SCAN APP PRIVACY POLICY
Last updated: 4 September 2026
Purpose of this Privacy Policy
This Privacy Policy explains how personal data is processed through the “Scan App” application (the “App”).
The App is a professional-use tool linked to the CoverExperiences service. It is intended exclusively for employees and other authorised users of restaurants, establishments or event organisers that have contracted that service with any of the following entities:
Restaurants Booking Distribution Services, S.L.U., trading under the CoverManager brand.
PremiumCover, S.L.U., trading under the CoverManager brand.
Zenchef SAS, trading under the Zenchef brand.
For the purposes of this Privacy Policy, the entity with which the restaurant, establishment or event organiser has contracted the service is referred to as the “Provider”.
The App enables authorised users to view information relating to tickets and attendees, validate tickets, manage access to events, detect possible duplicates and, where applicable, record the use of services or add-ons associated with a ticket.
The App is not a standalone service. It is an operational tool through which certain features of the CoverExperiences service are provided.
This Privacy Policy applies exclusively to the processing of personal data through the App. It does not govern processing carried out through other features, websites, platforms or products of the Provider, even where related to CoverExperiences. Such processing will be governed by the privacy information applicable in each case.
Who is the data controller?
The data controller of the personal data processed through the App is the restaurant, establishment, event organiser or other entity that has contracted the CoverExperiences service and authorised the user to use the App (the “Client”).
The Client determines the purposes and essential means of the processing. The Client is responsible for informing its employees, attendees and other data subjects about the processing of their personal data and for ensuring that such data is processed lawfully.
The Provider processes personal data on behalf of the Client, in accordance with the Client’s instructions and in its capacity as processor, pursuant to the agreement and data processing agreement entered into between the parties.
What personal data is processed through the App?
Depending on the features used and the configuration selected by the Client, the following categories of personal data may be processed through the App:
Data relating to authorised users
To enable access to the App, data associated with the user’s account on the relevant Provider platform will be processed. This data may include:
User identifier.
Data required to authenticate the user and maintain an active session.
The Client, establishment or event with which the user is associated.
Profile, role and access permissions.
Date and time of access and other session-related information.
The user account will originate from the relevant Provider platform, and access will take place through the authentication mechanism made available by that Provider.
Data relating to attendees and ticket holders
Identification and contact details associated with the ticket.
Ticket code, booking reference or identifier.
Information relating to the event, session, date, time, establishment and ticket type.
Ticket status, including whether it is valid, used, cancelled or potentially duplicated.
Information concerning products, services or add-ons associated with the ticket.
Date, time and outcome of search, validation and access operations.
Technical and security data
IP address.
Device type, operating system and App version.
Connection, session and authentication data.
Technical logs, errors, incidents and diagnostic data.
Information required to ensure the operation of the App, prevent unauthorised access and manage security incidents.
The App is not designed to request or process special categories of personal data. However, in exceptional circumstances, information entered by the Client or associated with a ticket may reveal data of this nature. Such data will be processed exclusively on behalf of the Client and for the purpose of providing the relevant features.
Access to the camera
The App will request access to the device’s camera exclusively to scan the QR codes associated with tickets and verify their validity.
The App processes the captured image only for the time required to read the code. It does not store or retain photographs, images or recordings captured using the camera.
The user may grant, deny or withdraw camera access permission through the device settings. Denying or withdrawing this permission will prevent the user from using the QR code scanning feature.
For what purposes is personal data used?
Personal data is processed for the following purposes:
To create, configure and manage authorised user accounts.
To authenticate users and manage their access permissions.
To enable tickets to be viewed, searched and validated.
To manage attendee access to events or establishments.
To detect invalid, cancelled, duplicated or previously used tickets.
To record ticket validations and the use of products or add-ons associated with tickets.
To ensure the operation, availability and security of the App.
To prevent unauthorised access, fraudulent use and other security incidents.
To diagnose errors, resolve incidents and provide technical support.
To maintain activity logs and ensure the traceability of operations performed through the App.
To analyse the use and operation of the App, and to aggregate and anonymise the information obtained, in order to produce statistics and improve the security, quality and features of the service.
The Provider carries out these operations on behalf of the Client, in accordance with the Client’s instructions and the applicable agreement and data processing agreement.
The Provider will not use the personal data of attendees, ticket holders or authorised users for its own purposes. However, it may use the resulting information for statistical and analytical purposes and to improve the service where that information has first been anonymised so that individuals are neither identified nor identifiable.
Lawful basis for processing
The Client, as controller, determines the lawful basis applicable to the processing carried out through the App and must inform its employees, authorised users, attendees and other data subjects of that lawful basis.
Depending on the relevant relationship and the purposes pursued, the Client may base the processing, among other grounds, on the performance of its contractual relationship with attendees or ticket holders, compliance with its legal obligations, its employment or professional relationship with authorised users, or its legitimate interests in managing events and ensuring their security.
The Provider processes personal data on behalf of the Client, in accordance with the Client’s documented instructions and pursuant to the agreement and data processing agreement entered into between the parties.
Where does the data come from?
The data processed through the App may come from:
The authorised user, when they log in to or use the App.
The Client or its account administrator.
The CoverExperiences platform, from which information relating to attendees, tickets and events is obtained.
The platform used to manage user accounts. Where the service has been contracted with CoverManager or PremiumCover, the data will come from the CoverManager platform. Where the service has been contracted with Zenchef, the data will come from the Zenchef platform.
The scanning of QR codes associated with tickets.
Search, validation and management operations performed by authorised users through the App.
With whom may personal data be shared?
Personal data may be accessible to:
The Client and the users authorised by the Client.
The Provider, as processor and contractual provider of the CoverExperiences service.
The other entities identified in Section 1, where they provide the Provider with technical, operational, hosting, maintenance, authentication, user management, security or support services required for the operation of the App. In such cases, they will act as sub-processors and will process the data only in accordance with the instructions of the Provider and the Client.
Providers of hosting, infrastructure, maintenance, security, communications or support services that act as sub-processors.
Public authorities, courts or other third parties where access is required by law.
Group entities and other service providers with access to personal data will be subject to appropriate contractual obligations concerning confidentiality, security and data protection.
Personal data is not sold or used for behavioural advertising.
Apple and Google may process certain data relating to the download, installation and operation of the App in accordance with their own terms and privacy policies. Such processing is carried out directly by those entities and not on behalf of the Client or the Provider.
International data transfers
Personal data processed through the App is hosted on servers located within the European Economic Area and is not subject to international data transfers by the Provider.
The above is without prejudice to the processing carried out by Apple and Google, as independent controllers, in connection with the download, installation and operation of the App through their respective app stores and operating systems. Such processing is governed by their respective privacy policies.
Data retention
Personal data processed through the App will be retained for as long as necessary to provide the CoverExperiences service and for the duration of the contractual relationship with the Client, in accordance with the Client’s instructions and the applicable agreement and data processing agreement.
Data linked to authorised user accounts will be processed for as long as those accounts remain active and the users remain authorised to use the App.
Data relating to attendees, tickets and validation operations will be retained for the period determined by the Client, taking into account the purpose of the processing and any applicable legal obligations.
Technical and security logs will be retained for as long as necessary to ensure the operation and security of the App, diagnose incidents and address potential liability.
When the provision of the service ends, the data will be returned, deleted or, where applicable, retained in a restricted form, in accordance with the Client’s instructions, the data processing agreement and applicable law.
Account deactivation and data deletion
Users cannot create an account directly within the App. Accounts are created, enabled and managed by the Client or by the Provider in accordance with the Client’s instructions, through the relevant CoverManager or Zenchef platform.
Users may request the deactivation of their account from their organisation’s account administrator. They may also contact the Provider’s support channel, which will handle the request in accordance with the Client’s instructions.
Deactivating an account will prevent the user from continuing to access the App, but will not necessarily result in the deletion of records associated with operations performed by that user. The Client may need to retain certain validation, security or traceability records in accordance with the applicable purposes and obligations.
Requests for the deletion of personal data must be addressed to the Client, as controller. The Provider will assist the Client in responding to such requests in accordance with the Client’s instructions, the data processing agreement and applicable law.
Data protection rights
Users may exercise their rights of access, rectification, erasure, objection, restriction of processing and data portability, where applicable, by contacting the Client as controller.
For this purpose, users may contact their employer or use the privacy contact channel provided by the Client.
If a request is submitted directly to the Provider, the Provider will forward it to the Client or assist the Client in responding to it, in accordance with the Client’s instructions and the applicable data processing agreement.
Data subjects also have the right to lodge a complaint with the competent supervisory authority. In Spain, they may contact the Spanish Data Protection Agency (Agencia Española de Protección de Datos) through its website: https://www.aepd.es.
Information security
The Provider implements appropriate technical and organisational measures to protect personal data processed through the App against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, that data.
These measures may include, where appropriate:
Encryption of communications in transit.
Access controls and authentication mechanisms.
Management of profiles and permissions.
Logging and monitoring of access and operations.
Measures to protect infrastructure, systems and communications.
Procedures for managing security incidents and vulnerabilities.
Users must keep their credentials confidential, use the App solely for authorised professional purposes and report any loss of the device, unauthorised access or security incident to the Client or the designated support channel.
Professional use and minors
The App is intended exclusively for employees and other users authorised by professional Clients. It is not directed at the general public or specifically designed for use by minors.
The Provider does not knowingly create user accounts for minors. The Client is responsible for authorising access to the App and ensuring that its users meet the applicable legal and professional requirements.
The above does not affect the processing of data relating to attendees who are minors and whose details may lawfully appear on tickets managed through CoverExperiences. Such data will be processed on behalf of the Client and solely for the purpose of providing the service.
Changes to this Privacy Policy
This Privacy Policy may be updated where changes are made to the App’s features, the processing of personal data or applicable law.
The current version, including the date on which it was last updated, will be available within the App and at the public URL provided in the app stores.
Where changes materially affect the processing of personal data, the Provider will inform the Client or affected users through appropriate means, taking into account the nature of the change.
Last updated: September, 2026
Contact
For technical queries or questions concerning the operation of the App, please use the following support channel: tech@covermanager.com
For queries concerning this Privacy Policy or the processing of personal data by the Provider in connection with the App, please contact:
CoverManager and PremiumCover: dpo@covermanager.com
Zenchef: privacy@zenchef.com
To exercise their rights or raise questions about the purposes and use of personal data determined by the Client, data subjects must contact the Client, as controller, through their employer, account administrator or the privacy contact channel provided to them.
If the Provider receives a request that must be addressed by the Client, the Provider will forward it to the Client or assist in handling it in accordance with the applicable agreement and data processing agreement.