Onyx Enterprises is a Canadian company serving Canadian restaurants first. Where the EU or UK General Data Protection Regulation applies — a European visitor to our website, a guest travelling from the EU, or a restaurant operating in Europe — this is how we meet it.
For restaurant users' account data and our website visitors, Onyx is the controller. For guest data generated inside a restaurant's account (orders, reservations, contact details), the restaurant is the controller and Onyx is the processor, acting only on the restaurant's instructions under the Terms of Service and the data-processing terms below.
Access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decisions with legal effect (we make none). Write to hello@onyxdine.com, subject "GDPR request". We respond within one month, extendable by two months for complex requests, and we'll tell you if we extend. Guests should contact the restaurant, which we assist. You may complain to your local supervisory authority; Canada is recognised by the EU as providing adequate protection for commercial data under PIPEDA.
Data is hosted in Canada, an EU adequacy jurisdiction. Sub-processors in the United States, the EU and India are bound by contracts including the EU Standard Contractual Clauses (and the UK Addendum) where required. A current sub-processor list is available on request.
When Onyx processes personal data on your behalf, Onyx will: process it only on your documented instructions; keep it confidential; apply the safeguards on the Security page; engage sub-processors only under equivalent terms and notify you of changes; assist with data-subject requests and impact assessments; notify you of a personal-data breach without undue delay and within 72 hours; delete or return the data at the end of the Service (30-day export window, then deletion); and make information available to demonstrate compliance. A signed DPA on this basis is available on request.
As set out in the Privacy Policy and Security pages: encryption in transit and at rest, role-based access, daily backups, and defined retention periods.
Onyx does not currently maintain an establishment in the EU/UK; we will appoint an Article 27 representative if our European activity reaches the threshold that requires one. Until then, GDPR queries go to the person responsible for personal information at hello@onyxdine.com.