1. Data Controller
The Data Controller is Kiran Ristorante Indiano
Registered Office: Via Scipione Pistrucci, 4 – 20137 Milano (MI), Italy (Porta Vittoria)
VAT Number (P.IVA): 10654740967
Phone: +39 333 1826263
Email for Privacy Inquiries: zahidshaik2399@gmail.com
2. Categories of Personal Data Collected
When you interact with our website, book a table, or send a contact request, we may process the following personal data:
- Contact & Identification Details: First Name, Last Name, Phone Number (or WhatsApp), Email Address.
- Table Reservation Data: Booking date, time slot, number of guests, seating preferences.
- Dietary Notes & Allergies (Special category data voluntarily provided): Any food intolerances, allergies, or special requests voluntarily communicated to guarantee safe dining service.
- Browsing Data: Technical logs and anonymized IP addresses collected solely to ensure site security and prevent unauthorized access.
3. Purposes of Processing & Legal Basis
Your personal data is processed for the following purposes:
-
Table Booking Management: To manage, confirm, and organize your dining experience, table allocation, and send transactional booking reminders.
Legal basis: Performance of a contract or pre-contractual measures requested by the customer (Art. 6.1.b GDPR). -
Customer Inquiries & Messages: To respond to requests sent via the contact form or direct communication channels.
Legal basis: Legitimate interest in providing customer assistance (Art. 6.1.f GDPR). -
Promotions, News & Exclusive Offers (Marketing): To send updates on new dishes, special promotions, and dedicated discounts.
Legal basis: Freely given, specific, and revocable consent (Art. 6.1.a GDPR). This consent is entirely optional and does not affect your ability to book a table. -
Legal & Accounting Obligations: Compliance with statutory tax, accounting, and public health obligations.
Legal basis: Legal obligation (Art. 6.1.c GDPR).
4. Processing Methods & Data Retention
Data processing is carried out using automated digital tools and manual methods with strict organizational and technical security measures (TLS encryption, role-based access control, PDO prepared statements) designed to prevent data loss, unauthorized access, or disclosure.
Data is stored for the time strictly necessary to fulfill the reservation and customer relationship, and for up to 24 months for marketing activities (unless consent is withdrawn earlier).
5. Rights of the Data Subject
Pursuant to Articles 15–22 of Regulation (EU) 2016/679, you have the right to:
- Access your personal data and obtain a copy.
- Request rectification of inaccurate data or completion of incomplete data.
- Request deletion of your data (“right to be forgotten”).
- Request restriction of processing or object to processing for marketing purposes.
- Withdraw your consent at any time without affecting prior lawful processing.
- Lodge a complaint with the Data Protection Authority (Garante per la Protezione dei Dati Personali - garanteprivacy.it).
To exercise your rights, you may contact the Data Controller at any time via email at zahidshaik2399@gmail.com or by phone at +39 333 1826263.