Version 1 document. This page describes our current practices accurately and in plain terms. It will be reviewed and finalised before commercial rollout of KitchenOps, and the legal entity details will be confirmed here at that point.
1. Who we are
KO Technologies is an Irish software business. We build and operate KitchenOps, operational software for school meal providers.
For the purposes of the EU General Data Protection Regulation (GDPR), KO Technologies is the data controller for the information described in sections 2, 3 and 12, and acts as a data processor for the customer data described in sections 4 to 6.
2. This website
This website is a static informational site. It does not require an account, does not accept payments, and does not store any personal data in a database of its own.
The only personal data involved when you use this website is:
- Emails you choose to send us. If you write to us, we receive your email address, your name and whatever you include in the message. We keep this correspondence so we can reply and maintain a record of the enquiry.
- Standard server logs. The infrastructure that serves this website may record ordinary access logs — including IP address, timestamp and requested page — for security and availability purposes. We do not use these logs to profile visitors or build marketing audiences.
The contact form on this website is a convenience only. It composes a message in your own email client and does not transmit anything to this website or to us until you send that email yourself.
Our lawful basis for processing this information is our legitimate interest in responding to enquiries and operating a secure website, and — where you are a prospective or existing customer — taking steps at your request before entering into a contract.
3. Cookies and tracking
This website:
- sets no cookies;
- uses no analytics or visitor-tracking services;
- includes no advertising or social media pixels;
- loads no third-party scripts, fonts or embeds — all styling and assets are served from this domain.
Because no cookies are set and no tracking takes place, there is no cookie banner on this site. If this ever changes, a consent mechanism will be added before any such technology is introduced.
4. Data processed in KitchenOps
KitchenOps is used by school meal providers to run their daily operation. To do that, it processes the meal data those organisations already hold. In practice this typically includes:
- pupil names and class or group assignment;
- meal selections, quantities and dietary requirements or flags;
- school, delivery and route information;
- operational records generated during the day — production, packing, dispatch and delivery status.
This data is processed for one purpose: to produce and support the operational output the organisation needs — production lists, packing and label information, dispatch records, driver routes and delivery confirmations. It is not used for advertising, profiling, resale or any purpose unrelated to operating the service.
Some of this data relates to children and may include health-related information in the form of dietary requirements. This is why the product is built around data minimisation, restricted access and limiting retention to what the operation needs.
5. Who is responsible for the data
The school meal provider that operates KitchenOps is the data controller for the meal and pupil data it processes. That organisation decides what data is loaded, who on its team can see it, and how long it is kept.
KO Technologies acts as a data processor: we process that data on the controller's instructions in order to provide the service. Where a provider deploys and operates KitchenOps on its own infrastructure, KO Technologies may not hold that data at all.
6. Data minimisation and retention
- Minimisation. KitchenOps uses the data it is given to produce operational output, and does not require more than that.
- Transient processing. Uploaded source files are processed to generate operational documents. By default, uploaded files are not permanently stored; processed data exists for the duration of the generation session unless it is explicitly saved as part of a draft, an export history or an operational record.
- Retention. How long operational records are kept is determined by the operating organisation and its own retention policy. We do not retain customer operational data beyond what is needed to provide the service.
7. Sharing and disclosure
We do not sell personal data, and we do not share it for advertising or marketing purposes.
Data is shared only where it is necessary to provide the service — for example with the hosting and infrastructure providers used to run the platform and this website — or where we are legally required to disclose it. Service providers are bound by contract to process data only on our instructions. A list of sub-processors is available on request.
8. Security
Access to KitchenOps is restricted to authenticated users within the operating organisation, with permissions applied by role. Generated operational documents are visible only to authorised users of that organisation; there is no public access to uploaded data or generated documents.
Security arrangements are reviewed as the platform develops, and we will provide a more detailed statement — including incident response commitments — before commercial rollout.
9. International transfers
We aim to keep data within the European Economic Area. Where a service provider processes data outside the EEA, we will ensure an appropriate transfer mechanism is in place and will document it here.
10. Your rights
Under the GDPR, individuals have the right to:
- access the personal data held about them;
- have inaccurate data rectified;
- have data erased where there is no continuing lawful reason to keep it;
- restrict or object to processing;
- data portability, where applicable;
- lodge a complaint with a supervisory authority.
If your request relates to meal or pupil data held by a school meal provider in KitchenOps, please contact that organisation first — as data controller, it is responsible for responding. We will assist the controller as required. You can also contact us directly and we will direct your request appropriately.
The supervisory authority for Ireland is the Data Protection Commission (dataprotection.ie).
11. Changes to this page
We will update this page when our practices change, and the date at the top of the page will change accordingly. A fuller policy — including formal retention schedules and sub-processor detail — will be published before commercial rollout of KitchenOps.
12. Contact
For any privacy question, or to exercise a right described above, contact:
KO Technologies — Cork, Ireland
Email: nicolas@kotechnologies.ie