Legal information

GDPR compliance

Last updated: July 1, 2026

Information on how smartapp.az processes personal data of users from the European Union and European Economic Area under GDPR principles.

1. Purpose and scope

This GDPR section explains how personal data is processed in relation to users, customers and contact persons located in the European Union or European Economic Area.

This document supplements the Privacy Policy. If a conflict arises, this section applies to rights and obligations that specifically arise under the GDPR.

2. Data controller

smartapp.az acts as a data controller for data processed in connection with user accounts, subscriptions, payments, support and platform security.

For customer, order, employee and operational data entered into the Business Panel, the user may act as the controller of its own business processes, while smartapp.az acts as a technical service provider and processor.

3. Categories of data processed

The following categories of data may be processed to provide the service:

  • account data: name, email, phone, user ID and login information
  • business data: restaurant name, branch data, menu, table, inventory and employee records
  • payment data: balance transactions, invoices, receipts and payment statuses
  • technical data: IP address, device and browser data, security logs and usage statistics
  • support data: support requests, communication history and files shared for troubleshooting

4. Legal bases

Personal data is processed under the following legal bases:

  • performance of a contract: account creation, subscriptions and service delivery
  • legitimate interests: platform security, fraud prevention and service improvement
  • legal obligations: accounting, invoicing and statutory retention requirements
  • consent: marketing communications, certain cookies and voluntarily submitted data

5. User rights

Where the GDPR applies, users have the following rights:

  • right of access
  • right to rectification of inaccurate or incomplete data
  • right to erasure
  • right to restriction of processing
  • right to data portability
  • right to object to processing based on legitimate interests
  • right to withdraw consent at any time
  • right not to be subject to solely automated decisions that produce legal or similarly significant effects

These rights are not absolute and may be limited by legal retention obligations, contract performance or the establishment, exercise or defence of legal claims.

6. Processors and third parties

smartapp.az may use trusted service providers for hosting, email, security, analytics, payment review and support operations.

These providers process data only to the extent necessary to deliver the service and are subject to confidentiality, security and processing obligations.

7. International transfers

Data may be processed through infrastructure and service providers located in the Republic of Azerbaijan, the European Union or other countries.

Where the GDPR applies, transfers outside the European Union are protected by appropriate safeguards, contractual obligations and technical security measures.

8. Retention

Personal data is retained only for as long as necessary for the relevant processing purpose. Account, subscription, invoice and security records may be retained according to legal, contractual and audit requirements.

When the retention period expires or no legal basis remains, data is deleted, anonymised or restricted under a lawful archive regime.

9. Security measures

smartapp.az applies technical and organisational measures such as access control, encryption, audit logs, backups, system monitoring and role-based permissions.

Users are responsible for protecting their account passwords, login credentials and the permissions of people who access their Business Panel.

10. Requests and complaints

Users may exercise GDPR rights through smartapp.az support channels. Requests are handled after identity verification and assessment of the applicable legal grounds.

Users also have the right to lodge a complaint with the data protection authority in the country where they live or work.