The essentials
- Sanito is used to keep a food business’s hygiene records. Those records belong to the business, not to us.
- Your data is hosted in the European Union, on Google Cloud infrastructure.
- In the app, photos of labels and invoices sent to Google’s text extraction service may be processed outside the EU. The marketing website also uses Google Analytics, only with your consent, as described below.
- We do not sell or resell your data, or use it for advertising or model training.
- Each business can only see its own data. This separation is enforced by the server, not by the app.
1. Who processes your data
The Sanito app is published by Sanito, in France. For any questions about your data, email contact@sanito.app.
There are two distinct roles, and the distinction matters:
- For account data — your professional identity, login credentials and technical operating data — the publisher is the data controller.
- For hygiene records entered in the app — temperature logs, tracked batches, cleaning, deliveries and non-conformities — the business is the data controller. These records provide evidence of its own regulatory obligations. The publisher acts as a data processor: it hosts and organises the records but does not decide what is recorded.
2. What Sanito processes
Requests sent through the marketing website
When you use the contact form, Sanito receives your name, email address, business name if provided, the reason for your request and your message. Our email delivery service sends this information to contact@sanito.app so that we can handle your request. If you choose to be notified of the launch, your address is also used to send you that information, based on your consent. You can withdraw this consent by emailing the same address. You are not automatically subscribed to a newsletter.
Temporary technical counters associated with hashes of your IP address and email address help limit abusive submissions. Your message is not stored in these counters. You can request access to, correction of or deletion of your request by emailing contact@sanito.app.
Marketing website analytics
With your consent, sanito.app loads Google Analytics (ID G-LVYKMB9EGV), provided by Google, to measure visits and actions such as exploring a feature, playing the video or receiving a contact request. The tag does not load before you agree. Accepting and rejecting are equally easy, and you can change your choice using ‘Manage cookies’ in the homepage footer.
Statistics may include a browser identifier, device information, the page viewed and the source of the visit. Events added by Sanito do not transmit your name, email address, business name or message contents. Advertising personalisation features and Google Signals are disabled in the tag.
Your choice is stored on this device for 180 days. Analytics cookies are configured to expire after 180 days without automatic renewal and are removed from the website when you withdraw your consent. Google may process data outside the European Union: see Google’s privacy policy. Rejecting analytics does not prevent you from using the website or the form.
Account and professional identity
Email address, password (never stored in plain text), display name, job role, phone number and profile photo if you provide them. Where applicable, the type, date and provider of your food hygiene training, together with supporting documentation — these documents may be requested during a food safety inspection.
Operational records
Everything your team records: temperature logs and corrective actions, tracked batches with batch numbers, expiry dates and origins, cleaning tasks, goods received, frying oil checks, cooling records, non-conformities, recipe specification sheets and allergens, job descriptions, suppliers, business documents and scanned invoices.
These entries carry the name of the person who made them and a timestamp. This is not a design choice: a hygiene record without an author or date has no evidentiary value during an inspection.
Photos
Photos of labels, invoices, equipment, prepared food and business documents, as well as profile photos.
Technical data
Connection and error logs needed to operate and secure the service, retained for a limited period.
The app collects no location data, does not track your browsing and contains no advertising trackers. On Android, it only requests internet access, network status and permission to display notifications.
3. Why we process data, and on what basis
Scroll horizontally to see all columns.
| Purpose | Legal basis |
|---|---|
| Create and manage your account, provide the service | Performance of a contract |
| Maintain hygiene records and produce the inspection file | The business’s legal obligation (the EU hygiene package, EC Regulations 852/2004 and 178/2002) |
| Alert you to a deviation, a deadline or a product recall | Performance of a contract and legal obligation |
| Secure the service, prevent abuse and diagnose failures | Legitimate interest |
| Contact you about your account (invitation, password reset) | Performance of a contract |
4. Where your data is hosted
The service runs on Google Cloud and Firebase. Data locations are as follows:
- Database:
eur3multi-region — European Union. - Server processing:
europe-west1, Belgium. - Files and photos: storage within the same Google Cloud project.
5. Service providers and what they can see
Scroll horizontally to see all columns.
| Provider | Role | Data shared |
|---|---|---|
| Google Ireland / Google Cloud (Firebase) | Authentication, database, storage, server processing and hosting | All data, hosted in the EU |
| Google — AI text extraction service | Read a photographed label or invoice to extract its text | Only the image you have just taken, when you request text extraction |
| Email delivery service | Send transactional messages | The recipient’s email address and message contents |
Transfers outside the European Union. The text extraction service may process the image outside the EU. This processing takes place when requested: the image is analysed and the extracted text is returned for you to check before saving. If you do not want an image to leave the EU, use manual entry, available alongside each photo capture option: no image is then transmitted.
Product recall notices come from RappelConso, the French government’s public database. This data comes into Sanito; none of your data is sent to RappelConso.
6. How long data is kept
- Account: for as long as it exists. When it is deleted, the associated personal data is erased.
- Hygiene records: the business decides, based on its own retention obligations. They remain accessible until the business deletes them.
- Technical logs: a limited period, strictly related to diagnostics and security.
A hygiene record naming an employee who has left the business retains their name: this preserves the record’s evidentiary value. Removing it would amount to backdating food safety evidence.
7. Who can access what
Each business’s data is kept separate. An account linked to one business cannot read or write another business’s data — the server enforces this rule on every read and write, regardless of the installed app. Within a business, the manager can see all records; team members can access the modules they need for their work.
8. Your rights
You have the right to access, rectify and erase your data, restrict or object to its processing, and obtain data portability, as well as the right to give instructions about what happens to your data after your death.
Email contact@sanito.app. If your request concerns operational records, contact your business’s manager first, as they are the data controller — we will assist them.
You can lodge a complaint with the CNIL at any time.
9. Deleting your account
The steps to follow, what is deleted and what remains are explained on a dedicated page: request deletion of my account.
In brief: email contact@sanito.app from the address associated with the account. Your request is processed within thirty days. If you manage the last account for a business, deleting it also deletes the business and its records — export your inspection file first.
10. Security
Communications are encrypted in transit, and the hosting provider encrypts data at rest. Access is protected by authentication, and data separation rules are enforced on the server. Passwords are never stored in plain text and the publisher cannot access them. Signing keys and infrastructure secrets are kept outside the app’s code.
11. Minors
Sanito is a professional tool for people working in kitchens. It is neither designed for nor offered to children under fifteen.
12. Changes
This policy may change as the service evolves. Any substantial change will be announced in the app, and the effective date above will be updated.