PRIVACY AND PERSONAL DATA PROTECTION POLICY
Effective Date: July 18, 2026
Cruslar LLC (hereinafter referred to as "Cruslar" or "the Company") values and respects the privacy of its users, clients, and visitors ("the User"). This Policy governs the collection, use, storage, protection, and disclosure of Personal Information obtained through our website and the provision of our services.
Data controller: Cruslar LLC · 8206 Louisiana Blvd NE, Suite A, Albuquerque, NM 87113 (United States) · [email protected] · +1 (917) 963-8237
1. Regulatory Framework and Compliance
This Policy has been designed to comply with applicable privacy laws in our U.S. operation, including, without limitation, the CCPA/CPRA (if applicable) and the California Online Privacy Protection Act (CalOPPA). Additionally, we acknowledge the applicability of the General Data Protection Regulation (GDPR) of the European Union for processing personal data of individuals residing in the EU or EEA.
2. Types of Information Collected and Processing Purposes
| Data Category | Examples of Information Collected | Legal Basis and Purpose of Processing |
| Identifiers (Direct) | Name, corporate or personal email address, phone number, postal address. | Contractual necessity and consent. Used for direct communication, sending proposals (SOW), and managing service contracts. |
| Identifiers (Indirect) | IP address, device ID, geolocation data, online identifiers. | Legitimate interest. Used for fraud prevention and network security. |
| Usage and Technical Data | Browsing history, referral/exit pages, session time, browser type, and operating system. | Legitimate interest and optimization. Used for internal audits, web performance analysis, and improving User experience. |
| Financial/Transactional Data | Payment card details (processed by third parties), payment and billing history. | Contractual and legal necessity. Used to process payments for contracted services and fulfill fiscal obligations. |
| Marketing Data | Subscription preferences, interactions with email campaigns. | Consent. Used for audience segmentation and sending promotional communications. |
3. Cookies and Tracking Technologies
This site uses first-party and third-party cookies. The full, up-to-date detail —which cookies are set, for what purpose, how long they last and who manages them— is available in our Cookie Policy.
Cookies that are necessary for the site to work do not require consent. All others are only set if you allow them, and you can accept or reject each purpose separately and change your decision at any time from the cookie preferences panel.
4. Retention Periods
We keep your Personal Information only for as long as necessary for the purposes described in this Policy. As a general rule we apply the following periods:
Enquiries and quote requests that do not lead to a contract: one (1) year from the last contact.
Client data and project documentation: six (6) years from the end of the contractual relationship, the period during which liabilities may arise from the contract.
Invoicing, accounting and tax obligations: six (6) years under commercial law, and a minimum of four (4) years for tax purposes.
Newsletter subscribers and marketing communications: until you unsubscribe. After that we keep only the minimum record needed to prove you asked to unsubscribe and to avoid contacting you again.
Operational messaging (WhatsApp and equivalent channels): twelve (12) months from the last message.
Technical and security records (logs): twelve (12) months.
Job applications and CVs received: one (1) year, unless you ask us to delete them sooner.
Cookies: the duration of each one is listed in our Cookie Policy.
Once the period has elapsed, data is deleted or irreversibly anonymised. If a claim, inspection or proceeding is ongoing, the data concerned is kept blocked until it is resolved.
5. User Rights and Exercise Mechanism
As a User, you possess rights regarding your Personal Information, which you can exercise by contacting Cruslar at [email protected]:
-
Right to Access: Request a copy of the information we hold about you.
-
Right to Rectification: Request the correction of incomplete or inaccurate data.
-
Right to Erasure ("Right to be Forgotten"): Request the deletion of your data, subject to our legal retention obligations.
-
Right to Object: Object to the processing of your data for direct marketing purposes or under certain legitimate interest bases.
-
Right to Data Portability: Receive your data in a structured, commonly used format.
-
Right to Opt-Out of Sale/Sharing (CCPA/CPRA): Exercise the right to request the non-sale or non-sharing of your Personal Information.
In addition, if you believe that the processing of your data does not comply with applicable law, or if your request has not been properly addressed, you have the right to lodge a complaint with a supervisory authority. In Spain this is the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid (www.aepd.es). If you reside in another European Economic Area country, you may contact the supervisory authority of your place of residence.
6. Our Services and Products
Cruslar provides professional services to clients (strategic consulting and custom software development) and operates digital products of its own. These include DineSync, a Cruslar brand consisting of a comprehensive restaurant management platform featuring an interactive digital menu, order and booking management, a conversational assistant, diner communications and payment processing through third-party payment gateways. When the User interacts with an establishment using DineSync, the processing of their data is additionally governed by section 8.
7. WhatsApp and Other Messaging Channels
Some of our products, including DineSync, allow communication with the User through the WhatsApp Business Platform, a service provided by Meta Platforms, Inc. Through this channel we may process: the phone number, the profile name and the content of the messages exchanged (for example orders, confirmations, availability notices and the receipt or simplified invoice when closing the bill).
This data is used exclusively for the operational management of the requested service (taking and confirming orders, coordinating table service, sending receipts) and never for unsolicited advertising. Meta acts as the messaging infrastructure provider under its own terms and privacy policy, which may involve international transfers covered by the safeguards Meta has in place. The User may stop using this channel at any time and request service through alternative means (web or in person).
8. DineSync: Data Controller and Data Processor Roles
In the operation of DineSync, each client restaurant or establishment acts as the Data Controller of its diners' personal data (identification, phone number, order history and, where applicable, dietary preferences or allergens provided by the diner). Cruslar, through its DineSync brand, acts as the Data Processor on behalf of such establishments, under the terms of Article 28 GDPR, processing data solely under the Controller's instructions and applying appropriate technical and organisational measures (encryption of credentials and secrets, role-based access control and per-instance isolation).
Payments are processed through third-party payment gateways (such as Redsys); Cruslar does not store full card data. Diners wishing to exercise their rights regarding data processed at a specific establishment should first contact that establishment, and Cruslar will provide the necessary assistance to address such requests.
9. International Data Transfers
Cruslar LLC is a company incorporated in the United States. As a result, processing personal data originating from the European Economic Area (EEA) may involve an international transfer outside the EEA.
Safeguards applied. Where we receive personal data from clients, suppliers or partners established in the EEA, the transfer is covered by the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, which are incorporated into the agreement signed with each client. Where necessary, they are complemented by additional technical and organisational measures, such as encryption of communications and credentials, role-based access control and minimisation of the data transmitted.
Service providers. The service providers we use (hosting, messaging, payment gateways, analytics) apply their own transfer mechanisms in turn, either through Standard Contractual Clauses or through adherence to adequacy frameworks recognised by the European Commission.
Your right to know. You may request information about the safeguards applying to a specific transfer, and obtain a copy of the clauses in place, by writing to [email protected].
10. Contact and Revisions
If you have questions or concerns about this Policy, please contact us at [email protected] or by mail at Cruslar LLC, 8206 Louisiana Blvd NE, Suite A, Albuquerque, NM 87113 (United States). This Policy may be updated periodically; we will notify you of any material changes by posting the new version on our website.