Data protection · GDPR
Privacy Policy
This page explains what personal data we collect through this website, why we collect it, who else sees it, how long we keep it and what you can ask us to do with it. It is written to be read, not to be survived. If anything here is unclear, write to us and we will explain it in plain words.
Last updated: 14 August 2026
1. Who is responsible for your data
The data controller — the person or organisation that decides why and how your personal data is used — is:
- Aleksei Rudenko, self-employed professional registered in Portugal, trading as Delivery Lift
- Registration number: NIF 310833019
- Registered address: Av. Duque de Loulé 94, 6.º A, 1050-086 Lisbon, Portugal
- Email: rudenkoalexey1996@gmail.com
For anything to do with your personal data — questions, requests, complaints — write to rudenkoalexey1996@gmail.com. We answer within one month, as the GDPR requires, and usually much sooner.
We have offices in Lisbon, Portugal and in Chicago, United States. This matters for your data, and section 6 explains why.
2. What data we collect
Data you give us in the contact form
The form on this website asks for the details we need in order to reply to you and to prepare a baseline calculation for your restaurant:
- restaurant name;
- city and country;
- a phone or WhatsApp number;
- an email address (optional);
- the delivery platforms you sell on.
We also store, together with your message, the page you sent it from, any campaign parameters in the link you arrived by, and the figures you entered into the calculator on the site if you used it. This is so that we can see what you were looking at when you wrote to us, and give you a relevant answer instead of a generic one.
Please do not send us special categories of data (health, political opinions, and so on) — we do not need them and we do not ask for them. We never ask for your platform passwords.
Data you give us when you contact us directly
If you write to us by email, WhatsApp or Telegram, we receive whatever you choose to send: your name or display name, your number, and the content of your messages. Messages sent over WhatsApp or Telegram also pass through those services, which handle your data under their own privacy policies.
Technical data and analytics
When you open this site, our hosting provider processes technical data that is unavoidable in any web connection — your IP address, the time of the request, the page requested, your browser and device type. This is needed to deliver the page to you and to keep the site secure.
Analytics is different: it runs only after you accept it. Until you press "Accept" in the cookie notice, no analytics data leaves your browser. No analytics tool is connected to this site at the moment, so today nothing is measured either way — section 4 explains what accepting does and does not do. If we connect one, it will collect statistics about how the site is used — pages viewed, clicks on the main buttons, whether a form was completed — and only after you accept.
3. Why we use it, and on what legal basis
Under the GDPR every use of personal data needs a legal basis. Ours are these:
- To answer your enquiry and prepare a free baseline audit. Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
- To perform a contract once you become a client — reporting, invoicing, day-to-day communication. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
- To keep this website secure and working, and to prevent spam and abuse of the form. Legal basis: our legitimate interest in a functioning, non-abused website (Article 6(1)(f) GDPR).
- To measure how the site performs using analytics cookies. Legal basis: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
- To keep accounting and tax records. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).
We do not sell your data, we do not rent it, and we do not use it for automated decision-making or profiling that produces legal effects for you.
4. Cookies and analytics
This site does not set analytics or advertising cookies before you agree to them. When you first open the site, a notice appears at the bottom of the screen with two buttons, Accept and Decline, and nothing is measured until you press one of them.
If you press Decline, no analytics is loaded and nothing about your visit is recorded beyond the technical logs described above. Declining does not break anything: every part of the site works the same either way.
How to change your mind. Your choice is kept in the memory of the current page only — this site does not write it to your browser's storage. Reloading the page brings the notice back, so withdrawing consent is as simple as reloading and pressing Decline. You can also block or delete cookies in your browser settings at any time.
Analytics provider: none. No analytics tool is connected to this site at present. Pressing "Accept" currently enables an event queue inside the page and nothing more: no analytics cookie is set, no analytics request leaves your browser and no analytics data is stored. This page will name the tool, its cookies and its retention period before any analytics is switched on.
5. Who we share data with
Your data stays with us and with the service providers we need in order to run the business. They fall into three groups, and the difference between them matters for your rights, so we set them out separately.
Processors acting on our instructions. These providers handle your data only for us and only for the purpose we give them, and they are not allowed to use it for their own purposes:
- Website hosting — serves this site and keeps server logs: Netlify (Netlify, Inc., United States).
- Form and enquiry handling — receives and stores what you submit through the form: Netlify Forms (Netlify, Inc., United States).
Independent services you or we use to communicate and to display this site. These are not our processors: they decide for themselves how they handle the data that passes through them, each under its own privacy policy, and we have no control over that:
- Email — we reply to you from a mailbox hosted by Google (Google Ireland Limited / Google LLC, United States), which therefore holds the correspondence between us.
- Messaging apps — WhatsApp (Meta Platforms Ireland Limited) and Telegram (Telegram Messenger Inc.), if you choose to write to us through those channels. Your messages pass through those services under their own terms.
Professional advisers. Accountants and, where necessary, lawyers. They see your data only where it is genuinely needed — for example in an invoice — and they are bound by professional confidentiality rather than by a data processing agreement with us.
We also disclose data where the law requires it: to a public authority acting within its powers, or to defend a legal claim. We will not do so more widely than the law obliges us to.
Delivery platforms such as Uber Eats, Glovo, Bolt Food or DoorDash are not our processors. When we work inside a client's own platform accounts, the platform is an independent controller of the data in those accounts, under its own terms and privacy policy.
6. Transfers outside the EEA
We have an office in Chicago, Illinois, United States, and some of the service providers we use are based outside the European Economic Area. This means your data may be transferred to and processed in a country outside the EEA, including the United States. In practice this applies to the hosting and form provider named in section 5 (Netlify, Inc.), to the mailbox and web fonts provided by Google, and to the messaging apps if you choose to use them.
The typefaces on this site are served from our own domain. They are not loaded from Google Fonts or any other third party, so opening a page of this site does not send your IP address anywhere outside our hosting provider.
Where a transfer happens, we rely on one of the safeguards the GDPR allows:
- a decision of the European Commission that the country in question provides an adequate level of protection; or
- Standard Contractual Clauses approved by the European Commission, together with additional technical and organisational measures where these are needed.
You can ask us for a copy of the safeguards that apply to a specific transfer by writing to rudenkoalexey1996@gmail.com.
7. How long we keep data
- An enquiry that does not become a contract: 24 months, after which we delete it.
- Client records: for the duration of the contract and then 10 years, which is set by the accounting and tax law that applies to us.
- Server logs: for the short period our hosting provider keeps them for security purposes.
When a retention period ends, we delete the data or anonymise it so that it can no longer be linked to you.
8. Your rights under the GDPR
These rights are yours, they are free to use, and using them costs you nothing in your relationship with us. You can:
- Ask what we hold about you and get a copy of it (right of access).
- Have it corrected if it is wrong or incomplete (rectification).
- Have it deleted where we no longer have a reason to keep it (erasure, the "right to be forgotten").
- Restrict how we use it while a dispute about it is being sorted out (restriction).
- Receive it in a portable format, or have it sent to another provider where this is technically possible (portability).
- Object to our use of it where we rely on legitimate interest (objection).
- Withdraw your consent at any time, where we rely on consent. Withdrawal does not affect what was lawfully done before you withdrew it.
To use any of these rights, write to rudenkoalexey1996@gmail.com. We may need to check who you are before we act, so that we do not hand your data to someone else.
Complaints. If you think we are handling your data wrongly, please tell us first — most problems are a misunderstanding and are fixed quickly. You also have the right to complain to a supervisory authority: in Portugal that is the CNPD — Comissão Nacional de Proteção de Dados (www.cnpd.pt), or the data protection authority of the EU country where you live or work.
9. How we protect data
We keep access to personal data limited to the people who need it to do their work, we use the access controls the tools we work with provide, and this site is served over an encrypted connection. No system is perfectly secure, and we do not claim otherwise — but if a breach affects your rights, we will notify you and the supervisory authority as the GDPR requires.
This website is aimed at restaurant owners and managers. It is not directed at children, and we do not knowingly collect data from anyone under 16.
10. Changes to this policy
When our tools, providers or services change, this page changes with them. The date at the top of the page always shows when it was last updated. If a change matters to you — a new purpose, a new category of recipient — we will make it visible rather than quietly editing the text.
Questions about this policy: rudenkoalexey1996@gmail.com. Company registration details are on the company details page, and the rules for using this website are in the website terms.
Delivery Lift · Restaurant growth agencyPrivacy