Data controller
- Controller: Robert de Nola, S.L. (Robert de Nola)
- Tax ID (NIF): B60060076
- Registered address: Passeig del Remei, 48-50 · 08140 Caldes de Montbui (Barcelona), Spain
- Premises: Passeig del Remei, 50 · 08140 Caldes de Montbui (Barcelona, Spain)
- Contact email for data protection matters: clients@robertdenola.cat
What we process
Table bookings made through the Website’s form
- Data: name and surname, telephone, email, party size, date and time of the booking, and your answers to any additional questions the restaurant has set up on the form (for example, remarks).
- Purpose: to manage your booking, send you the confirmation by email and contact you if necessary.
- Legal basis: performance of the booking contract (art. 6(1)(b) GDPR).
- Allergies and intolerances: if the form asks about them and you provide them, they are health data. They are processed only with your explicit consent (art. 9(2)(a) GDPR), which we ask for with a specific tick box before the booking is sent, and solely to attend to your booking. You may leave them out and tell the staff when you arrive.
- Processor: the taula.ai reservation system, operated by Joan Sanfeliu Vilarrasa (Barcelona), which processes the data on the restaurant’s behalf and hosts it on Amazon Web Services, region eu-west-3 (Paris, European Union).
- Retention: 24 months from the date of the booking; afterwards, blocked for the applicable statutory limitation periods.
Telephone and email
- Data: telephone number or email address and the content of the communication.
- Purpose: to deal with the enquiry, booking or request you send us.
- Legal basis: pre-contractual steps at your request and performance of the contract (art. 6(1)(b) GDPR).
- Retention: for as long as the matter is being handled and, afterwards, for the statutory limitation periods.
Browsing the Website
- The Website uses no analytics tools or advertising pixels and sets no cookies. The fonts are served from the Website itself: loading a page makes no request to third parties.
Google Maps
- On the “Find us” page, the map loads only if you click “Show the map”. At that moment your browser connects to Google (Google Ireland Limited), which receives your IP address and may set its own cookies, governed by its privacy policy. Until you click, no data is sent to Google. The links “Open in Google Maps” and “How to get here” take you to Google’s website or app.
Links to social networks
- Instagram, Facebook, X and YouTube are links, not embedded content: until you click them, no data is sent to those platforms. Once there, each platform’s own privacy policy applies.
Technical server logs
- Data: IP address, user agent, date and time of access.
- Purpose: to serve the Website, keep it secure and detect incidents.
- Legal basis: legitimate interest in information security (art. 6(1)(f) GDPR).
- Retention: the period the hosting provider applies to its technical logs.
Recipients of the data
3.1. Data is not disclosed to third parties, except where required by law.
3.2. The following providers, acting as processors, have access to the data to the extent needed to provide the service:
| Provider | Service | Location |
|---|---|---|
| Joan Sanfeliu Vilarrasa (Sanfeliu / taula.ai) | Development and maintenance of the Website; reservation system | European Union (Barcelona) |
| Amazon Web Services EMEA SARL | Hosting of the Website (AWS Amplify) and of the reservation system | European Union, region eu-west-3 (Paris) |
| Google Ireland Limited | Google Maps map, only if you click “Show the map” | European Union and United States |
3.3. International transfers: no international transfers of data are made, with the sole exception of the Google Maps map if you choose to load it, in which case Google may transfer data to the United States under the EU-US Data Privacy Framework and, where applicable, standard contractual clauses.
Your rights
4.1. You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent given, by writing to clients@robertdenola.cat and stating the right you are exercising. We may ask you to prove your identity.
4.2. If you believe your data is not being processed correctly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) or with the Catalan Data Protection Authority (apdcat.gencat.cat).
Security
5.1. We apply appropriate technical and organisational measures to protect your data, including encryption of communications over HTTPS, minimisation of the data requested and access control to our systems.
Minors
6.1. The Website is not aimed at children under 14 and does not knowingly collect data from minors.
Changes to this policy
7.1. This policy may be updated to reflect changes in the law or in the service. The version in force is the one published on the Website.