Privacy policy
The protection of your personal data is important to us. This website is deliberately kept simple: it sets no cookies, uses no analytics or tracking services and contains no contact or ordering forms. Below we explain the data processing that nevertheless takes place.
All passages marked with [ ] must be completed or removed by the operator before publication.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Deepa Food House, owner: Hardip Singh, Bahnstraße 22, 19322 Wittenberge, Germany. Phone: +49 3877 561440. Email: [add email address]
A data protection officer has not been appointed, as this is not required by law. [If a data protection officer has been appointed, add the details here.]
2. General information on data processing
Personal data means any information relating to an identified or identifiable natural person. We process personal data only insofar as this is necessary to provide a functioning website or where there is a legal basis for doing so.
This website uses no cookies, no web analytics, no tracking, no advertising networks, no social media plugins and no contact, reservation or ordering forms. Contact is made exclusively by telephone.
3. Hosting and server log files
This website is hosted by an external service provider: [add hosting provider, company name and address]. The provider processes the data generated when the website is accessed on our behalf, on the basis of a data processing agreement pursuant to Article 28 GDPR.
When you access this website, the hosting provider automatically collects information transmitted by your browser and stores it in so-called server log files. This comprises: the page or file requested, the date and time of access, the volume of data transferred, notification of successful retrieval, browser type and version, the operating system used, the referrer URL and the IP address of the requesting device.
This data cannot be attributed to specific individuals by us and is not merged with other data sources. Processing takes place on the basis of Article 6 (1) (f) GDPR. Our legitimate interest lies in the technically faultless provision, the security and the stability of this website.
The log files are deleted automatically after [add retention period in days, typically 7–30] days, unless they are required to investigate a specific security incident.
4. SSL / TLS encryption
For security reasons this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and a padlock symbol is displayed.
5. Contact by telephone
If you call us to reserve a table or enquire about a celebration, we process the information you provide (usually your name, telephone number, date, time and number of guests) solely in order to handle your request. The legal basis is Article 6 (1) (b) GDPR (steps prior to entering into a contract) or Article 6 (1) (f) GDPR.
Reservation notes are deleted once your visit has taken place, unless statutory retention obligations require otherwise.
6. Map display (OpenStreetMap)
On our contact page we embed a map from the OpenStreetMap service. The provider is the OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom.
When the map is loaded, your IP address is transmitted to OpenStreetMap's servers; without this transfer the map tiles could not be displayed. The legal basis is Article 6 (1) (f) GDPR; our legitimate interest is to make it easier for you to find our restaurant. Further information can be found in the OpenStreetMap Foundation's privacy policy at osmfoundation.org/wiki/Privacy_Policy.
[If the map is delivered only as a linked image without embedding, this section may be omitted.]
7. Recipients and transfers to third countries
Your data is not passed on to third parties, with the exception of the hosting provider named above acting as a processor and cases in which we are legally obliged to disclose it.
Transfers to countries outside the European Union are not intended. [If the hosting provider operates servers outside the EU, this section must be adjusted accordingly.]
8. Your rights as a data subject
Subject to the statutory requirements, you have the following rights:
- Right of access to the data we process about you (Article 15 GDPR)
- Right to rectification of inaccurate data (Article 16 GDPR)
- Right to erasure of your data (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object to processing based on legitimate interests (Article 21 GDPR)
- Right to withdraw consent with effect for the future (Article 7 (3) GDPR)
To exercise your rights, an informal message to the controller named above is sufficient.
9. Right to lodge a complaint with a supervisory authority
Without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement.
The authority responsible for us is: Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany.
10. Changes to this privacy policy
We update this privacy policy whenever changes to the website or to the legal situation make this necessary. The version published on this page always applies.
Last updated: [add date]