Privacy policy
This policy explains how La Gramola Mallorca processes personal data relating to website visitors and people who make an enquiry or request a booking.
Last updated: 2 August 2026.
1. Data controller
- Controller: Antonio Ramón Lería Silva.
- Spanish tax ID (NIF): 44796067F.
- Trading name: La Gramola.
- Address: C/ Vinya del Mar, 6, 07560 Cala Millor, Mallorca, Spain.
- Email: antonioleria@hotmail.es.
- Telephone: +34 971 81 40 56.
2. Data processed
- Contact and booking data: name, telephone, email, date, time, number of guests and the content of the enquiry or request.
- Communications: messages and information supplied through WhatsApp, email or telephone.
- Technical data: IP address, browser type, access date and time, and technical records needed for website security and operation.
- Special-category data: the restaurant does not request medical information. If users consider it essential to disclose an allergy or intolerance, they should provide only the necessary information and must expressly authorise its processing.
3. Purposes and lawful bases
- Answering enquiries and booking requests: steps taken at the user's request before entering into a contract and, where relevant, performance of the requested relationship.
- Managing a booking and communicating with the customer: performance of a contractual or pre-contractual relationship.
- Complying with tax, accounting, health or administrative duties: compliance with legal obligations.
- Protecting the website, preventing abuse and keeping technical records: the controller's legitimate interest in ensuring security and availability.
- Processing voluntarily supplied allergy or health information: the data subject's explicit consent, which may be withdrawn at any time.
Personal data will not be used for electronic marketing without a valid lawful basis and specific prior information.
4. Required information
Fields marked as required are needed to process the request. Without them, the restaurant may be unable to manage the booking. Users must provide accurate, up-to-date information and must not disclose another person's data without authorisation.
5. Data retention
Data will be kept for as long as needed to manage the enquiry or booking. It may then remain restricted for the statutory limitation periods applicable to potential claims. Tax and accounting records will be retained for the periods required by law. Data processed solely on the basis of consent will be erased when consent is withdrawn unless another legal retention duty applies.
6. Recipients
Personal data will not be sold. Service providers needed by the controller, such as website hosting, technical support and email providers, may access data under the relevant contractual safeguards. Data may also be disclosed to public authorities, courts or regulators where required by law.
If users communicate through WhatsApp or use Google Maps, Instagram or other external services, those providers process data under their own policies. Relevant providers may include Meta Platforms Ireland Limited, Google Ireland Limited and Microsoft Ireland Operations Limited.
7. International transfers
Some providers may process information outside the European Economic Area. Where this occurs, processing must rely on an adequacy decision, standard contractual clauses or another safeguard recognised by the General Data Protection Regulation. Details are available in the privacy policies of WhatsApp, Google and Microsoft.
8. Individual rights
Data subjects may request access, rectification, erasure, objection, restriction of processing and data portability where applicable. They may also withdraw consent without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, email antonioleria@hotmail.es, stating the right concerned and supplying the information needed to verify identity. If a person believes that processing breaches data protection law, they may lodge a complaint with the Spanish Data Protection Agency (AEPD).
9. Automated decisions and profiling
No automated decisions producing legal effects are made, and no commercial profiles are created from booking or enquiry data.
10. Security and updates
The controller applies reasonable and proportionate technical and organisational security measures. This policy may be updated when processing activities, providers or legislation change; the date shown above identifies the current version.
