Privacy policy
The German version of this document is authoritative. This translation is provided for information only.
1. Controller
The controller for data processing on this website is Konstantinos Savvidis, Taverna Hellas (sole trader), Güntzelstraße 19, 10717 Berlin, telephone +49 30 861 34 19.
No data protection officer has been appointed. The business employs at most five people, so the conditions of § 38 (1) BDSG are not met.
2. What this website does technically
The following points describe the actual technical state of this website and have already been checked:
- No cookies are set.
- There is no analytics and no tracking.
- Fonts are served locally (self-hosted). There is no connection to Google Fonts.
- No map is embedded. The directions link opens Google Maps in a new tab only after a deliberate click.
- The Instagram link is an ordinary link. No Instagram script, iframe or image is loaded.
- No social media plugins are embedded.
- Outside the reservation pages, no third-party service is loaded at all. For Cloudflare Turnstile on the reservation pages see section 6.
- Because nothing is stored on or read from your device outside the reservation pages, no consent is required for that under § 25 TDDDG. That is why this website deliberately shows no cookie banner.
3. Hosting and server logs
This website is hosted with Cloudflare, Inc. as a static site (Cloudflare Workers Static Assets). When a page is requested, Cloudflare processes technically necessary connection data such as the IP address, the time, the file requested, the volume of data transferred, the referrer and the user agent. Without that processing a page cannot be delivered at all.
The legal basis is Art. 6 (1) (f) GDPR. The legitimate interest is the technically sound and secure operation of the website. Cloudflare processes this data as a processor under Cloudflare’s data processing addendum, which incorporates the European Commission’s standard contractual clauses for transfers to the USA. We keep no access statistics of our own, do not evaluate the log files and do not combine them with any other source.
4. Reservations by telephone
If you reserve by telephone we note your name, the number of guests, the date, the time and, if you give it, your telephone number. The note serves only to carry out your reservation. The legal basis is Art. 6 (1) (b) GDPR. The note is destroyed after the day of your visit unless it is exceptionally still needed to clarify a matter or because of tax and commercial retention duties. Telephone calls are not recorded.
5. Online reservation request
You can send a reservation request using the form at /termin-buchen. It is expressly a request: a reservation only comes about once we confirm it to you personally. The times shown are possible request times, not a display of free tables.
Categories of data processed
- Mandatory fields: desired date, desired time, number of guests, name.
- Mandatory as an alternative: at least one means of contact, that is a telephone number or an email address. Without it we cannot confirm your request or ask you anything about it.
- Optional fields: the "Requests or notes" field. Please do not enter health data or other particularly sensitive information there.
- Sent along technically: the language you chose, a random submission ID, the time of receipt and the address of the form page the request came from.
No postal address, date of birth, payment details or marketing consent is requested. Your entries are not stored in your browser, are not carried in the address bar, and are not passed to any analytics or advertising service.
Purpose and legal basis
The data is used solely to process your reservation request, to reply to you and, where applicable, to confirm the reservation. The legal basis is Art. 6 (1) (b) GDPR, because the processing takes place at your request and in preparation for your visit.
How the request travels
The form sends your details over an encrypted connection to a single endpoint on our own domain, served by a Cloudflare Worker. The Worker checks the details, runs the abuse protection and hands the request to the mail service as an email. There is no database: your request is not stored in a form store, neither at Cloudflare nor with us. The Worker logs only the random submission ID, a coarse outcome category and a timestamp. Your name, contact details, notes, the content of your request and your IP address are not logged.
Recipients
Resend (Plus Five Five, Inc., USA) is used as a processor to deliver the notification; open and click tracking are disabled for these messages. The message is delivered to an internal mailbox currently maintained by Anova Projects on behalf of the business. That address is a temporary internal destination and is expressly not the public contact address of the taverna. Data processing agreements under Art. 28 GDPR are in place with Cloudflare, Resend and Anova Projects; the European Commission’s standard contractual clauses cover the transfer to the USA. No further disclosure to third parties takes place.
Retention
The notification stays as an email in the internal mailbox until your request has been dealt with, and is deleted at the latest three months after the requested date. At the mail service, the technical delivery data is deleted after its own retention period. Where tax or commercial retention duties exceptionally apply, those periods take precedence.
6. Cloudflare Turnstile and abuse protection
Cloudflare Turnstile is used on the reservation pages only, to keep automated submissions out. A script is loaded from challenges.cloudflare.com and your IP address together with technical device and browser characteristics is transmitted to Cloudflare. According to the provider, Turnstile does not build cross-site advertising profiles. Turnstile is not loaded on any other page of this website.
When you submit, we also limit the number of attempts per sender. Your IP address is not stored for this: it is combined with a secret key and reduced to a one-way value that is only comparable within a short time window. The legal basis for Turnstile and for the limit is Art. 6 (1) (f) GDPR; the legitimate interest is protecting the form and our mailbox from automated abuse. Here too Cloudflare, Inc. acts as a processor, with the standard contractual clauses as the safeguard for the transfer to the USA. Cloudflare processes the check data only briefly and only for the check itself; we store no result.
7. Your rights
You have the right to information, rectification, erasure, restriction of processing, data portability and objection under Art. 15 to 21 GDPR. Where we base processing on a legitimate interest, you may object on grounds relating to your particular situation.
To exercise these rights you can reach us by telephone on +49 30 861 34 19 or in writing at Taverna Hellas, Güntzelstraße 19, 10717 Berlin. You may also lodge a complaint with a supervisory authority; for Berlin this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.
8. Version date
This privacy policy describes the state of the website at the time of its last publication. It is updated whenever the technology in use changes.

