GDPR and transparency
Privacy Policy
This policy explains what personal data this website processes, why it is needed, how long it is kept and how you can exercise your rights.
1. Scope
This policy covers the main website, enquiry form and restaurant portfolio demonstrations, including booking, newsletter and administration features. Demo restaurant content must be adapted with the real operator’s identity and practices before any production use.
2. Personal data
- Business enquiries: name, business name, email, phone, current website or social profile, selected budget and message.
- Restaurant bookings: name, email, phone, date, time, party size, seating, occasion, language and optional notes.
- Newsletter: email, language, subscription status and registration date.
- Security: IP address or a derived identifier, approximate country, browser, request time and abuse-prevention logs.
- Preferences: the cookie choice stored locally on the device.
Do not include sensitive information unless strictly necessary, such as a food allergy relevant to a booking.
3. Purposes and lawful bases
Enquiries, proposals and requested services are processed for pre-contractual steps or contract performance under Article 6(1)(b) GDPR. Optional newsletters and optional cookies rely on consent under Article 6(1)(a). Security and fraud prevention rely on legitimate interests under Article 6(1)(f). Tax, accounting and other mandatory records are processed under Article 6(1)(c).
4. Recipients and processors
Strictly necessary technical suppliers may process data, including Netlify web hosting and functions, database hosting, email and technical support. They act under appropriate instructions and confidentiality obligations. Data may be disclosed to authorities where legally required. Personal data is not sold or shared for third-party advertising.
5. International transfers
Where a supplier processes data outside the European Economic Area, an approved safeguard is required, such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or Standard Contractual Clauses with supplementary safeguards.
6. Retention
- Enquiries that do not become a project: up to 24 months after the last contact.
- Contractual and tax records: for applicable legal periods, generally up to 10 years.
- Bookings: as needed to manage the booking and normally no longer than 24 months.
- Newsletter: until consent is withdrawn or the subscription becomes inactive.
- Security logs: normally up to 12 months unless an incident requires longer retention.
- Cookie preference: up to 6 months.
7. Your rights
Where applicable, you may request access, rectification, erasure, restriction, portability or object to processing. You may withdraw consent at any time without affecting prior lawful processing. Use the contact form and identify the request as “Privacy”. A response is normally provided within one month. You may complain to the Portuguese Data Protection Authority, CNPD.
8. Automated decisions, security and children
There is no solely automated decision-making with legal or similarly significant effects. The calculator is an informative estimate only. Access controls, secure sessions, validation, rate limiting, project separation and encryption are used where available. The services are not directed to children under 16.
9. Changes
This policy may change when features, suppliers or legal requirements change. The version published here is the current one.
Last updated: 30 July 2026.
Back to the website