At Carbón Carbón we treat your personal data with the same care we give the produce that reaches our grill: we only ask for what is essential, we use it for what we tell you, and we keep it only as long as needed. This policy explains how, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 (LOPDGDD).

1. Data controller

2. What data we process and where it comes from

We only process data you give us voluntarily. We do not buy databases and we do not obtain information from third parties.

Booking form

Name, telephone number and booking details are mandatory: without them we cannot process the request. The comments field is optional.

Important: how this data travels. The form does not store anything on a server of ours. When you press "Send request", WhatsApp opens on your device with a message already drafted, and it is you who decides to send it. In other words, the request reaches us as an ordinary WhatsApp message and is held on that platform and on the restaurant's phone. If you do not send the message, we receive nothing at all.

If you would rather not use WhatsApp, you can book by calling +34 616 321 296.

Allergy and intolerance information

If you tell us about food allergies or intolerances, that information may constitute health data, which the GDPR treats as a special category (Article 9). We process it only because you choose to share it voluntarily and explicitly so that we can prepare your service safely, and the legal basis is your explicit consent (Article 9(2)(a) GDPR), which we collect through a dedicated tick box in the form itself. It is used exclusively by our kitchen and floor staff for that specific booking, and it is deleted together with the rest of the message.

Bear in mind that, as the request is sent through WhatsApp, this information travels over that platform like any other message. If you would rather not put it in writing, do not type it into the form: you can tell us by telephone or in person when you arrive. We will take it into account just the same.

Contact by telephone or WhatsApp

Browsing data

3. Why we use your data and on what legal basis

We do not make automated decisions producing legal effects, and we do not profile you.

4. How long we keep it

Once these periods end, data is deleted or anonymised so that it can no longer be linked to you. Note that the copy of the message left on your phone is under your control and you can delete it whenever you like.

5. Who else has access to your data

We do not sell or share your personal data with third parties for commercial purposes. That said, the following third parties are involved in delivering the service:

The site's typefaces are served from our own domain, so browsing this website sends no data of yours to Google or to any other advertising platform.

We may also disclose data to the tax authorities, law enforcement, courts or banks where a legal obligation requires it.

6. International transfers

The most relevant transfer is the one WhatsApp performs when handling your message: Meta may process data outside the European Economic Area, relying on the safeguards in Chapter V of the GDPR. This transfer happens inside your own messaging app rather than being something we carry out, and you can avoid it by booking over the phone.

Vercel and Supabase may also process data outside the EEA under standard contractual clauses. You may request a copy of those safeguards by calling +34 616 321 296.

7. Security measures

We apply appropriate technical and organisational measures: encrypted communications over HTTPS, security headers on the server, typefaces served from our own domain, and access to the menu administration panel controlled through individual credentials and row-level security policies in the database.

As for bookings, the main safeguard is organisational: the phone that receives the messages is protected with a screen lock, only the floor staff responsible for bookings can access it, and conversations are deleted within the period stated above.

No system is infallible. Should a security breach occur that poses a high risk to your rights, we would inform you and notify the supervisory authority in accordance with Articles 33 and 34 GDPR.

8. Your rights

You may exercise the following rights at any time, free of charge:

To exercise them, call +34 616 321 296 or write to the postal address given in section 1, stating which right you wish to exercise and attaching a copy of a document proving your identity. We will reply within one month, extendable to two months if the request is particularly complex.

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es), or with the supervisory authority of your country of residence.

9. Minors

The booking form is not aimed at children under 14. If you are under that age, please ask a parent or guardian to make the booking. If we find that we have received a minor's data without authorisation, we will delete it.

10. Changes to this policy

We may update this policy to reflect legal changes or new services. The date of the latest update appears at the top of the document. If a change is substantial and affects processing based on your consent, we will ask for it again.