Legal
Privacy Policy
This policy explains how we process personal data on kolsche.de and in the Kolsche software — in line with the GDPR.
1. Controller
The controller for processing in connection with kolsche.de and the “Kolsche” software is:
A. Abou-Daher, Y. Abou-Daher, Ehsainieh GbR (brand: MA’NA — Levantine Catering)
Kiepenheuerallee 5, 14469 Potsdam, Germany
Email: info@ma-na.catering
Full provider details are in the legal notice (Impressum).
2. Scope
This privacy policy applies to the marketing website kolsche.de (“Website”) and the web-based catering software “Kolsche” (“Product”), which we provide to catering businesses as SaaS.
For personal data that our customers enter about their end customers, employees, or events, those customers are generally the controllers under the GDPR. We process that data as a processor under our contract with the customer (Art. 28 GDPR).
3. Website — visiting kolsche.de
When you visit the site, technically necessary data (IP address, date, time, page requested, browser type, referrer) is processed in server logs (Art. 6(1)(f) GDPR — legitimate interest in secure, stable delivery).
Hosting is provided by Hetzner Online GmbH, Germany/EU. Server logs are deleted automatically after at most 7 days.
We do not use analytics or marketing cookies on the website.
4. Website — demo & contact form
When you request a demo via the form, we process the data you provide to handle your request and contact you (Art. 6(1)(b) and (f) GDPR).
Data processed: name, company (optional), email, message, selected plan if any.
Submission is handled by FormSubmit (FormSubmit LLC, USA), which forwards the request to info@ma-na.catering. Transfers to the USA rely on Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Retention: requests remain in our mailbox until handled and are deleted within 24 months of last contact unless legal retention applies.
5. Website — fonts (Google Fonts)
We load fonts from Google (Google Ireland Ltd.) via fonts.googleapis.com and fonts.gstatic.com. Your IP address is transmitted to Google (Art. 6(1)(f) GDPR).
More information: https://policies.google.com/privacy
6. Website — language preference (localStorage)
Your language choice is stored locally under “kolsche-landing-lang” so the site can remember it on your next visit (Art. 6(1)(f) GDPR). This is not a tracking cookie.
7. Product — overview
Kolsche is catering management software (quotes, invoices, calendar, customers, staff, time tracking, optional AI assistant). Access is via a tenant-specific subdomain (multi-tenant SaaS).
The catering business using the product is generally the controller for business data processed in the app. We provide the platform and act as processor for that data.
8. Product — data processed
User accounts (catering staff): username, password (stored as hash only), login timestamps.
Company profile: name, address, contact details, tax/VAT IDs, bank details, logo, notes.
Customers: name, email, phone, address, contact person.
Quotes & invoices: event data, guest counts, line items, amounts, status, notes.
Staff & attendance: name, role, contact details (optional), QR identifier, clock-in/out times.
Calendar: events, descriptions, locations, reminders.
Optional AI assistant (if enabled): chat messages; the assistant may access tenant business data to answer questions or draft documents.
Optional email integration (if configured by customer): inbound mail via IMAP to detect catering inquiries.
9. Product — purposes & legal bases
Providing and operating the software, authentication: Art. 6(1)(b) GDPR (contract with the catering business).
Processing customer, staff, and event data on behalf of the customer: Art. 28 GDPR; the customer’s legal basis depends on use case.
QR time tracking: on behalf of the catering business (e.g. working time records).
AI assistant: Art. 6(1)(b) GDPR where booked; inputs may be sent to OpenAI (Ireland/USA).
Security and server logs: Art. 6(1)(f) GDPR.
10. Product — storage, hosting & retention
Production data is stored in PostgreSQL databases at Hetzner Online GmbH (Germany/EU). Each tenant has a separate database.
Authentication uses JWT tokens stored in browser localStorage until logout or expiry.
Business records remain until deleted by the customer or the tenant is fully removed.
AI chat threads are held in memory in the default production setup and are not retained after service restart.
Uploaded logos persist until replaced or the tenant is deleted.
PDFs are generated on demand and not stored long-term on the server.
11. Product — recipients & processors
Hetzner Online GmbH (Germany) — application and database hosting
OpenAI (Ireland/USA) — AI assistant when enabled; SCCs (Art. 46 GDPR)
LangSmith / LangChain (optional, USA) — AI call logging if enabled
ipapi.co (optional) — country detection for language on first visit
Customer’s email provider (IMAP) — only if email integration is enabled
We use Art. 28 GDPR agreements with relevant processors.
12. Product — customer responsibilities
Our customers must inform their end customers, employees, and other data subjects about processing in the product and ensure appropriate legal bases.
Requests from data subjects sent to us are forwarded to the relevant catering business where identifiable.
13. Your rights
You have rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), objection (Art. 21), and portability (Art. 20) under the GDPR.
You may withdraw consent at any time without affecting prior lawful processing.
You may lodge a complaint with a supervisory authority (Brandenburg, Germany: LfDI Brandenburg).
Privacy inquiries: info@ma-na.catering
14. Security
We use technical and organizational measures including TLS, password hashing (bcrypt), separate tenant databases, authentication, and rate limiting.
15. Changes
We update this policy when our services or the law change. The published version on this page applies.
Last updated: August 2026