Privacy Policy
Effective Date: February 27, 2026
Last Updated: July 14, 2026
1. Introduction
This Privacy Policy ("Policy") governs how Baboon Marketing (operating as "Caterway") ("Company," "we," "us," "our") collects, processes, uses, and protects personal data when you use our SaaS catering management platform, including our website, quote management tools, menu management features, calculator tools, and related services (collectively, the "Service").
Baboon Marketing is committed to protecting your privacy and ensuring transparency in how we handle your personal information. This Policy applies to all users of the Service, including catering professionals, event planners, and other business customers.
Applicable Laws: This Policy complies with:
- The European Union General Data Protection Regulation (GDPR) (EU 2016/679)
- Finnish Data Protection Act (Tietosuojalaki 1050/2018)
- Finnish Accounting Act (Kirjanpitolaki 1620/2015)
- ePrivacy Directive (2002/58/EC) and Finnish implementing legislation
- Finnish Consumer Protection Act (Kuluttajansuojalaki 38/1978)
We are committed to processing your personal data fairly, lawfully, and transparently in accordance with these regulations.
2. Definitions
For purposes of this Policy, the following terms have the meanings set forth below:
Personal Data: Any information relating to an identified or identifiable natural person ("Data Subject"), including name, email address, phone number, IP address, device identifiers, and any other identifier that could directly or indirectly identify an individual.
Processing (or "Process"): Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Data Controller: The natural or legal person, public authority, agency, or other body which alone or jointly with others determines the purposes and means of the Processing of personal data.
Data Processor: A natural or legal person, public authority, agency, or other body which Processes personal data on behalf of a Data Controller.
Data Subject: The individual to whom personal data relates.
Consent: Any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes by which they signify agreement to the Processing of personal data relating to them.
Special Categories of Data: Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification purposes, data concerning health, or data concerning sex life or sexual orientation.
Legitimate Interest: Our interest in conducting and managing our business operations in a way that is beneficial to all our customers and stakeholders.
Subprocessor: Any entity engaged by us or our Processors that processes personal data on our behalf.
Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
3. Data Controller Information
Company Legal Name: Baboon Marketing (trading as "Caterway")
Business ID (Y-tunnus): 3125660-7
Address: Sรถrnรคisten Rantatie 25 A1, 00500 Helsinki, Finland
Email: support@caterway.io
Country of Registration: Finland
For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us using the information provided above.
4. Roles and Responsibilities
Our relationship to your personal data depends on the context of your use of the Service. We operate in different capacities:
4.1 When We Are the Data Controller
Baboon Marketing acts as a Data Controller when Processing personal data for:
- Account management and authentication of users who register with Caterway
- Service delivery to our direct customers (catering firms, event planners, etc.)
- Direct marketing and communications with users (newsletters, product updates, promotional content) where consent has been obtained
- Analytics and service improvement through tracking cookies and analytics tools
- Payment processing and billing (though payment tokens are processed by our payment processor, Stripe)
- Compliance with legal obligations
- Fraud prevention and security measures protecting our Service
- Supporting customer service and communications with our users
As a Controller, we determine the purposes and means of Processing and comply fully with our GDPR obligations, including responding to Data Subject rights requests, conducting Data Protection Impact Assessments (DPIAs) where necessary, and notifying relevant authorities of Data Breaches.
4.2 When We Are the Data Processor
Baboon Marketing acts as a Data Processor when Processing personal data on behalf of our catering firm customers who are themselves Data Controllers. Specifically:
- When a catering firm uploads end-customer data (guest names, contact information, dietary requirements, allergies, event details, and other event-related information) into the Caterway platform for purposes of managing quotes, events, and customer relationships, the catering firm remains the Data Controller of this information, and we Process it according to a Data Processing Agreement (DPA).
- In this capacity, we Process such data only on documented instructions from the catering firm, for the specific purposes they determine, and we implement appropriate technical and organizational measures to ensure secure Processing.
This dual role is material: data you directly provide to Caterway (your account information, preferences) makes us a Controller; data that catering firms upload about their clients makes us a Processor subject to that firm's instructions and our DPA terms.
4.3 Limitation of Liability for End-Customer Data
Important: As a Data Processor, Baboon Marketing provides the technical platform and infrastructure for catering firms to manage their business operations. Baboon Marketing shall not be held liable for any acts, omissions, or data handling practices of catering firms (the Data Controllers) with respect to end-customer personal data. Each catering firm is solely and independently responsible for:
- Ensuring that all Processing of end-customer data complies with applicable data protection laws, including but not limited to the GDPR, national data protection legislation, and any sector-specific regulations;
- Obtaining all necessary consents, authorizations, and legal bases required for the collection and Processing of end-customer personal data prior to uploading such data to the Service;
- Providing adequate privacy notices to end-customers regarding how their data will be collected, used, stored, and shared;
- Responding to and fulfilling Data Subject rights requests from end-customers, including requests for access, rectification, erasure, restriction, and data portability;
- Implementing appropriate internal policies, procedures, and training to ensure that end-customer data is handled lawfully, fairly, and with the utmost care and respect;
- Complying with all applicable local, national, and international laws and regulations governing the protection of personal data in the jurisdictions in which they operate.
Advisory: We strongly advise all catering firms using the Service to familiarize themselves with, and at all times comply with, all applicable data protection laws and regulations. End-customer personal data, including but not limited to names, contact details, dietary requirements, allergies, and health-related information, must be treated with the highest degree of confidentiality and respect. Catering firms should implement robust data protection measures, maintain comprehensive records of their Processing activities, and seek independent legal counsel where necessary to ensure full compliance with their legal obligations as Data Controllers.
5. Personal Data We Collect
We collect personal data through various channels and for various purposes. The specific data we collect may vary depending on how you interact with our Service:
5.1 Account Registration and Profile Data
When you create an account with Caterway, we collect:
- Full name and email address (required)
- Phone number (required for business customers)
- Company name and business details (required for professional accounts)
- Business ID or Tax Identification Number (required where applicable)
- Professional title or role (optional)
- Profile photo or avatar (optional)
- Account preferences and settings (notification preferences, language, timezone)
- Password hash (securely hashed and salted, never stored in plain text)
5.2 Waiting List Data
If you subscribe to our waiting list or early-access program prior to launch, we collect:
- Email address (required)
- First and last name (optional)
- Business type or industry (optional)
- Primary business interest in Caterway (optional)
- Timestamp of subscription
5.3 Service Usage and Interaction Data
As you use the Caterway platform, we automatically collect:
- Feature usage logs (which features you access, how frequently, duration of use)
- Quote data (quotes created, menus selected, calculations performed)
- Menu management activities (menus created, items added/modified, templates used)
- Calculator tool usage (inputs used, calculations performed, results generated)
- Action sequences (workflow patterns demonstrating how you use the platform)
- Event and customer data (only if you upload such information to the platform; see section 5.6)
- Timestamps for all interactions
- Error logs (to help us improve the Service and diagnose technical issues)
5.4 Financial and Payment Data
For customers on paid subscription tiers (Pro, Enterprise), we collect payment-related information through our payment processor, Stripe:
- Payment method type (credit card, bank transfer, etc.)
- Last four digits of credit card (for identification purposes only)
- Card expiration date (required for recurring billing)
- Billing address and postal code
- Transaction history and amounts (charges, refunds, subscription changes)
- Invoice details and payment dates
- Billing email address
Important: Baboon Marketing does NOT collect, store, or have access to full credit card numbers (Primary Account Numbers). Payment card data is processed exclusively by Stripe, our certified PCI-DSS Level 1 compliant payment processor. We receive only tokenized references to payment methods, which we use solely to process recurring charges and maintain billing records.
5.5 End-Customer Data (Data Uploaded by Catering Firms)
When catering firms (our customers) use Caterway to manage their business, they may upload or input data about their own customers and event attendees ("End-Customer Data"). This data may include:
- Guest names and contact information (email, phone)
- Dietary requirements and restrictions (vegetarian, vegan, gluten-free, kosher, halal, etc.)
- Allergy information (nuts, shellfish, dairy, eggs, soy, sesame, etc.)
- Event details (date, location, number of attendees, event type)
- Special requests or notes (celebration type, specific preferences, access requirements)
- Guest list information (attendee counts by category)
- Communication records between the catering firm and their customers regarding events
The catering firm (our customer) is the Data Controller of this End-Customer Data. We act as a Processor following the catering firm's instructions as documented in our Data Processing Agreement. We do not use this data for our own purposes except as necessary to provide the Service.
5.6 Technical and Device Data
Our servers and client-side tracking automatically collect:
- IP address (both for user and request origin)
- Browser type and version
- Operating system and version
- Device type (desktop, mobile, tablet)
- Device identifiers (user agent string, device fingerprint components)
- Referring URL (the website that directed you to us)
- Pages visited and time spent on each page
- Clicks and interactions on our platform
- HTTP request headers
- Cookies and similar tracking identifiers
This data is collected via server logs and client-side tracking mechanisms described in Section 8 (Cookies and Tracking Technologies).
5.7 Cookie and Tracking Pixel Data
We and our third-party partners collect information through cookies, web beacons, pixel tags, and similar technologies:
- Session identifiers (used to maintain your login session)
- User preference data (language, timezone, notification settings)
- Analytics identifiers (Google Analytics cookies)
- Marketing identifiers (Meta Pixel identifiers, TikTok Pixel identifiers)
- Hashed email addresses and identifiers (used for cross-platform advertising, when you have consented)
- Advertising conversion data (whether you complete actions the advertiser wants to measure)
- Campaign attribution data (which marketing channel led to your acquisition)
See Section 8 for detailed information about cookies and tracking technologies.
5.8 Communication Data
When you contact us or communicate with our support team, we collect:
- Email message content (if you email support@caterway.io)
- Support ticket information (details about your issue or question)
- Chat logs (if you use in-app chat support)
- Feedback and survey responses (when you voluntarily provide product feedback)
- Communication preferences (how you prefer to be contacted)
We retain this data to resolve your issues, improve our Service, and maintain records of customer interactions.
6. Legal Bases for Processing
Under GDPR Article 6, we Process personal data only when we have a lawful basis. Below, we detail each processing activity and its corresponding legal basis:
6.1 Contractual Necessity (GDPR Article 6(1)(b))
We Process personal data because it is necessary to enter into or perform a contract with you:
- Account creation and authentication: Your name, email, and password hash are necessary to create your account and grant you access to the Service.
- Service delivery: We Process service usage data, quote data, menu preferences, and calculator inputs as necessary to provide the catering management features you request.
- Billing and payment: Your billing address, billing email, and transaction history are necessary to establish and maintain your subscription and send invoices.
- Service support: Your account information is necessary to respond to your support requests and troubleshoot issues.
- End-customer data Processing (as Processor): We Process end-customer data because the catering firm (Controller) contractually instructs us to do so under the DPA and our Service Agreement.
6.2 Consent (GDPR Article 6(1)(a))
We Process personal data on the basis of your freely given, specific, informed, and unambiguous consent:
- Marketing communications: We send newsletters, product announcements, and promotional emails only to users who have affirmatively opted in to receive marketing communications. We obtain this consent separately from account creation.
- Marketing cookies: We deploy Meta Pixel, TikTok Pixel, and Google Analytics only after receiving your cookie consent. We use a consent management platform (CMP) that does not pre-tick consent boxes; all cookie consent is truly opt-in.
- Retargeting and cross-platform advertising: We use hashed identifiers and conversion pixels for retargeting only with your prior consent.
- Non-essential cookies: Any cookie beyond strictly necessary session cookies is deployed only with consent.
- Waiting list subscription: If you sign up for our waiting list, you consent to receive communications about the launch of our Service.
Consent is freely withdrawable at any time by contacting support@caterway.io or using the unsubscribe mechanisms in our emails or cookie consent panel.
6.3 Legitimate Interests (GDPR Article 6(1)(f))
We Process personal data where necessary for legitimate interests pursued by us or third parties, provided such interests do not override your fundamental rights:
- Fraud prevention and security: We analyze usage patterns, IP addresses, and user behavior to identify and prevent fraudulent account activity, unauthorized access, and abuse of our Service. This is necessary to protect the integrity of our platform and the security of all users' data.
- Service improvement and optimization: We use analytics data (IP addresses, feature usage logs, error logs) to identify technical issues, optimize platform performance, fix bugs, and develop new features. This benefits all users.
- Compliance and record-keeping: We retain billing records, transaction history, and account activity logs to comply with legal obligations under the Finnish Accounting Act and to defend against potential disputes.
- Website security and monitoring: We monitor server logs and user activity to identify security threats, detect intrusions, and prevent Denial-of-Service attacks.
- Platform administration: We use access logs to manage user accounts, enforce our Terms of Service, and investigate potential violations.
- Business intelligence: We analyze aggregated and anonymized usage patterns to understand which features are valuable, identify market trends, and guide product development. (This data is anonymized and cannot be linked back to individuals.)
For each legitimate interest Processing, we have conducted and continue to conduct a balancing test to ensure that our interests do not override your rights and freedoms.
6.4 Legal Obligation (GDPR Article 6(1)(c))
We Process personal data because it is necessary to comply with legal obligations to which we are subject:
- Finnish Accounting Act compliance: We maintain financial records, transaction details, and billing information for a period of 10 years as required by Finnish law (Kirjanpitolaki 1620/2015). These records must be retained even after a customer account is closed.
- Tax reporting: We Process billing information necessary to file accurate tax returns with Finnish tax authorities.
- Data Breach notification: We Process personal data as necessary to notify Data Subjects and authorities of Data Breaches as required by GDPR Article 33.
- Law enforcement requests: We may Process personal data to respond to lawful requests from law enforcement, judicial proceedings, or government authorities.
7. Special Category Data (Health and Dietary Data)
Dietary requirements, allergies, and medical restrictions constitute special categories of personal data under GDPR Article 9 because they relate to health.
7.1 Health Data in End-Customer Datasets
When catering firms upload guest information including dietary requirements and allergy information, this data qualifies as health data. The catering firm (as Data Controller) is responsible for obtaining any necessary explicit consent from guests before uploading this data to Caterway. We recommend that catering firms include a privacy notice in their event invitations informing guests that their dietary and allergy information will be shared with the catering service provider.
Baboon Marketing processes this data as a Processor on behalf of the catering firm, following their documented instructions and the Data Processing Agreement. We implement enhanced security measures and access controls for this health data.
7.2 Our Processing of Health Data
We do not use health data for profiling, analytics, or marketing. Health data is processed only for:
- Service delivery: Enabling the catering firm to view, organize, and manage dietary information for event planning.
- Fulfillment of event catering: Helping the catering firm prepare appropriate meal options and accommodations.
- Compliance: Retaining records as instructed by the catering firm and our legal obligations.
7.3 Legal Basis
The legal basis for our Processing of health data is:
- Explicit consent of the Data Subject (Article 9(2)(a)): The guest has explicitly consented to the processing of their health data by the catering firm. The catering firm, as Controller, ensures this consent is obtained.
- Contract necessity (Article 9(2)(b)): Processing is necessary for the performance of obligations and exercise of rights under employment law, social security law, or labor law (in the context of catering event staffing).
- Public task (Article 9(2)(e)): If the event is a public event, official function, or charitable function where the lawful basis for Processing is a public task.
8. Cookies and Tracking Technologies
Caterway uses cookies, pixel tags, web beacons, and similar technologies to enhance the user experience, measure performance, and deliver targeted advertising. This section provides detailed information about our use of these technologies.
8.1 What Are Cookies and Tracking Technologies?
Cookies are small text files stored on your device by your web browser that contain information about your visit to a website. When you return, the website can read the cookie to remember your preferences or activities.
Pixel tags (also called "web beacons" or "clear GIFs") are tiny, transparent images embedded in web pages that track whether a page has been viewed or an action taken.
Device identifiers include user agent strings, device fingerprint components, and IP addresses that can be combined to identify or track a user across websites and devices.
8.2 Types of Cookies We Use
8.2.1 Essential/Strictly Necessary Cookies
These cookies are required for the Service to function. They are deployed without prior consent:
- Session cookies: Enable you to navigate the Caterway platform and use its features. Expires when you close your browser.
- Authentication cookies: Maintain your logged-in status and verify your identity across page requests.
- CSRF protection tokens: Prevent cross-site request forgery attacks.
- Security cookies: Detect and prevent fraudulent or unauthorized access.
Essential cookies do not track behavior across third-party websites and serve no marketing purpose.
8.2.2 Analytics Cookies
We use Google Analytics 4 to understand how visitors use our website and Service. Google Analytics cookies collect:
- Pages visited and time spent on each page
- Device type, browser, and operating system
- Approximate geographic location (country/city level)
- Traffic source (how you found us)
- User flows and interactions
Data Processing: Google Analytics is a service provided by Google LLC (USA) and processes data under the EU-US Data Privacy Framework and Standard Contractual Clauses. Google Analytics anonymizes IP addresses within the EEA.
Retention: Google Analytics data is retained for up to 26 months by Google.
Your Control: You can opt out of Google Analytics tracking using:
- Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
- Our cookie consent panel (see section 8.5)
- Your browser's "Do Not Track" setting (where supported)
8.2.3 Marketing and Retargeting Cookies
We use the following third-party pixels for advertising purposes:
Meta Pixel (Facebook Pixel)
- Deployed on behalf of Meta Platforms, Inc. (USA)
- Tracks visits, conversions, and user actions to measure advertising effectiveness
- Enables retargeting to show you Caterway ads on Facebook, Instagram, and partner sites
- Data basis: Consent from you via our CMP
- Data processing: Meta Platforms operates under EU-US Data Privacy Framework and SCCs
TikTok Pixel
- Deployed on behalf of TikTok Inc. (USA/China)
- Tracks conversions and engagement on TikTok
- Enables retargeting on the TikTok platform
- Data basis: Consent from you via our CMP
- Data processing: TikTok operates under its data processing agreements covering international transfers
Google Ads Conversion Tracking
- Deployed on behalf of Google LLC (USA)
- Tracks conversions (signups, purchases, etc.) for performance measurement
- Enables Google Search and Display Network retargeting
- Data basis: Consent from you via our CMP
- Data processing: Google operates under EU-US Data Privacy Framework
8.3 Advanced Matching and Hashed Identifiers
To improve the effectiveness of our advertising and understand which marketing channels acquire valuable customers, we may:
- Hash your email address (one-way encryption) and send the hashed identifier to Meta and Google for matching
- This allows these platforms to match your email to your account on their platform (if you have one)
- The hashing is performed only if you have consented to marketing cookies
- The hashed email is not reversible and does not reveal your actual email address to us or the platforms unless you access the ad while logged into your account
This practice is permitted under GDPR when consent has been obtained and is conducted transparently.
8.4 Third-Party Cookies
Third-party cookies are set by entities other than Caterway (e.g., Meta, Google, TikTok). These cookies:
- Track your activity on Caterway and across the web
- Are used to deliver personalized advertising
- Require your consent before being set
- Can be managed and withdrawn through our consent management platform
8.5 Cookie Consent Mechanism
Our Approach: Caterway implements a Consent Management Platform (CMP) that provides you with granular control over cookies:
- No pre-ticked boxes: All optional cookie categories default to unchecked. You must affirmatively select and confirm to accept non-essential cookies.
- Freely given: You are not required to accept marketing cookies to use our Service. Refusing non-essential cookies does not restrict your access to essential platform features.
- Specific: You can accept or reject different categories of cookies separately (analytics, marketing, etc.).
- Informed: Our cookie banner and cookie policy provide clear information about each category.
- Unambiguous: Acceptance is explicit and documented.
- Easily withdrawable: You can withdraw consent at any time via the cookie consent panel.
Cookie Banner: When you first visit Caterway, a cookie banner appears allowing you to:
- Accept All: Accept all optional cookies
- Reject All: Reject all optional cookies except essential ones
- Manage: Access detailed settings to accept/reject specific cookie categories
Withdrawal of Consent: You can withdraw cookie consent at any time by:
- Returning to the cookie consent panel at the bottom of our website
- Clicking your user preferences in your account dashboard
- Deleting cookies from your browser
- Using your browser's "Do Not Track" settings (if supported)
If you withdraw consent for marketing cookies, we will cease deploying new pixels and will instruct Meta, Google, and TikTok to stop tracking you.
8.6 Browser-Level Cookie Management
Most web browsers allow you to control cookies:
- Chrome: Settings > Privacy and Security > Cookies and other site data
- Firefox: Preferences > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Privacy, search, and services > Clear browsing data
Deleting cookies may affect your ability to use Caterway and may require you to re-authenticate upon your next visit.
8.7 Do Not Track (DNT) Signals
Some browsers include a "Do Not Track" feature. Caterway respects DNT signals:
- If your browser sends a DNT signal, we do not deploy non-essential marketing cookies
- Essential cookies remain active to maintain Service functionality
- DNT does not affect our use of cookies for fraud prevention or security
9. How We Use Your Data
Baboon Marketing uses personal data for the following purposes:
9.1 Service Provision and Account Management
- Creating and maintaining your user account
- Authenticating your identity and managing sessions
- Providing access to the Service features you have subscribed to (quote management, menu management, calculator tools)
- Storing your preferences, settings, and profile information
- Sending transactional emails (account confirmations, password resets, billing notifications)
- Providing customer support and responding to your inquiries
9.2 Quote and Event Facilitation
- Processing quotes you create and storing them in your account
- Managing menu selections and customizations you make
- Running calculations through our calculator tools
- Tracking event details, attendee counts, and special requests
- Generating reports and analytics specific to your quotes and events
9.3 Menu Management
- Storing and organizing menu items, categories, and prices you create or customize
- Enabling you to create menu templates and reuse them across events
- Tracking which menus you have used and how frequently
9.4 Marketing and Communications
With Your Consent:
- Sending newsletters featuring product updates, case studies, and catering industry insights
- Announcing new features and service improvements
- Promoting special offers or pricing tiers
- Conducting email surveys and requesting feedback
- Using retargeting ads to show you Caterway promotions on third-party platforms (Meta, Google, TikTok)
You may opt out of marketing communications at any time by clicking "Unsubscribe" in any promotional email or adjusting your preferences in your account settings.
9.5 Service Analytics and Improvement
- Analyzing feature usage to identify which features provide the most value
- Tracking error logs to identify and fix technical issues
- Measuring page load times and performance metrics to optimize the Service
- Conducting A/B testing of new features and interface designs
- Understanding user workflows to improve the user experience
- Using aggregated and anonymized data to guide product development
9.6 Fraud Prevention and Security
- Monitoring for suspicious login attempts and unauthorized account access
- Analyzing usage patterns to detect anomalous behavior indicating fraud or abuse
- Implementing technical controls (IP whitelisting, rate limiting, etc.) to prevent attacks
- Investigating and responding to Data Breaches
- Maintaining audit logs for security and compliance purposes
9.7 Legal Compliance and Record-Keeping
- Maintaining financial records and transaction history as required by the Finnish Accounting Act (10-year retention)
- Preparing and filing tax returns with Finnish tax authorities
- Responding to lawful requests from law enforcement or government agencies
- Defending against legal claims or disputes
- Complying with data protection, employment, and industry-specific regulations
9.8 Customer Service and Support
- Responding to your support requests and technical issues
- Providing product documentation, tutorials, and assistance
- Following up on feedback or complaints
- Keeping records of customer interactions to improve support quality
9.9 Business Operations
- Generating anonymous, aggregated reports about Service usage and user demographics
- Understanding customer acquisition costs and retention metrics
- Planning infrastructure capacity and scalability
- Conducting business analysis and strategic planning
10. Data Sharing and Recipients
Baboon Marketing shares personal data with the following categories of recipients:
10.1 Payment Processing
Stripe, Inc. (USA)
- What data: Billing address, billing email, credit card metadata (last 4 digits, expiration date, brand), transaction amounts and dates, subscription details
- Why: To process payments, manage recurring billing, issue receipts, and prevent payment fraud
- Legal basis: Contractual necessity (Stripe processes payment data as a Processor under our Data Processing Agreement)
- Data agreement: Stripe operates under its Data Processing Agreement and EU-US Data Privacy Framework
- Retention: Stripe retains payment data in accordance with PCI-DSS standards and payment processing requirements
Baboon Marketing does NOT receive or store full credit card numbers. Stripe tokenizes payment cards, and we interact only with the token, not the underlying card data.
10.2 Analytics and Performance Measurement
Google LLC (USA)
- What data: IP address (anonymized), device information, browser type, pages visited, time on page, referrer URL, user interactions, conversion events (signups, plans purchased)
- Why: To measure website traffic, user behavior, and marketing campaign effectiveness
- Legal basis: Consent (you must have consented to analytics cookies)
- Data agreement: Google processes analytics data under EU-US Data Privacy Framework and Standard Contractual Clauses
- Retention: Google Analytics retains data for up to 26 months
10.3 Advertising and Retargeting
Meta Platforms, Inc. (USA)
- What data: Hashed email address, IP address, device identifiers, page visits, conversion events (signup, plan purchase), user actions on Caterway
- Why: To measure the effectiveness of Meta advertising, identify new customers, and show targeted ads on Facebook and Instagram
- Legal basis: Consent (you must have consented to marketing cookies)
- Data agreement: Meta processes data under EU-US Data Privacy Framework and Standard Contractual Clauses
- Retention: Meta retains data in accordance with its privacy policy and applicable law
TikTok Inc. (USA/China)
- What data: Hashed email address, IP address, device identifiers, conversion events
- Why: To measure the effectiveness of TikTok advertising and show targeted ads on the TikTok platform
- Legal basis: Consent (you must have consented to marketing cookies)
- Data agreement: TikTok processes data under its data processing agreements
- Retention: TikTok retains data according to its privacy policy and applicable regulations
Google Ads (Google LLC, USA)
- What data: Hashed email address, conversion events, user interactions, device information
- Why: To show targeted ads in Google Search and Google Display Network
- Legal basis: Consent (you must have consented to marketing cookies)
- Data agreement: Google processes data under EU-US Data Privacy Framework
10.4 Infrastructure and Hosting
Supabase (Hosted on EEA Servers)
- What data: All personal data you provide to Caterway is stored on Supabase infrastructure
- Why: To securely store and retrieve data on our backend infrastructure
- Legal basis: Contractual necessity (Supabase is our essential service provider)
- Data agreement: Supabase operates as a Data Processor under our Data Processing Agreement. Supabase infrastructure is hosted on EEA servers, ensuring data remains within the European Economic Area.
- Subprocessors: Supabase may use additional subprocessors for infrastructure (Amazon Web Services, Google Cloud) as detailed in their subprocessor list
10.5 Professional Advisors
We may share personal data with the following categories of professional advisors when legally necessary or to pursue legitimate business interests:
Legal Counsel
- To obtain legal advice regarding data protection compliance, privacy litigation, or regulatory matters
- Data shared: Account information, transaction records, communication logs (as relevant to the legal matter)
- Basis: Legitimate interest (defending legal rights) and legal obligation
Accounting and Tax Advisors
- To prepare financial statements, tax returns, and audit information
- Data shared: Transaction history, billing information, customer contact information
- Basis: Legal obligation (Finnish Accounting Act and tax law)
Auditors
- To conduct financial and compliance audits
- Data shared: Financial records, transaction logs, account information
- Basis: Legal obligation
These advisors are bound by confidentiality obligations and process data only as necessary for their specific purposes.
10.6 Law Enforcement and Government Authorities
We may disclose personal data to law enforcement, judicial bodies, regulatory authorities, and government agencies when:
- Required by law or legal process (court order, subpoena, warrant)
- Necessary to enforce our Terms of Service
- Necessary to protect the safety, security, or rights of Caterway, our users, or the public
- Required for tax compliance or other statutory obligations
We will attempt to provide advance notice to affected users unless prohibited by law. We maintain logs of law enforcement requests to ensure we disclose only the minimum necessary information.
10.7 Other Users (Catering Firms and Their Teams)
Within the Caterway platform, some information is shared with other users:
- If you are part of a catering firm's account (team member), other team members of that firm may view your name, email, and role within the account
- Event data created by one catering firm is visible only to that firm and team members with access to that event
- We do not share your data between different catering firm customers unless you explicitly request it
10.8 Business Partners and Service Integrations
We may integrate with third-party services in the future. Any future integrations will:
- Be disclosed in this Privacy Policy update
- Require your explicit consent before sharing data
- Be governed by a Data Processing Agreement ensuring adequate protection
Currently, Caterway does not have third-party integrations beyond those listed above.
10.9 Business Transactions
If Baboon Marketing is involved in a merger, acquisition, bankruptcy, asset sale, or other business transaction:
- Your personal data may be transferred as part of that transaction
- We will provide advance notice and the opportunity to opt out if the new entity's data practices materially differ from this Policy
- The acquiring entity must maintain at least the same level of data protection
10.10 Explicit Statement on Data Sales
Baboon Marketing does NOT sell personal data to third parties. We do not rent, trade, or sell user information. The data sharing described above is limited to:
- Service providers who process data on our behalf under Data Processing Agreements
- Legally required disclosures
- Business transfers where data protection is maintained
11. International Data Transfers
Baboon Marketing is a Finnish company, and our primary infrastructure is located within the European Economic Area (EEA). However, we use service providers located outside the EEA. This section explains how we ensure the protection of your data in international transfers.
11.1 Data Storage Location
Primary infrastructure: Caterway data is stored on Supabase servers located within the EEA (European Economic Area). Data remains encrypted and within EEA jurisdictions to provide enhanced protection under GDPR.
CDN and Content Delivery: Some static content (images, stylesheets, scripts) may be cached on global Content Delivery Networks (CDNs) for faster delivery. These cached assets do not contain personal data.
11.2 Transfers to the United States
Some of our service providers are located in the United States:
Google Analytics, Google Ads, Meta Pixel, Stripe
For these transfers, we rely on the following mechanisms:
11.2.1 EU-US Data Privacy Framework (DPF)
Google LLC, Meta Platforms, and Stripe, Inc. are certified under the EU-US Data Privacy Framework, which the European Commission has decided provides an adequate level of protection for personal data transferred from the EU/EEA to the United States.
What this means: These companies have committed to:
- Processing personal data in accordance with GDPR principles
- Providing equivalent privacy protections to those required in the EU
- Submitting to oversight by the U.S. Department of Commerce and Federal Trade Commission
- Complying with annual recertification requirements
11.2.2 Standard Contractual Clauses (SCCs)
We have also executed Standard Contractual Clauses (as approved by the European Commission under Commission Decision 2021/914) with our service providers. These clauses:
- Legally bind our service providers to GDPR compliance even if they are located outside the EEA
- Provide contractual remedies and enforcement mechanisms if data protection is breached
- Are recognized by European Data Protection Authorities as a valid transfer mechanism
11.2.3 Supplementary Measures
In addition to DPF and SCCs, we implement supplementary technical and organizational measures:
- Encryption in transit: All transfers use TLS 1.2 or higher encryption
- Encryption at rest: Data stored by U.S. service providers is encrypted using AES-256 or equivalent
- Access controls: Service providers limit access to personal data to personnel who need it for specific purposes
- Data minimization: We transfer only the minimum personal data necessary for the service provider to perform its function
11.3 Transfer Impact Assessment
We have conducted Transfer Impact Assessments (supplementary measures assessments) under GDPR Article 46 to evaluate whether U.S. law enforcement could compel disclosure of your personal data. Based on our assessment:
- Legal mechanism: U.S. surveillance laws (FISA, Executive Order 12333) could permit the U.S. government to request data from U.S. service providers
- Safeguards: Service providers certified under the DPF and bound by SCCs have contractually committed to minimize such requests and challenge them where possible
- Our mitigation: We encrypt data, limit data transfers to the minimum necessary, and use service providers with robust privacy commitments
- Your rights: You retain all GDPR rights, including the right to restrict processing and object to international transfers
If you are concerned about transfers to the United States, you have the right to:
- Restrict processing of your data by U.S. service providers (which may limit certain Service features)
- Request deletion of your data (subject to legal retention obligations)
- Lodge a complaint with your supervisory authority
11.4 Other Potential Transfers
TikTok processes data in both the USA and potentially China. If you have concerns about data transfers to China or other jurisdictions, you should:
- Withdraw consent for TikTok marketing cookies
- Contact support@caterway.io to discuss your concerns
- Exercise your rights to object or restrict processing
We commit to notifying you if we establish partnerships with service providers in jurisdictions lacking an adequacy decision, and to implementing robust safeguards in such cases.
12. Data Retention
Baboon Marketing retains personal data only as long as necessary for the purposes it was collected, or as required by law. Retention periods vary by data category:
12.1 Account Data
Retention period: For the duration of your active account, plus 2 years after account closure
- This includes your name, email, phone number, company information, account settings, and profile data
- We retain this data for 2 years after closure to respond to potential account recovery requests, investigate disputes, and maintain records
- After 2 years, account data is securely deleted or anonymized
12.2 Financial and Billing Records
Retention period: 10 years from the date of transaction
Under the Finnish Accounting Act (Kirjanpitolaki 1620/2015), we are legally required to maintain accounting records, invoices, receipts, and transaction details for 10 years. This applies regardless of whether your account is active:
- Transaction amounts and dates
- Billing addresses
- Invoice records
- Payment method information (last 4 digits, expiration date, brand)
- Tax-related documents
These records are retained in secure, limited-access systems and are not used for marketing or other purposes during the retention period.
12.3 Service Usage and Analytics Data
Retention period: As follows per data category
- Server logs and IP addresses: 90 days (for security monitoring and fraud detection)
- Feature usage logs and event data: 26 months (for analytics, service improvement, and user behavior analysis, aligned with Google Analytics retention)
- Error logs: 30 days (for debugging and technical issue resolution)
- Aggregated, anonymized analytics: Indefinite (data that cannot be linked to individuals)
12.4 Marketing and Communications Data
Retention period: Until consent is withdrawn, plus 30 days
- Email addresses of newsletter subscribers are retained for as long as you remain subscribed
- Marketing consent records are maintained to demonstrate that consent was obtained
- After you unsubscribe, we retain your email in a suppression list for 30 days to ensure we do not re-contact you
- After 30 days, your email is securely deleted from active marketing systems
12.5 Cookie and Tracking Data
Retention period: According to cookie/pixel provider specifications
- Session cookies: Deleted when you close your browser
- Analytics cookies (Google Analytics): 26 months (configured via Google Analytics settings)
- Marketing cookies (Meta Pixel, TikTok Pixel, Google Ads): 13 months (platform default, can be withdrawn at any time)
- Local storage and browser cache: Persists until you manually clear your browser data
You can delete cookies at any time through your browser settings or our cookie consent panel.
12.6 End-Customer Data (Uploaded by Catering Firms)
Retention period: As instructed by the catering firm (Data Controller)
Guest information, dietary requirements, allergy data, and event details uploaded by catering firms are retained as long as the catering firm requests. The catering firm may delete this data at any time through the Caterway platform. Upon catering firm request or account closure:
- We will securely delete end-customer data within 30 days of request
- Backup copies are retained for disaster recovery purposes and are deleted after 90 days
12.7 Support and Communication Records
Retention period: 3 years
- Email support tickets, chat logs, and customer service interactions are retained for 3 years to resolve disputes, improve support quality, and maintain records of customer issues
- After 3 years, these records are securely deleted unless legal hold or litigation requires retention
12.8 Waiting List Data
Retention period: Until launch announcement or consent withdrawal, plus 30 days
- Email addresses and information from our waiting list are retained while the waiting list is active
- Once we launch the Service, we convert opted-in waiting list members to newsletter subscribers (with their prior consent)
- If you withdraw consent, your data is deleted within 30 days, unless legal obligations require retention
12.9 Data Subject Requests for Deletion
Even if a retention period has not expired, you may request deletion of your data under GDPR Article 17 (right to erasure). We will honor such requests unless:
- The data is necessary to perform the Service contract
- We have a legal obligation to retain the data (e.g., Finnish Accounting Act requires 10-year retention of financial records)
- The data is necessary for fraud prevention, security, or legal defense
- We have a compelling legitimate interest that overrides your rights
12.10 Secure Deletion
When data reaches the end of its retention period, we securely delete it using:
- Cryptographic erasure (rendering encrypted data unrecoverable by destroying encryption keys)
- Physical destruction of storage media
- Data overwriting techniques that make recovery infeasible
Backup systems may retain deleted data for up to 30 days for disaster recovery purposes, after which it is permanently purged.
13. Data Security
Baboon Marketing implements comprehensive technical and organizational measures to protect personal data against unauthorized processing, accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
13.1 Technical Security Measures
13.1.1 Encryption in Transit
- All data transmitted between your device and our servers is encrypted using Transport Layer Security (TLS) 1.2 or higher
- We use strong cipher suites and regularly update encryption protocols to address emerging security threats
- Mixed content (unencrypted assets) is not permitted on our Service
- HTTPS is enforced on all pages; HTTP connections are automatically redirected to HTTPS
13.1.2 Encryption at Rest
- Personal data stored in our databases is encrypted using AES-256 encryption or equivalent
- Encryption keys are stored separately from the encrypted data
- Key management follows industry best practices, including:
- Regular key rotation
- Separation of key management from data storage
- Multi-person authorization requirements for key access
13.1.3 Database Security
- Databases are hosted on Supabase infrastructure, which implements:
- Database firewalls and network segmentation
- Regular security patches and updates
- Automated backups with encryption
- Access controls based on the principle of least privilege
13.1.4 Application Security
- Our application code undergoes security code reviews
- We implement input validation and output encoding to prevent injection attacks
- CSRF tokens protect against cross-site request forgery
- Rate limiting prevents brute-force attacks and password guessing
- Session management employs secure, httpOnly cookies that cannot be accessed by JavaScript
- API authentication uses secure token-based mechanisms (not basic auth)
13.1.5 Network Security
- Our infrastructure is protected by firewalls and intrusion detection systems
- We use Web Application Firewalls (WAF) to detect and block malicious traffic
- DDoS mitigation is employed to protect against distributed denial-of-service attacks
- Network traffic is monitored for anomalous patterns
- We conduct regular vulnerability scanning and penetration testing
13.1.6 Endpoint Security
- Baboon Marketing employees use multi-factor authentication (MFA) for all systems
- All company devices are encrypted and security-hardened
- Automatic screen locks are enforced after periods of inactivity
- Regular security awareness training is provided to all staff
- Removable media is disabled on company devices
13.2 Organizational Security Measures
13.2.1 Access Controls
- Access to personal data is restricted to employees who need it for their job functions
- Access is granted based on the principle of least privilege (minimum necessary permissions)
- Access logs are maintained and regularly reviewed
- Termination of employment includes immediate removal of system access
- Privileged access (database admin, system admin) is logged and monitored
- Shared passwords are not permitted; individual user accounts are used
13.2.2 Personnel Security
- All personnel with access to personal data have signed confidentiality agreements
- Data protection training is provided to all employees during onboarding
- Regular refresher training occurs annually
- Background checks are conducted for employees with access to sensitive data
- Data protection responsibilities are documented in employee contracts
13.2.3 Incident Response
- We maintain a documented Data Breach Response Plan that includes:
- Immediate containment procedures
- Investigation and forensics protocols
- Notification procedures for affected Data Subjects
- Communication with supervisory authorities
- Documentation and record-keeping requirements
- A designated Data Protection Officer (DPO) oversees incident response
- We maintain incident logs tracking all security events
- Testing of incident response procedures is conducted regularly
13.2.4 Third-Party Security
- All Data Processors and Subprocessors are subject to Data Processing Agreements requiring:
- Equivalent or greater security measures
- Compliance with GDPR and applicable data protection laws
- Confidentiality obligations
- Restriction of data use to specified purposes
- Breach notification obligations
- Right to audit compliance
- Assistance with Data Subject rights requests
- Due diligence assessments are conducted before engaging any Processor
- Processors provide annual security certifications or audit reports (SOC 2, ISO 27001, etc.)
13.2.5 Data Protection Impact Assessments (DPIAs)
- We conduct DPIAs for high-risk Processing activities, including:
- Automated decision-making and profiling
- Large-scale systematic Processing
- Processing of special category data
- Processing that could restrict rights and freedoms
- DPIAs are documented and reviewed regularly
- Results are used to implement additional safeguards where necessary
13.2.6 Regular Auditing and Monitoring
- Security logs and access logs are reviewed regularly (at least monthly)
- Automated alerts notify us of suspicious activities
- Annual security audits are conducted by third parties
- Vulnerability assessments are performed quarterly
- We maintain a vulnerability disclosure program to identify security issues
- Internal security testing (penetration testing) occurs annually
- Compliance audits with this Privacy Policy occur annually
13.3 Limitations of Security
While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security of your personal data. Transmission of data over the internet or wireless networks carries inherent risks. You are responsible for:
- Maintaining the confidentiality of your password
- Not sharing your account credentials with others
- Logging out of your account when using shared devices
- Protecting the security of your email account (used for password recovery)
We encourage you to:
- Use strong, unique passwords
- Change your password regularly
- Enable two-factor authentication if available
- Keep your device software and antivirus up to date
- Use secure networks (avoid public WiFi) for sensitive account activities
14. Your Rights Under GDPR
As a Data Subject, you have the following rights under the GDPR and Finnish Data Protection Act. You can exercise these rights by contacting support@caterway.io with your request.
14.1 Right of Access (GDPR Article 15)
You have the right to obtain confirmation of whether we are processing your personal data and, if so, to receive a copy of the personal data we hold about you.
What you can request:
- Whether your personal data is being processed
- The purposes of processing
- The categories of personal data being processed
- The recipients of your data
- How long we retain your data
- Your rights regarding the data
- A copy of all personal data we hold in a structured, commonly used, machine-readable format (data portability)
How to request:
- Email support@caterway.io with the subject "Data Access Request"
- Provide sufficient information to identify you
- Specify which categories of data you want to access
Our response timeline: We will respond within 30 days. If your request is complex or voluminous, we may extend this to 90 days, with advance notice.
Format: We will provide your data in a clear, legible format, and will explain any technical terms.
14.2 Right to Rectification (GDPR Article 16)
You have the right to require us to correct inaccurate personal data and to complete incomplete data.
What you can request:
- Correction of name, email, phone number, company information, or other inaccurate data
- Addition of missing information
- Clarification of data you believe is incorrect
How to request:
- Log in to your Caterway account and update your profile directly (for account data)
- Email support@caterway.io with specific details of inaccuracies if you cannot correct them through the platform
Our response timeline: We will correct accurate information within 30 days.
Note: You may also exercise this right by updating your own account information directly through your Caterway dashboard.
14.3 Right to Erasure (GDPR Article 17)
You have the right to require us to delete your personal data in certain circumstances (also known as the "right to be forgotten").
When you can request erasure:
- The data is no longer necessary for the purposes we collected it
- You withdraw consent on which processing was based (for processing based on consent)
- You object to processing for direct marketing or other purposes, and there are no overriding legitimate interests
- The data has been processed unlawfully
- The data must be deleted to comply with a legal obligation
- The data concerns a child (under 18) and was collected based on consent
When we may refuse erasure:
- The data is necessary to perform the contract with you (e.g., billing records)
- Deletion is required to comply with a legal obligation (Finnish Accounting Act, tax law)
- The data is necessary for fraud prevention, security, or legal defense
- Deletion would impair our legitimate interests in maintaining records
How to request:
- Email support@caterway.io with the subject "Erasure Request"
- Specify which categories of data you want deleted
- Explain the basis for your request (e.g., data is inaccurate, consent withdrawn, no longer necessary)
Our response timeline: We will respond within 30 days. Where erasure is possible, we will delete the data securely.
Note: Deletion is subject to our legal obligations. For example, financial records may not be deleted due to the 10-year Finnish Accounting Act retention requirement.
14.4 Right to Restrict Processing (GDPR Article 18)
You have the right to request that we limit how we use your personal data while you resolve a dispute or exercise other rights.
What you can request:
- Stop processing while you verify accuracy (if you've requested rectification)
- Stop processing while you exercise the right to object
- Stop processing while you appeal an erasure refusal
- Limit processing to storage only while you decide on further action
Effect: While processing is restricted:
- We will not use your data for the stated purpose (e.g., marketing)
- We will store your data but not actively process it
- Essential processing (security, legal compliance) may continue
How to request:
- Email support@caterway.io with the subject "Processing Restriction Request"
- Explain the basis for your request
- Specify which processing activities you want restricted
Our response timeline: We will respond within 30 days.
14.5 Right to Data Portability (GDPR Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
What you can request:
- Your personal data in a portable format (CSV, JSON, XML, etc.)
- Direct transmission to another service provider you specify
Data included:
- Account information (name, email, phone, company details)
- Service usage data (quotes, menus, events, calculations)
- Communication records
- Preference data
Data excluded:
- End-customer data uploaded by your firm (this belongs to your customers)
- Aggregated or anonymized data
How to request:
- Email support@caterway.io with the subject "Data Portability Request"
- Specify the format you prefer for your data
- Indicate whether you want us to transmit directly to another service
Our response timeline: We will provide your data within 30 days in a portable format.
Technical note: We will provide data in standard formats compatible with common applications. If your request involves direct transmission to another service, we will coordinate with that service where possible.
14.6 Right to Object (GDPR Article 21)
You have the right to object to certain types of processing, including direct marketing and processing based on legitimate interests.
Right to object to direct marketing:
- You can object to all marketing emails, retargeting ads, and promotional communications at any time
- Upon receipt of your objection, we will cease all marketing activities targeting you
- This right applies to newsletters, promotional offers, and advertising
How to exercise:
- Click "Unsubscribe" in any marketing email
- Email support@caterway.io with "Opt-out from Marketing" in the subject
- Adjust preferences in your account settings
Right to object to legitimate interest processing:
- You can object to processing of your data for fraud prevention, service improvement, analytics, or other legitimate interests
- If you object, we will cease the processing unless we demonstrate compelling legitimate interests that override your rights
How to exercise:
- Email support@caterway.io with the subject "Objection to Processing"
- Specify which processing activities you object to
- Explain your grounds for objection
Our response: We will respond within 30 days. We will either cease processing or provide a detailed explanation of why we believe our legitimate interests override your rights.
Limitation: You cannot object to processing necessary to perform a contract with you (e.g., processing necessary to provide the Service).
14.7 Rights Related to Automated Decision-Making and Profiling (GDPR Article 22)
You have the right not to be subject to automated decision-making that produces legal effects or significantly affects you, except in specific circumstances.
What this means: We will not make decisions about you (e.g., account approval, pricing, eligibility) using only automated processing, nor will we create detailed profiles for automated decisions.
Current practice: Caterway does not currently employ fully automated decision-making with legal effects. Our analytics and fraud detection involve human review.
If we implement automated decision-making:
- We will provide advance notice
- You will have the right to request human review of any automated decision
- You will have the right to explain your position
- You will have the right to challenge the decision
How to request human review:
- If any automated decision affects you, email support@caterway.io requesting human review
- We will re-evaluate your case with human judgment
14.8 Right to Withdraw Consent (GDPR Article 7)
Where we rely on consent as the legal basis for processing (marketing emails, marketing cookies, tracking pixels), you have the right to withdraw that consent at any time.
How to withdraw consent:
For marketing communications:
- Click "Unsubscribe" in any marketing email
- Email support@caterway.io stating you withdraw marketing consent
- Update your preferences in your account dashboard
For cookies and tracking:
- Use our cookie consent panel on the website (available at the bottom of the page)
- Clear cookies from your browser
- Use browser "Do Not Track" settings
Effect of withdrawal: Upon withdrawal, we will cease the processing for which consent was given. We will not use subsequent data for that purpose. (However, any processing that occurred before withdrawal remains lawful.)
14.9 Right to Lodge a Complaint
You have the right to lodge a complaint with your supervisory authority if you believe we have violated your data protection rights.
Supervisory Authority for Finland:
Office of the Data Protection Ombudsman
(Tietosuojavaltuutetun toimisto)
Address:
Ratapihantie 9
00520 Helsinki
Finland
Website: https://tietosuoja.fi
Email: tietosuoja@om.fi
Phone: +358 9 191 4361
You have the right to lodge a complaint with the Office of the Data Protection Ombudsman at any time. Submitting a complaint will not affect our processing of your data or your relationship with us.
14.10 How to Exercise Your Rights
Contact Information:
- Email: support@caterway.io
- Address: Sรถrnรคisten Rantatie 25 A1, 00500 Helsinki, Finland
- Subject line: Clearly state your request (e.g., "Data Access Request," "Right to Erasure," "Objection to Marketing")
Information to include:
- Your full name
- Your email address associated with your account
- Description of your request
- Specific data categories you're referring to (if applicable)
- Proof of identity (if we cannot otherwise verify your identity)
Our response:
- We will respond within 30 days of receipt
- If your request is complex or voluminous, we will inform you and may extend the deadline to 90 days
- We will respond in the language of your request or English
- We will provide the requested information or explain why we cannot fulfill your request
- We will not charge a fee unless your request is manifestly unfounded or excessive
Verification of identity:
- For security, we may ask you to verify your identity before fulfilling your request
- We will compare your request with information we hold to ensure we're responding to the correct person
- We will not require excessive documentation
Your rights are not affected by:
- Your location (these rights apply to all data subjects)
- Whether you are a paying customer or free tier user
- Your relationship with Baboon Marketing
15. Data Processing Agreement (DPA)
This Privacy Policy applies to individuals whose personal data we collect and process. For business customers (catering firms, event planners) that are themselves Data Controllers, we offer a separate Data Processing Agreement (DPA).
15.1 Applicability
A DPA is required when:
- Your organization uploads personal data of your clients, customers, or employees to Caterway (end-customer data, guest lists, dietary information)
- Your organization is the Data Controller, and Caterway acts as your Processor
- GDPR Article 28 requirements apply to your data processing arrangement
15.2 DPA Availability
A standard Data Processing Agreement is available upon request. The DPA includes:
- Definition of Processor responsibilities and Controller responsibilities
- Scope of Processing (data categories, purposes, subjects, duration)
- Guarantees regarding data security and confidentiality
- Sub-processor management and notification
- Assistance with Data Subject rights
- Assistance with Data Protection Impact Assessments
- Breach notification procedures
- Deletion and return of data upon contract termination
- Audit and compliance verification rights
To request a DPA:
- Email support@caterway.io with the subject "DPA Request"
- Provide your organization name and tax ID
- Indicate your intended use of Caterway (e.g., event management, client tracking)
We will provide a DPA for execution within 10 business days.
15.3 Amendments and Negotiation
Our standard DPA is based on the EU's Standard Contractual Clauses and complies with GDPR Article 28. It can be customized to address specific requirements, such as:
- Additional security requirements
- Specific retention periods
- Audit and compliance verification procedures
- Insurance and indemnification provisions
Contact support@caterway.io to discuss customization options.
16. Subprocessors
A Subprocessor is any third party (other than our direct employees and contractors) that processes personal data on our behalf. This section lists our current Subprocessors and explains how we manage them.
16.1 Current Subprocessors
| Subprocessor | Location | Function | Data Processed |
|---|---|---|---|
| Stripe, Inc. | USA | Payment processing, billing | Payment tokens, billing addresses, transaction history |
| Meta Platforms, Inc. | USA | Advertising, conversion tracking | Hashed email, IP address, conversion events, device info |
| TikTok Inc. | USA/China | Advertising, conversion tracking | Hashed email, IP address, conversion events |
| Google LLC | USA | Analytics, advertising | IP address, device info, pages visited, conversion events |
| Supabase (Infrastructure) | EEA | Database hosting, storage, infrastructure | All personal data stored in Caterway |
| Amazon Web Services (AWS) | USA/EEA | Cloud infrastructure (used by Supabase) | Data hosted by Supabase |
| Google Cloud (Infrastructure) | USA/EEA | Cloud infrastructure (used by Supabase) | Data hosted by Supabase |
16.2 Subprocessor Management
Vetting:
- Before engaging any Subprocessor, we conduct a security assessment evaluating:
- Data protection compliance and certifications (SOC 2, ISO 27001)
- Security infrastructure and controls
- Financial stability and company history
- Incident response capabilities
- Audit rights and transparency
- Subprocessor restrictions in their own contracts
Data Processing Agreements:
- All Subprocessors are subject to Data Processing Agreements (or equivalent contractual arrangements) that require:
- Compliance with GDPR and data protection laws
- Processing only on our documented instructions
- Confidentiality of personal data
- Implementation of appropriate technical and organizational security measures
- Restriction of their own subprocessors
- Assistance with Data Subject rights requests
- Breach notification to us within 24 hours
Ongoing Monitoring:
- We annually review Subprocessor compliance with their contractual obligations
- We require Subprocessors to provide security certifications or audit reports (SOC 2, ISO 27001)
- We maintain updated documentation of Subprocessor security practices
- We conduct security audits of critical Subprocessors every 2-3 years
16.3 Changes to Subprocessors
Notification:
- We maintain an updated list of Subprocessors on our website
- If we add or replace a Subprocessor, we will provide at least 30 days' advance notice to our customers
- For business customers with a DPA, the DPA includes specific notice and objection procedures
Objection Rights:
- Business customers have the right to object to the use of a new Subprocessor within 30 days of notice
- If you object, we will:
- Discuss your concerns with the potential Subprocessor
- Assess the impact on the Service
- Work toward resolution before implementation
- If necessary, provide an alternative solution
Processor Changes:
- Material changes to Subprocessor security, data location, or processing scope will trigger re-assessment
- We will maintain transparency about Subprocessor relationships and functions
16.4 Subprocessor Subcontracting
Some Subprocessors (particularly cloud infrastructure providers like Supabase, AWS, Google Cloud) may engage their own subprocessors. Examples include:
- Supabase may use AWS or Google Cloud for infrastructure
- Cloud providers may use backup and disaster recovery services
- Content delivery networks may be used to cache content
For these indirect subprocessors:
- Contractual terms require that subprocessors meet the same data protection standards
- We maintain documentation of the subprocessor chain
- You can contact us at support@caterway.io for the complete subprocessor list
17. Children's Privacy
Caterway is not directed at children under the age of 18, and we do not knowingly collect personal data from children.
17.1 Age Restriction
The Service is intended for professional use by catering firms, event planners, caterers, and business users. Our Terms of Service require that users be at least 18 years old.
17.2 Children's Data
We do not:
- Knowingly collect personal data from children under 18
- Market the Service to children
- Use profiling or tracking that targets children
- Retain contact information from children
17.3 Children in End-Customer Data
Catering firms may upload guest lists that include minors (children attending events). In such cases:
- The catering firm (as Data Controller) is responsible for obtaining parental consent
- We process such data only as instructed by the catering firm
- We do not profile, market to, or retain data about child event attendees beyond the event management purpose
- The catering firm must provide privacy notices to parents/guardians as required by law
17.4 Parental Concerns
If a parent, guardian, or child believes we have collected data from a minor without consent, please contact us immediately at support@caterway.io. We will:
- Investigate the situation
- Delete data if necessary
- Work with parents/guardians to resolve concerns
18. Changes to This Privacy Policy
Baboon Marketing may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
18.1 How We Notify You
For material changes (changes affecting your rights or significantly altering our practices):
- We will email you at the email address associated with your account
- Email will be sent at least 30 days before the change takes effect
- We will explain the nature of the change and your rights
- You will have the opportunity to review the updated policy before it takes effect
For non-material changes (clarifications, minor updates, formatting):
- We will update the policy without advance notice
- The "Last Updated" date at the top of this document will change
- We encourage you to review this policy periodically
18.2 Your Rights Upon Changes
If you do not agree with changes to this Privacy Policy, you have the right to:
- Stop using the Service
- Close your account
- Delete your data (subject to our legal retention obligations)
- Request that we cease certain processing activities
We will not charge you for account closure due to policy changes.
18.3 Policy Version History
You can request a copy of previous versions of this Privacy Policy by emailing support@caterway.io.
19. Contact Information
19.1 Baboon Marketing Contact Details
For questions, concerns, or requests related to this Privacy Policy or your personal data:
Email: support@caterway.io
Mailing Address:
Baboon Marketing
Sรถrnรคisten Rantatie 25 A1
00500 Helsinki
Finland
Business ID (Y-tunnus): 3125660-7
Response Time: We will respond to all inquiries within 10 business days. For formal data subject rights requests, our response time is 30 days (extendable to 90 days for complex requests).
19.2 Data Protection Officer (DPO)
While we do not currently have a dedicated, standalone DPO role, our management team oversees data protection compliance. For data protection questions, contact support@caterway.io and mark your email "For the attention of: Data Protection Officer."
20. Supervisory Authority
If you have concerns about our data protection practices or wish to lodge a formal complaint, you have the right to contact your supervisory authority.
20.1 Office of the Data Protection Ombudsman (Finland)
Name: Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman)
Address:
Ratapihantie 9
00520 Helsinki
Finland
Contact Information:
- Website: https://tietosuoja.fi
- Email: tietosuoja@om.fi
- Phone: +358 9 191 4361
- Language: Finnish, Swedish, English
Jurisdiction: The Office of the Data Protection Ombudsman is responsible for monitoring compliance with data protection law in Finland and investigating complaints from Data Subjects.
How to Lodge a Complaint:
- Visit https://tietosuoja.fi and use their complaint form
- Email a description of your complaint to tietosuoja@om.fi
- Mail a written complaint to the address above
- Call to discuss your complaint
What to include in your complaint:
- Your name and contact information
- Description of what we did that you believe violated your rights
- Dates or timeframe of the activity
- Any relevant documents or correspondence
- What outcome you are requesting
Timing: You can lodge a complaint at any time. There is no time limit for submitting a complaint, though the Ombudsman may prioritize more recent complaints.
Your rights are not affected by filing a complaint: Filing a complaint will not negatively impact your account or our services to you.
20.2 Other Supervisory Authorities
If you are located outside Finland, you may have rights to contact the supervisory authority in your own country or the EU/EEA country where the infringement occurred:
- EU residents can contact their national supervisory authority
- A list of all EU supervisory authorities is available at https://edpb.ec.europa.eu/about-edpb/board/members_en
21. Effective Date and Final Notice
This Privacy Policy is effective as of February 27, 2026.
By accessing and using the Caterway Service, you acknowledge that you have read this Privacy Policy and understand our data protection practices. If you do not agree with this Policy, please discontinue use of the Service and contact us to request account closure.
Questions? We're happy to help. Contact support@caterway.io with any questions or concerns about this Privacy Policy, our data protection practices, or your personal data.
Baboon Marketing
Helsinki, Finland
February 27, 2026