Fermich Software

Privacy policy

Last updated: 16 August 2026

This policy describes how Fermich SRL processes personal data as part of the Ristoflow service. It is addressed to client restaurants, to the people who contact them, and to anyone who wants to check how the service works before using it.

Who we are

Ristoflow is a service of Fermich SRL, Via Walther von der Vogelweide 11/A, 39031 Brunico (BZ), Italy — VAT and tax number 03195880210, REA BZ-240085. Contact for any matter concerning personal data: gianmaria.ferrari@fermich.cloud.

Roles

Each client restaurant is the data controller for its customers' data. Fermich SRL acts as data processor on its behalf under Art. 28 of Regulation (EU) 2016/679, and processes the data only on its documented instructions, on the basis of a written agreement signed before the service is activated.

What we process

We process the data needed to run the conversations the restaurant configures: the phone number of whoever contacts the restaurant or receives a reply from it; the date, time and outcome of calls and messages; the content of the messages exchanged, inbound and outbound. If the restaurant enables it, we also process the conversation history predating the connection. Of the restaurant's staff we process name, email address and role, to allow access to the service.

We do not process special categories of data under Art. 9 GDPR, and we do not ask recipients for information beyond what is needed to handle a booking or a request.

How we use it

The restaurant builds conversation flows, and to run them we may: send one or more messages in reply to a call or a message; analyse the content of incoming messages to recognise keywords, intent or answers to questions, and choose the appropriate next step; present WhatsApp menus, buttons and interactive forms, for instance to pick a language or an option; and, where the restaurant enables it, generate automated replies, including by means of artificial intelligence systems, taking into account previous conversations with the same person. Conversations always remain visible to the restaurant, which can step in at any time.

What we don't do

We do not use this data for advertising, we do not sell or transfer it to third parties for their own purposes, and we do not use it to train artificial intelligence models, ours or a provider's. We do not allow contact list uploads or bulk campaigns. The restaurant may keep the history of its own customers in order to serve them better, but that data does not leave its perimeter.

Legal bases

Performance of the contract between Fermich SRL and the restaurant; the restaurant's legitimate interest in replying to those who contacted it; and, where the nature of the message requires it, consent collected by the restaurant.

How long we keep data

Retention periods depend on the type of data and are set by the restaurant as controller.

Call and message log
Kept for 90 days and then deleted automatically, unless the restaurant sets otherwise.
Customer relationship history — contacts, conversations, stated preferences
Kept for as long as the restaurant maintains the relationship, and in any case deleted at the request of the data subject or the restaurant.
Restaurant staff data
For the duration of the relationship with the restaurant.

On termination of the contract between Fermich SRL and the restaurant, all data is returned or deleted within thirty days, subject to legal obligations.

Security

Phone numbers, message contents and credentials are encrypted before being written to the database, with separate keys for each organisation. Each restaurant's data is isolated at the database level, so that one organisation cannot read another's. Credentials never appear in the browser or in system logs. The measures are described in full on the Security page.

Who we share data with

To deliver the service we rely on Meta Platforms Ireland Ltd. for WhatsApp messaging and Twilio Inc. for calls and SMS, both as sub-processors. When AI-assisted reply features are activated, the relevant provider will be named in this policy before activation. Transfers to third countries are covered by the Standard Contractual Clauses adopted by the European Commission. The current list is published on the Security page.

Your rights

Any data subject may request access, rectification, erasure, restriction and portability, and object to processing, by writing to gianmaria.ferrari@fermich.cloud or to the restaurant that contacted them. Instructions for deletion are set out on the Data deletion page. It is always possible to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali).

Cookies and this website

This site is static: it uses no profiling cookies, embeds no advertising tools and does not track visitors across sites.

Changes

Material changes to this policy will be notified to client restaurants at least thirty days in advance.