Privacy Policy

Privacy Policy

June 14, 2023 2026-06-15 14:47


Publication Date: ______________________

Please read this document carefully to understand our position and policy regarding your Personal Data and how we will use it.

The Privacy Policy of the “GetOrder” Service (hereinafter referred to as the “Privacy Policy”) describes our policy regarding the privacy of Personal Data processed by the Service.

References to “we”, “our” or “us” (or similar terms) shall mean the “GetOrder” Service, depending on the context of this Privacy Policy.

References to “you”, “your” (or similar terms) shall mean our Client or Consumer, depending on the context of this Privacy Policy.

This Privacy Policy applies only to Personal Data collected in the course of providing the Services.

This Privacy Policy does not apply to Personal Data collected offline or by means other than those used by the Service.

Words “he/she” and related pronouns in this document shall refer to both male and female individuals, depending on the context of the document.

  1. DEFINITIONS 

  1. Aggregator means an online food and beverage delivery service that accepts orders from Consumers and transmits such orders to the Client for fulfillment.

  1. Client means a sole proprietor or legal entity using the GetOrder Service for the purpose of integration with Aggregators.

  1. Controller means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data and/or Statistical Data, within the scope of applicable legislation.

  1. Processor means a natural or legal person, public authority, agency or other body which processes Personal Data and/or Statistical Data on behalf of the Controller, pursuant to a Data Processing Agreement or other binding arrangement.

  1. Personal Data means any information relating to an identified or identifiable natural person (in particular, the Client), including but not limited to name, contact details, IP address, or other identifying information.

  1. Client Consent (hereinafter — “Consent”) means any freely given, specific, informed and unambiguous indication of the Client’s will, by a statement or by a clear affirmative action, signifying agreement to the processing of their Personal Data.

  1. Services means the set of tools, functionalities, software, documentation, and other resources provided by GetOrder to the Client for the purpose of Integration.

  1. GetOrder Service (hereinafter — the “Service” or “GetOrder”) means the web-based platform available at https://api.getorder.biz/, through which the Client accesses the Services.

  1. Integration means the process carried out by the Client via the Service’s web platform, involving the installation of the Service on the Client’s website to enable connection with Aggregators.

  1. Statistical Data means publicly available information that identifies the Client and is required for the proper performance of Integration and receipt of the Services, but does not qualify as Personal Data.

  1. Cookies means small text files stored on the Client’s device during visits to the Service’s website, which are used to enable functionality and personalize user experience.

  1. Consumer means any natural person placing an order for the Client’s products through an Aggregator.

  1. Third Party means any natural or legal person, public authority, agency or body other than the Client, Consumer, Controller or Processor, and persons who, under the direct authority of the Controller or Processor, are authorized to process Personal Data.

  1. Personal Account means an environment within the GetOrder web platform where the Client is able to perform the following operations: uploading menu data from the POS system, managing dish visibility, changing dish data (name, description, order), viewing the menu, uploading the menu to platforms, viewing the list of orders, checking order statuses, and analyzing errors during transmission to the POS system.

  1. GENERAL PROVISIONS

  1. This Privacy Policy applies to the Personal Data and Statistical Data provided by the Client to the Service during the use of the Services and/or interactions with the Service’s personnel.

  1. The Service provides Services to Clients from various regions of the world; therefore, the Service operates in accordance with the legislation of different jurisdictions.

  1. The Service processes and stores Personal and Statistical Data on the basis of the following legal acts:

  1. The processing of Personal and Statistical Data of residents of Ukraine is governed by the Law of Ukraine “On Personal Data Protection”;

  1. The processing of Personal Data of residents of the EU and EEA is carried out in accordance with the principles of lawfulness, fairness, and transparency, pursuant to the General Data Protection Regulation (GDPR);

  1. The processing of Personal and Statistical Data of residents of the Republic of Kazakhstan is governed by the Law of the Republic of Kazakhstan “On Personal Data and Their Protection”;

  1. The processing of Personal and Statistical Data of residents of Georgia is carried out in accordance with the Law of Georgia “On Personal Data Protection”.

  1. The Service acts as the Processor in relation to the processing of Personal and Statistical Data obtained in the course of providing Services to the Client, while the Client acts as the Controller with respect to the processing of such Personal and Statistical Data.

  1. The Service acts exclusively as a Processor with respect to the Personal and Statistical data of Consumers that are received by the Service within the Integration through the Client and/or an Aggregator, and processes such data solely on behalf of and in the interests of the Client, who is the Controller of such data. At the same time, with respect to the Personal and Statistical data of the Client processed in connection with the provision of the Services, access to the Service, technical support, billing, information security, and administration of the Service, GetOrder may act as a Controller within the purposes defined by this Privacy Policy.

  1. PERSONAL AND STATISTICAL DATA

  1. During interaction with the Client, the Service may receive the following categories of Personal data relating to the employees or authorized representatives of the Client:
  1. full name and surname;
  2. contact phone number (mobile or landline);
  3. email address;
  4. Personal Account data: email, login and password;
  5. IP address, device type, operating system, browser, and other technical identifiers related to access to the Service.

  1. Within the scope of provision of the Services under this Agreement, the Service shall have the right to process the Client’s Personal Data provided during registration, authorization, authentication, use of GetOrder, and use of the Personal Account, as well as the data contained in, generated, uploaded to, transmitted through, stored in, or otherwise processed in the Personal Account, including for the purposes of granting access to GetOrder, ensuring the functioning of the Personal Account, carrying out the Integration, providing technical support, communicating with the Client, ensuring information security, administering GetOrder, and performing this Agreement. Such processing shall be carried out in accordance with this Agreement, the Privacy Policy, and the applicable laws of Ukraine.

  1. During the provision of Services, the Service may collect the following Statistical data of the Client, which is not Personal data but may be used within the scope of contractual relations:
  1. company name (sole proprietor or legal entity);
  2. official legal address;
  3. addresses of physical locations where the Client serves Consumers;
  4. banking details (only in case of submitting a refund request);
  5. interface language used by the Client when interacting with the Service.

  1. When visiting the website of the Service or receiving the Services, GetOrder may automatically collect Personal data using cookies, log files, web beacons, and other technologies, including:
  1. IP address;
  2. time zone and language settings;
  3. browser type, version, and configuration;
  4. operating system, device model, screen resolution;
  5. approximate geolocation (country, city);
  6. information about the visit to the Service’s website, including URL addresses, referrers, date and time of entry/exit, session duration, page response speed, loading errors, user activity (scrolling, clicks, mouse movement), contact phone numbers used to call the support service.

  1. GetOrder does not collect or process sensitive Personal data of the Client’s employees or Consumers, such as race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health information, sex life or sexual orientation.

  1. The Service may collect and process the Client’s Personal and Statistical data through the following methods:
  1. when filling out registration forms, ordering Services, or contacting technical support;
  2. by browsing pages of the website, clicking buttons, leaving reviews, or performing interactive actions on the website;
  3. using log files, cookies, Google Analytics, Facebook Pixel, Hotjar, Meta Tools, or similar technologies;
  4. via messengers (e.g., Telegram, Viber, WhatsApp), if the Client communicates with the Service representatives through such means;
  5. via lead forms published on the Service’s website, in Google Forms, or on social media;
  6. during the technical or commercial Integration of Aggregators;
  7. through analysis of information voluntarily provided by the Client via email, personal accounts, or documents (including contracts);
  8. when submitting a refund request or providing banking details;
  9. via social media platforms, including but not limited to: Facebook, Instagram, LinkedIn.

  1. The purposes of processing the Client’s Personal and Statistical data include:
  1. entering into, performing, and maintaining contractual obligations for the provision of Services;
  2. ensuring uninterrupted operation and information security of the website;
  3. technical maintenance, troubleshooting, functionality testing, analytical data collection;
  4. supporting the Client, including responses to requests, complaints, and technical issues;
  5. processing refunds in accordance with the rules specified in the contractual terms;
  6. informing the Client about new services, updates, promotional offers, and other relevant information, subject to prior consent;
  7. improving interaction with the website and personalizing the interface;
  8. conducting marketing activities (behavioral advertising, remarketing, direct email marketing with consent);
  9. fulfilling requests from law enforcement agencies, government authorities, or complying with court orders;
  10. protecting the rights, interests, and security of the Service and the Client within the limits of applicable law.

  1. When processing orders for the Client’s products via an Aggregator, the Service may receive Personal and Statistical data of the Consumer, including: name, contact details, delivery address, order content, payment method, etc. Such data is processed by the Service solely for the purpose of fulfilling the Service functionality and in accordance with this Privacy Policy. The Client undertakes to inform the Consumer before processing their Personal data and to obtain their Consent to the transfer of data to the Service. In the event of failure to fulfill this obligation, all responsibility for violating the Consumer’s rights lies with the Client. The Service shall not be held liable for any actions or omissions of the Client related to compliance with personal data protection laws of the Consumers.

  1. DISCLOSURE AND TRANSFER OF PERSONAL AND STATISTICAL DATA

  1. The Service may transfer the Client’s Personal and Statistical Data to third parties with whom GetOrder cooperates in the implementation and provision of Services, including but not limited to:
  1. Contractors and employees: The Service may transfer Personal and Statistical Data to employees, individual contractors, and external specialists, including legal and tax consultants, as well as parties providing accounting, marketing, IT development, cybersecurity, customer support, cloud infrastructure, hosting, and technical support services.
  2. Subprocessors and service providers: The Service may use external service providers (data subprocessors) such as CRM systems, email delivery platforms, analytics providers (including Google Analytics, Facebook Pixel, Hotjar), payment processors, database storage services, and automation tools that process Client data strictly under instructions from GetOrder and solely for the purpose of delivering the Services.
  3. Courts, law enforcement, and public authorities: The Service is entitled to transfer Personal and Statistical Data in order to comply with legal obligations, including responses to lawful requests by courts, law enforcement bodies, tax authorities, supervisory regulators, or in compliance with subpoenas, court orders, or legal processes.
  4. Third parties in corporate transactions: The Service may disclose or transfer the Client’s Personal and Statistical Data to third parties in connection with any acquisition, merger, financing, corporate restructuring, joint venture, sale of assets, or in the event of insolvency, bankruptcy, or receivership, where such information may be transferred as a business asset.
  5. Aggregators: The Service may transfer Personal and Statistical Data to Aggregators during the process of Integration and/or direct interaction with the Aggregator’s personnel, solely for the purpose of enabling or facilitating the Client’s use of the Services in connection with such Aggregators.
  6. Communication providers: The Service may share certain data with messaging or communication platforms (such as Telegram, Viber, WhatsApp, or email delivery services) when the Client initiates or maintains communication with GetOrder through such channels.
  7. Cloud infrastructure and hosting providers: The Service may transfer data to providers of cloud platforms, data centers, or hosting services located in the EU or other jurisdictions that ensure adequate protection under applicable data protection laws (e.g., AWS, Google Cloud, Microsoft Azure, Hetzner, Cloudflare).
  8. Professional advisers: The Service may disclose Personal or Statistical Data to external auditors, legal advisers, compliance experts, or financial consultants for the purpose of fulfilling its legitimate interests and legal obligations.
  9. Affiliate companies or subsidiaries: Where applicable, the Service may transfer data to affiliated entities within the same corporate group for the purposes aligned with this Privacy Policy.

  1. The transfer of Consumers’ Personal and Statistical data to Third Parties, including subprocessors, service providers, cloud providers, and other engaged persons, within the provision of the Services is carried out by the Service solely to the extent necessary for the performance of the Client’s documented instructions and the proper functioning of the Service, with the application of appropriate contractual and organizational data protection measures.

  1. ACCESS TO PERSONAL AND STATISTICAL DATA

  1. Access to Personal and Statistical Data is granted exclusively to those employees, contractors, or authorized representatives of the Service for whom such access is necessary in the course of fulfilling their employment or contractual duties. The level of access is determined based on the principle of least privilege and corresponds to the functional role of the respective person.

  1. Before obtaining access to Personal or Statistical Data, each employee or contractor must sign a separate non-disclosure agreement (NDA), which includes provisions on:
  1. the obligation to maintain the confidentiality of received data;
  2. a prohibition on transferring, copying, or distributing data without authorization;
  3. liability for breach of the agreement, including financial and disciplinary consequences.

  1. The Service implements organizational and technical measures to monitor and control the actions of persons who have access to the Client’s Personal and Statistical Data. Such measures include, but are not limited to:
  1. maintaining access logs;
  2. using internal access management systems;
  3. conducting periodic audits of data access activities;
  4. limiting access rights upon role changes or contract termination.

  1. The Service guarantees that all authorized persons adhere to the principles of confidentiality and data protection and shall not disclose or misuse any Personal Data or confidential information, whether during or after their cooperation with the Service.

  1. STORAGE AND PROTECTION OF PERSONAL DATA

  1. The Service implements all necessary technical and organizational security measures to protect the Personal Data of Clients and Consumers processed by the Service from unauthorized access, accidental loss, destruction, alteration, or unlawful disclosure. These measures aim to ensure the confidentiality, integrity, and availability of Personal Data.

  1. The Service guarantees that Personal Data is stored under secure conditions and protected against the following risks:
  1. loss of Personal Data due to failures, technical errors, or human factors;
  2. unlawful use, transmission, disclosure, alteration, deletion, or destruction of Personal Data by third parties or unauthorized personnel.

  1. To implement the above-mentioned security measures, the Service may use, among other things, the following technical and organizational tools in accordance with Article 32 of the GDPR “Security of processing” or equivalent provisions of the applicable national legislation:
  1. application of pseudonymization and encryption of Personal Data;
  2. ensuring the ongoing confidentiality, integrity, availability, and resilience of systems and services that process Personal Data;
  3. regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures to ensure the security of processing.

  1. The Service undertakes to delete the Client’s and/or Consumer’s Personal or Statistical Data upon receiving a written request from the Client or upon termination of contractual relations between the Parties. “Deletion” shall mean the complete removal of such data from internal electronic systems, servers, and paper or other physical storage media.

  1. Notwithstanding the termination of cooperation with the Client, the Service reserves the right to retain Personal and Statistical Data for up to two years after the termination of the relationship in the following cases:
  1. for statistical reporting or business analytics purposes;
  2. where data retention is required by applicable legislation of the relevant jurisdiction;
  3. to enable further communication with the Client or Consumer (e.g., in case of inquiries or claims);
  4. where such retention is necessary within the scope of the Service’s legitimate interest in ensuring lawful business operations.

  1. The Service does not retain the Client’s Personal Data if it receives an official deletion request pursuant to the “right to erasure” under Article 17 of the GDPR or the corresponding provision of another applicable law. Such deletion will be carried out in accordance with the Service’s established timelines and technical capabilities.

  1. After the termination of the contractual relationship with the Client, the Service does not process, transfer, or disclose the Client’s or Consumers’ Personal Data, except for its retention within the scope permitted by this Policy and applicable law.

  1. LEGAL GROUNDS FOR PROCESSING PERSONAL DATA

  1. The Service processes the Personal and Statistical Data of Clients and Consumers exclusively on lawful grounds, in accordance with the principles of legality, proportionality, transparency, and purpose limitation. The main legal bases for processing include:
  1. Consent of the Client or Consumer: The Service may process Personal and Statistical Data on the basis of clear, voluntary, specific, informed, and unambiguous Consent provided by the Client or Consumer, including in electronic form. Such Consent may be obtained during registration, when signing a contract, using the Service’s functionality, or by accepting the terms of this Policy.
  2. Provision of advisory or informational Services: Personal Data may be processed in connection with the provision of consultations, technical support, or responses to requests from Clients or Consumers, including via any electronic communication channels.
  3. Integration with external services or platforms: If the Client uses integration capabilities of the Service with other software products or platforms (e.g., Aggregators or CRM systems), the processing of Personal Data is carried out to ensure the proper performance of integration functionalities.
  4. Performance of a contract or payment obligations: The Service is entitled to process the Client’s Personal and Statistical Data for the purpose of entering into, executing, and administering a contract, as well as ensuring proper interaction between the parties in relation to the provision of Services, including payment and accounting.
  5. Compliance with legal obligations: Where the applicable laws of the relevant jurisdiction require the retention, processing, or transfer of Personal Data, such processing shall be carried out on the basis of mandatory legal provisions (e.g., for tax or financial control purposes).

  1. If the processing of Personal Data is based on the Consent of the Client or Consumer, such individual has the right to withdraw their Consent at any time without providing any justification.

  1. Consent may be withdrawn by submitting a written (including electronic) request to the Service via official communication channels.

  1. In case of Consent withdrawal, the Service reserves the right to cease providing Services to the respective Client or Consumer and to terminate all active contractual relationships.

  1. Following the withdrawal of Consent, the Service undertakes to stop processing the relevant Personal and Statistical Data no later than within ten (10) business days from the date the request is received.

  1. Within the limits of technical feasibility and in accordance with applicable law, the Service will delete all Personal Data provided on the basis of Consent in full and in such a manner that prevents any future recovery.

  1. CLIENT’S CONSENT

  1. The Client shall be deemed to have given Consent to the terms of this Privacy Policy upon performing any of the following actions:
  1. using the functionality of the Service, including integration with external platforms or programs;
  2. receiving the Services, including registration, authorization, submitting requests, or any other actions aimed at interaction with the Service.

  1. The Service may additionally obtain the Client’s Consent by displaying a pop-up form containing the consent text and a corresponding confirmation field (e.g., a checkbox). Checking such a box shall constitute valid Consent to the processing of Personal and Statistical Data in accordance with the terms of this Policy.

  1. The Client has the right to withdraw their Consent at any time by sending a corresponding written request (including via email) to the Service through official communication channels. In such case, the Service shall terminate all contractual and factual relationships with the Client, cease providing the Services, and ensure the complete and irreversible deletion of the Client’s Personal and Statistical Data.

  1. JURISDICTION OF THE EUROPEAN UNION AND THE EUROPEAN ECONOMIC AREA

  1. The provisions of this section apply to residents of the European Union and the European Economic Area. Under the terms of this section, the Client is entitled to the following rights:
  1. Right of Access: The Client/Consumer may contact us directly to request access to their Personal Data that we hold, as well as any information in accordance with Article 15 of the General Data Protection Regulation (GDPR).
  2. Right to Erasure: The Client/Consumer has the right to have their Personal Data deleted in accordance with Article 17 of the GDPR. In such cases, the Personal Data will be permanently erased.
  3. Right to Data Portability: Upon request by the Client/Consumer, we may transfer their Personal Data to third-party organizations in accordance with Article 20 of the GDPR.
  4. Right to Rectification: The Client/Consumer has access to their Personal Data and may update, correct, or supplement it at any time. They may also request the Service to make such corrections or modifications in accordance with Article 16 of the GDPR.
  5. Right to Object: The Client/Consumer has the right to object at any time to the processing of their Personal Data in accordance with Article 21 of the GDPR.
  6. Automated Individual Decision-Making, Including Profiling: The Client/Consumer has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, in accordance with Article 22 of the GDPR.

  1. JURISDICTION OF UKRAINE

  1. In the case of processing Personal Data of residents of Ukraine, such Personal Data shall be processed in accordance with the Law of Ukraine “On Personal Data Protection”.

  1. The Client/Consumer has the following rights to:
  1. be informed about the sources of collection, the location of their Personal Data, the purpose of its processing, and the location of the data controller;
  2. receive information regarding the conditions for granting access to their Personal Data, including information about Third Parties to whom the data is transferred;
  3. access their Personal Data;
  4. receive, no later than thirty calendar days from the date of receipt of the request (unless otherwise provided by law), a response as to whether their Personal Data is being processed, and to obtain the content of such Personal Data;
  5. submit a reasoned request objecting to the processing of their Personal Data;
  6. submit a reasoned request for the modification or deletion of their Personal Data;
  7. protect their Personal Data from unlawful processing, accidental loss, destruction, or damage due to intentional concealment, failure to provide or untimely provision, and to be protected against the provision of false or defamatory information that may harm the honor, dignity, or business reputation of the Client/Consumer;
  8. file complaints with the court regarding the processing of their Personal Data;
  9. seek legal remedies in the event of violations of personal data protection legislation;
  10. include reservations regarding the limitation of the right to process their Personal Data when providing Consent;
  11. withdraw their Consent to the processing of Personal Data;
  12. be informed about the mechanism of automated processing of their Personal Data;
  13. be protected from automated decision-making that has legal consequences for them.

  1. JURISDICTION OF THE REPUBLIC OF KAZAKHSTAN

  1. In the case of processing Personal Data of residents of the Republic of Kazakhstan, such Personal Data is processed in accordance with the Law of the Republic of Kazakhstan “On Personal Data and Their Protection”.

  1. Pursuant to Article 24 “Rights and Obligations of the Subject” of the Law of the Republic of Kazakhstan “On Personal Data and Their Protection”, the Service grants the following rights to residents of the Republic of Kazakhstan:
  1. to be informed of the existence of their Personal Data held by the Service or any Third Party, and to receive information containing:
  • confirmation of the fact, purpose, sources, and methods of collection and processing of Personal Data;
  • a list of the processed Personal Data;
  • terms of Personal Data processing, including storage periods;
  1. to request the Service to amend or supplement their Personal Data if there are grounds confirmed by relevant documents;
  2. to request the Service and/or any Third Party to block their Personal Data if there is evidence of a violation of the conditions for collecting Personal Data;
  3. to request the Service and/or any Third Party to delete their Personal Data if the collection and processing were carried out in violation of the legislation of the Republic of Kazakhstan, or in other cases as provided by this Law and other regulatory legal acts of the Republic of Kazakhstan;
  4. to withdraw their consent to the collection, processing, distribution in publicly available sources, transfer to Third Parties, and cross-border transfer of their Personal Data;
  5. to give or deny consent to the Service for the distribution of their Personal Data in publicly available sources;
  6. to protect their rights and legitimate interests, including the right to compensation for moral and material damages.

  1. JURISDICTION OF GEORGIA

  1. In the event of processing Personal Data of residents of Georgia, such Personal Data is processed in accordance with the Law of Georgia “On Personal Data Protection”.

  1. Pursuant to Article 15 of the Law of Georgia “On Personal Data Protection”, the Service may provide the following information to the Client or Consumer:
  1. the identity and registered address of the data processor and the authorized person (if applicable);
  2. the purpose of data processing;
  3. whether the provision of data is mandatory or voluntary, and if mandatory, the legal consequences of refusal to provide such data;
  4. the right of the Client/Consumer to access their processed data and to request rectification, updating, supplementation, blocking, deletion, or destruction of such data.

  1. Upon request, the Client/Consumer has the right to receive the following information from the Service regarding the processing of their data:
  1. which data concerning them is being processed;
  2. the purposes of the data processing;
  3. the legal grounds for the data processing;
  4. how the data was collected;
  5. to whom the data was disclosed, the grounds and purposes for such disclosure.

  1. At the request of the Client/Consumer, the Service may take the following actions: rectify, update, supplement, block, delete, or destroy Personal and Statistical Data if such data is incomplete, inaccurate, outdated, or collected and processed unlawfully.

  1. SUBMISSION OF REQUEST

  1. The Client/Consumer from any jurisdiction has the right to submit a request to the Service if they believe that their rights have been violated, by sending a written request to the Service support at the following address: serg.chaika@getorder.biz

  1. The Client’s/Consumer’s request must contain clear and specific information about the demands addressed to the Service. If the request lacks specific demands, the Service reserves the right to refuse to fulfill the request.

  1. We may be unable to respond to your request or provide you with your Personal and Statistical Data if we cannot verify your identity and confirm that the Personal and Statistical Data pertains to you. If the request contains inaccurate information and/or if identity verification is not possible, the Service reserves the right not to process such a request and may contact the Client/Consumer for clarification. Upon receiving a clarification request, the Client/Consumer is required to submit a corrected or new request.

  1. The Service shall respond to the request or fulfill the demands set forth therein within twenty-one (21) business days from the date of receipt.

  1. If the Service receives a request from a Consumer regarding Personal data processed by the Service as a Processor on behalf of the Client, the Service has the right to forward such request to the Client for handling and/or take actions in relation to such request solely on the basis of the Client’s documented instructions, except where otherwise expressly required by applicable law.

  1. LIABILITY

  1. The Service expressly informs the Client that the processing of Personal and Statistical Data is carried out for the proper provision of the Services, including integration with third-party platforms, transmission of data via the Aggregator, and ensuring interaction between the Client and the Consumer. If the Client disagrees with the terms of data processing, they must immediately cease using the Service and the Services.

  1. The Client bears full responsibility for the accuracy, relevance, completeness, and lawfulness of the Personal and Statistical Data they provide while using the Service. In case of submission of inaccurate or false data, the Client assumes all risks related to the inability to receive the Services, errors in displayed information, misdelivery of Consumer data, or account suspension.

  1. The Service shall not be held liable for any damages or breaches arising from:
  1. unauthorized access by Third Parties to Personal or Statistical Data, including but not limited to hacker attacks, malicious software, or breaches of the Service’s infrastructure;
  2. provision by the Client of false, outdated, or incomplete information, including data regarding the company, points of sale, locations, or staff;
  3. the Client’s failure to obtain the Consumer’s Consent to process their data during order placement through the integrated Aggregator.

  1. The Service makes every reasonable effort to safeguard the transmission of the Client’s Personal and Statistical Data; however, it cannot guarantee the absolute security of data transmitted via the internet. The Client acknowledges and assumes all risks associated with data transmission and agrees that the Service shall not be liable for any technical malfunctions, interception, or data loss during transmission. Upon receipt of the data, the Service commits to implementing appropriate organizational and technical security measures to prevent unauthorized access or interference.

  1. The Client bears sole responsibility for properly informing the Consumer and obtaining their Consent for the transfer of their Personal and Statistical Data to the Service when using the Aggregator. In case of a complaint from the Consumer regarding unlawful data processing, the Client shall independently resolve the matter, including providing responses, remedying violations, and fully compensating the Consumer for any damages. The Service is under no obligation to handle such complaints, participate in dispute resolution, or reimburse any expenses or losses incurred by the Consumer due to the Client’s actions or omissions.

  1. The Client bears full and exclusive responsibility for the lawfulness of the collection, use, and transfer of Consumers’ Personal Data to the Service, including obtaining valid Consent or another lawful basis, properly informing Consumers about the conditions of processing and transfer of their data, as well as handling any requests, complaints, or claims from Consumers. In the event that any demands, complaints, or claims are brought by a Consumer as a result of the Client’s failure to duly perform these obligations, the Client shall independently and fully resolve such demands and indemnify and hold the Service harmless from any losses, damages, or expenses incurred in connection therewith, including legal fees. The Service shall not be liable for any violations of Consumers’ rights arising from the actions or omissions of the Client.

  1. The Service shall not be liable for the Client’s failure to have a valid legal basis for the collection and transfer of Consumers’ Personal data, for improper notice to Consumers, or for the Client’s violation of applicable personal data protection laws, provided that the Service acted within the Client’s documented instructions and the terms of the provision of the Services.

  1. CLIENT’S OBLIGATIONS REGARDING CONSUMER DATA

  1. The Client acts as the Controller of the Consumer’s Personal Data that is transmitted to the Service through the Aggregator or other integrated channels. The Service acts solely as a Processor and processes such data only in accordance with the Client’s instructions and within the scope of providing the Services.

  1. The Service processes the Personal and Statistical data of Consumers exclusively on the basis of the Client’s documented instructions and within the scope of the Services and the Integration functionality. The Service does not independently determine the purposes of processing such data and does not use the Personal and Statistical data of Consumers for its own marketing, advertising, or other purposes unrelated to the proper provision of the Services.

  1. Prior to transmitting any Consumer’s Personal Data to the Service, the Client shall:
  1. obtain explicit Consent or another valid legal basis for the processing and transfer of such data;
  2. ensure that the Consumer has been properly informed of the scope, purposes, and conditions of processing their Personal Data, including its transfer to the Service as Processor;
  3. provide the Consumer with information about their rights as required by applicable data protection legislation (including the right of access, rectification, erasure, etc.).

  1. The Client, as the Controller, guarantees that it has a valid legal basis for the collection, use, and transfer of Consumers’ Personal data to the Service, including Consent or any other legal basis provided by applicable law, and also guarantees that the Consumer is properly informed about such transfer and the processing of their Personal data by the Service.

  1. The Client warrants that it maintains appropriate evidence of obtaining the Consumer’s Consent/authorization (such as a mark in a mobile application, an electronic form, or a signed document). The Service reserves the right to request proof of such Consent/authorization from the Client at any time.

  1. The Client bears full responsibility for the lawfulness of the collection, use, and transfer of Consumers’ Personal Data, including:
  1. informing Consumers about the transfer of their data to the Service;
  2. obtaining the necessary Consent or relying on another valid legal basis;
  3. properly handling any requests, complaints, or claims from Consumers.

  1. In the event that the Service receives a request or claim from a Consumer regarding their Personal Data, the Service reserves the right to:
  1. forward such request directly to the Client for handling;
  2. suspend the processing of the relevant data until the lawfulness of its collection is confirmed;
  3. require the Client to provide proof of Consent or another legal basis for processing.

  1. The Service has the right to temporarily restrict or suspend the processing of Consumers’ Personal and Statistical data within a specific Integration in the event of receiving a substantiated complaint, a request from a competent authority, or where there are reasonable grounds to believe that the Client has not ensured a valid legal basis for the transfer of such data, until the Client provides proper confirmation of the lawfulness of such processing.

  1. The Client shall place and keep up to date the privacy policy for Consumers provided by the Service on the Site, in the App, and/or in other channels of interaction with Consumers through which Personal data is collected and orders are placed. Such privacy policy shall be made available to Consumers prior to the collection of their Personal data and shall contain proper notice of the fact, scope, purposes, and legal grounds for the collection, processing, and transfer of Consumers’ Personal data to the GetOrder Service as a Processor, as well as the Consumer’s rights and the procedure for exercising them. The Client shall bear full responsibility for the proper placement of such privacy policy in the relevant channels of interaction with Consumers and for ensuring that Consumers are able to review its terms before their Personal data is transferred to the Service.

  1. COOKIES

  1. The Service does not use Cookies for profiling or targeted advertising purposes. However, during the Client’s use of the Service functionality on the website, technical Cookies may be automatically applied. These are necessary to ensure the stable operation of the website, user authentication, session settings retention, and navigation optimization.

  1. The Client may restrict or completely block the use of Cookies by adjusting their web browser settings, including using private browsing mode, blocking the storage of Cookies, or deleting already stored Cookies. However, the Service warns that blocking Cookies may result in limited access to certain platform features or reduced usability of the Services.

  1. The Service may use Cookies for the following purposes:
  1. storing the Client’s personal preferences and settings, including interface language, display options, and previous session data;
  2. maintaining the Client’s current session, including authentication and security;
  3. collecting aggregated statistical data on the Client’s actions within the Service, including number of visits, traffic sources, on-site actions, and session duration.

  1. The Service may use third-party web analytics tools that also apply Cookies, in particular:
  1. Facebook Pixel (Meta Platforms, Inc.) — to track the effectiveness of user interactions with the platform via Facebook and Instagram advertising channels;
  2. Google Analytics (Google LLC) — to analyze website traffic, technical errors, traffic sources, and user behavior.

  1. These services may process technical or aggregated data in accordance with their own privacy policies. The Service does not control the content or use of such files by these Third Parties but uses them solely to ensure analytics and improve the Platform’s functionality.

  1. AGE POLICY

  1. The Service does not collect, store, or process any Personal or Statistical Data of individuals who have not reached the age of majority in accordance with the laws of their country of citizenship or permanent residence.

  1. Individuals who have not reached the age of majority are prohibited from using the functionality of the Service, including but not limited to registration, authorization, placing orders, submitting requests, or performing any other actions aimed at receiving the Services of the Platform.

  1. If it is discovered that the Service is being used by a minor or if the Service obtains information about the submission of false Personal or Statistical Data belonging to a minor, the Service reserves the right, without prior notice and without any liability to the Client or such individual, to:
  1. immediately delete the relevant Personal and/or Statistical Data;
  2. block access to the account (if one was created);
  3. terminate the provision of Services to the Client on whose behalf or in whose interest such minor was acting.

  1. Responsibility for violation of this provision, including the submission of false information regarding age, lies with the individual who provided such information or with the legal representative of such individual.

  1. CHANGES TO THE PRIVACY POLICY

  1. The Service reserves the right to amend the provisions of this Privacy Policy in order to ensure the protection of Personal and Statistical Data and in response to changes in legislation governing the processing of Personal Data.

  1. The Service shall notify Clients of any amendments to the Privacy Policy by publishing updates on the website. GetOrder will update the “Last Updated” date in the current version of the Privacy Policy accordingly.

  1. It is the Client’s responsibility to review the updated terms of the Privacy Policy. The Service shall not be held liable if the Client fails to familiarize themselves with the new terms of the Privacy Policy.

  1. Electronic or otherwise stored copies of the Privacy Policy shall be deemed authentic, complete, valid, and enforceable versions of this Privacy Policy as in effect at the time the Client accesses the Service’s website.

  1. CONTACT INFORMATION

  1. The Client has the right to contact the Service’s support team at: serg.chaika@getorder.biz in order to exercise their rights in accordance with this Privacy Policy, report a violation of their rights, leave feedback, or ask a question.

Dark

Light

Dark

Light