Data Processing & Consent Notice
How Pilot application data, restaurant operational data, evidence uploads and conditional AI processing are handled.
1. Pilot application consent
I request MAUZOP to use the information I submit — including my name, work contact details, restaurant/brand, city, role, outlet count, current POS/billing system and stated goal — to evaluate my Pilot request, contact me, onboard me if accepted and provide Pilot support. I understand that submission does not guarantee acceptance. I will not submit passwords, OTPs, payment-card secrets or unnecessary sensitive information through this form. I have read the Privacy Policy and this Data Processing & Consent Notice.
2. Operational Customer Data
If you are accepted into the Pilot and upload/connect operational data, you instruct MAUZOP to process the data reasonably necessary to provide the agreed restaurant-intelligence workflows. Customer Data may include business records and incidental personal data. You should provide only data you are authorised to provide and only what is necessary for the agreed purpose.
3. Roles
- For MAUZOP's own account administration, direct communications, security, billing/fee records and legal obligations, MAUZOP determines the relevant purpose and handles that personal data in its own operational capacity.
- For personal data inside Customer Data that MAUZOP processes solely to provide the customer's requested service, the customer generally determines the business purpose and MAUZOP processes the data on those instructions, subject to applicable law and the signed relationship.
4. Infrastructure used for the Pilot
- UpCloud: production application/runtime, Caddy, malware scanning and ClamAV.
- Supabase production project (Mumbai): PostgreSQL database, authentication and storage/evidence workflows.
- Resend: transactional/notification emails.
- OpenAI: conditional external AI-report provider where the applicable AI feature is approved and enabled.
5. Evidence uploads and AI
Uploaded evidence may pass through security/malware scanning and application processing. The production design separates evidence-upload/scanning from AI-report routes. External AI may be disabled or enabled depending on the controlled service configuration. When an external AI feature is enabled, data needed for the requested analysis may be transmitted to the disclosed AI provider. The exact content can be feature-dependent; do not upload information that is unnecessary for the requested analysis.
6. No sale, no targeted advertising, no general training by default
- MAUZOP does not sell Customer Data or personal data.
- MAUZOP does not currently use identifiable Customer Data for targeted advertising.
- Identifiable Customer Data is not used for general-purpose/cross-customer model training unless a separate written agreement and legally sufficient notice/permission expressly authorise it.
- Properly de-identified or aggregated information may be used for product reliability and improvement.
7. Subprocessors
MAUZOP may use the infrastructure/service providers listed above and other providers that become necessary to provide the agreed service. A material change that creates a new category of processing should be reflected in the applicable privacy/processing notice before that processing is enabled.
8. Security and confidentiality
MAUZOP limits access to authorised personnel/service providers with a need to know and uses reasonable technical and organisational safeguards, including authentication, access controls, logging/monitoring, malware scanning and incident response. No system is risk-free.
9. Data requests and withdrawal
You may contact mauzopind@gmail.com to withdraw optional consent or raise a privacy/data request. If the withdrawn processing is necessary to provide a requested feature, MAUZOP may have to stop that feature. Withdrawal does not retroactively make prior lawful processing unlawful.
10. Customer responsibilities
- Provide required notices/permissions to individuals whose personal data is included in Customer Data.
- Avoid unnecessary sensitive information.
- Maintain account security and notify MAUZOP of compromised credentials.
- Independently verify material decisions based on MAUZOP output.