Kellno

Privacy policy

1. Controller

Oleksandr Rybalchenko, An d. Ottosäule 14, 85521 Ottobrunn, Deutschland. Email: support@kellno.com.

2. Hosting and server log files

When you visit this website, technically necessary data (IP address, date and time, requested page, browser and operating system information) is processed in server log files. This serves the secure and stable operation of the website (Art. 6(1)(f) GDPR).

The website is hosted by Railway Corporation. Enquiries from the contact form are stored in a database at Supabase Inc. (data centre in London, United Kingdom). Data processing agreements are or will be concluded with both providers. Where data is transferred to countries outside the EU/EEA (e.g. the United Kingdom, the USA), this is based on an adequacy decision of the EU Commission or standard contractual clauses.

3. Cookies and tracking

The public pages of this website and the menus for guests do not set cookies, store nothing on your device and do not use third-party tracking or analytics services. A cookie banner is therefore not required.

In the customer area we use only technically necessary cookies: cookies for signing in (session) and one cookie that remembers the language you chose for the customer area for one year (Art. 6(1)(b) GDPR, Section 25(2) no. 2 TDDDG).

4. Contact form and email

If you contact us via the form or by email we process restaurant name, name, email address and – where provided – phone number, city and message, to answer your enquiry and present our offer. The legal basis is your consent (Art. 6(1)(a) GDPR) or steps prior to entering into a contract (Art. 6(1)(b) GDPR). You can withdraw consent at any time with effect for the future.

We delete your details once they are no longer needed for the purpose, at the latest twelve months after the last communication, unless statutory retention obligations apply.

5. Demo on the home page

The interactive demo on the home page (menu, language switch, AI chat) runs entirely in your browser with fixed sample data. No data is transmitted to us, to any third party or to OpenAI, and no cookies are set.

A link on the page also leads to the real, public menu of our reference customer Donisl at donislki.nocodly.com. The notes under section 6 for guest menus apply there.

6. Customer account, menu data and AI features

If you create an account we process your email address and password (as a hash only) through Supabase authentication so that you can use the customer area (Art. 6(1)(b) GDPR). Your menu content (dishes, prices, photos, logo, texts) is stored at Supabase and shown publicly at your menu address.

You can also sign in with your Google account. In that case we receive your email address and name from Google (Google Ireland Limited); Google learns that you are signing in to Kellno. The legal basis is Art. 6(1)(b) GDPR. To protect against automated sign-ups, the Turnstile service of Cloudflare, Inc. may be used during registration and sign-in; it checks technical characteristics of your browser for this purpose (Art. 6(1)(f) GDPR).

Paid plans are billed through the payment provider Stripe (Stripe Payments Europe, Ltd., Ireland). You enter payment details such as card or account numbers directly at Stripe; we do not receive them. We store your plan status, the Stripe customer number and the billing period (Art. 6(1)(b) GDPR). Invoice data is retained for the statutory periods.

For AI features (importing your files, automatic translation, the AI assistant for guests) we send the content needed for them – e.g. uploaded menu documents, dish descriptions and guests' questions – to OpenAI (USA). Uploaded documents are not stored permanently; only the result you confirm is added to your menu. Please do not upload documents containing third parties' personal data. The transfer is based on standard contractual clauses; data processing agreements are or will be concluded with the providers.

Guests who open a menu are served without cookies; nothing is stored on their device. We use the browser language to provide the menu. For restaurants' usage statistics (views, opened dishes, the "How was it?" rating) we record anonymised events without storing IP addresses; individual guests are not recognised across days. These events are deleted after 120 days at the latest.

When a guest asks the AI waiter a question, the text of the conversation is sent to OpenAI (USA) together with the content of the menu in order to generate the answer. We do not store the conversation; it is only visible in the guest's browser for the duration of the visit. Guests are asked not to enter personal data.

You can download your data as a file in the customer area at any time and permanently delete your account there yourself, together with the restaurant, menu and photos.

Restaurants using the service are responsible for the content of their menu themselves, in particular the accuracy of allergen information. Where we process guests' data on behalf of the restaurant, the data processing agreement (DPA) available on this website applies; it is part of the contract with the restaurant.

7. Error monitoring

To detect and fix technical errors quickly we use the service Sentry (Functional Software, Inc., processing in a data centre in the EU). If an error occurs on our server or in your browser, the error message, the page concerned, technical details of the program flow and the type of browser and operating system are transmitted. IP addresses, cookies, sign-in data and the content of menus or chat messages are not passed on to Sentry; no additional third-party program is loaded in the browser for this and nothing is stored on your device.

The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). Error reports are deleted after 90 days at the latest. A data processing agreement is in place with the provider.

8. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Contact us at the email address above. You also have the right to lodge a complaint with a supervisory authority, for example the Bavarian State Office for Data Protection Supervision (www.lda.bayern.de).

9. Last updated

October 2026

← Back to home