Privacy policy

What we collect when you book, eat, write to us or visit this website, why, who helps us with it, and what you can ask of us. In plain words, as far as the law allows.

Last updated:

Who we are

The controller (the business responsible for your data) is ΦΛΟΡΙΑΝ ΣΝΑΪΝΤΕΡ & ΣΙΑ Ε.Ε. (ΚΤΗΜΑ ΦΛΟΡΙΑΝ Ε.Ε., trading as Domaine Florian), VAT number EL801330443, 120 Ipanema - Kamila, Trilofos 57500, Thessaloniki, Greece. It runs our restaurant, events, bookings, newsletter, wine club and online shop, and this website.

For anything about your data, write to felix@domaineflorian.com or call +30 690 837 2316. We are a small family business and have not appointed a data protection officer; I, Felix Gerd Schneider, answer privacy questions myself.

Our booking terms are a separate page: /book/terms. The full company details are on /imprint.

In short

  • We collect what we need to host you: your name and email for a booking, your phone number if you give it, and what you tell us about your visit.
  • We never see your card details. Viva handles payments.
  • Marketing cookies, the Meta Pixel and noting which ad brought you here run only if you say yes in the cookie banner. Our newsletter, Viber news and Viber reminders reach you only if you ask for them.
  • We do not sell your data, and no computer makes decisions about you.
  • You can ask us at any time what we hold about you, and have it corrected or deleted.

Bookings and tickets

What we collect. Your name, email address, party size and arrival time (required), and optionally your phone number, departure time, the reason for your visit, a coupon code and a note. If you need an invoice for a ticket, also the company name, VAT number, tax office and address you give us. We store your booking, a copy of the booking terms you accepted with the date, your IP address and your browser (user agent), and, if you came from one of our ads or links and accepted marketing cookies, how you reached us (see "Using our website").

Why. To take and manage your booking, send you your confirmation, tickets and QR code, check you in, and contact you if something changes. Legal basis: the contract with you (GDPR Art. 6(1)(b)). Without a name and an email address we cannot take an online booking; everything else is optional. We keep the record of your acceptance to be able to show it (Art. 6(1)(c) with Art. 7(1)).

Allergies and diets. The booking form has no allergy field, but you can write one in the note. Information about your health, such as an allergy, is a special category of data (Art. 9). If you tell us, you give us your explicit consent (Art. 9(2)(a)) to use it for one purpose: preparing your food safely. It is entirely optional.

Ticket transfers. If you pass your ticket on, we ask you for the new holder's name, email and optionally phone number, replace your details on the booking with theirs, and keep a short history of the transfer (names, emails, date and a shortened fingerprint of the IP address). If someone has passed a ticket on to you, that is how we got your details. Legal basis: Art. 6(1)(b), and our legitimate interest in knowing who holds a ticket (Art. 6(1)(f)).

Wallet passes. If you add your ticket to Apple Wallet or Google Wallet, the pass carries your name, the event, date, time, party size and booking reference. Adding it to Google Wallet sends these to Google; an Apple Wallet pass is created by us and downloaded to your device.

Our team. When you book, our staff get a notification with your booking — in the staff app, as a push notification on their phones, and in a private group chat of our team on Telegram. That message includes your contact details and notes, and what we know about earlier visits (see "How we remember our guests"). Legal basis: our legitimate interest in running service smoothly (Art. 6(1)(f)).

Payments, receipts and invoices

Card payments are processed by Viva (viva.com), a payment institution based in Greece. To create a payment we send Viva your name, email, phone number (if given), the amount and the booking reference. You enter your card details on Viva's own page; they never reach us. Viva processes payment data under its own legal obligations as a payment institution. Our servers reach Viva through a relay server we rent from Fly.io in Frankfurt, Germany, so that Viva sees one fixed address; the relay passes the data on and does not log its contents.

Greek law requires us to issue a receipt for every sale and report it to the Independent Authority for Public Revenue (ΑΑΔΕ, myDATA). A retail receipt sent to ΑΑΔΕ does not carry your name. If you ask for an invoice, the VAT number of your company is reported. We email you the receipt as a PDF and keep a copy. Legal basis: legal obligation (Art. 6(1)(c)).

For group payments we also store the payer's name, email, optional phone number, the number of people paid for and, if an invoice is wanted, the billing details.

Group menus (weddings and groups)

If the organiser of your event sends you a menu link, we store what you enter: your name, whether you are coming, the dishes you choose, any comment, any allergy or dietary requirement, and, if the organiser asks for it, an email address or phone number. If the organiser has a seating plan, we may also record your table and seat.

Our kitchen and service staff use this to prepare and serve your meal. The organiser of your event — for a wedding, the couple — can see your answers too, including any allergy or dietary requirement and any contact details you left, so they can plan seating and catering and reach guests who have not answered. Legal basis: serving the meal you ordered (Art. 6(1)(b)) and the organiser's legitimate interest in planning their event (Art. 6(1)(f)).

Telling us about an allergy or dietary requirement is optional. Because it is health data (Art. 9), we use it only with your explicit consent (Art. 9(2)(a)): when you fill in that field, a separate tick box asks you to agree that we use it to prepare your meal at that event, and that our kitchen and service staff and the organiser may see it. Without the tick the answer is not saved. We keep the date and the exact sentence you agreed to with your answer. You can withdraw your consent at any time by clearing the field from the same link, or by writing to us. Group menu answers, with the allergies and the consent record, are deleted 60 days after the event, in the monthly clean-up that follows, so at the latest about three months after it.

Messages, calls and reminders

We may text or email you about your booking — a confirmation, a change, a cancellation or a reminder — and you can reply. Texts are sent from and received on our restaurant's own phone number. What you write, with your phone number or email address, is kept next to your booking so our team can see the conversation and answer you. This is part of managing your booking (Art. 6(1)(b)) and is not marketing. Reply STOP (or ΣΤΟΠ) to any text and we stop texting you; we can still reach you by email or phone about your booking.

  • SMS go through the SMS Gateway for Android app on our phone and its relay service (sms-gate.app), which uses Google Firebase Cloud Messaging to wake the phone. Pictures you send by MMS are stored with the conversation.
  • Email is sent through Amazon Web Services (Amazon SES). Your replies to our booking emails are received for us by Resend.
  • Viber messages go through Yuboto, a Greek messaging provider, and Rakuten Viber. We send a Viber reminder before your event only if you opted in to Viber messages (Art. 6(1)(a)), for example with the news box when you booked, and have not opted out since. Without that opt-in you get no Viber reminder.
  • Missed calls. When we miss your call, our phone notes your number and the time, and we may send you one text saying when we are open (at most once a week, Greek mobile numbers only). Legal basis: our legitimate interest in calling you back (Art. 6(1)(f)).

If you email us directly (for example felix@domaineflorian.com, events@ or sales@), your message is stored in our mailboxes, which Migadu-Mail GmbH in Switzerland hosts for us.

Feedback and reviews

About a day after your visit we may email you to ask how it was — at most twice in twelve months. If you answer, we store your rating, your comment and whether you would like us to contact you, and our team is notified. We also show everyone a link to leave a Google review; we only note that you clicked it, and we send nothing to Google. Legal basis: our legitimate interest in learning from your visit (Art. 6(1)(f)). You can object at any time and we stop asking.

Newsletter and Viber news

You can ask for our news when you book (one box covers email and Viber) or at your table. It is separate from the wine club's emails (see "Wine club") and always optional. We store your email address, your name if you give it, the topics you chose, and a record of your consent: the text you agreed to, the date, your IP address and browser. Legal basis: your consent (Art. 6(1)(a)). Saying no never affects a booking.

Emails are sent through Amazon SES. Every email has an unsubscribe link; once you use it, we keep your address on a do-not-send list so you are not added again by mistake. Viber news can be stopped from the link in each message or by writing to us. Withdrawing consent does not make earlier sending unlawful.

Until our old website is switched off, our newsletter list is also kept in the newsletter plugin of that website, and addresses that signed up there were brought into our own system together with the consent records kept there.

Wine club

To join, we ask for your name, email address and tier, and a confirmation that you are 18 or older. We send a six-digit code to your email to confirm it is yours. We then store your membership (tier, status, member card code, language, where you joined from and a log of changes) and create your member card. Legal basis: the membership you asked for (Art. 6(1)(b)).

The club's emails. They are part of the membership: new release dates and members' first chance to book, member offers and the monthly programme. The join form says so plainly above its button, and joining is your consent to them (Art. 6(1)(a), and Art. 11 of Greek Law 3471/2006 for electronic marketing). The six-digit code we email you confirms that the address is yours (double opt-in), and as the record of your consent we keep the exact sentence you were shown, in your language, with the date, your IP address and your browser. You can stop the emails at any time with the link in every email, and turn them back on from your member page. You keep your membership, your card and every perk at our venue either way: the consent is a condition only of the emails themselves. Our general newsletter is separate and stays optional. If you join the waiting list for a paid tier, we store your name, email and the tier you chose. If you leave the club, we keep a note that you left and why, if you told us.

Wine shop

When online ordering is open, an order needs your name, email address, phone number and date of birth, a declaration that you are 18 or older, and, for delivery, your address. We store the order, the payment reference from Viva and, once sent, the courier's tracking number. When you collect an order, we check your ID and note only that we did. Legal basis: the sales contract (Art. 6(1)(b)), and the legal duty to sell alcohol only to adults (Art. 6(1)(c)). Your cart is kept only in your own browser.

Private events and weddings

When you ask about a private event or a wedding, we store your name, email, phone number, the occasion, guest count, the dates and preferences you give, your message, and optionally a company name and VAT number for an invoice. We also record your IP address, browser and the page or ad you came from. Our events team is notified by email and on their phones, and you get an email confirming we received it. If your event goes ahead, its entry in our Google calendar may carry your name. Legal basis: steps you asked us to take before a contract (Art. 6(1)(b)).

Job applications

When you apply for a job, we store your first and last name, email, phone number, CV, and optionally a cover message, your years of experience and availability, together with the date you sent it, your IP address and browser. Your CV is kept in our file storage. Our managers are notified and can read your application. We use it to consider you for the position you applied for: steps before a possible employment contract (Art. 6(1)(b)). The form has a second, optional box: only if you tick it do we also consider you for later openings, on the basis of your consent (Art. 6(1)(a)); we record when you gave it and the sentence you agreed to. You can take it back at any time by writing to felix@domaineflorian.com, and from then on we consider your application for its own position only. Either way we keep your application for up to 24 months, unless you ask us to delete it sooner. Deleting applications after 24 months is not automated yet: we delete them by hand.

Ordering at your table

Scanning the QR code on your table asks for no name or contact details. We store your order or request (for example calling a waiter or asking for the bill) with the table number, your browser and a one-way fingerprint of your IP address, which helps us stop abuse. A cookie remembers your table for three hours. Legal basis: Art. 6(1)(b) for orders and Art. 6(1)(f) for protecting the service.

How we remember our guests

We link your bookings by your phone number, email or name into a guest profile that shows our team how often you have visited, how much you have spent, no-shows and cancellations, the average of your feedback ratings, and whether you are a returning, regular or top guest. Our team may add notes, such as a seating preference, a birthday or anniversary, or an allergy you told us about so we remember it next time.

This is shown to our team only — in the staff app and in the booking notifications described above. Nothing happens automatically because of it: a person always decides. Legal basis: our legitimate interest in welcoming returning guests well (Art. 6(1)(f)); an allergy is recorded only because you told us (Art. 9(2)(a)). You can object to this at any time (see "Your rights").

Using our website

  • Hosting. This website and our booking system run on Cloudflare (Workers, D1 database, R2 file storage). Cloudflare processes your IP address and request data to deliver pages and protect them from attacks, and our system keeps short technical logs. Legal basis: Art. 6(1)(f).
  • Visitor statistics. Cloudflare Web Analytics counts page views on every page. It sets no cookies and does not identify you; Cloudflare sees your IP address, browser and the page you visit. It runs without asking, on the basis of our legitimate interest in knowing which pages are used (Art. 6(1)(f)).
  • Bot check. Our booking, payment, menu and inquiry forms use Cloudflare Turnstile to tell people from bots. It looks at your browser and IP address. Legal basis: Art. 6(1)(f).
  • No embedded review widgets. We link to our reviews on Google and Tripadvisor rather than embedding Google's or any other review site's badge or widget, so your browser contacts a review site only if you click such a link.

With your consent only

  • Microsoft Clarity (statistics) records how visitors use our booking, menu, spaces and events pages — clicks, scrolling, mouse movement and device — so we can find what is confusing. Form fields and allergy answers are masked. It links a session to a booking number. Only with "Statistics" consent.
  • Our booking-form statistics note which field a visitor stopped at and how long the form took, without names or contact details. Only with "Statistics" consent.
  • Meta Pixel (marketing) tells Meta (Facebook, Instagram) which pages you visit and when you book or pay, so we can measure and improve our ads. Meta and we are jointly responsible for that collection; Meta is responsible for what it does with the data afterwards.
  • Meta Conversions API (marketing) sends the same booking and payment events from our server to Meta, with your email, phone and name only as one-way hashes (SHA-256), your IP address, browser and Meta's click identifier. Only if you accepted marketing cookies when you booked.
  • Ad visit records (marketing): if you accept marketing cookies, our server records each visit to our booking and event pages — a random visitor id, landing page, referrer, browser, device type, country, a hash of your IP address and campaign tags — to link ad visits to bookings.
  • How you reached us (marketing): if you accept marketing cookies, your browser remembers on our booking pages, for 90 days, the campaign tags of the link that brought you here (such as utm_source, utm_campaign, ref and fbclid) with a random visitor id, and we store them with your booking so we know which campaigns bring guests. Without marketing consent nothing is kept in your browser and nothing is sent with your booking; if you withdraw it, what was kept is deleted.

The cookie banner has two switches besides the necessary cookies, and each controls exactly what is listed here: "Statistics" (Microsoft Clarity and our booking-form statistics) and "Marketing" (Meta Pixel, Meta Conversions API, ad visit records and how you reached us). Legal basis for these: your consent (Art. 6(1)(a), and Art. 4(5) of Greek Law 3471/2006). You can change your choice at any time from "Cookie settings" at the bottom of every page; we keep a record of each choice (with a daily-changing hash of your IP address, your browser and the policy version) to be able to prove it.

Cookies and browser storage

Cookies and browser storage marked "necessary" make the site work and need no consent. The others are set only after you agree.

NameWhat it doesHow longType
df_consent_v2Remembers your cookie choices180 daysNecessary
df_consentOlder copy of the same choice, being phased out90 daysNecessary
cookie_consent, df_consent_migratedOlder copy of your choice (browser storage)Until you clear itNecessary
df_langRemembers the language you choseUp to 400 daysNecessary
pending_booking_…Lets you return to a booking you have not paid yet12 hoursNecessary
gm_…Lets you change your group menu answer90 daysNecessary
gm_manage_…Keeps an organiser's page unlocked30 daysNecessary
df_memberKeeps you signed in to the wine club30 daysNecessary
df_club_pendingHolds your wine club sign-up while you enter the email code15 minutesNecessary
df_tableRemembers the table whose QR code you scanned3 hoursNecessary
tableOrder:…, tableReview:…Your table order in progress (browser storage)Until you close the tabNecessary
df_cartYour wine shop cart (browser storage)Until you clear itNecessary
df_ann_dismissedNotices you have closed1 yearNecessary
auth-sessionSigns in our staff; never set for guests30 daysNecessary
df_tab_sessionGroups one visit for statistics (browser storage)Until you close the tabStatistics
_clck, _clskMicrosoft Clarity (set by Microsoft)1 year, 1 dayStatistics
df_visitorRandom visitor id linking an ad visit to a later booking400 daysMarketing
df_sessionGroups the pages of one visitUntil you close the browserMarketing
df_trackedAvoids recording the same visit twice30 minutesMarketing
df_attribution_v1The campaign tags of the link that brought you to our booking pages (browser storage)90 daysMarketing
_fbp, _fbcMeta Pixel (set by Meta)90 daysMarketing
meta_lead_fired:…Stops one booking being counted twice (browser storage)Until you clear itMarketing

Who else sees your data

We do not sell your data. These companies work for us as processors, under contract and only on our instructions, unless noted otherwise:

WhoWhat forWhere
Cloudflare, Inc.Hosting, database, file storage, bot check, visitor statisticsWorldwide network; US company
Amazon Web Services (Amazon SES)Sending our emailsUS company
ResendReceiving your replies to our booking emailsUSA
SMS Gateway for Android (sms-gate.app), Google Firebase Cloud MessagingCarrying texts between our system and our restaurant phoneSee "Outside the EU"
Yuboto, Rakuten ViberViber reminders and newsEU
Migadu-Mail GmbHOur email inboxesSwitzerland
VivaCard payments (for payment data, Viva is responsible itself)Greece
Fly.io, Inc.Relay server for our connection to VivaFrankfurt, Germany; US company
TelegramBooking and feedback notifications to our teamOutside the EU
GoogleCalendar (event planning), Google Wallet (if you add a ticket), Firebase Cloud MessagingUS company
Apple, Google, Mozilla push servicesDelivering encrypted notifications to our staff's devicesUS companies
Meta Platforms Ireland LtdMeta Pixel and Conversions API — only with your consent; jointly responsible for collectionIreland, and Meta in the USA
MicrosoftClarity — only with your consentUS company
ΑΑΔΕ (Independent Authority for Public Revenue)Tax receipts, by law — a public authority, not a processorGreece
The organiser of your group eventYour group menu answers (see "Group menus")—

We may also give data to our accountant, lawyers, courts or authorities where the law requires it or to defend a legal claim.

Outside the EU

Some of these providers are based in the USA or elsewhere outside the European Economic Area, so your data can be accessed from there.

  • Cloudflare, Amazon Web Services, Google, Microsoft and Resend are certified under the EU–U.S. Data Privacy Framework, which the European Commission has found to give an adequate level of protection (Decision (EU) 2023/1795).
  • Switzerland, where Migadu is based, has an adequacy decision of the European Commission.
  • Meta Platforms Ireland is responsible for its own transfers to Meta Platforms, Inc. in the USA; see Meta's privacy policy at https://www.facebook.com/privacy/policy.
  • For other transfers (Fly.io, the SMS relay service and Telegram), we rely on the European Commission's standard contractual clauses where the provider offers them. You can ask us for a copy of the safeguards that apply.

How long we keep it

  • Messages with us (SMS, email and Viber): each message is deleted 24 months after it was sent. Conversations that belong to no booking and that nobody answered are deleted after 90 days, and missed-call records after 90 days.
  • Group menu answers, including allergies: 60 days after the event.
  • Print jobs (receipts and kitchen tickets with names or allergies): 30 days after printing.
  • Receipts and tax records: as long as Greek tax law requires.
  • Job applications: up to 24 months, for the position you applied for and, only if you ticked the optional box, for later openings; sooner if you ask. We delete them by hand; this is not automated yet.
  • Newsletter: until you unsubscribe. After that we keep only your address on our do-not-send list.
  • Consent records: as long as we may need to prove your consent.

Our automatic deletion runs once a month, so data can stay up to a month past these dates. For everything else — bookings, guest profiles, club membership, event inquiries, feedback, shop orders and website visit records — we have not set fixed periods yet. We keep it while we have a reason to, for example to welcome you back or to answer a question about an earlier visit, and you can ask us to delete it at any time, unless the law requires us to keep it.

Your rights

You have the right to:

  • know what data we hold about you and get a copy (Art. 15);
  • have it corrected (Art. 16) or deleted (Art. 17);
  • have its use restricted (Art. 18);
  • receive the data you gave us in a common machine-readable format (Art. 20);
  • object to our use of your data based on legitimate interest, and to direct marketing at any time (Art. 21);
  • withdraw any consent at any time, without affecting what was done before (Art. 7(3)).

Write to felix@domaineflorian.com. We answer within one month and may ask you to confirm who you are. It is free.

You can also complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1-3, 115 23 Athens, phone +30 210 6475600, contact@dpa.gr, www.dpa.gr — or to the authority where you live or work.

No automated decisions

We do not make decisions about you by automated means that have legal or similarly significant effects (Art. 22). Our system automatically cancels a booking that is not paid by its deadline and marks a booking as a no-show when nobody checked in; neither affects later bookings automatically.

Changes to this policy

When we change how we use your data, we update this page and the date at the top. If a change needs your consent, we will ask for it.