Terms of use
Version: 9 September 2026. These terms describe the free menu service for businesses.
The service
VULU RAZI provides tools to create, publish and share restaurant and bar menus. Guests view menus in their browsers. Vulu Menu does not take food orders, process guest payments or sell the venue’s products.
Organisation number: 921080840.
Business address: Munkestranda 6, 6076 Moltustranda, Norway.
Your business and content
You must be authorized to manage the business you register. Your business is responsible for menu accuracy, prices, ingredient and allergen declarations, dietary labels and the rights to uploaded content. Check your menu before publishing and keep it updated. Do not upload unlawful content or personal information about guests.
You retain ownership of your content and permit us to store, process and display it to provide your menu. Public menu links can be shared by anyone.
Accounts and changes
Keep passwords and private setup links confidential. Assign staff access carefully and remove it when no longer needed. Publishing applies the current item draft to your guest menu. Availability and saved venue design changes can take effect immediately.
Availability and support
The service may be interrupted for maintenance or incidents. Keep another way for guests to read your menu. Contact support for access problems, content removal or ending use of the service.
Cost, changes and ending use
This version is free. We will not charge your business or begin a paid subscription without a separate agreement. You can stop using the service at any time and ask support to export or erase your workspace. Access may be suspended to address unlawful content, misuse or an immediate security risk. Where practicable, we explain the reason and give you an opportunity to correct the issue or retrieve your content.
We notify the account owner before material changes to these terms or discontinuing the service, except where an immediate change is necessary for security or legal reasons. Mandatory legal rights remain unaffected. Norwegian law governs this business agreement, subject to any mandatory law that applies. Contact support first about disputes; unresolved disputes may be brought before a court with competent jurisdiction.
Data-processing agreement
When your business supplies personal information for its workspace, it is the controller and the Vulu Menu operator is its processor. These terms are your documented instruction to store, organise, display, secure, export and erase that information to provide the service for the duration of your workspace. The people concerned are your authorised staff and any people identified in content you choose to upload. The information may include staff names, contact details, roles, workspace activity and uploaded text or images. Do not submit sensitive personal information or guest customer lists.
We process this information only on your documented instructions, unless law requires otherwise; in that case we inform you unless prohibited. We inform you if an instruction appears to infringe data protection law. People permitted to access the information must maintain confidentiality. Safeguards include encrypted transport, password hashing, access roles, tenant isolation, restricted storage, audit records, rate limits and recovery backups.
You authorise Railway for application/database hosting, Cloudflare for delivery/security/storage, and Resend for account emails when enabled. We require applicable data-processing obligations from subprocessors and remain responsible for our obligations to you. We will give the account owner at least 14 days’ notice of a new subprocessor, allowing an objection on reasonable data-protection grounds before the change. If it cannot be resolved, you may end the affected service and retrieve or erase your data.
We assist with access, correction, export, erasure, security, incident reporting and required impact assessments, taking account of the service and information available to us. We notify the business without undue delay after becoming aware of a personal-data breach affecting its workspace and provide available information needed to investigate and respond. We make information needed to demonstrate these obligations available and cooperate with reasonable audits, with appropriate protection for other customers and security.
At the end of the service, we return or erase workspace personal information at your choice, except information required by law. Remaining recovery copies stay restricted until expiry, and deletions are reapplied following restoration. International processing is subject to applicable transfer safeguards described in the privacy notice. Contact support for additional documented instructions or to exercise these rights. These data-processing terms prevail over conflicting service terms for the processing they cover.