Dyner
About UsLog inContact Us

Legal

Privacy policy

How Dyner collects, uses and protects personal information, and what you can ask us to do about it.

Last updated1 December 2025

On this page

  1. 1.Introduction
  2. 2.Who We Are and Our Role
  3. 3.Scope
  4. 4.Personal Information We Process
  5. 5.How We Collect Personal Information
  6. 6.Purposes and Lawful Basis of Processing
  7. 7.Data Minimisation and Retention
  8. 8.Sharing of Personal Information
  9. 9.Cross‑Border Transfers
  10. 10.Security Safeguards
  11. 11.Data Subject Rights
  12. 12.Facial Recognition and Geolocation – Additional Detail
  13. 13.Children's Information
  14. 14.Cookies and Similar Technologies
  15. 15.Changes to this Policy
  16. 16.Contact and Complaints
Jump to a clause
  1. 1.Introduction
  2. 2.Who We Are and Our Role
  3. 3.Scope
  4. 4.Personal Information We Process
  5. 5.How We Collect Personal Information
  6. 6.Purposes and Lawful Basis of Processing
  7. 7.Data Minimisation and Retention
  8. 8.Sharing of Personal Information
  9. 9.Cross‑Border Transfers
  10. 10.Security Safeguards
  11. 11.Data Subject Rights
  12. 12.Facial Recognition and Geolocation – Additional Detail
  13. 13.Children's Information
  14. 14.Cookies and Similar Technologies
  15. 15.Changes to this Policy
  16. 16.Contact and Complaints

1.Introduction

Dyner Proprietary Limited ("Dyner", "we", "our" or "us") provides an AI‑driven platform for restaurants, including: anomaly and theft detection, invoice automation, stock sheet management, price benchmarking, online ordering automation, attendance tracking (with geotagging and facial recognition), employee performance monitoring, margin tracking and roster management.

We are committed to complying with the Protection of Personal Information Act 4 of 2013 (POPIA) in relation to all personal information that we process.

This policy explains how we collect, use, disclose and protect personal information when you use Dyner or interact with us.

2.Who We Are and Our Role

We are Dyner Proprietary Limited ("Dyner", "we", "our" or "us"), a private company incorporated in accordance with the laws of the Republic of South Africa. We are a technology company that provides restaurant intelligence, analytics and operational optimisation services. Dyner is a subsidiary of Yoco Technologies Proprietary Limited ("Yoco").

Responsible party / operator:

  • We act as a responsible party where we determine the purpose and means of processing (e.g. our own user accounts, billing, sales and support data).
  • We act as an operator where we process personal information on behalf of restaurant clients (e.g. staff attendance, facial recognition, geolocation, POS‑linked performance metrics).

When we act as operator, our obligations and those of the client are set out in written contracts, and we process personal information only with the knowledge or authorisation of the responsible party.

3.Scope

This policy applies to:

  • Restaurant owners, managers and employees using Dyner
  • Individuals whose information appears in data our clients upload or integrate (e.g. staff, suppliers, some restaurant customers)
  • Visitors to our website, dashboard and related digital services
  • Job applicants and other business contacts.

It covers personal information processed via our web and mobile interfaces, APIs, integrations and support channels.

4.Personal Information We Process

"Personal information" has the meaning given in POPIA and includes information relating to an identifiable natural person and, where applicable, an existing juristic person.

Depending on the modules used, we may process:

4.1 Account and Contact Data

  • Names and surnames
  • Business name, role/position
  • Contact details (email, phone)
  • Usernames and hashed passwords
  • Communication records with Dyner (support, sales).

4.2 Restaurant Transactional and Operational Data

  • POS transaction data (items sold, times, discounts, voids, tables, staff identifiers)
  • Invoice data (supplier name, invoice numbers, line items, prices, quantities)
  • Stock counts and stock sheet data
  • Recipes, menu items and ingredient costs for margin tracking
  • Roster rules and generated schedules.

Where such data can be linked to an identifiable person (e.g. staff code mapped to a named waiter) it is treated as personal information.

4.3 Employee / Staff Data

Used particularly by attendance tracking, employee performance, roster management and anomaly modules:

  • Name, employee number, role, branch
  • Attendance data (clock‑in/out times, shift allocations)
  • Geolocation data at the time of clock‑in/out
  • Facial images / facial recognition templates used to verify identity and prevent spoofing (biometric information)
  • Performance metrics derived from POS data (e.g. revenue by waiter, average bill size, discount usage, void patterns)
  • Audit logs relating to anomalies and alerts.

4.4 Customer and Supplier Information (as Contained in Client Systems)

  • Supplier details appearing on invoices (names, contact details)
  • Limited customer data contained in POS / online ordering systems (e.g. name on booking/order, where present).

4.5 Technical and Usage Data

  • IP address, device identifiers, browser type, operating system
  • Usage logs and event data within Dyner
  • Cookies and similar technologies where used.

4.6 Special / Sensitive Personal Information

We may process "special personal information" where applicable, including biometric information (facial recognition templates). This is done only where permitted under POPIA (for example, with the data subject's consent or another applicable authorisation).

5.How We Collect Personal Information

We collect personal information:

  • Directly from you – when you create a Dyner account, use our platform, contact us or respond to communications.
  • From our clients and their systems – via POS integrations, invoice uploads, stock sheets, rosters and HR/staff records that restaurants choose to connect to Dyner.
  • Automatically – through system logs, telemetry and cookies while you use Dyner.
  • From third parties – e.g. online ordering platforms and integration partners, where our clients have enabled such connections.

Where practicable, personal information is collected directly from the data subject unless an exception applies (such as where data comes from existing restaurant systems).

6.Purposes and Lawful Basis of Processing

We process personal information only where there is a lawful basis under POPIA and for specific, explicitly defined and lawful purposes.

6.1 Providing and Managing Dyner Services

To:

  • Provide and administer all Dyner modules
  • Integrate with POS and online ordering platforms
  • Generate dashboards, reports and analytics for restaurant owners and managers
  • Implement anomaly detection to flag potentially irregular transactions for investigation.

Lawful bases include:

  • Performance of a contract with our clients, or steps taken at their request
  • Legitimate interests of Dyner and clients in operating and improving restaurant management and theft/fraud detection.

6.2 Attendance Tracking, Facial Recognition and Geolocation

To:

  • Verify employee presence on site at clock‑in/clock‑out
  • Prevent spoofing, buddy‑punching and related attendance fraud
  • Support accurate rostering and payroll records.

This involves processing biometric information (facial templates) and geolocation.

Lawful bases:

  • Legitimate interests of the employer in accurate attendance and fraud prevention
  • Where required for biometric data, applicable authorisation for processing special personal information such as data subject consent or another condition in POPIA.

6.3 Employee Performance and Margin Tracking

To:

  • Derive performance metrics (e.g. sales per server, discount patterns)
  • Calculate margins, wastage and losses using invoice, stock and recipe data
  • Provide insights to restaurant owners and managers.

Lawful bases: Legitimate interests of clients in managing staff performance, profitability and operational risk.

6.4 Security, Monitoring and Fraud / Theft Detection

To:

  • Secure our platform and systems
  • Monitor and investigate anomalies and suspected theft or fraud within restaurants
  • Detect and prevent unauthorised access or misuse of Dyner.

Lawful bases:

  • Legitimate interests in protecting assets and systems
  • Compliance with legal duties where applicable.

6.5 Communication, Support and Administration

To:

  • Communicate with users about the service, updates and incidents
  • Provide technical and customer support
  • Handle billing, account management and contractual matters.

Lawful bases:

  • Performance of contracts with clients
  • Legitimate interests in running our business and servicing clients.

6.6 Product Improvement and Analytics

To:

  • Analyse usage to improve functionality and user experience
  • Train and refine our models, where appropriate
  • Conduct aggregated, anonymised benchmarking and reporting (e.g. price benchmarking).

Where feasible, we use de‑identified or aggregated data so that individuals cannot be identified.

6.7 Legal Obligations and Claims

To:

  • Comply with applicable laws, regulatory requests and lawful court orders
  • Establish, exercise or defend legal claims.

Lawful basis: compliance with legal obligations and legitimate interests.

7.Data Minimisation and Retention

We only process personal information that is adequate, relevant and not excessive for the purpose for which it is processed.

We retain personal information only for as long as necessary to:

  • Provide Dyner services to the relevant client
  • Meet legal and regulatory record‑keeping obligations
  • Resolve disputes and enforce agreements.

Thereafter we securely destroy, delete or de‑identify records so they cannot be reconstructed in intelligible form.

8.Sharing of Personal Information

We do not sell personal information. We may share personal information as follows:

8.1 With Restaurant Clients

Attendance, performance and other staff‑related data is made available to the specific restaurant client that is the employer. Anomaly, margin and operational analytics are provided to the relevant restaurant.

8.2 With Operators / Service Providers

We use third‑party service providers for hosting, storage, communications, analytics and integrations. Where they process personal information for us they are "operators" and must:

  • Establish and maintain appropriate security measures, and
  • Process information only with our knowledge or authorisation and maintain confidentiality unless disclosure is required by law.

We ensure these obligations are recorded in written contracts.

8.3 Legal and Regulatory Disclosures

We may disclose personal information where required to:

  • Comply with applicable law or court process
  • Assist law enforcement and regulatory authorities, where lawful and appropriate.

8.4 Business Transfers

If Dyner is involved in a merger, acquisition or sale of all or part of its business, personal information may be transferred as part of that transaction, subject to appropriate safeguards.

9.Cross‑Border Transfers

Where we or our service providers store or process personal information outside South Africa, we will ensure that:

  • The recipient is subject to a law, binding corporate rules or binding agreement which provides an adequate level of protection substantially similar to POPIA, or
  • Another lawful ground for cross‑border transfer under POPIA applies.

10.Security Safeguards

We implement appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of personal information in our possession or under our control, to prevent:

  • Loss of, damage to or unauthorised destruction of personal information; and
  • Unlawful access to or processing of personal information.

Measures include (without limitation):

  • Encryption in transit, and where appropriate at rest
  • Access controls and role‑based permissions
  • Secure development and testing practices
  • Monitoring, logging and incident response processes
  • Regular review and updating of safeguards in response to new risks.

Where an operator processes personal information on our behalf, we require it by written contract to maintain equivalent security measures and to notify us immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by any unauthorised person.

If we have reasonable grounds to believe that a data subject's personal information has been accessed or acquired by any unauthorised person, we will notify the Information Regulator and the affected data subjects as required by POPIA.

11.Data Subject Rights

Data subjects have the right to have their personal information processed in accordance with POPIA's conditions and may exercise, among others, the following rights (subject to applicable limitations):

  • Right to be informed that personal information is being collected or has been accessed or acquired by an unauthorised person.
  • Right of access – to request confirmation whether we hold personal information about them and to request access to that information.
  • Right to correction or deletion – to request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, or to request destruction or deletion of records that we are no longer authorised to retain.
  • Right to object – to object, on reasonable grounds relating to their particular situation, to the processing of their personal information where we rely on certain lawful bases.
  • Right to withdraw consent where processing is based on consent (without affecting the lawfulness of processing that took place before withdrawal).
  • Right to lodge a complaint with the Information Regulator.

Where we act as an operator on behalf of a restaurant client, we may be required to forward requests to that client (as the responsible party) for handling.

Requests can be submitted using the contact details in section 16.

12.Facial Recognition and Geolocation – Additional Detail

For the attendance tracking module specifically:

  • Purpose: identity verification at clock‑in/out, prevention of spoofing and attendance fraud, evidentiary support for attendance and payroll.
  • Data: facial images or templates (biometric), timestamps, geolocation and device metadata, linked to employee profiles.
  • Use: matching faces to enrolled profiles at clock events, verifying on‑site presence and generating attendance records.
  • Retention: limited to what is necessary for attendance, payroll and dispute purposes, subject to statutory retention requirements, after which data is securely deleted or de‑identified.
  • Access: restricted to authorised Dyner personnel and authorised representatives of the applicable restaurant client.

Restaurant clients are responsible for informing their employees of the use of this module and obtaining any required consents or authorisations for biometric processing in their environment.

13.Children's Information

Our services are aimed at businesses and adult staff. We do not knowingly process personal information of children as a responsible party unless permitted by POPIA (for example, with the consent of a competent person).

If you believe we have collected children's personal information contrary to POPIA, please contact us so we can investigate and, where appropriate, delete or otherwise lawfully deal with that information.

14.Cookies and Similar Technologies

Dyner may use cookies and similar technologies to enable core functionality, remember user settings and analyse usage. Where required by law, we will obtain your consent for non‑essential cookies.

15.Changes to this Policy

We may update this policy from time to time. When we do:

  • We will post the updated version in our applications or on our website; and
  • Update the "last updated" date at the top.

Material changes may be notified through the platform or by email. Continued use of Dyner after changes take effect will constitute acceptance of the updated policy.

16.Contact and Complaints

For any questions, requests or concerns regarding this policy or our processing of personal information, please contact:

Dyner Proprietary Limited

Attention: Information Officer / Privacy Officer

You also have the right to lodge a complaint with the Information Regulator (South Africa) in accordance with POPIA.

Cutting-edge AI analytics and real-time insight into every cost that moves - built for restaurants first, and for anyone else living on stock, suppliers and thin margins.

Follow on LinkedIn

Product

  • What it saves
  • What it does
  • Questions

Company

  • About us
  • Blog
  • Contact us
  • Book a demo

Sign in

  • Owner log in
  • Employee clock-in

Legal

  • Privacy policy
  • Terms and conditions
Dyner

© 2026 Dyner. All rights reserved. ◆ A proud subsidiary of Yoco.