Privacy Policy

Last Updated: 1 August 2026

Version: v1.1

1. Who We Are

Theodosios Bratelis, trading as Metiflow, provides Metiflow Trader and Metiflow Resto. For data protection purposes, Theodosios Bratelis is the controller for account and platform administration data and processor for customer business data as instructed by account holders.

2. Data We Process

  • Account data: names, business details, email addresses, user roles, login metadata.
  • Operational data: quotes, jobs, invoices, schedules, material records, uploaded documents.
  • Restaurant operational data (Metiflow Resto): staff names and shift PINs, order and payment records, diner name/phone where provided for takeaway orders or reservations, and device identifiers used for multi-device sync.
  • Technical data: IP address, browser/device information, security and audit logs.
  • Optional analytics data, only where consent is provided for non-essential cookies.

3. Legal Basis and Use of Data

We process personal data in accordance with applicable data protection laws including the UK GDPR and Data Protection Act 2018.

We process data to provide the Platform, ensure security, support customers, comply with legal obligations, and improve service quality.

4. Cookies and Tracking

Necessary cookies are used to operate the site and service. Optional analytics cookies are not activated until consent is given. You can update cookie preferences at any time in your browser and through our cookie controls.

See our Cookie Policy for details.

5. Data Sharing and Subprocessors

We use trusted infrastructure and service providers to host, operate, and support Metiflow Trader. A current list is available at Subprocessors.

6. Data Retention

We apply soft delete for account-level data where feasible. After deletion requests or account termination, data may be retained in a restricted state for a retention window (typically up to 90 days) for recovery, compliance, and dispute handling, then permanently purged according to internal schedules unless legal retention obligations apply.

7. Security Measures

We implement industry-standard safeguards and commercially reasonable security measures to protect personal data. No online service can guarantee absolute security.

8. Data Subject Rights

Where applicable, you may request access, rectification, erasure, restriction, portability, or objection regarding personal data. Contact us at admin@metiflow.com.

Account owners will also be able to download a copy of their organisation's data (including, where applicable, diner contact details entered by staff) directly from the Platform at any time, without needing to raise a request. Until that self-service tool is available in a given Service, you can request an export by emailing us at the address above.

9. Contact and Company Details

Theodosios Bratelis, trading as Metiflow
45 Hadrian Way
CA3 0LU
United Kingdom
Email: admin@metiflow.com