We read your back office. We write only when you say so
Point by point: the access we ask for, what it lets us do and what it does not, where the data sits, how long we keep it and how to take the access back. Everything here works today - none of it is a plan.
A separate user, not yours and not an administrator. While read-only mode is on, no accounting document reaches Syrve
Separation sits at the database row level, not at the screen level: a company sees its own data only
Logged with the application, user, company, tool and time. A log entry can be added, never edited or deleted
Who signs in
Sign-in, the second factor and what sits behind it.
The first sign-in is a link sent to your email or a Google account. A password is set for later sign-ins.
Switched on in security settings: a one-time code from an authenticator app. Which app you keep it in is your choice - the secret can also be typed in by hand.
Google already asks for confirmation, and we will not demand another code for form's sake. An email link and a one-time email code do not count: email is the first factor.
Without confirmation the platform side is closed. For restaurant owners it stays voluntary for now.
Export to Syrve, month-end closing, transfers, automatic write-offs, reconciliation decisions, company details, the subscription and connecting an AI application are each checked separately.
The removal is written to a log, and the log sits on the same screen as the button.
What we ask of your back office
The objection "you will get into our accounting" comes up here, so this is where we answer it.
We do not change Syrve settings, rights or reference data. We do not post documents without your confirmation. We do not write to suppliers on your behalf.
Not your account and not an administrator: we read reference data, sales, stock and recipes.
While it is on, no accounting document reaches Syrve at all. The block sits on the write path itself, not on a button, so neither screens nor nightly jobs get around it.
An operator sends an invoice into accounting after checking its lines. There is no automatic posting without confirmation.
At the connection step we check that the access works and write nothing down.
Access and secrets
What happens to the password you gave us, and how to take it back.
Syrve, the mailbox, Google Drive: the password is stored encrypted with AES-256-GCM. A copy of the database does not hand the passwords over.
Access separation sits at the database row level. A screen someone forgot to close still will not show another company's row.
The connection is deleted together with the password, and the system confirms that the password is gone.
It is visible who connected the access and when, and who removed it.
External AI and assistant connections
RestoAudit can be connected to Claude or ChatGPT. That is a separate access, and it is built as strictly as the others.
The application gets access over OAuth on your behalf. No keys need to be forwarded to anyone in a chat.
The consent screen asks for the same confirmed sign-in as an export into accounting.
The list of connected applications and the companies opened to them lives in settings. Access is removed there with a button.
Every tool hands data out; nothing can be written into RestoAudit through them.
Application, user, company, tool and time. A log entry can be added, never edited or deleted.
Where the data sits and who processes it
The wording is the same as in the privacy policy and the data processing agreement: they are not allowed to drift apart.
- Data is encrypted in transit and at rest.
- The European Commission has recognised the United Kingdom as a country with an adequate level of data protection, so a transfer there needs no separate contractual clauses.
- Document content is recognised by Anthropic (USA) under the European Commission's standard contractual clauses.
- In the assistant only the text of your question leaves us: no invoices, no prices, no suppliers, no stock. The phrasing is parsed by Google (USA), on an access key separate from the one used to read documents.
- We give at least thirty days' notice before engaging a new subprocessor, and within that period you may object.
How long we keep it
The periods come from the privacy policy and the data processing agreement.
- Document content and reference data: 3 years after the service ends.
- Account and correspondence: 3 years after the service ends.
- Enquiries that did not become a contract: 12 months.
- Our invoices to you and accounting records: for the period set by Latvian law; a deletion request does not apply to them.
- When the contract ends the data is deleted or returned - your choice - within 14 days of the request.
Long-term retention of accounting documents is the restaurant's own duty: in Germany that means the GoBD, HGB and AO periods, elsewhere the local ones. We keep documents for the term of the service plus three years, and that is not enough for a statutory retention period. There is no bulk download of all documents for a period in the product yet: we return a copy of the data on request, within 14 days.
Article 32 GDPR measures
The list comes from the data processing agreement. We hold no certifications and no independent audit, and we are not going to claim any.
Incidents and support
What happens when something goes wrong, and how fast we answer.
We notify you without undue delay after we become aware of it, describing the nature of the breach and the measures taken.
A response time is a human answering with an assessment of the situation, not a time to fix.
Working hours: Monday to Friday, 09:00-18:00 Riga time, except Latvian public holidays.
The full list of request classes is in the terms of useFound a vulnerability or noticed something odd - write to us directly.
security@restoaudit.aiWhat people ask most often
This page describes the product; the binding documents are the data processing agreement, the privacy policy and the terms of use.