At Carbón Carbón we treat your personal data with the same care we give the produce that reaches our grill: we only ask for what is essential, we use it for what we tell you, and we keep it only as long as needed. This policy explains how, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 (LOPDGDD).
1. Data controller
Controller: Carmelo González Guisado (Restaurante Carbón Carbón)
Tax ID (NIF): 08872406H
Address: Calle Felo Monzón n.º 11, alto izquierda, Arrecife, 35500, Las Palmas, Spain
Telephone: +34 616 321 296
WhatsApp: +34 691 474 823
Data Protection Officer: not appointed (the cases set out in Article 37 GDPR do not apply)
2. What data we process and where it comes from
We only process data you give us voluntarily. We do not buy databases and we do not obtain information from third parties.
Booking form
- Identification and contact data: name and telephone number.
- Booking details: date, time and number of guests.
- Comments: any free text you choose to write (allergies, celebrations, preferences).
Name, telephone number and booking details are mandatory: without them we cannot process the request. The comments field is optional.
Important: how this data travels. The form does not store anything on a server of ours. When you press "Send request", WhatsApp opens on your device with a message already drafted, and it is you who decides to send it. In other words, the request reaches us as an ordinary WhatsApp message and is held on that platform and on the restaurant's phone. If you do not send the message, we receive nothing at all.
If you would rather not use WhatsApp, you can book by calling +34 616 321 296.
Allergy and intolerance information
If you tell us about food allergies or intolerances, that information may constitute health data, which the GDPR treats as a special category (Article 9). We process it only because you choose to share it voluntarily and explicitly so that we can prepare your service safely, and the legal basis is your explicit consent (Article 9(2)(a) GDPR), which we collect through a dedicated tick box in the form itself. It is used exclusively by our kitchen and floor staff for that specific booking, and it is deleted together with the rest of the message.
Bear in mind that, as the request is sent through WhatsApp, this information travels over that platform like any other message. If you would rather not put it in writing, do not type it into the form: you can tell us by telephone or in person when you arrive. We will take it into account just the same.
Contact by telephone or WhatsApp
- The contact details and the content of the message you send us.
- In the case of WhatsApp, the conversation takes place on that platform's infrastructure and is subject to its own terms and privacy policy.
Browsing data
- IP address, browser and device type and pages visited, processed by our hosting provider for security and operational purposes.
- Information stored locally in your browser, described in our Cookies Policy.
3. Why we use your data and on what legal basis
| Purpose | Legal basis | If you do not provide it |
|---|---|---|
| Managing and confirming your booking request, and contacting you if there is an issue. | Pre-contractual measures and performance of the restaurant service contract (Art. 6(1)(b) GDPR). | We could not process the booking. |
| Adapting our service to allergies or intolerances you tell us about. | Explicit consent (Arts. 6(1)(a) and 9(2)(a) GDPR). | We could not take your dietary needs into account. |
| Answering enquiries received by telephone or WhatsApp. | Legitimate interest in replying to those who contact us (Art. 6(1)(f) GDPR). | We could not reply to you. |
| Complying with tax, accounting and consumer-protection obligations. | Compliance with a legal obligation (Art. 6(1)(c) GDPR). | Mandatory by law where applicable. |
| Ensuring the security, availability and correct operation of the website. | Legitimate interest in protecting our systems (Art. 6(1)(f) GDPR). | Browsing is not possible without this basic processing. |
| Measuring website use in aggregate form and, where applicable, running marketing activities. | Your consent, given through the cookie panel (Art. 6(1)(a) GDPR). | None: the site works exactly the same and you may refuse. |
We do not make automated decisions producing legal effects, and we do not profile you.
4. How long we keep it
- Booking requests: as they arrive as WhatsApp messages, they remain in the conversation until we delete it. We undertake to erase booking conversations within a maximum of 12 months from the date of service, unless a complaint is pending.
- Allergy information: deleted together with the message of the booking it relates to. We do not copy it into any database or customer record.
- Enquiries and messages: up to one year from the last interaction, unless retention is needed to handle a claim.
- Tax and accounting records: for the periods required by law (generally between 4 and 6 years, depending on the applicable rules).
- Cookie consent record: 12 months, after which we ask you again.
Once these periods end, data is deleted or anonymised so that it can no longer be linked to you. Note that the copy of the message left on your phone is under your control and you can delete it whenever you like.
5. Who else has access to your data
We do not sell or share your personal data with third parties for commercial purposes. That said, the following third parties are involved in delivering the service:
| Third party | What it sees and why | Role | Location / transfers |
|---|---|---|---|
| WhatsApp (Meta) | All the data in your booking request — name, phone, date, guests and comments, including any allergies — because the request is sent as a WhatsApp message. | Independent controller of the messaging service. It does not act on our behalf: its own terms apply. | Ireland and USA. Subject to the WhatsApp privacy policy for the EEA. |
| Vercel | Your IP address and technical connection data when serving the pages. | Processor (Art. 28 GDPR). | Global network; its parent company is in the USA. Transfers covered by standard contractual clauses. |
| Supabase | None of your data. It only hosts the restaurant's menu (dishes, categories and prices) and the staff accounts that update it. | Processor, with no access to customer data. | Infrastructure in the European Union; its parent company is based in the USA. |
| jsDelivr | Your IP address when downloading the library that loads the menu. | Content delivery provider. | Global network. |
The site's typefaces are served from our own domain, so browsing this website sends no data of yours to Google or to any other advertising platform.
We may also disclose data to the tax authorities, law enforcement, courts or banks where a legal obligation requires it.
6. International transfers
The most relevant transfer is the one WhatsApp performs when handling your message: Meta may process data outside the European Economic Area, relying on the safeguards in Chapter V of the GDPR. This transfer happens inside your own messaging app rather than being something we carry out, and you can avoid it by booking over the phone.
Vercel and Supabase may also process data outside the EEA under standard contractual clauses. You may request a copy of those safeguards by calling +34 616 321 296.
7. Security measures
We apply appropriate technical and organisational measures: encrypted communications over HTTPS, security headers on the server, typefaces served from our own domain, and access to the menu administration panel controlled through individual credentials and row-level security policies in the database.
As for bookings, the main safeguard is organisational: the phone that receives the messages is protected with a screen lock, only the floor staff responsible for bookings can access it, and conversations are deleted within the period stated above.
No system is infallible. Should a security breach occur that poses a high risk to your rights, we would inform you and notify the supervisory authority in accordance with Articles 33 and 34 GDPR.
8. Your rights
You may exercise the following rights at any time, free of charge:
- Access: find out what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete data that is no longer necessary.
- Restriction: ask us to suspend processing while a complaint is verified.
- Objection: object to processing based on our legitimate interest.
- Portability: receive your data in a structured, commonly used format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise them, call +34 616 321 296 or write to the postal address given in section 1, stating which right you wish to exercise and attaching a copy of a document proving your identity. We will reply within one month, extendable to two months if the request is particularly complex.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es), or with the supervisory authority of your country of residence.
9. Minors
The booking form is not aimed at children under 14. If you are under that age, please ask a parent or guardian to make the booking. If we find that we have received a minor's data without authorisation, we will delete it.
10. Changes to this policy
We may update this policy to reflect legal changes or new services. The date of the latest update appears at the top of the document. If a change is substantial and affects processing based on your consent, we will ask for it again.