GDPR (the EU regulation) and the Swedish Data Protection Act give every guest the right to request their data and the right to be "forgotten". As the restaurant, you are the data controller – Vendion is the processor. This means you handle the request, but Vendion has the tools.
Guest rights under GDPR:
| Right | What it means | Deadline |
|---|---|---|
| Right of access (Art. 15) | Learn what data you hold | 30 days |
| Right to rectification (Art. 16) | Correct errors | 30 days |
| Right to erasure / "right to be forgotten" (Art. 17) | Have data deleted | 30 days |
| Right to data portability (Art. 20) | Receive data in machine-readable format | 30 days |
| Right to object (Art. 21) | Stop marketing | Immediately |
How to handle a request step-by-step:
1. Verify it is the right person. Requests can come by phone, email, or letter. Before handing out data – verify identity. Ask for a phone number that matches the guest profile, or have the guest confirm via email from the address on file. This is a GDPR requirement – you must not hand out data to the wrong person.
2. Find the guest. Go to Marketing → Guests and search by name, phone, or email. Click the guest to open the profile.
3a. If the request is EXPORT (guest wants to see their data):
3b. If the request is ERASURE ("forget me"):
4. Reply to the guest in writing within 30 days. Template you can copy:
"Hi [name], we have received your request for [access to / deletion of] personal data dated [date]. We have now [exported your data and attached it / deleted your data from our systems]. If you have questions, contact us at [email]. Best regards, [restaurant]"
What CANNOT be deleted (and why):
| Data | Why it is kept | Legal basis |
|---|---|---|
| Receipts, invoices, Z-reports | Bookkeeping obligation | Swedish Bookkeeping Act, 7 years |
| Receipt numbers, amounts, dates | Bookkeeping obligation | Swedish Bookkeeping Act, 7 years |
| Tax authority audit trail | Cash register law | Kassalagen |
| Anonymized order rows | Statistics, no personal data | GDPR Art. 89 |
Note: When you delete a guest in Vendion, contact details disappear but order history remains as "Unknown guest" orders. This is fully GDPR-compliant – the personal data is deleted, and the financial transaction is preserved as the law requires.
Right to object (marketing stopped immediately): If the guest just wants to stop receiving marketing (not delete the whole profile) – simply disable SMS and email consent in the guest profile. No deletion needed. This must happen immediately, not within 30 days.
STOP-SMS counts too: If a guest replies "STOP" to a campaign SMS, the guest's consent is updated automatically – SMS consent is turned off and the unsubscribe timestamp is recorded. You don't need to do anything manually – the system handles it.
Tools to know:
Privacy policy on vendion.com: /integritetspolicy (Swedish) and /en/privacy-policy (English) should always be linked in consent boxes, campaign SMS (via short link), and email footers.
This feature is part of Vendion Marketing.
Curious how it looks in practice? Read more about the product or book a short demo.
Was this article helpful?