What we collect when you contact us, why we keep it, and how to have it removed. The short version: only what you type into the contact form, and only so we can reply.
Last updated: 11 August 2026
Kalsora is a menu onboarding service for ordering platforms, operating the website kalsora.com. We are the ones who decide what happens to the data described on this page, and we work from Greece, inside the European Union. For anything on this page — a copy of your data, a correction, a deletion — write to contact@kalsora.com and it reaches the person who can action it.
Only what you choose to send us through the contact form on this site:
Nothing else is asked for, and we do not buy, scrape or enrich this data from other sources.
To read your message and reply to it, and to carry out any work you go on to ask us for. Nothing else. We do not sell, rent or share your details with third parties for marketing, and you will not be added to a mailing list you did not ask for.
The legal basis is our legitimate interest in answering a business enquiry you started, and — where work follows — performance of a contract with you.
If you send a menu for a pilot or a paid catalog, it is used to build that catalog and for nothing else. We do not publish it, resell it, or use it to train anything. Source files are deleted once the catalog is delivered and any revision window has closed, unless you ask us to keep them on file for future work.
This site sets no cookies and runs no analytics or tracking scripts. There is nothing to opt into, so there is no cookie banner and no consent wall.
None, currently. Every file this page needs — the stylesheet, the scripts, the typefaces, the images — is served from kalsora.com itself, so simply reading this site sends your IP address to nobody but our host. There is no font CDN, no tag manager, no embedded video, no chat widget.
The contact form currently has no form provider behind it: submitting it opens your own email client with the message pre-filled, so the email travels through your mail account and ours, and through nothing in between. If a form-processing service is ever introduced, it will be named here before it goes live.
Our web hosting provider keeps standard server logs, as every host does.
Enquiries that go nowhere are deleted within 12 months. If we end up working together, correspondence is kept for as long as the working relationship lasts, plus any period Greek law requires business records to be retained.
Wherever you are, you can ask us to:
Email contact@kalsora.com and we will action it within one month, free of charge. These rights are applied to everyone who asks, not only to people the GDPR happens to cover — including residents of US states with their own privacy laws. We do not sell or share personal information as those laws define it, and we do not use it for targeted advertising or profiling.
We are established in Greece, so if you think we have handled your data badly you can complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) at dpa.gr. If you are in the United States you can also raise it with your state Attorney General.
We are based in Greece, so a message you send is read and stored in the European Union. If you are writing from the United States, that is an international transfer of your data — one you initiate by contacting us, and one we keep as small as the enquiry itself.
The site is served over HTTPS. Messages land in a password-protected mailbox with two-factor authentication. No system is perfectly secure, but the amount of data we hold is kept deliberately small.
If this policy changes, the date at the top of this page changes with it.