GDPR β€” Regulation (EU) 2016/679

Privacy Policy

Last updated:

This policy describes how Tommaso DI VRUSA, operating the 3Smiles service, collects, uses, shares and protects your personal data, in accordance with the General Data Protection Regulation (GDPR β€” Regulation EU 2016/679) and the Belgian law of 30 July 2018.

1. Data controller

Identity : Tommaso DI VRUSA

CBE : 0891.476.322 β€” VAT : BE 0891.476.322

Address : Rue des Bans 13, 6141 Fontaine-l'Γ‰vΓͺque, Belgique

Contact : contact@3smiles.eu

For data relating to the user account, billing, support and the showcase site, Tommaso DI VRUSA acts as data controller.

For data processed on behalf of a subscribing establishment, in particular guest data and operational data, the establishment is the data controller and 3Smiles acts as data processor within the meaning of the GDPR. This relationship is governed by the Data Processing Agreement (Annex 1 of the Terms, art. 28 GDPR).

2. Personal data collected

2.1 Via the showcase site (3smiles.eu)

When you use the contact form, we collect:

  • First and last name
  • Professional email address
  • The content and subject of your message
  • The date and time of the request

Third-party analytics and tracking tools (Google Analytics, Google Tag Manager, Google Search Console) are only activated with your consent where this is required.

2.2 Via the application (app.3smiles.eu)

When creating an account and using the service, we may collect:

  • Identity data : last name, first name, email, Microsoft Entra External ID technical identifier
  • Establishment data : name, address, description, configuration settings
  • Service data : spaces, tables, services, operating parameters and rules
  • Operational data : history of service requests, anonymised customer notes and reviews, activity KPIs
  • Billing data : information required for billing and subscription management, processed mainly by Stripe (see Β§4) β€” we do not store any payment card data
  • Technical data : IP address, user-agent, connection logs (retention: 30 days)

We limit ourselves to the data strictly necessary for the purposes pursued, in accordance with the data minimisation principle.

Providing the data necessary to create the account and for billing is a condition of access to the service: without it, the service cannot be provided.

3. Purposes and legal bases of processing

We process personal data for the following purposes:

Purpose Legal basis (GDPR)
Respond to a contact or demo requestArt. 6.1.b β€” Performance of the contract
Create and manage a user accountArt. 6.1.b β€” Performance of the contract
Provide the 3Smiles serviceArt. 6.1.b β€” Performance of the contract
Manage payments and billingArt. 6.1.b β€” Performance of the contract
Ensure the security, monitoring and stability of the serviceArt. 6.1.f β€” Legitimate interest
Comply with legal and accounting obligationsArt. 6.1.c β€” Legal obligation
Send communications about the service or its developments (opt-in only)Art. 6.1.a β€” Consent

Where we rely on legitimate interest, we ensure that the processing does not excessively infringe the rights and freedoms of the data subjects.

No solely automated decision producing legal effects or significantly affecting you, and no profiling, is carried out within the framework of the service.

4. Retention periods

We retain data for the following periods:

  • Contact requests : 12 months after the last exchange
  • Active account data : the duration of the subscription, then deletion or anonymisation after 30 days, unless otherwise required by law
  • Operational data : the duration of the subscription, then deletion or anonymisation according to reversibility or contractual requirements
  • Technical and security logs : 30 rolling days, unless longer retention is necessary in the event of a security incident
  • Billing data : 7 years from the end of the relevant accounting year (Belgian accounting obligation β€” art. III.86 CEL)

5. Processors and recipients

We use processors that provide sufficient guarantees within the meaning of the GDPR, in particular:

Microsoft Azure

Hosting, database, identity, storage, application services

EU region

Stripe, Inc.

Payment processing, subscription management, billing

USA β€” EU SCCs

Stripe is PCI DSS Level 1 certified. Payment data is processed under the European Commission's Standard Contractual Clauses (SCCs). DPA available at stripe.com

Web3Forms

Email delivery of messages sent through the showcase site's contact form (name, email address, message)

USA β€” EU SCCs

Data entered in the contact form is sent to Web3Forms for the sole purpose of delivering your request by email to 3Smiles. Transfer outside the EU is governed by the Standard Contractual Clauses (SCCs). Privacy policy at web3forms.com

No personal data is sold, rented or transferred to third parties for commercial or advertising purposes.

6. Transfers outside the European Union

Application data is hosted and processed within the European Union.

Certain processing related to Stripe may involve transfers outside the European Union; in such cases, these transfers are governed by appropriate safeguards, in particular the European Commission's Standard Contractual Clauses.

7. Cookies and trackers

Showcase site (3smiles.eu): uses Google Analytics and Google Tag Manager for traffic analysis and SEO optimisation (Google Search Console), activated only after explicit consent via the cookie banner. You can change your preferences or refuse these cookies at any time.

Application (app.3smiles.eu): session cookies are set by Microsoft Entra External ID to maintain your authentication. These cookies are deleted on logout or when the session expires.

Strictly necessary cookies: some cookies are essential to the operation of the site and access to its features (such as authentication, session management or security). Refusing these cookies may prevent the proper operation of the site or restrict access to some of its features. In that case, we cannot guarantee full access to the site or its optimal operation.

You can manage or delete cookies at any time from your browser settings, without affecting your access to the showcase site, with the exception of strictly necessary cookies whose refusal may limit the use of the service.

8. Your rights

In accordance with the GDPR, you have the following rights regarding your personal data:

  • Right of access : obtain a copy of the data concerning you (art. 15)
  • Right to rectification : correct inaccurate or incomplete data (art. 16)
  • Right to erasure : request the deletion of your data (art. 17)
  • Right to portability : receive your data in a structured format (art. 20)
  • Right to object : object to processing based on legitimate interest (art. 21)
  • Right to restriction of processing : request the restriction of processing (art. 18)
  • Right to withdraw consent : withdraw your consent at any time, without prejudice to prior processing (art. 7.3)

To exercise your rights, send your request to: contact@3smiles.eu

In the event of reasonable doubt about your identity, proof of identity may be requested.

We undertake to respond within one month of receiving your request (art. 12.3 GDPR).

You may also lodge a complaint with the Data Protection Authority (DPA) β€” Rue de la Presse 35, 1000 Brussels.

9. Data security

We implement appropriate technical and organisational measures to protect data against any unauthorised access, loss, alteration or disclosure, in particular:

  • Encryption of data in transit (TLS 1.2+) and at rest (Azure Storage Service Encryption)
  • Strong authentication
  • Strict access management
  • Logging of access and security events
  • Infrastructure monitoring
  • Logical separation of environments and data

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we undertake to notify the DPA within 72 hours in accordance with art. 33 GDPR.

10. Changes to the policy

We may modify this policy at any time to reflect changes to the service, regulations or our practices. In the event of a substantial change, active users will be informed by email at least 30 days before the changes take effect. The last update date appears at the top of the document. Users are invited to review this policy regularly to stay informed of any updates.