ostro
Book diagnosis
Privacy & Data Protection

Privacy Policy

GDPR • International Standards Last updated: October 2026 Scope: Institutional website & consulting services

At ostro, we prioritize the privacy, transparency, and strict confidentiality of all personal and operational data belonging to our clients, partners, and users.

This Privacy Policy clearly outlines how we collect, process, retain, and safeguard your information in full compliance with the General Data Protection Regulation (GDPR — Regulation EU 2016/679) and global privacy benchmarks.

Section 01

Data Controller

The data controller responsible for personal and operational data processed through this website is ostro, accessible at https://www.ostro.food.

For any questions, requests, or to exercise your privacy rights, please reach out directly to our dedicated channel: consult.ostro@gmail.com.

Section 02

Data Collected and How We Obtain It

We collect exclusively the information strictly necessary to manage inquiries, schedule strategic diagnosis sessions, and deliver restaurant food cost and profitability advisory.

1. Information provided directly via forms

  • Identification and contact: Full name, corporate email address, and phone / WhatsApp number (with international dialing code).
  • Business context: Name of the restaurant, hospitality group or food service brand, requested service type, and description of current operational needs.

2. Operational F&B consulting data

  • Supplier invoices, purchasing data & recipe costing: During audits or monthly monitoring, clients may voluntarily share cost files, purchasing records, and menu engineering data. All operational figures are treated under rigorous professional secrecy and non-disclosure commitments.

3. Technical & infrastructure logs

  • Server logs: IP address (processed in an aggregated, privacy-preserving manner), access timestamps, browser user agent, and screen resolution to protect system stability and mitigate malicious traffic.
Section 03

Purposes and Legal Grounds for Processing

All data processing performed by ostro is grounded on legitimate legal bases under Article 6 of the GDPR:

  • Pre-contractual steps upon request: Responding to contact inquiries, scheduling free operational diagnosis sessions, and drafting commercial proposals.
  • Performance of a contract: Delivering consulting services, food cost auditing, recipe engineering, and granting access to the ostro+ platform.
  • Compliance with legal obligations: Invoicing, financial accounting, and tax compliance requirements.
  • Legitimate interests: Protecting our digital systems, preventing brute-force and automated spam (including invisible honeypot protections).
Section 04

Data Sharing and Third-Party Providers

ostro does not sell, rent, or trade your personal or operational business data to third parties for advertising or commercial exploitation.

Sharing is strictly confined to trusted digital infrastructure providers essential for web hosting (secure SSL/TLS cloud servers), institutional email systems, and aggregated Google Analytics telemetry.

Section 05

Data Retention Periods

Data is stored only for as long as strictly required to fulfill the purposes for which it was gathered:

  • Non-converted contact requests: Retained for a maximum of 12 months following the last interaction, after which they are securely deleted or anonymized.
  • Active client relationships: Preserved throughout the contractual term and subsequently for the statutory retention periods required by applicable tax and commercial laws.
  • Security and access logs: Retained for up to 6 months for technical auditing.
Section 06

Your Rights as a Data Subject

Under European GDPR provisions, you hold the following rights:

  • Right of Access: Confirm whether your data is being processed and obtain a copy.
  • Right to Rectification: Request correction of inaccurate or incomplete information.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of data no longer required for contractual or statutory duties.
  • Right to Restriction & Objection: Object to processing based on legitimate interests or request temporary restriction.
  • Right to Data Portability: Receive your personal data in a structured, commonly used digital format.
  • Right to Lodge a Complaint: File a grievance with the relevant national supervisory authority (e.g., CNPD in Portugal at cnpd.pt).
Section 07

Security & Operational Secrecy

All website communications are secured over encrypted HTTPS with active SSL/TLS certificates.

At an operational level, all recipe costing, supplier prices, and margin reports shared with ostro consultants are protected under strict non-disclosure obligations, accessible solely to consultants directly assigned to your account.

Section 08

Cookies and Session Analytics

We use exclusively essential technical cookies required for navigation and aggregated Google Analytics to measure audience readership. We do not deploy invasive third-party cross-site advertising or behavioral tracking cookies.

Section 09

Policy Revisions

ostro reserves the right to revise this policy periodically to align with evolving regulatory guidelines or new operational services. The effective version date is consistently shown at the top of this page.

Privacy Inquiries

Exercise your privacy rights or request details

If you wish to access, update, or remove operational or personal data related to your hospitality business, please contact our dedicated privacy channel.

Response commitment: within 15 business days