Skip to content

Legal notice

Information pursuant to § 5 of the German Digital Services Act (DDG)

Surf N' Turf Kitchen (Rechtsform bitte ergänzen)

Dorotheenstraße 54, 22301 Hamburg

Represented by

Managing Director: Vasile Diaconu

Contact

Email: info@surf-n-turf-kitchen.de

Phone: 040 63608072

Register entry

Entered in the commercial register.

Register court: Amtsgericht Hamburg

Register number: HRB 000000

VAT identification number

VAT identification number pursuant to § 27a of the German VAT Act: DE000000000

Restaurant licence

As a catering business we operate on the basis of a licence under the German Restaurants Act (Gaststättengesetz). The authority responsible for the licence is: Bezirksamt Hamburg-Nord (district office), consumer protection authority, Hamburg.

Supervisory authority

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg

Responsible for the content

Responsible for the content pursuant to § 18 (2) of the German Media State Treaty (MStV): Vasile Diaconu, Dorotheenstraße 54, 22301 Hamburg

Online dispute resolution and consumer dispute resolution

The European Commission provides a platform for online dispute resolution (ODR): https://ec.europa.eu/consumers/odr. We are neither willing nor obliged to participate in dispute resolution proceedings before a consumer arbitration board.

Liability for content

As a service provider, we are responsible for our own content on these pages in accordance with general laws pursuant to § 7 (1) DDG. Pursuant to §§ 8 to 10 DDG, however, we are not obliged as a service provider to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity. Obligations to remove or block the use of information under general laws remain unaffected. Liability in this respect is, however, only possible from the point in time at which knowledge of a specific infringement of the law becomes known. Upon becoming aware of corresponding infringements, we will remove this content immediately.

Liability for links

Our offer may contain links to external websites of third parties over whose content we have no influence. We therefore cannot accept any liability for this third-party content. The respective provider or operator of the linked pages is always responsible for their content. The linked pages were checked for possible legal violations at the time of linking. Illegal content was not recognisable at the time of linking. Upon becoming aware of legal violations, we will remove such links immediately.

Copyright

The content and works created by the site operators on these pages are subject to German copyright law. Reproduction, editing, distribution and any kind of use outside the limits of copyright law require the written consent of the respective author or creator. Downloads and copies of this page are only permitted for private, non-commercial use. Insofar as the content on this site was not created by the operator, the copyrights of third parties are respected. Should you nevertheless become aware of a copyright infringement, please inform us accordingly. Upon becoming aware of legal violations, we will remove such content immediately.

Privacy policy

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Surf N' Turf Kitchen (Rechtsform bitte ergänzen), Dorotheenstraße 54, 22301 Hamburg, represented by Vasile Diaconu. Email: info@surf-n-turf-kitchen.de, phone: 040 63608072.

Data protection contact: info@surf-n-turf-kitchen.de.

2. Subject of this policy

This policy explains what personal data we process when you visit our website and use our services (table reservations, contact and celebration enquiries, newsletter and gift cards), for what purposes and on what legal bases, who receives the data, how long we store it and what rights you have.

3. Access data / server log files

When you visit our website, your browser automatically transmits data that is temporarily stored in server log files: the IP address of the requesting device (shortened or hashed where possible), date and time of the request, the requested resource, the referrer URL, and information about the browser and operating system. This data is required to deliver the website, to guarantee stability and security and to prevent misuse.

Legal basis: Article 6(1)(f) GDPR (legitimate interest in the secure and stable provision of the website).

4. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.

5. Table reservation

When you reserve a table, we process the data you enter (name, email address, phone number, number of guests, date and time and any message). We use it to process, confirm and manage your reservation and to send you a confirmation and, where applicable, a self-service link to change or cancel it.

Legal basis: Article 6(1)(b) GDPR (performance of pre-contractual measures and the reservation) and, for the associated confirmation emails, Article 6(1)(f) GDPR.

6. Contact and celebration enquiries

If you send us an enquiry via a contact or celebration form, we process the data you provide (e.g. name, email address, phone number, occasion and the content of your message) in order to answer and process your request.

Legal basis: Article 6(1)(b) GDPR (pre-contractual measures) and Article 6(1)(f) GDPR (legitimate interest in answering enquiries).

7. Newsletter (double opt-in)

You can subscribe to our newsletter with your email address. We use the double opt-in procedure: after registering, you receive a confirmation email and your subscription only becomes active once you click the confirmation link. We store the email address, the confirmation and the time of registration and confirmation in order to prove your consent. You can unsubscribe at any time using the link in every newsletter or by contacting us; this revokes your consent with effect for the future.

Legal basis: Article 6(1)(a) GDPR (consent).

8. Gift cards and payment processing

If you purchase a gift card, we process the data required to conclude and perform the contract (e.g. name, email address, the chosen amount, the motif and delivery method and, where applicable, a delivery address and a dedication text) and to send you confirmations and the gift card. Payment is handled by our payment service provider Mollie; we do not receive or store your full payment card or account details.

Legal basis: Article 6(1)(b) GDPR (performance of the contract) and Article 6(1)(c) GDPR (compliance with legal, in particular commercial and tax, retention obligations).

9. Map embedding

On our contact page we embed a map. The map is only loaded after you have actively consented (two-click / consent overlay); before that, no connection to the map provider is established and no data is transferred. When you activate the map, the provider (Google Ireland Limited) may process your IP address.

Legal basis: Article 6(1)(a) GDPR (consent).

10. Cookies and consent

We only use cookies and comparable technologies that are technically necessary to operate the website, unless you have given your consent to further use. You can withdraw consent given at any time with effect for the future. Technically necessary storage is based on Article 6(1)(f) GDPR; any non-essential technologies are based on Article 6(1)(a) GDPR.

11. Recipients and processors

To operate the website and services we use carefully selected service providers who process data on our behalf under a data processing agreement pursuant to Article 28 GDPR: our hosting and platform provider (Tasteclick, including the hosting infrastructure Vercel and the database service Supabase), an email delivery provider (Amazon Web Services / Amazon SES) and, for paid transactions, the payment service provider Mollie. We only pass on data to public authorities where we are legally obliged to do so.

12. Transfer to third countries

Where a processor also processes data outside the European Economic Area, this is done on the basis of the EU standard contractual clauses or another valid transfer mechanism pursuant to Chapter V GDPR to ensure an adequate level of data protection.

13. Storage period

We store personal data only for as long as is necessary for the respective purpose or as required by statutory retention periods (in particular under commercial and tax law, e.g. § 257 HGB and § 147 AO). Afterwards the data is deleted or anonymised. Reservation and enquiry data is deleted once the respective matter has been fully processed and no retention obligations apply.

14. Your rights

You have the right to access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), data portability (Article 20 GDPR) and to object to processing based on Article 6(1)(f) GDPR (Article 21 GDPR). Where processing is based on your consent, you may withdraw it at any time with effect for the future. To exercise your rights, please contact us using the details above.

15. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg.

16. Currency of this policy

This privacy policy is current. We will amend it if changes to our services or the legal situation make this necessary.

External content (videos, maps, booking areas)

Third-party external content, such as videos, maps and booking areas, only loads once you explicitly agree in the placeholder shown. If you agree, we store your decision for that specific provider in a small text entry (cookie) on your device; all that is stored is the day of your consent. Its sole purpose is to spare you from agreeing again on your next visit. No reach measurement and no profiling take place.

The stored decision is valid for 180 days. After that it expires and the placeholder reappears.

When you access this website we do not use any cookies or comparable technologies that require consent; external content that requires consent is only loaded after you have expressly approved it (§ 25(1) TDDDG). No consent banner therefore appears.

You can withdraw your consent at any time via the “Privacy settings” item, directly below this paragraph and in the footer of all pages. There you can see each provider individually, switch it off individually and apply your choice with “Save selection”; “Reject all” resets every stored consent in one step.