This policy explains what personal data we collect when you use the website and services of Bistro Étoile (reservations, online orders, loyalty programme), how we use it, who we share it with, and what your rights are under EU Regulation 2016/679 (GDPR) and Romanian Law 190/2018.
1. Who we are (Data Controller)
Data Controller: Bistro Étoile SRL, registered at the Trade Register no. J40/0000/2024, VAT RO99999999, with registered office at Str. Academiei 14, Sector 1, Bucharest, Romania.
Data Protection Officer (DPO): dpo@bistro-etoile.ro.
Supervisory authority: ANSPDCP (Romanian DPA). You have the right to lodge a complaint if you believe processing breaches GDPR.
2. What data we collect
We collect only the data strictly needed to deliver the service you requested and to meet legal obligations (fiscal, consumer protection).
- Identification data: first name, last name, email, phone number.
- Reservation / order data: date, time, party size, delivery address (when applicable), dietary preferences (allergens — optional).
- Payment data: we NEVER store full card numbers. Payments are processed exclusively by Stripe (PCI DSS Level 1). We store only a token + last 4 digits + card brand (needed to display order history).
- Browsing data: IP, user agent, browser locale (used for security, fraud prevention, anonymous statistics).
- Marketing data: email (only if you explicitly subscribe to the newsletter), channel preferences (email / SMS).
3. Why we collect (purpose) and legal basis
Every processing activity has a clear GDPR legal basis:
- Contract performance (Art. 6(1)(b)): to process reservations, orders, deliveries, payments, account management.
- Legal obligation (Art. 6(1)(c)): to issue tax invoices (Law 227/2015) — invoiced data is kept for 10 years under the Tax Code.
- Legitimate interest (Art. 6(1)(f)): for fraud prevention, application security, service improvement (anonymised analytics).
- Consent (Art. 6(1)(a)): for marketing newsletter, analytics and marketing cookies — you can withdraw consent at any time at /cookies or in your account.
4. How long we keep data
We apply the minimisation principle — data is kept only as long as needed.
- Active client account: for as long as the account exists + 30 days after deletion (historical anonymisation for statistics).
- Tax invoices: 10 years (legal obligation — Tax Code).
- Reservations & orders: 5 years from event date.
- Marketing data (consent): until consent withdrawal or 36 months of inactivity.
- Security audit log: 5 years (specs §7.1).
- Cookies: see /cookies for exact duration per category.
6. Your GDPR rights
Under Art. 15-22 GDPR you have the following rights:
- Right of access — request a copy of the data we hold about you. Available from /account/security or by emailing dpo@bistro-etoile.ro.
- Right to rectification — correction of inaccurate data. Directly from /account or by email.
- Right to erasure ("right to be forgotten") — we anonymise data, keeping only what is legally mandatory (invoices). Request from /account/security.
- Right to portability — receive your data in structured JSON/CSV format, easy to import elsewhere.
- Right to object and withdraw consent — for marketing, at any time from /cookies or via the unsubscribe link in any email.
- Right to lodge a complaint with ANSPDCP (Romanian Data Protection Authority).
7. How we protect you
We apply reasonable technical and organisational measures to protect your data:
- TLS 1.3 encryption for all connections.
- Passwords are hashed with bcrypt (cost factor 12).
- Two-factor authentication (2FA) available at /account/security.
- Daily encrypted backups, 30-day retention.
- Immutable audit log for sensitive actions.
- Strict internal access with RBAC (role-based access control) — staff access only what their role requires.
9. Changes
We will occasionally update this policy. Material changes (purpose, legal basis, sub-processors) will be announced via email (account holders) and a site banner, at least 30 days before they take effect.