EMIR ETRESTAURANT & EVENTS CATERING

LEGAL

Privacy

What data we process, what for — and how to have it deleted.

Noch auszufüllen: Diese Seite enthält Platzhalter (vatId). Bitte in src/config/legal.ts eintragen — ohne vollständige Angaben darf die Seite nicht online gehen.

1. Controller

The controller for the processing of personal data on this website within the meaning of the GDPR is:

EMIR-ET GmbH, Allerheiligenstraße 21, 60313 Frankfurt am Main, Deutschland

Phone: +49 69 61994023

E-mail: info@emiretrestaurant.de

We have not appointed a data protection officer; we are not legally required to.

2. Overview

You can use this website in full without giving us any personal data: the menu, opening hours, prices and information are shown without us learning anything about you.

Personal data only arises when you act — booking a table, placing an order, sending an event enquiry or allowing notifications.

We use no advertising or analytics trackers, build no user profiles and never pass your data on for advertising purposes.

3. Table reservations

Data processed: name, phone number, party size, date and time, and an optional message.

Purpose: to hold the table and to reach you about questions or changes.

Legal basis: Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract).

Without a name and phone number we cannot accept a reservation.

4. Event and catering enquiries

Data processed: name, phone number, occasion, date, number of guests and your message.

Legal basis: Art. 6(1)(b) GDPR.

If you expressly choose to, you can send the enquiry via WhatsApp instead. Your data then leaves this website and is processed by WhatsApp Ireland Ltd. under their privacy terms. The legal basis in that case is your consent, Art. 6(1)(a) GDPR — WhatsApp only opens after you click the button. The same applies to the optional WhatsApp buttons shown for reservations and orders.

5. Orders

Data processed: name, phone number, the items and quantities ordered, the pick-up time and optional notes (e.g. allergies).

Purpose: preparing, handing over at pick-up and invoicing your order.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract); for retaining the records also Art. 6(1)(c) GDPR (German commercial and tax law).

Each order carries a randomly generated tracking link. Anyone who has that link can see the order — please do not share it.

6. Push notifications

If you allow notifications we store the technical identifier your browser or device issues for that purpose, together with your chosen language.

Purpose: status updates and reminders about your own order or table reservation only. We never send advertising by push.

Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw it at any time by turning notifications for this website or our app off in your browser or device settings; withdrawal takes effect for the future.

In a browser, the notification is delivered by the browser vendor’s push service (e.g. Google, Apple, Mozilla). In our app it is delivered via Google’s Firebase Cloud Messaging and, on iPhones, additionally via the Apple Push Notification service. The push identifier and the text of the notification are transmitted to them.

7. Loyalty programme

Taking part is voluntary and only begins once you explicitly tick the box at checkout. Without that tick your order is processed as normal and no loyalty profile is created.

Data processed: your phone number (normalised, as the identifier), the name from your order, the time of your consent, the number of orders you have completed and the coupons earned from them.

Purpose and scope: we store your phone number with every order anyway, in order to perform the contract. What the tick additionally permits is the linking: joining individual orders under that number into a persistent customer profile and counting them, so that after a set number you receive a coupon.

Legal basis: Art. 6(1)(a) GDPR (consent).

Withdrawal: you can tap "Leave the loyalty programme" under "My orders" at any time. Your loyalty profile and any open coupons are then deleted. Your orders themselves are not affected — they are subject to commercial and tax retention obligations (§ 147 AO, § 257 HGB).

Separate programmes: the restaurant and the butchery are independent companies and run separate loyalty programmes. Consent given to one does not apply to the other, and coupons are not transferable.

Deletion period: loyalty profiles with no completed order in the last 24 months are deleted.

8. Data that stays on your device

The website remembers locally in your browser: your language choice, the contents of your basket, the links to your most recent orders, and whether you have already dismissed a notice.

None of this is transmitted to us or used for analytics. It disappears when you clear this site’s data in your browser.

We set no advertising or analytics cookies, which is why there is no consent banner.

9. Server log files

When the pages are requested, the hosting provider automatically records the usual access data (address requested, time, volume transferred, browser type, referrer, IP address). This serves secure, trouble-free operation and is not combined with other data.

To stop the enquiry forms being abused by automated mass submissions, we count requests per sender. For this we do not store your IP address, only a non-reversible hash of it, which we delete after six weeks at the latest. Sign-in attempts to the administration area are logged with the IP address to protect against attacks and deleted after two months at the latest.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical provision and security).

10. Recipients and processors

• IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, as hosting provider, runs the servers this website is delivered from and the database in which orders and enquiries are stored. A data processing agreement under Art. 28 GDPR is in place.

• Google (Firebase Cloud Messaging) — only if you allow notifications in our app — and, on iPhones, Apple (Apple Push Notification service), solely for delivering those notifications.

• The push services of browser vendors, if you allow notifications in your browser, likewise solely for delivery.

A transfer to third countries (in particular the USA) is only possible within the push services and relies on the EU-US Data Privacy Framework or standard contractual clauses. Beyond this we do not pass your data on, unless we are legally obliged to.

Fonts, images and videos are loaded from our own server. No fonts are fetched from Google servers.

11. Retention

Reservations and event enquiries are deleted automatically no later than 12 months after the date they concern.

Orders are retained for 8 years from the end of the calendar year of the order, to meet German commercial and tax law obligations (§ 147 AO, § 257 HGB), and are then deleted automatically.

Push identifiers for an order or reservation are deleted automatically no later than six months after sign-up — sooner, as soon as the push service reports them as invalid.

12. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR) at any time, as well as the right to withdraw consent you have given.

To exercise them, simply write to info@emiretrestaurant.de or call +49 69 61994023. We reply within one month.

You may also lodge a complaint with a supervisory authority. The one responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany.

13. Deleting your data

You can ask us to delete everything we hold about you at any time — an e-mail to info@emiretrestaurant.de quoting the name and phone number you used for the order is enough. We then delete everything we are not legally required to keep.

The order history stored in your browser is removed by clearing this site’s data.

You do not create a customer account here, so there is no account to delete. The administration area is for staff only.

14. Changes to this policy

We update this privacy policy when the website or the legal situation changes. The version published here applies.

Last updated: 2026-09-24

Last updated: 2026-09-24