This Policy explains how NetMenu, the digital menu by MDC Software, handles personal data. It speaks to two different people: the Establishment that subscribes to the service and builds its menu, and the Diner who opens that menu on a phone, usually by scanning a QR code. What we process, and in which role, differs between the two — and that is what this Policy makes clear.
This is a courtesy translation. The Portuguese (Brazil) version of this document is the binding text; if the two differ, the Portuguese version prevails.
For the Establishment's account and subscription data — registration, billing, support — MDC is the controller: we decide why and how it is processed.
For menu data and Diners' browsing of that menu, the Establishment is the controller and MDC is the processor. It is the Establishment that decides to publish the menu and to follow its reports; we process that data on its instructions and in accordance with the law.
In practice: if you are a Diner and wish to exercise rights over data tied to a particular menu, contact the Establishment behind that menu. We can help, but the decision is theirs. For MDC account data, contact us directly.
On sign-up and while using the Console we collect: the name and email of whoever creates and accesses the account, company details, the data needed to bill the chosen Plan, and access logs (date, time and IP address), which Brazilian law requires us to keep.
We also hold the content the Establishment registers — products, prices, photos, ingredients — which as a rule is not personal data, but may contain the business's own contact details.
Opening a menu requires no account, and no name, phone number or email. We do not ask the Diner to identify themselves.
We record menu usage events to produce the Establishment's reports: which menus and products were opened, when, and technical details of the visit such as device type, language and IP address. The IP address is used for security and for an approximate sense of where a visit came from; we do not use it to identify people.
These reports are presented to the Establishment in aggregate. We do not build an individual profile of the Diner, nor combine this data with other sources to identify them.
When the Establishment enables ordering from the menu, the order data passes to the back-office system it has contracted (today Pagalee) and is then handled under that system's policy and the Establishment's.
To provide the service: publish the menu, run the Console, authenticate access and offer support.
To produce the usage reports the Establishment has subscribed to.
To bill paid Plans and meet tax and accounting obligations.
To keep the platform secure and prevent fraud and abuse.
To improve the service, using aggregate data that identifies no one.
We do not sell personal data and do not use it for third-party advertising.
We process personal data on the basis of performance of the contract (providing the service to the Establishment), compliance with a legal obligation (retention of access logs and tax obligations), and legitimate interests (platform security and aggregate menu usage reports), always weighing the impact on the data subject.
Where processing depends on consent, it will be requested prominently and may be withdrawn at any time.
Part of our infrastructure sits outside Brazil, as indicated above. For those transfers we apply the safeguards required by the LGPD, including contractual clauses with the suppliers.
We keep data for as long as the account is active and for as long as the purposes in this Policy require.
Access logs are kept for the period set by the Brazilian Internet Civil Framework (Law 12.965/2014).
Once the account is closed, we delete or anonymise the data within internally defined periods, save for retention required by law or to exercise rights in legal proceedings. [RETENTION: specific periods to be settled with legal before publication.]
The LGPD gives you the right to confirmation that processing exists, access, correction of incomplete or outdated data, anonymisation or deletion of unnecessary data, portability, information about sharing, and withdrawal of consent where consent is the legal basis.
To exercise these rights, write to dpo@mdc.com.br. We will respond within the statutory periods. If the request concerns data tied to a particular menu, we may forward it to the Establishment responsible, and will tell you that we have.
We apply technical and administrative measures to protect the data, including encryption in transit, role-based access control, isolation of each Establishment's data, and logging of administrative activity.
Access to the Console is protected by a password and by the supported authentication providers. Keeping that password confidential is the responsibility of whoever holds it.
No system is immune to incidents. Should an incident occur with material risk, we will notify the data subjects and the ANPD as the law requires.
NetMenu is not directed at children. A menu is public and may be opened by anyone, but we do not deliberately collect children's data and require no identification to consult it.
We may update this Policy. The version in force is always the one published on this page, with the update date at the end. Material changes will be communicated through the Establishment's contact channels.
MDC Software's Data Protection Officer (DPO) can be reached at: dpo@mdc.com.br.
For other legal matters, write to juridico@mdc.com.br.
Last updated: September 7, 2026.