Who processes your data, and in what capacity
Two distinct roles coexist, and confusing them is the most common source of error.
Alcess is the controller for the restaurateur’s account data: identity, email address, tax identifiers, billing, connection logs.
Alcess is a processor for guests’ data — phone number, first name, order history. The restaurant is the controller: it decides to offer a loyalty programme, and it determines the purpose.
In practice: an erasure request concerning a loyalty account is addressed to the restaurant, which has the tool to act on it in its dashboard. Alcess does not, on its own initiative, erase data for which it is not the controller.
Data processed
From the restaurateur: establishment name, address, public phone and email address, tax identifiers (NIF, NIS, commercial register), account email address, billing details, IP addresses and connection timestamps.
From the guest: phone number and first name if they join a loyalty programme, the content of their orders, amounts, timestamps, and their consent to notifications.
From staff: first name, hashed access code, assigned permissions, and a named log of sensitive operations — discount, refund, drawer opening.
No banking data is processed or stored by Alcess. Payments are handled by an approved provider, which alone handles card numbers.
Purposes and basis
Performance of the contract: providing the Platform, taking orders, taking payment, producing receipts and closure statements.
Legal obligation: retaining unalterable sales records and the journals required by article 51 bis of the turnover tax code, together with accounting documents.
Consent: loyalty programme, order-ready notifications, marketing messages. Consent is collected separately for each purpose, and is withdrawn as simply as it is given.
Legitimate interest: security of the Platform, fraud prevention, aggregated and non-nominative audience measurement.
Retention periods
Sales data, closures and tax journals: retained for the statutory retention period for accounting and tax records. They cannot be deleted, including on request — erasing them would deprive the restaurateur of the documents they must produce in the event of an inspection.
Loyalty account: until consent is withdrawn, and at the latest three (3) years after the last order.
Restaurateur’s account: for the whole term of the contract, then one (1) year after termination for non-tax data.
Connection logs: twelve (12) months.
An erasure request concerning a sale does not delete the sale: it detaches the customer’s identity from it. The amount, the date and the receipt number remain, because they are the accounting trace of the transaction.
Recipients
Data is neither sold, nor rented, nor transferred.
It is accessible to the restaurant concerned and its authorised staff, within the limits of the permissions the restaurateur has granted them.
It is disclosed only to the providers necessary to perform the service: host, approved payment provider, email and notification delivery service. Each acts on instruction and for the single purpose assigned to it.
It may be disclosed to administrative or judicial authorities upon a lawful request.
Transfer of data outside Algeria
This is the point that calls for the most attention. Transferring personal data to a foreign country is subject to the prior authorisation of the National Authority for the Protection of Personal Data (ANPDP) — not to a mere declaration.
The authorisation is assessed in the light of the adequate level of protection in the destination country, respect for fundamental rights and freedoms, the existence of a supervisory authority in that country and the security measures applied.
Alcess undertakes to carry out no transfer outside the authorised framework, and to state on this page the status of the authorisation together with the list of countries concerned.
Security
Encryption in transit for all exchanges, and encryption at rest of payment providers’ secrets.
Strict separation of data between establishments, enforced at database level rather than in the interface: an interface-level guard can be bypassed.
Second authentication factor for dashboard access, and re-authentication required before any operation touching bank details.
Named logging of sensitive operations, itself unalterable.
Your rights
You have a right of access, rectification, objection, erasure and restriction of processing, together with a right to the portability of your data.
You may withdraw a consent at any time, without calling into question the lawfulness of processing already carried out.
For a loyalty account: contact the restaurant, which has the anonymisation tool in its dashboard.
For a restaurateur account: the request is made from the account settings, or in writing to the details shown in the legal notice.
A reply is given within one (1) month. That period may be extended if the request is complex; you are then informed.
Data breach
In the event of a personal data breach, the ANPDP is informed within five (5) days of becoming aware of it — a period shortened by law no. 25-11.
The persons concerned are warned without delay where the breach is likely to result in a high risk to their rights and freedoms.
The notification describes the nature of the breach, the categories and approximate number of persons concerned, the likely consequences and the measures taken.
Register and audit log
A register of processing operations is kept and updated, in accordance with the obligations strengthened by law no. 25-11.
Access to sensitive data and operations involving money are recorded in an unalterable audit log, retained and admissible.
No decision producing legal effects is taken on the sole basis of entirely automated processing.
Trackers and audience measurement
The Platform uses only trackers strictly necessary to its operation: keeping the session, the current basket, the chosen language.
No advertising tracker, no sharing with an ad network, no profiling for targeting purposes.
Any audience measurement is aggregated and does not allow a person to be re-identified.
Complaint
If you consider that your rights are not being respected, write to us first: a reasoned reply will be sent to you.
You may, at any time and without any prior step, refer the matter to the National Authority for the Protection of Personal Data (ANPDP), the independent administrative authority responsible for overseeing the application of the law.