Privacy notice

Canadian edition dated 2026-09-13

How ProCafe handles Canadian personal information, international processing, choices and privacy requests.

Consulter ce document en français

Responsibility and contact

ProCafe is operated by Serdar K. Postal address: Cleekim Drive, EH15 3QP, Edinburgh, UK. Contact: support@procafe.app.

The cafe determines the purposes for its staff and operational records; ProCafe processes those records on its documented instructions. ProCafe is responsible for its own account, billing, support, consent, security and audit information. The person responsible for privacy requests is Serdar K., reachable at support@procafe.app; mark the request ‘Privacy’.

Applicable Canadian requirements include PIPEDA and provincial private-sector privacy laws according to the activity and jurisdiction. Our existing UK data protection obligations also apply where relevant. A UK legal basis does not replace consent or another requirement under applicable Canadian law.

Information and purposes

We use the account name, email and password hash to create and secure access. We hold staff names, shifts, time-off requests, readings, documents and other operational information on behalf of the cafe. Payments and invoices are handled with Stripe; full card numbers are not received or stored by ProCafe. Support correspondence and limited security logs help us resolve problems and protect the service.

Provide only information needed for the task. We do not ask for health or other sensitive personal details in free text. Where such details reach information we control, we seek to redact or delete them where possible.

Optional analytics and marketing

Necessary session and optional trusted-device cookies support sign-in. On public pages only, Google Analytics runs after Analytics consent. A separate Marketing choice controls Meta Pixel and consent-bound Conversions API measurement when configured. Neither is loaded in signed-in operational pages or internal administration. We do not sell personal information.

Consented Meta events can include browser or click identifiers, hashed account identifiers, IP address, browser user agent, time and source page. They do not include passwords or operational records. Analytics and Marketing can be withdrawn separately in Cookie preferences. This browser advertising choice does not sign you up for promotional email.

Hosting and international processing

The application and database are hosted in Germany in the European Union. Encrypted backups are held with a separate EU-region provider. The recipient list identifies providers for payments, email, monitoring and consented public-page measurement; some processing takes place in the United States. Canada support does not mean Canadian data residency.

Personal information processed abroad can be subject to lawful access by courts, law enforcement or national-security authorities there. Contractual safeguards cannot override those laws. Review the data processing agreement and recipient list. A business remains accountable for outsourcing; Québec businesses must assess applicable privacy-impact and written-agreement requirements before sending information outside Québec.

Retention, access and correction

The retention schedule sets the service's periods and deletion process. You may request access, correction and information about use and disclosure, and raise a privacy concern at support@procafe.app. Withdrawal of optional consent applies prospectively; necessary service or legal retention may continue. Requests about employer-controlled records usually go to the employer, with ProCafe assisting on its instructions.

We respond within the applicable statutory period. PIPEDA access requests normally require a response within 30 calendar days; an extension needs a permitted reason and the required notice. You may complain to the Office of the Privacy Commissioner of Canada or the competent provincial commissioner, including Québec's Commission d’accès à l’information, or to the UK ICO where its law applies.

Security incidents

We use appropriate access and security controls and notify affected customer organisations of personal-data breaches without undue delay. We assess and perform reporting, individual notification and incident-record duties required by applicable law; Canadian thresholds and timelines are assessed separately from the UK GDPR's 72-hour reporting rule. Report a concern to support@procafe.app without including unnecessary sensitive information.