Privacy Policy
This Privacy Policy explains how we process personal data in accordance with the General Data Protection Regulation (GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and, where information is stored on or accessed from terminal equipment, Spanish Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE). It applies to our website and our social media profiles.
Controller
The controller within the meaning of Art. 4(7) GDPR is:
VDF Gastro S.L.U.
Plaça de Peralada, 14
07200 Felanitx
Illes Balears, Spain
Managing Director: Felix Passow
Email: info@restaurant-estragon.com
Data processed, purposes and data subjects
Depending on how you use our services, we process in particular:
connection and device data when you access the website;
usage data for audience measurement;
the language, display and interface preferences you select;
contact and communication data when you submit an enquiry;
reservation data such as your name, contact details, date, time and party size;
data generated when you interact with our social media profiles.
We process this data to provide a secure and functional website, display it in a user-friendly manner, statistically improve our services, deal with enquiries and table reservations, comply with contractual and legal obligations and manage our public relations. Data subjects include website visitors, guests, prospective guests and users of our social media profiles.
Legal bases
We process personal data on the following legal bases:
Art. 6(1)(a) GDPR where you have given your consent;
Art. 6(1)(b) GDPR where processing is necessary for a contract or to take steps at your request before entering into a contract;
Art. 6(1)(c) GDPR where processing is necessary to comply with a legal obligation;
Art. 6(1)(f) GDPR where processing is necessary for our or a third party's legitimate interests and those interests are not overridden by your interests, fundamental rights or freedoms.
Where information is stored on or accessed from your device, we also comply with Art. 22(2) LSSI-CE. We obtain your prior consent for storage that is not technically necessary.
Recipients and processors
We disclose personal data only where this is necessary for a purpose described in this Policy, where the law requires it or where you have consented. Recipients may include hosting and IT providers, reservation providers, communications providers, public authorities and legal or tax advisers.
Service providers that process data solely on our behalf are contractually bound in accordance with Art. 28 GDPR. Where a provider processes data for its own purposes, it is independently responsible for that processing.
Transfers to third countries
Processing outside the European Union or European Economic Area takes place only in accordance with Arts. 44 et seq. GDPR. Transfers to certified US organisations may be based on the European Commission's adequacy decision of 10 July 2023 concerning the EU-US Data Privacy Framework (DPF). Otherwise, we use in particular the European Commission's Standard Contractual Clauses or other appropriate safeguards. Details of specific providers are given below.
Erasure and retention
We retain personal data only for as long as it is needed for the relevant purpose. It is then erased or its processing is restricted unless statutory retention obligations or legitimate evidentiary needs require otherwise.
Business correspondence, books and business documents may in particular be subject to the six-year retention period in Art. 30 of the Spanish Commercial Code and tax-related periods, generally four years under Art. 66 of the Spanish General Tax Law. Different or longer special and limitation periods remain unaffected. Backup copies of the website database are currently retained on a rolling basis for up to approximately 33 days. Information erased from the production system may remain in a backup until that backup is overwritten.
Hosting and server logs
We operate the website, content management system, database, media files and analytics on a server in Germany. Our hosting provider and processor is:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
More information: Hetzner Privacy Policy
Each time you access our website, technically necessary connection data is processed. This may include your IP address, date and time, requested address, amount of data transferred, referrer URL, HTTP status, browser type and version, browser language and operating system. This processing is necessary to deliver the website, identify errors and protect our systems. The legal basis is Art. 6(1)(f) GDPR; our legitimate interests are the secure, stable and abuse-free operation of the website.
Server logs are generally retained for 70 days and then erased automatically. If a security incident occurs, affected log data may be retained until the incident has been fully resolved and, where necessary, for the establishment, exercise or defence of legal claims.
Cookies and browser storage
Our website uses cookies as well as your browser's local storage and session storage. The storage currently used is:
cookie-consent (cookie): contains the version, time and your cookie-settings selection. It is retained for one year and is necessary so that we can respect your decision. The legal basis is Art. 6(1)(f) GDPR; the storage is necessary for the consent-management feature you use within the meaning of Art. 22(2) LSSI-CE.
payload-locale (cookie): contains the selected language code and is retained for one year. The website sets this cookie only if you have consented to the “Preferences” category. The legal basis is your consent under Art. 6(1)(a) GDPR and Art. 22(2) LSSI-CE.
payload-theme (local storage): contains your express choice of light or dark display. The entry remains until you change it, select “automatic” or clear your browser storage. It is used solely to provide the display you requested.
info-banner:dismissed (local storage): remembers which current information notice you closed so that it does not immediately reappear. The value remains until a new notice is published or you clear your browser storage.
menuOpen (session storage): temporarily records whether the mobile navigation menu is open during the current browser session and is removed when the menu is closed or, at the latest, when the session ends.
The final three storage operations occur only following an interface action you requested and are necessary for the relevant feature. To the extent that they involve personal data at all, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the user-friendly operation of the website.
We do not use advertising, marketing or tracking cookies or cookies from advertising networks. You may change or withdraw your cookie consent at any time using “Cookie settings” in the website footer. You can also clear cookies and local storage in your browser, in which case stored settings may be lost.
Audience measurement with Umami
We use the open-source tool Umami to statistically evaluate the use of our website and improve our services. We self-host Umami on the same server in Germany. The script and collection endpoint are delivered through our own domain; analytics data is not transferred to an external analytics provider.
Umami does not use cookies and does not track visitors across different websites. It processes in particular the page visited and its title, time, referrer, browser language and screen size, as well as information about browser, operating system, device type and approximate geographic region derived from technical data. The IP address and user agent are used on the server to generate a pseudonymous session identifier; the IP address itself is not stored in the analytics database. We do not assign names, email addresses or our own user identifiers to Umami sessions. Nevertheless, as a precaution we treat session and usage data as personal data.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is privacy-friendly audience measurement and improvement of the website. The data is retained only for as long as it is needed for comparative usage statistics and is then erased. If you enable “Do Not Track” (DNT) in your browser, Umami will not collect data.
Map display using CARTO
The website displays an interactive MapLibre map. The map style, fonts and tiles are automatically retrieved from servers of the CARTO platform (*.cartocdn.com). As a technical consequence of these requests, CARTO receives in particular your IP address, the time, requested file, referrer and information about your browser and operating system.
The provider is CartoDB Inc. (CARTO), 307 Fifth Avenue, Floor 9, New York, NY 10016, USA. The legal basis for the integration is Art. 6(1)(f) GDPR. Our legitimate interest is to provide clear directions to our restaurant. CARTO states that it is certified under the EU-US Data Privacy Framework and relies on Standard Contractual Clauses for transfers not covered by that framework.
More information: CARTO Privacy Notice
The “Google Maps” and “Apple Maps” buttons are external links only. No data is transmitted to Google or Apple through these links when our website is displayed. Only when you click a link do you access the relevant service on your own responsibility. The Google Privacy Policy or Apple Privacy Policy then applies.
Online reservations through Agora Bookings
On our reservations page we embed a script and reservation window from Agora Bookings (bookings.agorapos.com). The service provider is:
Spotlinker, S.L.
Avenida de los Torneros, 7
28830 San Fernando de Henares, Madrid
Spain
Tax ID (CIF): B-8630021
Email: ayuda@spotlinker.com
Privacy contact: dpo@spotlinker.com
When you open the reservations page, connection data such as your IP address, date and time, referrer and browser and device information is transmitted to Spotlinker to deliver the script and embedded window. If you make a reservation, the data you enter – in particular your name, contact details, requested date and time and party size – is transmitted to Spotlinker and to us so that the reservation can be reviewed, confirmed and performed.
The legal basis for reservation data is Art. 6(1)(b) GDPR. We additionally process the technical connection data on the basis of Art. 6(1)(f) GDPR; our legitimate interest is to offer straightforward online reservations. Fields marked as required are needed to enter into and perform the reservation. Without them, an online reservation is not possible; you may contact us by telephone instead.
Spotlinker's publicly available notice lists subprocessors and backups in the United States. Where reservation data is transferred to a third country, the transfer must comply with Arts. 44 et seq. GDPR. Further information about recipients, third-country transfers and retention criteria is available in the Agora Bookings Privacy Policy.
We retain reservation data for as long as it is necessary to perform the reservation, deal with possible queries and comply with legal obligations. It is then erased or its processing is restricted.
Contact by form, email or post
If you contact us through a form provided on the website, by email or by post, we process your contact details and the content of your message in order to answer your enquiry. Form entries are stored for this purpose in our content management system on the German server.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the appropriate handling and documentation of enquiries. If the enquiry concerns a reservation, contract or pre-contractual steps, Art. 6(1)(b) GDPR also applies. Where consent is requested, the legal basis is Art. 6(1)(a) GDPR.
We erase the data once the enquiry has been fully dealt with and there are no remaining retention or evidentiary obligations. Where the correspondence is a business record or is tax-relevant, the periods described in “Erasure and retention” apply.
Contact by telephone
If you call us, we process your telephone number, if transmitted, and the information provided during the call to deal with your request and, where necessary, call you back. The legal basis is Art. 6(1)(f) GDPR or, for contract-related matters, Art. 6(1)(b) GDPR. We erase the data when it is no longer needed for these purposes and no statutory retention obligation applies.
Facebook and Instagram
Our website links to our Facebook and Instagram profiles. We do not use social plugins, the Meta Pixel or embedded posts, so merely visiting our website does not transmit data to Meta.
If you visit our profiles or communicate with us there, Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, processes personal data under its own responsibility. We process your messages, comments and other interactions to communicate with you and present our services. The legal basis is Art. 6(1)(f) GDPR and, for contract-related enquiries, additionally Art. 6(1)(b) GDPR.
For certain statistical data (“Page Insights”), we and Meta are joint controllers under Art. 26 GDPR. Under the joint-controller arrangement, Meta takes primary responsibility for informing data subjects and handling data-subject rights in relation to Insights data. You may also exercise your rights against us. Meta may process data in the United States; Meta Platforms, Inc. states that it is certified under the EU-US Data Privacy Framework.
More information:
Information about Page Insights
Your rights
Subject to the applicable statutory conditions, you have the following rights:
access under Art. 15 GDPR;
rectification under Art. 16 GDPR;
erasure under Art. 17 GDPR;
restriction of processing under Art. 18 GDPR;
data portability under Art. 20 GDPR;
objection to processing based on Art. 6(1)(e) or (f) GDPR under Art. 21 GDPR;
withdrawal of consent with effect for the future under Art. 7(3) GDPR.
To exercise your rights, contact us using the details above. Where processing is based on your consent, withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority generally responsible for us is:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6
28001 Madrid
Spain
www.aepd.es
No automated decisions
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
Data security
We implement appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. Data transmitted between your browser and our website is encrypted using TLS. We review and update our security measures in line with technological developments.
Last updated: 25 July 2026