Fermich Software

Trust

Security and data protection

Ristoflow processes the phone numbers and conversations of people who called a restaurant. That is personal data, and we treat it as such. This page describes the technical and organisational measures in full — it is written to be read by a privacy adviser or a procurement team as well.

Roles

Each client restaurant is the data controller for its customers' data. Fermich SRL acts as data processor on its behalf under Art. 28 of Regulation (EU) 2016/679, on the basis of a written agreement signed before activation, and processes data only on the restaurant's documented instructions. The data processing agreement is available on request before the contract is signed.

Encryption

  • Phone numbers, message contents and platform credentials are encrypted before being written to the database, with separate keys for each organisation.
  • Traffic to the panel and to Meta's and Twilio's APIs travels exclusively over encrypted channels (TLS).
  • Credentials and access tokens never appear in the browser or in system logs, and are not visible to restaurant staff.

Separation between organisations

  • Each restaurant's data is isolated at the database level: by construction, one organisation cannot read another's data.
  • Every request to the system is scoped to the authenticated user's organisation; isolation does not depend on any single screen being written correctly.
  • Test environments contain no real customer data.

Access

  • Panel accounts have distinct roles — owner, manager, staff — with the minimum permissions each needs.
  • Fermich staff access to production data is limited to the people who deliver support, is logged, and is revoked when someone leaves.
  • We intervene in an individual conversation only at the restaurant's request or when needed to resolve a reported fault.

Retention and deletion

  • The call and message log is kept for 90 days and then deleted automatically, unless the restaurant sets otherwise.
  • Customer relationship history is kept for as long as the restaurant maintains the relationship, and is deleted at the request of the data subject or the restaurant.
  • On termination of the contract all data is returned or deleted within thirty days, subject to legal obligations.
  • Deletion requests follow the procedure set out on the dedicated page.

Continuity and incidents

  • Data is backed up periodically, encrypted.
  • In the event of a personal data breach we inform the restaurant without undue delay and in any case in time for it to meet its own notification duties under Art. 33 and 34 GDPR.
  • Planned maintenance is announced in advance; faults that interrupt the service are communicated while they are happening, not afterwards.

Sub-processors

We rely on the following sub-processors to deliver the service. The list is kept current on this page, and changes are notified to client restaurants in advance, with a right to object under the data processing agreement.

ProviderRoleData processed
Meta Platforms Ireland Ltd. — IrelandSending and receiving WhatsApp messages through the WhatsApp Business PlatformPhone number, message content, delivery metadata
Twilio Inc. — United States / EUReceiving calls, voice announcement, fallback SMSPhone number, call time and duration

Transfers to third countries are covered by the Standard Contractual Clauses adopted by the European Commission. When AI-assisted reply features are activated, the relevant provider will be added to this list and notified before activation.

Artificial intelligence

Where the restaurant enables it, Ristoflow can analyse the content of incoming messages to recognise intent and answers, and generate automated replies. Under no circumstances is restaurant or end-customer data used to train models, ours or a provider's. Conversations remain visible to the restaurant at all times, and it can step in by hand at any moment.

What we don't do

  • We don't use the data for advertising.
  • We don't sell or pass the data to third parties for their own purposes.
  • We don't use it to train AI models.
  • We don't allow contact list uploads or bulk campaigns.
  • We don't ask for or store restaurants' Facebook or WhatsApp passwords.

Reporting a vulnerability

If you have found a security issue in our systems, write to gianmaria.ferrari@fermich.cloud with «Security» in the subject line. We reply within five working days. We ask that you don't disclose the issue publicly before it is fixed and that you don't access data that isn't yours.

Related documents: Privacy Terms Data deletion