Privacy statement Jesdi

Version 1.0 · effective from 1 October 2026

This is a translation of the Dutch original. In case of any difference in meaning, the Dutch version prevails.

Jesdi supplies an online reservation system to restaurants and other hospitality businesses. In this privacy statement you can read which personal data we process, why, and what rights you have.

Have you made a reservation at a restaurant? Then that restaurant is responsible for your data and we are only the supplier of the system (processor). For questions, access or deletion, please see the restaurant's privacy statement or contact the restaurant. You can always unsubscribe from a restaurant's newsletter via the link at the bottom of every e-mail. See also Data of restaurant guests.

Who are we?

Jesdi, established at Eksterstraat 139, 1742 ER Schagen, registered with the Netherlands Chamber of Commerce (Kamer van Koophandel, KvK) under number [KvK-nummer], is the controller for the processing operations described in this statement. You can reach us at info@jesdi.nl.

Which data do we process, why and on what legal basis?

Whose dataWhich dataWhyLegal basis
Customers (restaurants) and their contact personName, e-mail address, telephone number, company name, address, company registration number (KvK), VAT number, payment details such as IBAN and direct debit mandateCreating and managing the account, providing the service, invoicing and contact about the servicePerformance of the contract
CustomersWhich version of the terms and conditions and data processing agreement was accepted, when and by whom, with a hashed representation of the IP addressBeing able to demonstrate that the agreement was concludedLegitimate interest
Users of the back office and appName, e-mail address, encrypted password, login times, device data for push notificationsSecure login and sending notificationsPerformance of the contract
Anyone who e-mails us or fills in the sign-up formThe data you send usAnswering your question, processing your sign-upPerformance of the contract or legitimate interest
Visitors to our website and the serviceIP address, browser data, time, in server logsSecurity, preventing misuse and resolving faultsLegitimate interest
CustomersInvoice dataComplying with the statutory tax retention obligationLegal obligation

We do not sell personal data and do not use it for advertising. We do not take decisions based solely on automated processing.

How long do we keep data?

  • Account data: for as long as the customer uses the service, and up to 90 days thereafter.
  • Invoices and accounting records: 7 years, due to the statutory tax retention obligation.
  • Proof of acceptance of the terms and conditions: for the duration of the agreement plus 2 years.
  • Server logs: no more than 90 days.
  • E-mails with questions: for as long as necessary to deal with the question, no more than 2 years.

With whom do we share data?

We engage only parties that are necessary to provide the service, and where necessary we conclude a data processing agreement with them:

  • STRATO AG for hosting and back-ups (Germany, EU);
  • STRATO AG for sending e-mail (Germany, EU);
  • the notification services of Google, Apple, Mozilla and Microsoft for encrypted push notifications (they cannot read the content);
  • Moneybird B.V. (Netherlands), for our accounting, sending invoices and the direct debit of customers' subscriptions;
  • our accountant, for our accounting records.

We only provide data to others if the law requires us to do so.

Transfers outside the EEA

We store data within the European Economic Area. Only encrypted push notifications pass through services that also operate outside the EEA; for these, the EU-U.S. Data Privacy Framework or standard contractual clauses of the European Commission apply.

Cookies

Our website and the service use only functional cookies that are necessary to log in and stay logged in. We do not use tracking, advertising or analytics cookies. That is why we do not ask for consent for cookies. The reservation widget on a restaurant's website does not place any cookies.

Security

We secure data with measures including encrypted connections (HTTPS), passwords stored in encrypted form, strict separation between restaurants and regular back-ups. A comprehensive list can be found in Annex 2 of our data processing agreement.

Data of restaurant guests

If you make a reservation via a restaurant's website, the restaurant records your name, e-mail address, telephone number, the reservation and any comments in our system. The restaurant is the controller for this; we process those data only on behalf of the restaurant, in accordance with our data processing agreement. The restaurant can also see how often you have visited.

  • You will only receive newsletters or a monthly menu if you ticked the box for this yourself when making your reservation. You can unsubscribe with one click at the bottom of every e-mail.
  • You can view or cancel your reservation via the link in your confirmation e-mail.
  • Would you like access, correction or deletion? Please contact the restaurant; the restaurant can arrange this directly in our system. If you e-mail us, we will forward your request to the restaurant.

Your rights

You have the right to access your data, to have it corrected or deleted, to have its processing restricted, to object to processing based on legitimate interest, and to receive your data in a commonly used format (data portability). Send your request to info@jesdi.nl. We will respond within one month and may ask you to confirm your identity.

Do you have a complaint about how we handle your data? Let us know and we will work with you to find a solution. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Changes

We may amend this privacy statement. The date at the top shows when this was last done. In the event of important changes, we will inform customers by e-mail.