Privacy Policy

DATA PROTECTION

Privacy Policy under the GDPR

We take the protection of your personal data seriously. This page explains what data we collect when you use our website, why we collect it, and what rights you have. We process personal data only in accordance with the General Data Protection Regulation (GDPR) and German data protection law.



1. Who is responsible

The controller responsible for data processing on this website is:

Amrut Indian Restaurant
Represented by Gajjar & Ballagan GbR
Tiroler Str. 55
87629 Füssen, Germany

Tel: +49 (0)8362-9263298
Email: info@amrut-fuessen.de

Full company details can be found in our Imprint.



2. Hosting

This website is hosted by an external hosting provider (Hostinger International Ltd.). Personal data collected on this website is stored on the provider's servers. This may include IP addresses, contact requests, and other data generated through a website visit.

Hosting is used for the purpose of fulfilling our contract with potential and existing guests, and in the interest of a secure, fast and reliable provision of our website by a professional provider (Art. 6 (1) (f) GDPR). We have concluded a data processing agreement with our provider as required by Art. 28 GDPR.



3. Server log files

Our hosting provider automatically collects and stores information in server log files, which your browser transmits to us. These are:

• browser type and version
• operating system used
• referrer URL
• host name of the accessing computer
• time of the server request
• IP address

This data is not merged with other data sources. It is collected on the basis of Art. 6 (1) (f) GDPR: we have a legitimate interest in the technically error-free presentation and optimisation of our website, which requires server log files to be recorded. Log files are stored for a limited period and then deleted.



4. SSL/TLS encryption

This site uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content, such as the reservation requests you send to us. You can recognise an encrypted connection by the address line of your browser changing from "http://" to "https://" and by the lock symbol in your browser bar. When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.



5. Table reservation form

When you request a table through the booking form on this website, we collect the following information:

• first name and last name
• email address
• telephone number
• date, time and number of guests
• table preference (optional)
• special requests or dietary requirements (optional)

Purpose and legal basis. We use this data solely to process and confirm your reservation and to contact you if anything about your booking needs clarifying. The legal basis is Art. 6 (1) (b) GDPR, as the processing is necessary to carry out pre-contractual measures at your request.

Please note that any information you voluntarily enter into the "special requests" field is transmitted to us as you write it. Please do not enter health data or other sensitive information there. If you need to tell us about an allergy or dietary requirement, a general description is sufficient.

Transmission and storage. Your reservation request is sent to us by email and is therefore also processed by our email provider. A confirmation copy is sent to the email address you provide. We retain reservation data only for as long as is necessary to handle your booking and to comply with statutory retention obligations; after that it is deleted.



6. Contact by email, telephone or WhatsApp

If you contact us by email, telephone or WhatsApp, your enquiry and all resulting personal data will be stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.

This data is processed on the basis of Art. 6 (1) (b) GDPR where your request is related to a contract or pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us (Art. 6 (1) (f) GDPR), or on your consent (Art. 6 (1) (a) GDPR) where this has been requested.

Please note that WhatsApp is a service provided by WhatsApp Ireland Ltd. If you contact us via WhatsApp, that service's own privacy policy applies to the transmission of your message.



7. Cookies

We do not use any tracking, advertising or analytics cookies. This website contains no Google Analytics, no Meta/Facebook pixel, and no comparable tracking technology.

The only cookie this website may set is a technically necessary session cookie, and only for the administrator of this website when signing in to the internal content management area. It contains no personal information about visitors, is not used to analyse behaviour, and is deleted when the browser session ends. Its legal basis is § 25 (2) TTDSG, as it is strictly necessary to provide a service that has been expressly requested.

As an ordinary visitor to this website, no cookie requiring consent is set.



8. Web fonts

This website uses the typefaces Poppins, Lora, Playfair Display and Inter. These fonts are hosted locally on our own server. No connection is made to Google servers when you visit this site, and your IP address is not transmitted to Google in order to display the fonts.



9. Google Maps

This website embeds a map from the mapping service Google Maps, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"), so that you can find your way to the restaurant easily.

To use the functions of Google Maps, it is necessary to transmit your IP address to Google. This information is generally transferred to a Google server and stored there; transfer to servers in the USA cannot be ruled out. The operator of this website has no influence over this data transfer.

Google Maps is used in the interest of an appealing presentation of our online offering and to make the locations indicated on the website easy to find. This constitutes a legitimate interest within the meaning of Art. 6 (1) (f) GDPR.

For transfers to third countries, Google relies on the EU Standard Contractual Clauses and is certified under the EU-U.S. Data Privacy Framework. Further information on the handling of user data can be found in Google's privacy policy: https://policies.google.com/privacy.



10. Share buttons on blog articles

Our blog articles contain sharing buttons provided by AddToAny. When you open a blog article, a script is loaded from AddToAny's servers, which means your IP address is transmitted to that provider. This is done in our legitimate interest in allowing our articles to be shared easily (Art. 6 (1) (f) GDPR). Further information is available at https://www.addtoany.com/privacy.



11. Externally hosted images

Some illustrations of nearby sights on our home page are loaded directly from external sources (including Unsplash, fuessen.de, hohenschwangau.de and neuschwanstein.de). When such an image is displayed, your IP address is transmitted to the server hosting it. This happens in our legitimate interest in presenting the surrounding area attractively (Art. 6 (1) (f) GDPR). We have no influence over any further processing by those providers.



12. Social media and review portals

Our website contains simple links to our profiles on Instagram, TripAdvisor and WhatsApp. These are ordinary hyperlinks, not embedded plugins: no data is transmitted to those providers until you actively click a link. Once you do, the privacy policy of the respective provider applies.



13. Your rights

You have the following rights in relation to your personal data:

Right of access (Art. 15 GDPR) – to ask what data we hold about you
Right to rectification (Art. 16 GDPR) – to have incorrect data corrected
Right to erasure (Art. 17 GDPR) – to have your data deleted
Right to restriction of processing (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object (Art. 21 GDPR) – to processing based on legitimate interest
Right to withdraw consent (Art. 7 (3) GDPR) at any time, with effect for the future

To exercise any of these rights, simply contact us at info@amrut-fuessen.de. Exercising your rights is free of charge.



14. Right to lodge a complaint

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de



15. No automated decision-making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Your data is not used to create user profiles, and it is never sold or passed on for advertising purposes.



16. Changes to this privacy policy

We may update this privacy policy from time to time so that it always reflects the current legal requirements and any changes to our website. The current version always applies.

Last updated: 14 August 2026