VietBowl

DRAFT — PUBLICATION BLOCKED

VietBowl Demonstration Privacy Notice

This draft separates fictional restaurant facts from real personal-data processing. It must not be published until controller details and the processing map are verified.

Revision
0.1.0-draft
Last reviewed
2026-08-29

1. Status and transparency principle

VietBowl is a public demonstration of a fictional restaurant, but fictional menu and restaurant facts do not make personal-data processing fictional. This draft is not a completed Privacy Notice.

This document must not be published with empty controller, contact, recipient, retention, or rights-request fields.

2. Controller and contact

The real data controller's name, postal address, and monitored privacy contact have not yet been supplied. The fictional Warsaw VietBowl address cannot be used instead.

Before publication, only verified details of the real operator must be entered, and whether a data protection officer has been designated must be established.

3. Known demonstration scope

The public demonstration supports Guest Checkout, an optional Customer Account with order history, and simulated orders. Under the product decision, accounts, carts, and demonstration orders are not automatically reset.

The exact fields, sources, purposes, lawful bases, field requirements, and consequences of omission must come from a verified data map, not this draft.

4. Recipients, transfers, and automated decisions

No verified inventory of vendors, hosting, backups, email, media, monitoring, or transfers has yet been published. Do not claim that such recipients or transfers are absent until the inventory is verified.

Do not state that profiling or significant automated decisions are absent until the implementation assessment is complete.

5. Retention, deletion, and backups

Retention periods, deletion criteria, treatment of sessions, logs, and backups, and the owner of the manual deletion process are not decided in this draft. Do not assign invented time periods or promise immediate erasure from backups.

Before publication, an access, correction, and deletion request must be tested with seeded data across every real system.

6. Rights and complaints

After the controller is verified, describe the real route for access, rectification, erasure, restriction, objection, and portability where applicable, as well as the right to complain to the President of UODO.

The request route must be monitored, have an established identity-verification method, and cannot be a fictional restaurant contact.