This English version is provided for convenience. In case of discrepancy, the Catalan and Spanish versions prevail.
1. Data controller
- Controller: [RAÓ SOCIAL] (L'Home dels Nassos)
- Tax ID (NIF): [NIF]
- Address: [DOMICILI FISCAL]
- Phone: 633 19 76 67
- Email: [CORREU ELECTRÒNIC]
2. What data we process
When you book a table with the form, we process: full name, phone number, email (optional), the number of guests, any notes you add, and the chosen day, time and table.
Health data. The notes field may contain food allergies or intolerances, which the GDPR treats as health data, a special category of data (art. 9). We only process it if you give your explicit consent by ticking the specific checkbox in the form, and only the restaurant's kitchen and dining-room staff uses it, to prepare your meal safely. We don't use it for any other purpose or share it with third parties. Please write only what is necessary.
3. What we use it for
- Managing your booking: holding the table, contacting you to confirm or change it, and attending to you on the day of your visit.
- Preparing your menu taking into account any allergies or intolerances you tell us about (only the restaurant's kitchen and dining-room staff).
- Sending you the booking confirmation, if you leave us your email.
We don't build profiles, make automated decisions, or use the data for advertising.
4. Legal basis
Taking pre-contractual steps at your request (art. 6.1.b of Regulation (EU) 2016/679, GDPR) and the consent you give by ticking the form's checkbox (art. 6.1.a GDPR). You can withdraw consent at any time, without affecting the lawfulness of earlier processing.
For allergies and intolerances in the notes, the legal basis is your explicit consent (art. 9.2.a GDPR), given by ticking the specific checkbox in the form. If you'd rather not give it, leave the notes blank and tell the staff on the day, or book by phone. You can withdraw it at any time by writing to [CORREU ELECTRÒNIC], and we will delete that data.
5. How long we keep it
Booking data is kept for [TERMINI DE CONSERVACIÓ, p. ex. 12 mesos després de la reserva]. If the visit generates an invoice, the data it contains will be kept for the periods required by tax and commercial law.
6. Who we share it with
We do not share your data with third parties, except where legally required. To run the website we rely on providers who process data on our behalf (data processors), under contract and with appropriate safeguards:
- Supabase: the database where bookings are stored.
- Cloudflare: website hosting (Cloudflare Pages).
- Resend: sending confirmation emails and the booking alert to the restaurant.
Some of these providers may process data outside the European Economic Area. In such cases, the transfer is covered by the safeguards set out in the GDPR, such as the European Commission's standard contractual clauses or the EU-US Data Privacy Framework.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to [CORREU ELECTRÒNIC] or contacting the restaurant directly, stating which right you wish to exercise. If you believe we haven't properly handled your request, you can file a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Cookies, map and local storage
This website does not use advertising, analytics or third-party cookies, and fonts are served from the same domain. The OpenStreetMap map only loads if you press "Show the map"; your browser then connects to OpenStreetMap's servers, which receive your IP address. The browser stores your chosen language (Catalan, Spanish or English) to remember it on your next visit. The private admin area stores the authorised user's session in the browser, strictly necessary for it to work.
9. Security
We apply technical and organisational measures to protect the data: encrypted connection, access to bookings limited to the restaurant's authorised staff, and storage with providers that offer security guarantees.