Nomli (operated by AALA Solutions) provides restaurant operations software: point-of-sale terminals, online ordering surfaces, billing, and back-office reporting. This policy explains what personal data we collect, why we collect it, and the rights you have over it.
1. Who is the controller?
For data we collect to operate Nomli itself (the marketing site, sales pipeline, and the staff admin panel), the controller is AALA Solutions, contact privacy@nomli.co.
For data captured by a restaurant's ordering / POS surface (diner orders, customer accounts at that restaurant), the restaurant is the controller and Nomli is the processor. Each restaurant has its own privacy notice.
2. What we collect
- Marketing & sales: name, work email, restaurant name, country, phone, current POS, monthly orders estimate, and the free-form message you submit via our contact / demo forms.
- Tenant accounts: owner / staff name, work email, role, authentication metadata (last login, MFA enrollment status).
- Billing: contract details, invoice records, payment references, bank statement entries the operator uploads for reconciliation.
- Site analytics: page-view and interaction counts via Google Analytics 4, which sets cookies and assigns a pseudonymous identifier to your browser. We do not send it your name, email, phone number, or any other directly identifying field.
- Operational logs: request traces with redacted secrets and PII patterns (per our error-logger redact list) for at most 30 days, retained for security and debugging.
3. Why we collect it
- To respond to sales enquiries and provision tenants (legitimate interest, contract).
- To operate the platform: authentication, billing, audit logs (contract).
- To meet legal obligations: tax records, AML for high-value invoices.
- To improve the product: aggregated, non-identifying analytics.
4. Sub-processors
We rely on the following sub-processors. Where applicable, EU-only routing is offered for tenants that request it.
- Hetzner, primary hosting and encrypted database backups (EU regions).
- Backblaze B2, object storage for receipts, exports, and branding assets (EU).
- Cloudflare, bot protection and content delivery.
- Resend and AWS SES, transactional email.
- Twilio, SMS delivery.
- Google Analytics 4, site analytics.
- Sentry, error monitoring.
- Google Firebase Cloud Messaging, mobile push notifications (where enabled).
5. Retention
- Marketing leads: 24 months from last contact, then deleted.
- Tenant data: for the duration of the contract plus 7 years for tax records.
- Operational logs: 30 days rolling.
6. Your rights
Where applicable (e.g. GDPR, UK GDPR, CCPA) you can request access, correction, deletion, portability, and to object to processing. Email privacy@nomli.co from the address on file and we will respond within 30 days.
7. Cross-border transfers
Default storage is in the EU (the Hetzner Falkenstein region in Germany and Backblaze B2 in the EU). Some sub-processors, such as Cloudflare, Twilio, and Google Firebase Cloud Messaging, operate global networks; where personal data reaches them, we rely on standard contractual clauses or an equivalent transfer mechanism.
8. Changes to this policy
Material changes will be announced by email to active tenant owners at least 30 days before they take effect.
9. Contact
Email privacy@nomli.co for any privacy question, complaint, or rights request.