Skip to content

Privacy Policy

We respect your privacy. This policy explains what personal data we process through mariasiion.ro, why, and what rights you have, under Regulation (EU) 2016/679 (GDPR).

Last updated: September 2026

1. Data controller

The controller is SC RESTAURANT LA MARIA SI ION SRL, registered office at Splaiul Independenței 290, Regie student quarter, Bucharest, Romania, tax ID (CUI) 43718579, Trade Register no. J2021002400409.

For any request about your data: evenimente@mariasiion.ro, phone 0753 473 781.

2. What data we process and why

We do not ask for or process special-category data (health, opinions, etc.). Please do not enter such data in the notes field; if you tell us about an allergy, we use it only to prepare your order.

  • Reservation request (site form): name, phone number, desired date and time, number of guests and any notes. Purpose: to take and confirm the reservation and to contact you.
  • E-mail or phone communications: the data you send us. Purpose: to answer your request.
  • Technical data: IP address, browser type, server logs. Purpose: security, operation and abuse prevention.

3. Legal basis

  • your consent, given by ticking the box in the form — Art. 6(1)(a) GDPR;
  • pre-contractual steps at your request (arranging the reservation) — Art. 6(1)(b) GDPR;
  • our legitimate interest in keeping the site secure — Art. 6(1)(f) GDPR.

4. Who we share data with

We do not sell or rent your data. We do not use it for advertising.

  • the provider of the reservation e-mail service (Resend), which processes the message solely to deliver it to us;
  • the site's hosting provider, on whose infrastructure the app runs;
  • public authorities, only where required by law.

5. Transfers outside the European Economic Area

If a provider processes data outside the EEA, the transfer relies on appropriate safeguards (standard contractual clauses approved by the European Commission, or an adequacy decision).

6. How long we keep data

Reservation-request data is kept for at most 12 months after the reservation date, unless another legal basis requires keeping it, then deleted.

E-mail correspondence is kept as long as needed to handle the request and for a reasonable period afterwards.

Technical logs are kept short-term, for security.

7. Your rights

Under GDPR, you have the right to:

  • access your data and receive a copy;
  • have inaccurate data corrected;
  • erasure ("the right to be forgotten");
  • restrict processing;
  • data portability;
  • object to processing;
  • withdraw consent at any time, without affecting prior lawful processing;
  • lodge a complaint with the Romanian Data Protection Authority (ANSPDCP).

8. Supervisory authority

ANSPDCP — B-dul G-ral Gheorghe Magheru 28-30, Sector 1, Bucharest; e-mail anspdcp@dataprotection.ro; www.dataprotection.ro.

9. Security

We apply reasonable technical and organisational measures to protect data against unauthorised access, loss or disclosure: encrypted transmission (HTTPS), limited access to data, GDPR-compliant providers.

10. Automated decisions

We do not make decisions based solely on automated processing, and we do not carry out profiling.

11. Changes

We may update this policy. The last update date is shown above.