Tembrel. It also explains our role when a food-service business uses Tembrel to provide menu recommendations and answer guest questions.

We act as controller when we decide why and how to handle our business contacts, account administration and our own operational or security records. When we handle a business customer's menu content, guest conversations and associated data to provide that customer's configured service under its instructions, we act as processor on its behalf. That customer's privacy notice and our Data Processing Agreement govern those activities. The role follows the particular processing activity, not simply whether someone uses a widget.

Information we handle

  • Business contacts: your name, email, business name, website and information you choose to include in an enquiry or support message. These may come from you or a colleague acting for your business.
  • Accounts: names, email addresses, password hashes, authentication and recovery records, permissions, organization and location membership, session identifiers and expiry, and IP address or browser information where available.
  • Business content: menu items, descriptions, house notes, pairings, configuration and revisions. This may include personal data entered by staff.
  • Guest interactions: random session identifiers, menu and recommendation references, recommendation text, displays and actions, add-to-order events, language and timestamps. Questions and answers can include up to three preceding conversation turns, menu context and escalation information. Feedback can include a rating and free-text comment. The business can review these records.
  • Order evidence: source order and item identifiers, timestamps, revisions, quantities, prices, currency and source/channel information. The order contract has no dedicated fields for guest names, email, addresses or payment-card details, but source identifiers and free text may still be personal data.
  • Operations: request identifiers, paths, status and timing, account/security events, audit actors and changes, and integration delivery records. Configured billing or integrations may also involve customer/subscription identifiers, billing status and protected connection credentials.

Demo handling also uses keyed, non-readable representations of email, network address and a submission identifier to limit abuse and duplicate requests, plus delivery attempts and provider message identifiers. We do not store the raw network address in the demo-request record.

Information needed to authenticate an account, administer access or answer a request is necessary for that function. Optional fields can be left blank. Avoid putting sensitive personal information into menu notes, questions or feedback.

The website and demo requests

The website's Fennel & Ash examples use fictional menu content and a local, deterministic simulation. They do not call live AI, activate a microphone or send product analytics.

When enabled, the Request a demo form sends your name, email and business name, plus an optional website and message, to Tembrel for validation and handling. We store the request, notify our team and queue a transactional acknowledgement. This does not book an appointment or subscribe you to marketing. If submission is unavailable, the form reports that rather than confirming receipt. Local development confirmations explicitly distinguish local storage from email delivery. Direct correspondence is used to respond and manage the conversation.

The marketing application does not set analytics or advertising cookies or include an application analytics tracker. Fonts and images are served locally. Ordinary requests to load a website expose network and request information to its hosting infrastructure; this is distinct from the guest-product events described above.

Purposes and lawful bases

Where the GDPR applies to activities for which we are controller, we use the following bases, limited to what is necessary for the stated purpose:

  • Enquiries and business relationships: our legitimate interests in answering requests and communicating with business representatives. Where you personally are the prospective or existing contracting customer, processing necessary to take steps you request or perform that contract is based on Article 6(1)(b).
  • Account administration and service operation: our legitimate interests in providing and administering the business service, managing authorized users and diagnosing problems. A business contract does not automatically make contract performance the legal basis for processing an employee's data.
  • Security and abuse prevention: our legitimate interests in protecting accounts, enforcing access permissions, preventing misuse and investigating incidents.
  • Legal obligations: Article 6(1)(c) where an applicable law requires particular records or disclosures.
  • Optional activities requiring consent: Article 6(1)(a) where we ask for a specific choice and consent is required. Reading this policy or using the website is not consent to unrelated processing.

We rely on legitimate interests under Article 6(1)(f) only where those interests are not overridden by your rights and interests. You can object as explained below. Customer-directed guest processing follows the customer's instructions and lawful basis; this policy does not supply that basis for the customer. Sensitive data requires an additional applicable legal condition and must not be requested merely because a guest can enter free text.

Cookies, storage and voice input

The live guest widget uses browser session storage for a random identifier, interaction state, recent recommendations and conversation turns. Admin uses session cookies for authentication and tab storage for sign-in and integration state. Authentication cookies are HttpOnly and SameSite=Lax, with Secure protection outside development. You can manage cookies and storage through your browser; blocking them may affect sign-in or continuity. The business embedding the widget is responsible for its website's notices and any consent needed for its chosen use.

Live dictation uses your browser's speech-recognition capability when supported and activated. The browser may transmit audio to its vendor's service. Tembrel's widget does not upload or store an audio recording itself. The transcript is text and, if submitted, is processed like a typed question, including storage of the question and relevant conversation context. Browser-vendor processing is subject to that vendor's arrangements. You can type instead and manage microphone permission in your browser. The marketing simulation captures no audio.

AI-assisted answers

When enabled, AI-assisted questions and dish explanations use Anthropic. The request may include menu facts, house knowledge, the question, recent conversation turns, language, tone and relevant menu or popularity context. Deterministic pairing recommendations are separate and do not require generating every answer with a model.

Guest answers are made available to the customer for its menu experience and review. Do not include information that is unnecessary for the question. A model can produce an incomplete or incorrect answer, and should not be relied upon for allergy or dietary safety. Confirm safety-sensitive information with the business's staff.

This policy does not promise that a model provider retains no data or processes it only in a particular country. Provider handling is governed by the applicable service and data-processing arrangements.

Providers and other disclosures

  • Resend: Transactional email delivery and delivery webhooks. Configured and verified in staging; controlled transactional delivery accepted. Production is not active..
  • Cloudflare: Workers, Pages, Hyperdrive and Worker logs. Configured and verified in staging.
  • Neon: Hosted PostgreSQL through Cloudflare Hyperdrive. Configured and verified in staging.
  • Anthropic: API for enabled menu questions and dish explanations. Enabled in staging; a real response and quota enforcement are documented.

See the Subprocessor List for purpose, location, evidence scope and transfer information. These records do not establish live production appointments.

Inbound messages to our public Tembrel addresses are forwarded by Cloudflare Email Routing to a monitored Google Gmail mailbox. This is our business and legal correspondence, separate from transactional application sending and customer-directed guest processing. Mailbox and routing-provider processing may occur outside the EEA; we do not claim an exclusive European location.

Resend sends transactional account messages and demo-request acknowledgements and internal notifications when those features are enabled. These messages are not marketing mail. Resend processes recipient addresses, message content and delivery metadata; its documented US storage and transfer arrangements are described in the Subprocessor List. Cloudflare Email Routing separately forwards inbound messages to our published Tembrel addresses.

Other integrations only process information when configured for a customer. The presence of Stripe, Square or Lightspeed code does not mean those services are active for every customer. Customer-authorized integrations and browser voice services may have their own privacy terms. Information about processors used for a customer's service is addressed in its processing arrangements; the Subprocessor List records the evidenced services and their scope.

We may disclose information where necessary to comply with a binding legal requirement, establish or defend legal claims, or address a serious security or safety issue. We limit disclosure to what is appropriate for that purpose. If our business is involved in an acquisition, financing or restructuring, relevant information may be disclosed subject to appropriate confidentiality and data-protection requirements. This does not authorize unrelated use of guest data processed for a customer.

International processing

Processing location depends on the provider and service configuration. The Subprocessor List records established locations and the limits of that evidence. Database location alone does not establish where all hosting, support, logs or AI processing occurs.

Before a service transfers personal data subject to EEA restrictions to a country without an applicable adequacy decision, the relevant processing arrangement must establish a lawful safeguard, such as the European Commission's standard contractual clauses, with additional measures where necessary. Customer instructions and processing terms also apply to transfers made on a customer's behalf. We do not present provider availability of these clauses as proof that a particular arrangement has been executed.

Contact us for the processing locations and safeguards relevant to your service, and for information about obtaining a copy of applicable safeguards, subject to appropriate redaction.

Retention and deletion

For our own purposes, we retain personal data for the period reasonably needed to respond to an enquiry, administer the relationship, protect the service or meet an applicable legal obligation. Relevant factors include whether the relationship is active, the sensitivity and purpose of the records, unresolved issues, applicable claim periods and legal requirements. We do not use a single retention period for every category.

The implemented demo-intake workflow expires the original request and its delivery-job records after 90 days, with bounded scheduled deletion. An earlier verified deletion request can also be handled. This schedule does not automatically erase copies already delivered to an inbox or provider-held copies. Correspondence retained for an ongoing business relationship follows the purpose-based criteria above; inbox and provider copies must be addressed separately when handling deletion.

Customer-directed data follows the applicable processing agreement and instructions. The documented staging event-cleanup configuration uses a 400-day cutoff for recommendation events, menu-add events and guest questions, with daily bounded deletion. Linked feedback is deleted with its question. Batch limits or failures can delay completion; this is not a promise of deletion at an exact instant. Separate rules clean up eligible recovery, delivery and session records.

Source orders and general audit records are not erased by the guest-event schedule. Organization offboarding disables access and revokes sessions but does not itself erase all records or backups. Data return or deletion must be addressed separately through the customer processing arrangements. An operational audit export is not a complete response to a privacy-access request. Records kept for a legal obligation or claim are restricted to that purpose.

Security

Implemented controls include password hashing, multi-factor authentication, role and location access checks, database row-level controls, session protection, origin checks and rate limits. Stored POS connection credentials are protected with encryption. Operational logging supports diagnosis and security investigation.

No website or service can guarantee absolute security. These controls are not a certification or a guarantee of uninterrupted or error-free service. Protect your account credentials. Business users should promptly notify their account administrator of suspected unauthorized access.

Your rights and choices

Where applicable, you can request access to your personal data, correction, erasure, restriction of processing and portability. You can object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. These rights have conditions and exceptions; not every right applies to every record.

Contact [email protected] to make a request. Describe the request and your relationship to Tembrel without sending unnecessary sensitive information. We may request proportionate information to verify identity or authority. We respond within the applicable statutory timeframe, normally one month under the GDPR, and explain any permitted extension or refusal.

For data submitted through a business's guest experience, contact that business first. If you contact us, we will help identify the responsible customer where reasonably possible and support it under the applicable processing arrangements. You can complain to a competent supervisory authority, including in the EEA country where you live, work or believe an infringement occurred. You do not have to contact us before doing so.

Children, changes and contact

Tembrel's business accounts and sales relationship are intended for adults acting for a business. A guest-facing menu may be viewed by people of different ages; we do not assume every guest is an adult. Customers must consider their audience and provide any required age-appropriate notices or consent arrangements. Contact us if you believe a child has provided personal data that needs attention.

We update this policy when relevant practices change and show the update date above. For a material change, we provide additional notice where appropriate or required. A change to this policy does not by itself create consent for a new purpose.

Zadok Enterprise (eenmanszaak), Netherlands. Trading as Tembrel.
KVK: 42135196
VAT: NL005523644B68
Privacy contact: [email protected]
Legal contact: [email protected]

Back to top
Tembrel.
Privacy PolicyTerms of ServiceDPASubprocessors