Konki Labs

Privacy policy (GDPR)

This policy explains how we collect, use and protect your personal data, in accordance with the General Data Protection Regulation (GDPR) and, for UK users, the UK GDPR.

1. Data controller

Konki Labs SAS, 221 Bd des Provinces Françaises, 92000 Nanterre, France.

2. Data collected

Depending on how you interact with the website, we may collect:

  • Identification and business data: surname, first name, business email, restaurant/brand, city, number of restaurants, delivery volume, telephone (if provided).
  • Enquiry data: message content (contact form), correspondence history.
  • Technical data: logs, IP address, browsing data and cookies (see Cookie policy).

3. Purposes and legal bases

PurposeExamplesLegal basis
Responding to enquiries (contact, demo)Handling incoming enquiriesLegitimate interest and/or pre-contractual measures
Account creation and subscriptionsOpening the account, payment, billing, supportPerformance of the contract / legal obligations
Waiting listSign-up, reminders when orders openLegitimate interest (B2B) and/or consent
Security and fraud preventionLogs, website securityLegitimate interest
Audience measurementTraffic statisticsConsent

B2B email marketing: email marketing to business contacts is permitted provided they are informed and can easily opt out.

4. Data recipients

Your data is accessible to authorised internal teams and, where necessary, to our service providers (processors):

HostingIONOS
Website formsWeb3Forms
PaymentStripe
ShippingChronopost, Mondial Relay
Audience measurementMatomo

These providers act on our instructions and with appropriate security measures.

5. Transfers outside the European Union

If any providers process data outside the EU (or, for UK users, outside the UK), we put appropriate safeguards in place (for example standard contractual clauses).

6. Retention periods

Prospects and enquiries without a contract3 years from collection or from your last contact with us
CustomersTerm of the contract, then archiving in line with legal obligations and limitation periods
Accounting records10 years from the end of the financial year
Technical logs12 months

7. Security

We implement technical and organisational measures to protect your data: access control, encryption where relevant, and backups.

8. Your rights

You have the rights of access, rectification, erasure, objection, restriction and, in some cases, portability. You can also lodge a complaint with your local data protection authority (in the UK, the Information Commissioner’s Office – ICO) or with our lead supervisory authority, the CNIL (France).

9. Exercising your rights

For any request, please use our contact form.

10. Updates

Last updated: 24/09/2026