Privacy notice
What we collect, where it is stored, who else touches it, and how you get it back. Written to be read rather than to be defensible.
1. Who we are
Sellex provides restaurant management software. Our registered entity, its commercial registration number and its address are named in your subscription agreement, and are shown here once the entity is registered: not yet published — ask us on the call and we will tell you exactly where we are with it
For anything in this notice, write to sales@sellexapp.com and a person — not a ticket queue — will answer.
2. Two different kinds of data
It matters which one is being discussed, because our role differs:
- Your enquiry. If you use the contact form, your name, company, branch count, phone number, email and message reach us as an email you send from your own mail app. Nothing is transmitted to us until you press send there — the website has no server that receives it. We use it to answer you and to keep a record of the conversation, and nothing else. No advertising, no list sales, no profiling.
- Your business data, if you become a customer. Your menu, sales, stock, staff records and your customers' names and phone numbers. This is yours. We process it only to run the service for you and to support you when you ask. We do not mine it, we do not aggregate it across customers, and we do not sell or share it with anyone for their own purposes — including any delivery marketplace.
3. What the website itself does
This site loads nothing from any third party — no analytics, no advertising pixels, no font or script CDN, no embedded video, no cookie banner because there is nothing to consent to. It stores exactly two things in your browser, both local to your device and never sent anywhere: your language choice, and which enquiry type you clicked. That is the whole list.
4. Where your data actually lives
Being specific, because vague answers here are worthless:
- The application runs on Google Cloud Run in Belgium (region
europe-west1). - Your database is a dedicated PostgreSQL database of your own, hosted by Neon in Frankfurt, Germany (
aws-eu-central-1). One database per customer — your rows are never in a table alongside another restaurant's. - Backups are held in the same region.
So: today your data is stored in the European Union, not in the Kingdom. If your own policy, your legal advice or your sector requires data residency inside Saudi Arabia, say so at the first call. Moving a tenant to a Saudi or Gulf region is a deployment decision rather than a rewrite — but it is not what happens by default today, and you should decide with that on the table rather than discover it during an audit.
5. Who else processes it
The complete list of sub-processors. Each is used for the stated purpose only:
| Processor | What for | Where |
|---|---|---|
| Google Cloud | Running the application and storing backups | Belgium (EU) |
| Neon | Your dedicated database | Germany (EU) |
| Cloudflare | Serving this marketing website and DNS | Global edge |
| Meta (WhatsApp Business) | Only if you switch on WhatsApp receipts — then the customer's phone number and receipt total go to Meta to deliver the message | Per Meta's terms |
| Your payment gateway, tax authority or delivery marketplace | Only where you connect one yourself, and only the data that integration needs | Per that provider |
We will tell you before adding a sub-processor that touches customer data, and you may object.
6. Getting your data out, and having it deleted
- Export any time. Every list and report in the product exports as CSV, and the full database is exportable on request in an open format at no charge. You do not need our permission or our continued goodwill to leave.
- On cancellation we keep your data for 30 days so you can change your mind, then delete it — including backups — within a further 60 days. Ask and we will delete it sooner, or send you a final export first.
- Enquiry emails are deleted after two years if you do not become a customer.
7. Your rights
Under Saudi Arabia's Personal Data Protection Law, and the GDPR where it applies to the EU hosting above, you and the individuals whose data you hold can ask for access, correction, deletion, or a copy in a portable format. Where you are our customer, those requests usually come to you first — you are the controller of your own customers' and staff data and we act on your instructions. Send anything you cannot handle yourself to the address above and we will help within 30 days.
8. Security, plainly
Traffic is encrypted in transit; databases are encrypted at rest by the host; passwords and cashier PINs are stored only as hashes and cannot be read back by us or anyone else; access to production is limited to the people who operate the service. We are a small company and will not pretend to hold certifications we do not have — we hold none today. If you need a security questionnaire completed before signing, send it and we will answer it honestly, including where the answer is "no".
9. Changes
If this notice changes in a way that affects you materially — a new sub-processor, a new location, a new purpose — we will email you before it takes effect, not quietly update the date at the top.