Skip to content
echtasien

Privacy policy

The following information explains, pursuant to Article 13 GDPR, which personal data we process in connection with this website and the services offered through it.

1. Controller within the meaning of the General Data Protection Regulation (GDPR)

Sangai GmbH (trading as „Echtasien“)

Blankeneser Landstraße 1, 22587 Hamburg, Germany

Represented by its managing director Santosh Kumar Lama

Phone +49 40 53008876 (Winterhude) and +49 40 18011932 (Blankenese), email verwaltung@echtasien.de

We operate the restaurants Echtasien Winterhude (Alsterdorfer Straße 85, 22299 Hamburg) and Echtasien Blankenese (Blankeneser Landstraße 1, 22587 Hamburg).

Please send data protection enquiries to verwaltung@echtasien.de or to the postal address given above.

2. Scope of this policy

This policy covers your visit to this website and the services offered through it: table reservations, contact and job enquiries, and the newsletter. For each of these we describe below which data we process, why, on which legal basis, who receives it and how long we keep it.

3. Legal bases

We process personal data on the basis of Article 6(1)(a) GDPR (consent), (b) (contract and pre-contractual measures), (c) (legal obligation) and (f) (legitimate interest; the interest concerned is stated in the relevant section). The storage of information on your device and access to it are additionally governed by § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG).

4. Hosting and server logs

This website is hosted, delivered and image-optimised by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Server-side functions run, according to our configuration, in the EU region of Frankfurt am Main; delivery takes place via Vercel's globally distributed edge network. Build processes and product-related log data are partly processed by Vercel in regions in the USA.

When you access the website, technically necessary connection data is processed: IP address, date and time, the requested path including its query parameters, the HTTP method and HTTP status, the requested host name, the browser identifier (user agent, which also carries information about the operating system), the delivery-network region handling the request, the cache status and a request identifier; any further details only insofar as your browser transmits them. The purposes are the secure and stable provision of the website, protection against misuse and error analysis; the legal basis is Article 6(1)(f) GDPR.

Vercel retains the logs of our server-side functions (runtime logs) for one day in the plan we use; they are deleted after that. We do not use any forwarding of these logs to external recipients. Build logs are a separate matter: they are created when a new version of this website is published, record the course of the build process, contain no visitor data and are retained by Vercel indefinitely for each publication. Individual connection data is retained for longer only where necessary to defend against a specific attack or to investigate a fault.

A data processing agreement is in place with Vercel. Vercel Inc. is based in the USA and operates a globally distributed infrastructure; transfers to third countries are expressly provided for in that agreement and are based on the EU Commission's standard contractual clauses (Article 46(2)(c) GDPR). You can read their wording in Implementing Decision (EU) 2021/914 at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj. Vercel Inc. is additionally certified under the EU-U.S. Data Privacy Framework; you can find the entry at https://www.dataprivacyframework.gov/list.

5. Database and application backend

The content, master and transaction data of this website, namely page content, reservations, enquiries, newsletter sign-ups and our guest directory, are processed in a database of the Supabase service. Our contractual partner is Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Data is stored in a database region within the EU (Ireland); separation from the data of other businesses is enforced at database level.

The images and videos of this website are also stored there. Photographs, however, are not delivered directly from there: our hosting provider Vercel retrieves them from that storage, converts them into a space-saving image format (AVIF or WebP), keeps the converted version in its delivery network for up to one year and delivers it from there to your browser; your IP address is transmitted to Vercel in the process. The purpose is faster display with a smaller volume of data; the legal basis is Article 6(1)(f) GDPR. The provider, the place of processing and the third-country safeguards are set out in the section "Hosting and server logs". Videos and graphics in SVG format continue to be delivered directly from that storage to your browser; your IP address is transmitted to Supabase in the process.

The purpose is the provision and management of the website content and functions; the legal basis is Article 6(1)(f) GDPR and, where necessary for the performance of a contract, Article 6(1)(b). A data processing agreement is in place. Where administrative access from third countries cannot be ruled out, it is based on the EU Commission's standard contractual clauses (Article 46 GDPR); this provider is not certified under the EU-U.S. Data Privacy Framework.

6. Protection against misuse

To protect our forms and ordering channels against automated submissions, we limit their number per time window. For this purpose we store, for every reservation, enquiry and newsletter sign-up, a cryptographic hash of your IP address (the IP address itself is not stored) and, on the next submission, count how many transactions with the same hash fall within the time window. We do not keep a separate counter; the hash is stored for as long as the transaction it belongs to. The purpose is the security of our systems; the legal basis is Article 6(1)(f) GDPR.

7. Protection against automated requests (Cloudflare Turnstile)

To protect our contact form, our job application form and our table reservation against automated submissions by programs (bots), we use the Turnstile service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, as soon as and for as long as we have switched this protection on for our website. Even then, Turnstile is only loaded once you start working with one of these forms, for example by clicking into a field or entering something. Merely visiting our pages does not establish any connection to Cloudflare.

Once loaded, a Cloudflare script checks in the background whether the form is being filled in by a human. In doing so, your IP address, characteristics of your browser and device (such as browser type and version, operating system, language setting and screen properties) and signals of your interaction with the page (such as the type and timing of mouse, keyboard or touch input) are transmitted to Cloudflare and evaluated there. This usually happens invisibly; only if the check is inconclusive does a short confirmation appear in the form. As a result, your browser receives a verification token that is sent to us together with the form. Our server has this token confirmed by Cloudflare without transmitting your IP address again. The result is used solely to decide whether we accept the submission; if Cloudflare is temporarily unavailable, we accept it without this check.

The purpose is to protect our forms and the systems behind them against misuse, spam and automated mass submissions; the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to receive only genuine submissions and to keep our forms available to all visitors.

While the protection is switched on, the check is required in order to submit a form, and the data transmitted in the process are mandatory to that extent: without them we cannot accept the submission, for example if a content blocker suppresses the verification script. You can then reach us by email or by phone using the contact details above.

Insofar as the verification script reads information from your device or temporarily stores information on it for this purpose, this is permitted without consent under § 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG): the check only takes place when you expressly use a form, and it is strictly necessary for us to provide that form protected against automated misuse. We do not use Turnstile for advertising or analytics purposes.

We ourselves do not store the verification token beyond processing the respective submission. How long Cloudflare retains the verification data is determined by Cloudflare's Turnstile privacy addendum, which you can view at https://www.cloudflare.com/turnstile-privacy-policy/.

Cloudflare acts as a sub-processor of our technical service provider (see “Recipients of personal data”); a data processing agreement is in place. Cloudflare operates a globally distributed network; processing in the USA cannot be ruled out. Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (https://www.dataprivacyframework.gov/list); in addition, the EU Commission's standard contractual clauses apply (Implementing Decision (EU) 2021/914, https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj). Further information can be found in Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/.

8. Error and stability monitoring

To detect and fix technical errors we use the Sentry service of Functional Software, Inc. (d/b/a Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, in its EU region (data centre in Frankfurt am Main). When a technical error occurs, diagnostic data is transmitted: the error message and the technical call stack, the address concerned, the time, and browser and device information.

Before transmission, automatic filtering removes information that could identify a person, in particular access keys, email addresses, IP addresses in the message text, cookies and the query parameters of requested addresses. No deliberate transmission of personal data takes place; that such information may occasionally be included by chance cannot be entirely ruled out technically.

The purposes are error analysis and the stability and security of this website; the legal basis is Article 6(1)(f) GDPR. Error event data is processed in the EU region and deleted after 90 days. A data processing agreement is in place; where administrative access takes place from the USA, the adequacy decision on the EU-U.S. Data Privacy Framework and, in addition, the EU Commission's standard contractual clauses apply.

9. Error reports from your browser

If a technical error occurs in your browser, for example while displaying a page, an error report is sent directly from your device to Sentry; the provider, data location and retention are the same as in the section "Error and stability monitoring". The data transmitted comprises technical error data (the error message and call stack, the requested address without its query parameters, the time, and browser and device information) and, unavoidably because it is part of every internet connection, your IP address.

We have deliberately limited this function to the minimum: there is no session recording, so your screen is not recorded. Visits are not counted and the loading times of your visit are not transmitted. Your actions before the error are recorded only as a technical position in the page structure (which button, which page), not with what you entered or read.

No information is stored on your device and no information stored there is read. This is therefore not a case under § 25 TDDDG, and no consent is required. The purpose and legal basis correspond to the section "Error and stability monitoring" (Article 6(1)(f) GDPR); here too, the incidental capture of personal information cannot be entirely ruled out technically.

10. Fonts

The fonts used on this website are served from our own server. No connection to third-party servers is established, in particular no retrieval of Google Fonts via a Google CDN.

11. Reach measurement

For statistical analysis of the use of this website we use Umami in the "Umami Cloud" variant. The provider is Umami Software, Inc., 28 Geary St, Suite 650 #243, San Francisco, California, USA. The counts are transmitted to the provider's European collection endpoint.

Counting works as follows: a small counting signal provided by us reports, for each page view, the requested page path to our own website address. No third-party script is loaded, no cookie is set and nothing is stored on or read from your device. As with every request to a website, your browser itself transmits the address of the page you are on, your IP address and your browser identifier. From the page address our server takes, where applicable, the campaign details (only the parameters “utm_source”, “utm_medium”, “utm_campaign”, “utm_term” and “utm_content”; other parameters, such as click identifiers of advertising networks, and values that look like a customer or recipient identifier are not taken over). In order to group visits made on the same day, our server derives a check value (daily pseudonym) from your IP address, your browser identifier and the identifier of this website, using a randomly generated daily key that is deleted on the following day. Umami can never trace this value back to your IP address or your browser, and once the daily key has been deleted no one can; it does not allow you to be recognised across several days or across different websites. Your IP address and browser identifier are used for this only at the moment of the page view and are not stored for this purpose. Our server then passes on to Umami only the page path including the campaign details, the page language, the identifier of this website and the daily pseudonym; neither your IP address nor your browser identifier is transmitted to Umami. No cross-site tracking and no profiling take place.

The purposes are reach measurement and the improvement of our offering; the legal basis is Article 6(1)(f) GDPR. No storage of or access to information on your device within the meaning of § 25(1) TDDDG takes place, so no consent is required. The counts transmitted to Umami contain neither your IP address nor your browser identifier; Umami cannot attribute the daily pseudonym they contain to a person. They are retained there in accordance with the plan we have booked and then deleted. As the parent company is based in the USA, administrative access from the USA cannot be entirely ruled out; in that respect the EU Commission's standard contractual clauses apply (Article 46 GDPR).

12. Table reservation

When you reserve a table through this website, we process the details you enter in the reservation form: the desired location, the number of guests, date and time, your name and your contact details (email address and phone number; the form indicates which of them is mandatory) and, where the form offers them, optionally your seating preference, the occasion and a note. We also store the channel through which the reservation reached us and the language in which you booked. Your IP address is processed only as a cryptographic hash for protection against misuse.

We use these details to accept your reservation, assign a table to it, confirm and manage it. Depending on our restaurant's settings, we confirm a reservation automatically as soon as a suitable table is available, or we review it and confirm it personally; until then your reservation is treated as a request. The legal basis is Article 6(1)(b) GDPR (performance of the reservation); for the assignment to our guest directory, Article 6(1)(f) GDPR (orderly management of our guests).

The fields marked as mandatory in the reservation form are those we need in order to accept your reservation, assign a table to it and confirm it; without them we cannot accept a reservation. All other details are optional.

By email you receive, depending on the course of your reservation, an acknowledgement of your request, the confirmation or refusal of the reservation, a notice if your reservation is changed or cancelled, a confirmation if you cancel it yourself, and a reminder before the appointment; if you have provided a phone number, we may also call you. These messages are part of performing your reservation (Article 6(1)(b) GDPR). Our messages include a calendar entry that contains only the location, address, time and your reservation number, and no further details about you; if you add it to a calendar service, it is transferred there and that provider's notices apply. If you reply to one of these emails, your reply goes directly to the address of the respective restaurant. Your reservation is also shown to our team in the restaurant; at the team's express request it can additionally be sent as a notification to their work devices.

If our restaurant has switched on the review request, we send you a short email once after your visit, thanking you for your visit and asking you to rate us via a link; if you follow the link, the privacy notices of the review platform apply. You receive this message only once, even if you reserve with us more often. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is our guests' feedback on their visit. You can object to this at any time, using the unsubscribe link in that email or informally via the contact details above (Article 21(2) GDPR). Unsubscribing applies to all promotional emails from our restaurant, including our newsletter. Anyone who has unsubscribed from our newsletter or objected to receiving it does not receive this message.

Using a personal link in these messages you can change or cancel your reservation yourself; the link contains a random identifier, is addressed to no one else and remains valid for up to twelve months after the reservation. Please do not pass it on. Anyone who knows it can view and change the reservation. By default a change is possible until 120 minutes before the reservation time and a cancellation until it starts; the exact periods are set by our restaurant and stated in your confirmation. After that, please contact us by phone. You do not need a customer account to reserve or to use this link.

If guests repeatedly fail to appear at the reserved time without cancelling, our restaurant may decide that an online booking using the same email address or phone number is only possible as a request, or is no longer accepted; for this we process the number of no-shows in the past twelve months from your entry in our guest directory. The legal basis is Article 6(1)(f) GDPR (protection against repeatedly unused tables). The telephone route to us always remains open and any reservation can be created manually by our team; a decision based solely on automated processing within the meaning of Article 22 GDPR therefore does not take place. You may object to this processing under Article 21 GDPR and may ask us for access and rectification at any time.

The note field is intended for organisational information such as a high chair or a terrace request. Please do not enter any information about your health there; please tell us about allergies and intolerances on site or by phone (see the next paragraph). If you do enter health information there nonetheless, we use it solely for this visit; the legal basis is then your explicit consent under Article 9(2)(a) GDPR, which you give by making the entry and can withdraw at any time. We delete your note and the occasion automatically no later than 30 days after the reservation date.

You do not state allergies or intolerances when booking online. If you explicitly ask us, on site or by phone, to take allergies or intolerances into account, we record this with your reservation and in your entry in our guest directory; the same applies if you tell us about a particular diet, such as vegetarian, vegan, halal or kosher. Details of allergies and intolerances are data concerning health (Article 4(15) GDPR); details of your diet may allow conclusions about your religious or philosophical beliefs (Article 9(1) GDPR). We use these details solely in order to prepare your visit and advise you; the legal basis is your explicit consent under Article 9(2)(a) in conjunction with Article 6(1)(a) GDPR, which you give with your request. Without these details we accept your reservation just the same.

You may withdraw your consent at any time with effect for the future, informally using the contact details given above; we then delete the information. With the reservation, the information is deleted together with your note no later than 30 days after the reservation date. Your entry in our guest directory always holds the most recently recorded information; if you tell us something different later, your new information replaces the previous one. In the guest directory it remains until you withdraw your consent or the entry is anonymised after the periods stated in the section „Guest directory“. Within our business, only those people who handle your reservation anyway can see it.

Your reservation data is linked to your entry in our guest directory (see „Guest directory“); once its contact details are anonymised, only the date, time, number of guests and table remain of the reservation, without any personal reference.

13. Contact and job enquiries

When you write to us via the contact form, we process your subject, name, email address, optionally your phone number and your message in order to handle your enquiry. Your message is additionally delivered to us by email; the provider of our mailbox processes it as a recipient (see „Email mailbox and domain“). The legal basis is Article 6(1)(b) GDPR where your enquiry is aimed at a contract (for example an event or celebration), otherwise Article 6(1)(f) GDPR (orderly handling of enquiries). We store enquiries for the duration of their handling and delete them automatically no later than 180 days after receipt. Where your enquiry leads to a contract, the periods stated there apply; statutory retention obligations remain unaffected.

If we already hold an entry in our guest directory for the email address you enter in the contact form (see “Guest directory”), we automatically assign your enquiry to that entry when it arrives. This lets us see, when replying, whether and about what we have been in contact with you before, and we do not have to record your details twice. An enquiry on its own does not create an entry. In individual cases our team may transfer your name, email address and phone number from the enquiry to the guest directory, for example when your enquiry turns into a celebration or an event; the enquiry is then assigned to that entry. We never assign or transfer job applications or messages identified as spam.

The legal basis is Article 6(1)(b) GDPR where your enquiry is aimed at a contract with us, otherwise Article 6(1)(f) GDPR. Our legitimate interest is to look after our guests consistently and to be able to answer enquiries in the context of earlier contacts. You can object to this assignment at any time; an informal message to verwaltung@echtasien.de suffices (see also “Right to object”). The assignment does not extend any retention period: we still delete the enquiry itself no later than 180 days after receipt. If our team transfers your details to the guest directory, the periods stated there apply to that entry, counted from the receipt of your enquiry.

Mandatory fields are marked in the form; without your name and email address we cannot answer an enquiry. All other details are optional.

Job applications: via the application form we additionally process the desired position and the desired location. If you attach a CV, this file is not stored in our website database; it is attached solely to the notification email sent to us and afterwards exists only in our email mailbox. The confirmation sent to you contains no attachment. The legal basis is § 26(1) sentence 1 of the German Federal Data Protection Act (BDSG) in conjunction with Article 6(1)(b) GDPR; under § 26(8) sentence 2 BDSG, applicants are treated as employees.

The fields marked as mandatory in the application form are those we need in order to process your application; without them we cannot consider it. All other details are optional. If your application is unsuccessful, we delete the application data no later than six months after the end of the procedure, unless a longer retention period is required by law. If you are hired, we transfer the data to the employment relationship.

14. Newsletter

You can subscribe to our newsletter via the sign-up form on the website or by ticking a box when reserving. The box is always optional and never pre-ticked; the consent text reads: „Yes, I would like to receive the echtasien newsletter.“ For this we process your email address and the time of your sign-up in order to send you news and offers. The legal basis is your consent under Article 6(1)(a) GDPR. Sign-up uses the double opt-in procedure: you first receive an email with a confirmation link, and only after your confirmation do we add you to the mailing list. If you do not confirm your sign-up, we will not send you any newsletter; the confirmation link expires after 72 hours. An unconfirmed sign-up is kept solely as a record of that event and is deleted as soon as you ask us to or we review the data we hold.

The only mandatory detail is your email address; without it we cannot deliver the newsletter. Signing up is voluntary and is not required in order to use this website or our services.

To prove your consent we store the time of sign-up and confirmation, the version of the consent text, the place of sign-up (form, reservation) and a cryptographic hash of your IP address, never the IP address itself. You can withdraw your consent at any time with effect for the future: via the unsubscribe link at the end of every newsletter email or informally via the contact details above. After withdrawal we process your details only insofar as necessary to prove the earlier consent and to ensure that you are not contacted again. Technical dispatch takes place via the email delivery service named below.

Our newsletter issues contain no tracking pixel and no redirected links; we do not record whether or when you open an issue or click a link. The issue sent is retained together with the technical dispatch data for as long as the associated campaign exists in our system. If delivery is permanently refused or you object to receipt, we additionally store a cryptographic hash of your address on a suppression list. Its purpose is to ensure permanently that you are not contacted again; the legal basis is Article 6(1)(f) GDPR, our legitimate interest being the lasting observance of your unsubscription. The suppression list contains no plain-text addresses, is kept permanently (a block that expired would lose its purpose) and remains in place even after your other data has been deleted (Article 17(3)(b) GDPR).

15. Guest directory

An entry in our guest directory is created from your reservations and newsletter sign-ups and contains your contact details, the origin of the entry, the time of the last contact and the associated transactions (for example your previous reservations with date, number of guests and notes). The purpose is the orderly management of our guests and the assignment of your transactions; the legal basis is Article 6(1)(f) GDPR and, for sending the newsletter itself, your consent under (a).

If you write to us via the contact form, we assign your enquiry to an existing entry with the same email address; in individual cases our team may also create an entry with your name, email address and phone number from your enquiry (see “Contact and job enquiries”). The entry then also contains the enquiries assigned to it.

Reservations you made in the past through our previous reservation system may be transferred to the guest directory with your name, contact details and reservation history, so that your history with us is preserved. We were and remain the controller for this data. From such transferred contacts we send a newsletter only to persons whose consent we can demonstrate.

We keep your entry in our guest directory for as long as it is needed to look after our relationship with you, in particular to take your preferences and previous visits into account for future reservations, and until you object to the processing or request deletion. Free-text notes and information on intolerances are deleted automatically once the period stated in the section “Table reservation” has expired. Proof of any newsletter consent you have given and records we are required to retain remain unaffected.

Unsubscribing from the newsletter ends dispatch but does not by itself delete your entry in the guest directory. If you wish to be deleted before the stated period expires, an informal message to the contact details above suffices; we then anonymise the entry without delay unless a retention obligation prevents this.

16. Sending emails

For the technical dispatch of our emails (reservation confirmations, reminders and notices of changes and cancellations, acknowledgements from the forms and confirmation and newsletter emails) we use Amazon Simple Email Service (SES) of Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, in the Europe (Stockholm) region. Sender and recipient details, dispatch times, subject and message content, and technical delivery data such as delivery status and bounce notifications are processed; the content is passed through for dispatch and not stored there permanently.

The purpose is reliable delivery; the legal basis is Article 6(1)(b) or (f) GDPR. A data processing agreement is in place as part of the provider's service terms. Our contracting party is a company established in the European Union; for any transfers to the USA the EU Commission's standard contractual clauses apply (Implementing Decision (EU) 2021/914, https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj), and the parent company Amazon.com, Inc. is certified under the EU-U.S. Data Privacy Framework, with Amazon Web Services listed as a covered entity under that certification (https://www.dataprivacyframework.gov/list).

17. Email mailbox and domain

We receive, store and process incoming messages, form notifications and application documents in our business email mailbox. The purposes are the receipt and handling of business messages; the legal basis is Article 6(1)(f) or (b) GDPR. Data is stored until the matter has been fully dealt with, plus statutory retention periods.

Our mailbox and domain are operated on our behalf by jweiland.net e.K., owner Jochen Weiland, Echterdinger Straße 57, Gebäude 9, 70794 Filderstadt, Germany, on email servers of DomainFactory GmbH, Neuturmstraße 5, 80331 Munich, Germany, in data centres within the European Union. A data processing agreement is in place with jweiland.net. No transfer to a third country takes place in this respect.

18. Photos of persons

This website may contain images in which persons are recognisable, for example members of our team. The legal basis for such publication is the consent of the person depicted (Article 6(1)(a) GDPR, §§ 22, 23 of the German Art Copyright Act, KUG), and for minors the consent of the persons with parental responsibility; it can be withdrawn at any time with effect for the future without affecting the lawfulness of publication up to that point. If you appear in an image and do not or no longer wish it to be published, an informal message to the contact details above suffices; we will then promptly remove the image from the website.

19. External maps (Google Maps)

The maps on our location pages are only loaded once you explicitly request them. Before that, no connection to Google is established. After you give your consent, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, processes in particular your IP address, browser and device information and the previously visited address; processing in the USA cannot be ruled out, and Google sets its own cookies.

The legal basis for loading the map is your consent under § 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. You can withdraw it at any time: via "Privacy settings" in the footer and in the section "External content (videos, maps, booking areas)" at the end of this page, there for Google only, or with "Reject all" for all providers at once. For transfers to the USA, Google LLC is certified under the EU-U.S. Data Privacy Framework; in addition, the EU Commission's standard contractual clauses apply. Google's privacy policy is available at https://policies.google.com/privacy. The "Get directions" button is a simple link to Google Maps that opens in a new tab; no data flows before you click it.

How we remember your consent and for how long is explained in the section "External content (videos, maps, booking areas)" at the end of this page. There you can also withdraw a consent you have given directly.

20. Linked services without embedding

Our Instagram profile is only linked and opens in a new tab. Merely visiting our website transmits no data to Instagram: it is a simple link, not embedded content, and no connection is established before you click. Only when you follow the link do you leave our area of responsibility; from then on the privacy policy of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, applies.

21. Recipients of personal data

The recipients are the following service providers, insofar as necessary for the respective function. Data processing agreements under Article 28 GDPR are in place with processors.

Our technical service provider for the operation and support of this website and for providing the reservation, enquiry, job application, newsletter and guest management functions (processor under Article 28 GDPR); data location EU. We remain the controller responsible for the processing of your data.

We or our technical service provider engage the following services in order to provide these services. They are sub-processors of our technical service provider (Article 28(2) and (4) GDPR); we have agreed to their engagement and are informed in advance of any intended changes. Our technical service provider is liable to us for their compliance with their data protection obligations.

Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA: hosting, delivery and image optimisation. Place of processing: server-side functions in the EU region of Frankfurt am Main, delivery via the worldwide edge network, build processes and logs partly in the USA. Safeguards: standard contractual clauses (Implementing Decision (EU) 2021/914) and the EU-U.S. Data Privacy Framework.

Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513: database, application backend and storage of this website's images and videos, as well as their direct delivery where it does not run through Vercel's image optimisation. Place of processing: database region EU (Ireland). Safeguards: standard contractual clauses (Implementing Decision (EU) 2021/914) for administrative access from third countries that cannot be ruled out; this provider holds no Data Privacy Framework certification.

Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg: technical email dispatch (Amazon SES). Place of processing: Europe (Stockholm) region. Safeguards: standard contractual clauses (Implementing Decision (EU) 2021/914) and the EU-U.S. Data Privacy Framework certification of Amazon.com, Inc., under which Amazon Web Services is listed as a covered entity.

Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA: error and stability monitoring. Place of processing: EU region (Frankfurt am Main). Safeguards: EU-U.S. Data Privacy Framework and, in addition, standard contractual clauses (Implementing Decision (EU) 2021/914).

Umami Software, Inc., 28 Geary St, Suite 650 #243, San Francisco, California, USA: reach measurement. Place of processing: the provider's European collection endpoint. Safeguards: standard contractual clauses (Implementing Decision (EU) 2021/914).

Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA: protection of our forms against automated requests (Turnstile), only while this protection is switched on and only after your first input into a form. Place of processing: the provider's globally distributed network, including the USA. Safeguards: EU-U.S. Data Privacy Framework and, in addition, standard contractual clauses (Implementing Decision (EU) 2021/914).

Not on our behalf, but as independent controllers in their own right, the following process personal data:

Google Ireland Limited (Ireland): map display, only after your consent; data location worldwide.

In addition, the provider of our business email mailbox, see the section „Email mailbox and domain“. We pass data on to public authorities only where legally obliged to do so; receipt and payment data is also received by the parties entrusted with our bookkeeping and tax returns.

22. Transfers to third countries

Where personal data is processed outside the EU and the EEA, this is based on the safeguards of Articles 44 et seq. GDPR: on the adequacy decision on the EU-U.S. Data Privacy Framework (Article 45 GDPR) where the US provider concerned is certified (Vercel, Sentry, Google, Cloudflare and, under the certification of Amazon.com, Inc., Amazon Web Services), and otherwise, in particular for Supabase and Umami, on the EU Commission's standard contractual clauses under Implementing Decision (EU) 2021/914 (Article 46(2)(c) GDPR). Where data is processed exclusively within the EU and the EEA, no transfer to a third country takes place.

23. Cookies and similar technologies

When you access this website we do not use any cookies or comparable technologies that require consent; external content that requires consent is only loaded after you have expressly approved it (§ 25(1) TDDDG). No consent banner therefore appears. For visitors, this website sets only one cookie of its own per provider you have approved, and only once you explicitly approve an external content. It stores solely the day of your approval for exactly that provider, is valid for 180 days and is strictly necessary under § 25(2) no. 2 TDDDG, because without it you would have to decide again on every page view. Details and how to withdraw are given in the section „External content (videos, maps, booking areas)“ at the end of this page.

You withdraw your approvals via „Privacy settings“, in the footer of every page and in the section „External content (videos, maps, booking areas)“ at the end of this page. There you see each provider individually and can switch it off individually; exactly the one associated cookie is then deleted while the others remain. „Reject all“ resets all stored approvals in one step. You confirm your choice with „Save selection“; „Accept all“ and „Reject all“ apply without this step. The change takes effect immediately, without reloading the page.

After approval, Google (maps) additionally sets its own cookies within the embedded frame. While our form protection is switched on and you start using one of our forms, Cloudflare Turnstile may store or read information on your device; details are given in the section “Protection against automated requests (Cloudflare Turnstile)”. Beyond this, no cookies, local storage or comparable technologies are used on this website for advertising or tracking purposes; in particular, reach measurement and error monitoring work entirely without access to your device. For both, there is therefore no consent you could withdraw; „Privacy settings“ merely explains them and shows no switch for them. The functions offered through this website work without cookies; the personal link for managing your reservation carries its identifier in the address itself. As soon as you use the reservation form, it stores a random identifier in your browser's session storage (sessionStorage) so that a form accidentally sent twice does not result in two reservations; it contains no information about you and is deleted when you close the browser tab. This access to your device is strictly necessary for the reservation you have requested (§ 25(2) no. 2 TDDDG).

A further cookie named "__Host-tc_preview" does not concern guests: it is set only when a person who maintains our website clicks a preview link sent to them in order to review an as yet unpublished draft. It contains only a random string without personal reference, is restricted to this website, becomes invalid after 72 hours at the latest and can be deleted at any time via "End preview"; it is technically necessary (§ 25(2) no. 2 TDDDG), and no third party is involved.

24. Retention period and deletion

We store personal data only for as long as necessary for the purposes stated or as long as statutory retention obligations exist; the specific periods are given in the respective sections. Tax and commercial retention periods are generally six, eight or ten years (§ 147 AO, § 257 HGB). Once the purpose no longer applies, the data is deleted or anonymised. Upon termination of the cooperation with our technical service provider, the data is returned to us and deleted there.

25. Your rights

You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20), the right to object to processing based on Article 6(1)(f) GDPR (Article 21), and the right to withdraw consent at any time with effect for the future (Article 7(3)). To exercise these rights, contact Sangai GmbH, Blankeneser Landstraße 1, 22587 Hamburg, Germany, by email at verwaltung@echtasien.de or by phone on the numbers above. We respond without undue delay and at the latest within one month. Erasure is carried out by us; no data is deleted through the website alone, for example by unsubscribing from the newsletter or cancelling a reservation.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit), Ludwig-Erhard-Straße 22, 7th floor, 20459 Hamburg, Germany, phone +49 40 428 54-4040, email mailbox@datenschutz.hamburg.de, www.datenschutz-hamburg.de.

26. Right to object

You have the right to object at any time to the processing of your data.

Where we process your personal data on the basis of a legitimate interest (Article 6(1)(f) GDPR), for example for the orderly management of our guests, the handling of enquiries, the security of our systems or reach measurement, you may object to that processing at any time on grounds relating to your particular situation (Article 21(1) GDPR). If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where we process your data for direct marketing purposes, you may object to that processing at any time (Article 21(2) GDPR); this also applies to profiling connected with such direct marketing. If you object, we will no longer process your data for that purpose.

No particular form is required and objecting is free of charge. A message to verwaltung@echtasien.de or to the postal address given above is sufficient; you need to give reasons only for an objection under Article 21(1), not for direct marketing.

27. Automated decision-making

No automated decision-making with legal effect and no profiling within the meaning of Article 22 GDPR take place. The automatic confirmation of reservations checks only the availability of a table at the desired time and does not evaluate any personal characteristics. The check for repeated no-shows described under „Table reservation“ likewise does not result in such a decision: it only closes the online route, while the telephone route and manual entry by our team remain open.

28. Currency of this privacy policy

We update this privacy policy as soon as the functions used on this website or the legal requirements change. The version available on this page is always the authoritative one. In case of doubt, the German version prevails.

Last updated: September 2026

29. External content (videos, maps, booking areas)

Third-party external content, such as videos, maps and booking areas, only loads once you explicitly agree in the placeholder shown. If you agree, we store your decision for that specific provider in a small text entry (cookie) on your device; all that is stored is the day of your consent. Its sole purpose is to spare you from agreeing again on your next visit. No reach measurement and no profiling take place.

The stored decision is valid for 180 days. After that it expires and the placeholder reappears.

When you access this website we do not use any cookies or comparable technologies that require consent; external content that requires consent is only loaded after you have expressly approved it (§ 25(1) TDDDG). No consent banner therefore appears.

You can withdraw your consent at any time via the “Privacy settings” item, directly below this paragraph and in the footer of all pages. There you can see each provider individually, switch it off individually and apply your choice with “Save selection”; “Reject all” resets every stored consent in one step.