Privacy policy
What we collect when you book, eat, write to us or visit this website, why, who helps us with it, and what you can ask of us. In plain words, as far as the law allows.
Last updated:
Contents
Who we are
The controller (the business responsible for your data) is ΦΛΟΡΙΑΝ ΣΝΑΪΝΤΕΡ & ΣΙΑ Ε.Ε. (ΚΤΗΜΑ ΦΛΟΡΙΑΝ Ε.Ε., trading as Domaine Florian), VAT number EL801330443, 120 Ipanema - Kamila, Trilofos 57500, Thessaloniki, Greece. It runs our restaurant, events, bookings, newsletter, wine club and online shop, and this website.
For anything about your data, write to felix@domaineflorian.com or call +30 690 837 2316. We are a small family business and have not appointed a data protection officer; I, Felix Gerd Schneider, answer privacy questions myself.
Our booking terms are a separate page: /book/terms. The full company details are on /imprint.
In short
- We collect what we need to host you: your name and email for a booking, your phone number if you give it, and what you tell us about your visit.
- We never see your card details. Viva handles payments.
- Marketing cookies, the Meta Pixel and noting which ad brought you here run only if you say yes in the cookie banner. Our newsletter, Viber news and Viber reminders reach you only if you ask for them.
- We do not sell your data, and no computer makes decisions about you.
- You can ask us at any time what we hold about you, and have it corrected or deleted.
Bookings and tickets
What we collect. Your name, email address, party size and arrival time (required), and optionally your phone number, departure time, the reason for your visit, a coupon code and a note. If you need an invoice for a ticket, also the company name, VAT number, tax office and address you give us. We store your booking, a copy of the booking terms you accepted with the date, your IP address and your browser (user agent), and, if you came from one of our ads or links and accepted marketing cookies, how you reached us (see "Using our website").
Why. To take and manage your booking, send you your confirmation, tickets and QR code, check you in, and contact you if something changes. Legal basis: the contract with you (GDPR Art. 6(1)(b)). Without a name and an email address we cannot take an online booking; everything else is optional. We keep the record of your acceptance to be able to show it (Art. 6(1)(c) with Art. 7(1)).
Allergies and diets. The booking form has no allergy field, but you can write one in the note. Information about your health, such as an allergy, is a special category of data (Art. 9). If you tell us, you give us your explicit consent (Art. 9(2)(a)) to use it for one purpose: preparing your food safely. It is entirely optional.
Ticket transfers. If you pass your ticket on, we ask you for the new holder's name, email and optionally phone number, replace your details on the booking with theirs, and keep a short history of the transfer (names, emails, date and a shortened fingerprint of the IP address). If someone has passed a ticket on to you, that is how we got your details. Legal basis: Art. 6(1)(b), and our legitimate interest in knowing who holds a ticket (Art. 6(1)(f)).
Wallet passes. If you add your ticket to Apple Wallet or Google Wallet, the pass carries your name, the event, date, time, party size and booking reference. Adding it to Google Wallet sends these to Google; an Apple Wallet pass is created by us and downloaded to your device.
Our team. When you book, our staff get a notification with your booking — in the staff app, as a push notification on their phones, and in a private group chat of our team on Telegram. That message includes your contact details and notes, and what we know about earlier visits (see "How we remember our guests"). Legal basis: our legitimate interest in running service smoothly (Art. 6(1)(f)).
Payments, receipts and invoices
Card payments are processed by Viva (viva.com), a payment institution based in Greece. To create a payment we send Viva your name, email, phone number (if given), the amount and the booking reference. You enter your card details on Viva's own page; they never reach us. Viva processes payment data under its own legal obligations as a payment institution. Our servers reach Viva through a relay server we rent from Fly.io in Frankfurt, Germany, so that Viva sees one fixed address; the relay passes the data on and does not log its contents.
Greek law requires us to issue a receipt for every sale and report it to the Independent Authority for Public Revenue (ΑΑΔΕ, myDATA). A retail receipt sent to ΑΑΔΕ does not carry your name. If you ask for an invoice, the VAT number of your company is reported. We email you the receipt as a PDF and keep a copy. Legal basis: legal obligation (Art. 6(1)(c)).
For group payments we also store the payer's name, email, optional phone number, the number of people paid for and, if an invoice is wanted, the billing details.
Messages, calls and reminders
We may text or email you about your booking — a confirmation, a change, a cancellation or a reminder — and you can reply. Texts are sent from and received on our restaurant's own phone number. What you write, with your phone number or email address, is kept next to your booking so our team can see the conversation and answer you. This is part of managing your booking (Art. 6(1)(b)) and is not marketing. Reply STOP (or ΣΤΟΠ) to any text and we stop texting you; we can still reach you by email or phone about your booking.
- SMS go through the SMS Gateway for Android app on our phone and its relay service (sms-gate.app), which uses Google Firebase Cloud Messaging to wake the phone. Pictures you send by MMS are stored with the conversation.
- Email is sent through Amazon Web Services (Amazon SES). Your replies to our booking emails are received for us by Resend.
- Viber messages go through Yuboto, a Greek messaging provider, and Rakuten Viber. We send a Viber reminder before your event only if you opted in to Viber messages (Art. 6(1)(a)), for example with the news box when you booked, and have not opted out since. Without that opt-in you get no Viber reminder.
- Missed calls. When we miss your call, our phone notes your number and the time, and we may send you one text saying when we are open (at most once a week, Greek mobile numbers only). Legal basis: our legitimate interest in calling you back (Art. 6(1)(f)).
If you email us directly (for example felix@domaineflorian.com, events@ or sales@), your message is stored in our mailboxes, which Migadu-Mail GmbH in Switzerland hosts for us.
Feedback and reviews
About a day after your visit we may email you to ask how it was — at most twice in twelve months. If you answer, we store your rating, your comment and whether you would like us to contact you, and our team is notified. We also show everyone a link to leave a Google review; we only note that you clicked it, and we send nothing to Google. Legal basis: our legitimate interest in learning from your visit (Art. 6(1)(f)). You can object at any time and we stop asking.
Wine club
To join, we ask for your name, email address and tier, and a confirmation that you are 18 or older. We send a six-digit code to your email to confirm it is yours. We then store your membership (tier, status, member card code, language, where you joined from and a log of changes) and create your member card. Legal basis: the membership you asked for (Art. 6(1)(b)).
The club's emails. They are part of the membership: new release dates and members' first chance to book, member offers and the monthly programme. The join form says so plainly above its button, and joining is your consent to them (Art. 6(1)(a), and Art. 11 of Greek Law 3471/2006 for electronic marketing). The six-digit code we email you confirms that the address is yours (double opt-in), and as the record of your consent we keep the exact sentence you were shown, in your language, with the date, your IP address and your browser. You can stop the emails at any time with the link in every email, and turn them back on from your member page. You keep your membership, your card and every perk at our venue either way: the consent is a condition only of the emails themselves. Our general newsletter is separate and stays optional. If you join the waiting list for a paid tier, we store your name, email and the tier you chose. If you leave the club, we keep a note that you left and why, if you told us.
Wine shop
When online ordering is open, an order needs your name, email address, phone number and date of birth, a declaration that you are 18 or older, and, for delivery, your address. We store the order, the payment reference from Viva and, once sent, the courier's tracking number. When you collect an order, we check your ID and note only that we did. Legal basis: the sales contract (Art. 6(1)(b)), and the legal duty to sell alcohol only to adults (Art. 6(1)(c)). Your cart is kept only in your own browser.
Private events and weddings
When you ask about a private event or a wedding, we store your name, email, phone number, the occasion, guest count, the dates and preferences you give, your message, and optionally a company name and VAT number for an invoice. We also record your IP address, browser and the page or ad you came from. Our events team is notified by email and on their phones, and you get an email confirming we received it. If your event goes ahead, its entry in our Google calendar may carry your name. Legal basis: steps you asked us to take before a contract (Art. 6(1)(b)).
Job applications
When you apply for a job, we store your first and last name, email, phone number, CV, and optionally a cover message, your years of experience and availability, together with the date you sent it, your IP address and browser. Your CV is kept in our file storage. Our managers are notified and can read your application. We use it to consider you for the position you applied for: steps before a possible employment contract (Art. 6(1)(b)). The form has a second, optional box: only if you tick it do we also consider you for later openings, on the basis of your consent (Art. 6(1)(a)); we record when you gave it and the sentence you agreed to. You can take it back at any time by writing to felix@domaineflorian.com, and from then on we consider your application for its own position only. Either way we keep your application for up to 24 months, unless you ask us to delete it sooner. Deleting applications after 24 months is not automated yet: we delete them by hand.
Ordering at your table
Scanning the QR code on your table asks for no name or contact details. We store your order or request (for example calling a waiter or asking for the bill) with the table number, your browser and a one-way fingerprint of your IP address, which helps us stop abuse. A cookie remembers your table for three hours. Legal basis: Art. 6(1)(b) for orders and Art. 6(1)(f) for protecting the service.
How we remember our guests
We link your bookings by your phone number, email or name into a guest profile that shows our team how often you have visited, how much you have spent, no-shows and cancellations, the average of your feedback ratings, and whether you are a returning, regular or top guest. Our team may add notes, such as a seating preference, a birthday or anniversary, or an allergy you told us about so we remember it next time.
This is shown to our team only — in the staff app and in the booking notifications described above. Nothing happens automatically because of it: a person always decides. Legal basis: our legitimate interest in welcoming returning guests well (Art. 6(1)(f)); an allergy is recorded only because you told us (Art. 9(2)(a)). You can object to this at any time (see "Your rights").
Using our website
- Hosting. This website and our booking system run on Cloudflare (Workers, D1 database, R2 file storage). Cloudflare processes your IP address and request data to deliver pages and protect them from attacks, and our system keeps short technical logs. Legal basis: Art. 6(1)(f).
- Visitor statistics. Cloudflare Web Analytics counts page views on every page. It sets no cookies and does not identify you; Cloudflare sees your IP address, browser and the page you visit. It runs without asking, on the basis of our legitimate interest in knowing which pages are used (Art. 6(1)(f)).
- Bot check. Our booking, payment, menu and inquiry forms use Cloudflare Turnstile to tell people from bots. It looks at your browser and IP address. Legal basis: Art. 6(1)(f).
- No embedded review widgets. We link to our reviews on Google and Tripadvisor rather than embedding Google's or any other review site's badge or widget, so your browser contacts a review site only if you click such a link.
With your consent only
- Microsoft Clarity (statistics) records how visitors use our booking, menu, spaces and events pages — clicks, scrolling, mouse movement and device — so we can find what is confusing. Form fields and allergy answers are masked. It links a session to a booking number. Only with "Statistics" consent.
- Our booking-form statistics note which field a visitor stopped at and how long the form took, without names or contact details. Only with "Statistics" consent.
- Meta Pixel (marketing) tells Meta (Facebook, Instagram) which pages you visit and when you book or pay, so we can measure and improve our ads. Meta and we are jointly responsible for that collection; Meta is responsible for what it does with the data afterwards.
- Meta Conversions API (marketing) sends the same booking and payment events from our server to Meta, with your email, phone and name only as one-way hashes (SHA-256), your IP address, browser and Meta's click identifier. Only if you accepted marketing cookies when you booked.
- Ad visit records (marketing): if you accept marketing cookies, our server records each visit to our booking and event pages — a random visitor id, landing page, referrer, browser, device type, country, a hash of your IP address and campaign tags — to link ad visits to bookings.
- How you reached us (marketing): if you accept marketing cookies, your browser remembers on our booking pages, for 90 days, the campaign tags of the link that brought you here (such as utm_source, utm_campaign, ref and fbclid) with a random visitor id, and we store them with your booking so we know which campaigns bring guests. Without marketing consent nothing is kept in your browser and nothing is sent with your booking; if you withdraw it, what was kept is deleted.
The cookie banner has two switches besides the necessary cookies, and each controls exactly what is listed here: "Statistics" (Microsoft Clarity and our booking-form statistics) and "Marketing" (Meta Pixel, Meta Conversions API, ad visit records and how you reached us). Legal basis for these: your consent (Art. 6(1)(a), and Art. 4(5) of Greek Law 3471/2006). You can change your choice at any time from "Cookie settings" at the bottom of every page; we keep a record of each choice (with a daily-changing hash of your IP address, your browser and the policy version) to be able to prove it.
Who else sees your data
We do not sell your data. These companies work for us as processors, under contract and only on our instructions, unless noted otherwise:
| Who | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, bot check, visitor statistics | Worldwide network; US company |
| Amazon Web Services (Amazon SES) | Sending our emails | US company |
| Resend | Receiving your replies to our booking emails | USA |
| SMS Gateway for Android (sms-gate.app), Google Firebase Cloud Messaging | Carrying texts between our system and our restaurant phone | See "Outside the EU" |
| Yuboto, Rakuten Viber | Viber reminders and news | EU |
| Migadu-Mail GmbH | Our email inboxes | Switzerland |
| Viva | Card payments (for payment data, Viva is responsible itself) | Greece |
| Fly.io, Inc. | Relay server for our connection to Viva | Frankfurt, Germany; US company |
| Telegram | Booking and feedback notifications to our team | Outside the EU |
| Calendar (event planning), Google Wallet (if you add a ticket), Firebase Cloud Messaging | US company | |
| Apple, Google, Mozilla push services | Delivering encrypted notifications to our staff's devices | US companies |
| Meta Platforms Ireland Ltd | Meta Pixel and Conversions API — only with your consent; jointly responsible for collection | Ireland, and Meta in the USA |
| Microsoft | Clarity — only with your consent | US company |
| ΑΑΔΕ (Independent Authority for Public Revenue) | Tax receipts, by law — a public authority, not a processor | Greece |
| The organiser of your group event | Your group menu answers (see "Group menus") | — |
We may also give data to our accountant, lawyers, courts or authorities where the law requires it or to defend a legal claim.
Outside the EU
Some of these providers are based in the USA or elsewhere outside the European Economic Area, so your data can be accessed from there.
- Cloudflare, Amazon Web Services, Google, Microsoft and Resend are certified under the EU–U.S. Data Privacy Framework, which the European Commission has found to give an adequate level of protection (Decision (EU) 2023/1795).
- Switzerland, where Migadu is based, has an adequacy decision of the European Commission.
- Meta Platforms Ireland is responsible for its own transfers to Meta Platforms, Inc. in the USA; see Meta's privacy policy at https://www.facebook.com/privacy/policy.
- For other transfers (Fly.io, the SMS relay service and Telegram), we rely on the European Commission's standard contractual clauses where the provider offers them. You can ask us for a copy of the safeguards that apply.
How long we keep it
- Messages with us (SMS, email and Viber): each message is deleted 24 months after it was sent. Conversations that belong to no booking and that nobody answered are deleted after 90 days, and missed-call records after 90 days.
- Group menu answers, including allergies: 60 days after the event.
- Print jobs (receipts and kitchen tickets with names or allergies): 30 days after printing.
- Receipts and tax records: as long as Greek tax law requires.
- Job applications: up to 24 months, for the position you applied for and, only if you ticked the optional box, for later openings; sooner if you ask. We delete them by hand; this is not automated yet.
- Newsletter: until you unsubscribe. After that we keep only your address on our do-not-send list.
- Consent records: as long as we may need to prove your consent.
Our automatic deletion runs once a month, so data can stay up to a month past these dates. For everything else — bookings, guest profiles, club membership, event inquiries, feedback, shop orders and website visit records — we have not set fixed periods yet. We keep it while we have a reason to, for example to welcome you back or to answer a question about an earlier visit, and you can ask us to delete it at any time, unless the law requires us to keep it.
Your rights
You have the right to:
- know what data we hold about you and get a copy (Art. 15);
- have it corrected (Art. 16) or deleted (Art. 17);
- have its use restricted (Art. 18);
- receive the data you gave us in a common machine-readable format (Art. 20);
- object to our use of your data based on legitimate interest, and to direct marketing at any time (Art. 21);
- withdraw any consent at any time, without affecting what was done before (Art. 7(3)).
Write to felix@domaineflorian.com. We answer within one month and may ask you to confirm who you are. It is free.
You can also complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1-3, 115 23 Athens, phone +30 210 6475600, contact@dpa.gr, www.dpa.gr — or to the authority where you live or work.
No automated decisions
We do not make decisions about you by automated means that have legal or similarly significant effects (Art. 22). Our system automatically cancels a booking that is not paid by its deadline and marks a booking as a no-show when nobody checked in; neither affects later bookings automatically.
Changes to this policy
When we change how we use your data, we update this page and the date at the top. If a change needs your consent, we will ask for it.