Crêperie Carré

Privacy policy

The protection of your personal data is important to us. Below we explain which data is collected when you visit this website, what it is used for and what rights you have.

This website collects as little data as possible. There is no contact form, no newsletter, no registration, and no user account. No advertising services are used. Anonymized, cookie-free analysis of visitor behavior is carried out exclusively via our self-hosted service Umami — see the section “Web Analytics with Umami” below for details.

This English version is a translation provided for convenience. In case of doubt, the German version is legally binding.

Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Crêperie Carré Owner: Sergiu Goinic Josephsburgstr. 56 81673 Munich Phone: +49 89 52064828 Email: info@carre-creperie.de

A data protection officer is not required by law and has not been appointed.

Hosting

This website is hosted on servers provided by netcup GmbH, Emmy-Noether-Str. 10, 76131 Karlsruhe, Germany. The servers are located in Nuremberg, Germany. No transfer of personal data to third countries takes place as part of this hosting.

We have concluded a data processing agreement pursuant to Art. 28 GDPR with the provider. The legal basis is our legitimate interest in a secure and reliable provision of this website pursuant to Art. 6 (1) (f) GDPR.

Server log files

When you access this website, information transmitted by your browser is automatically recorded. This includes:

– IP address of the requesting device – date and time of access – name and URL of the file accessed – volume of data transferred – notification of successful retrieval – browser type and version used – operating system – referrer URL, if transmitted

This data is processed solely to ensure trouble-free operation, to guarantee system security and to analyse errors. This data is not merged with other data sources or evaluated for marketing purposes.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the secure and functional operation of this website. Log files are deleted automatically after 14 days at the latest.

Cookies and consent

This website uses technically necessary cookies required for the operation of the site. This includes in particular storing your cookie decision. No consent is required for these cookies pursuant to § 25 (2) TDDDG.

In addition, we embed content from external providers which is only loaded after your explicit consent. As long as you have not given consent, no connection to these providers is established and no data is transmitted to them.

Your consent is voluntary and can be withdrawn at any time with effect for the future. You can access and change the settings at any time using the “Cookies” button in the footer of this website. The legal basis for consent is § 25 (1) TDDDG and Art. 6 (1) (a) GDPR.

Google Maps

On the “Contact” page we embed a map from the Google Maps service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The map is not loaded automatically. Initially you only see a placeholder image. Only when you actively click the “Load map” button is a connection to Google's servers established. Your IP address and information about your browser and device are transmitted to Google in the process. Transfer to the USA and processing by Google LLC cannot be ruled out.

The legal basis is your consent pursuant to § 25 (1) TDDDG and Art. 6 (1) (a) GDPR. Further information can be found in Google's privacy policy at https://policies.google.com/privacy

Instagram

On the “Gallery” page we show exclusively our own photos, stored on our own server. No content is loaded from Instagram and no data is transmitted to Meta.

We only link to our Instagram profile. Merely visiting our website does not transfer any data. If you follow the link, you leave our website; from that point on, only the privacy policy of Meta Platforms Ireland Limited applies.

Gift cards via SumUp

For the purchase of gift cards we link to an offer provided by SumUp Limited. This is a simple link. No data is transmitted to SumUp when you merely visit our website.

If you follow the link, you leave our website. From that point on, only SumUp's privacy policy applies. We have no influence over the data processing that takes place there.

Fonts

This website uses the fonts Lato and Bricolage Grotesque. The font files are served exclusively from our own server. At no point is a connection established to servers operated by Google or other third parties, and no data is transmitted to such providers.

Web Analytics with Umami

This website uses the web analytics service Umami to evaluate visitor behavior in an anonymized way. Umami runs exclusively on our own server in Germany; no data is transferred to third parties or to servers outside the EU.

Umami does not use cookies and does not collect any personal data that would allow individual visitors to be identified. Only aggregated, anonymous information is recorded, such as pages visited, time spent, country of origin, and browser type. IP addresses are not stored.

The legal basis for using Umami is our legitimate interest (Art. 6 (1) (f) GDPR) in the statistical analysis of user behavior to improve our website. Since no personal data is processed, no separate consent is required.

Contacting us

This website does not contain a contact form. If you contact us by email or telephone, the data you provide will be processed solely to handle your enquiry.

The legal basis is Art. 6 (1) (b) GDPR insofar as your enquiry serves the initiation or performance of a contract, and otherwise Art. 6 (1) (f) GDPR based on our legitimate interest in responding to enquiries.

Your enquiry will be deleted once it has been fully dealt with and no statutory retention obligations prevent deletion.

SSL / TLS encryption

For security reasons, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the browser's address bar changes from “http://” to “https://” and a padlock symbol is displayed.

Your rights

You have the right at any time:

– to obtain information about the data stored about you (Art. 15 GDPR) – to request the correction of inaccurate data (Art. 16 GDPR) – to request the deletion of your data (Art. 17 GDPR) – to request the restriction of processing (Art. 18 GDPR) – to object to processing (Art. 21 GDPR) – to receive your data in a transferable format (Art. 20 GDPR) – to withdraw consent given at any time (Art. 7 (3) GDPR)

Withdrawing consent does not affect the lawfulness of processing carried out up to the point of withdrawal. An informal message to the email address given above is sufficient to exercise your rights.

Right to lodge a complaint with a supervisory authority

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 27 91522 Ansbach https://www.lda.bayern.de

Changes to this privacy policy

We update this privacy policy whenever changes to the services we use or to the legal situation make this necessary. The current version applies to each of your visits.