Skip to content
La cassola d'or

Privacy policy

Last updated: [DATA D'ACTUALITZACIÓ]

This English version is provided for convenience. In case of discrepancy, the Catalan and Spanish versions prevail.

1. Data controller

2. What data we process

When you book a table with the form, we process: your full name, phone number, email address (optional), the number of people, any notes you add, and the day, time and table you choose.

Health data. The notes field may contain food allergies or intolerances, which the GDPR treats as health data, a special category of data (art. 9). We only process them if you give your explicit consent by ticking the specific box in the form, and they are only used by the restaurant's kitchen and floor staff to prepare your meal safely. We do not use them for any other purpose or share them with third parties. Please write only what is needed.

3. Why we use it

We do not build profiles, make automated decisions or use your data for advertising.

4. Legal basis

Taking steps at your request before entering into a contract (art. 6.1.b of Regulation (EU) 2016/679, GDPR) and the consent you give by ticking the box in the form (art. 6.1.a GDPR). You can withdraw your consent at any time, without affecting the lawfulness of earlier processing.

For allergies and intolerances in the notes, the legal basis is your explicit consent (art. 9.2.a GDPR), given by ticking the specific box in the form. If you prefer not to give it, leave the notes blank and tell the staff on the day, or book by phone. You can withdraw it at any time by writing to [CORREU ELECTRÒNIC], and we will delete that data.

5. How long we keep it

Booking data is kept [TERMINI DE CONSERVACIÓ, p. ex. 12 mesos després de la reserva]. If your visit results in an invoice, the data on it will be kept for the periods required by tax and commercial law.

6. Who we share it with

We do not share your data with third parties unless required by law. To run the website we use providers that process it on our behalf (data processors), under contract and with appropriate safeguards:

Some of these providers may process data outside the European Economic Area. In that case the transfer relies on the safeguards set out in the GDPR, such as the European Commission's standard contractual clauses or the EU-US Data Privacy Framework.

7. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to [CORREU ELECTRÒNIC] or at the restaurant, saying which right you want to exercise. If you think we have not handled your request properly, you can complain to the Spanish Data Protection Agency (www.aepd.es).

8. Cookies, map and local storage

This website uses no advertising, analytics or third-party cookies, and fonts are served from our own domain. The OpenStreetMap map only loads if you press “Show the map”; your browser then connects to OpenStreetMap's servers, which receive your IP address. Your browser stores your language choice (Catalan, Spanish or English) to remember it on your next visit. The private admin area stores the authorised user's session in the browser, which is strictly necessary for it to work.

9. Security

We apply technical and organisational measures to protect your data: encrypted connections, access to bookings limited to authorised restaurant staff, and storage with providers that offer security guarantees.