Privacy
Privacy policy
This page explains which personal data is processed when you visit this website and when you book a table, for what purpose, on which legal basis and for how long. Last updated: October 2026.
This is a translation for your convenience. If the two versions differ, the German version (Datenschutzerklärung, “DE” above) prevails.
1. Controller
The controller responsible for data processing on this website is:
Auréa Café & LoungeBerlinerstr 196, 14547 Beelitz, Germany
Phone: +49 33204 634887
2. Overview
We only process what is needed for the website and your reservation. There are no customer accounts: you book without registering, and we reply by email. We currently use no analytics or statistics services and no advertising or social media pixels. We only send offers by email if you have expressly asked for them and confirmed via a link. The Google Maps map on the “Visit” page only loads once you allow it. The links to social networks in the footer do not load any content from those providers. There is no contact form; if you call us, we use your details only to deal with your request.
We do not use automated decision-making or profiling.
3. Visiting the website & hosting
When you open the website, our hosting provider processes the technically necessary connection data so that the pages can be delivered: IP address, date and time, the address requested, the amount of data transferred, and your browser and operating system.
- Provider
- Legal basis
- Art. 6(1)(f) GDPR – our legitimate interest in a secure, working website
- Retention
4. Table reservations
When you request a table through the booking dialog or the form on the homepage, we store your request in our database (see Supabase). Our team sees it in our internal, password-protected dashboard. You immediately receive an email confirming that your request has arrived, and another one as soon as we confirm or decline it or have a question (see reservation emails).
- Data
- Name, phone number, email address, date, time, party size, seating preference, the language you booked in, your choice about offers by email, – voluntarily – special requests, as well as our reply to you and when we sent it.
- Purpose
- Handling, confirming or declining your reservation and contacting you about it, mainly by email.
- Legal basis
- Art. 6(1)(b) GDPR (steps taken at your request before entering into a contract).
- Required details
- We need your name, phone number and email address to confirm the reservation. Without them, online booking is not possible; you can always call us instead.
- Retention
- Two years after the reservation date, we automatically remove everything that identifies you (name, phone number, email address, requests, our reply, your choice about offers). Only the date, time, party size and status remain, with no link to you, for our planning. If you ask for deletion earlier, we delete all your reservations completely.
Questions by phone, text message or WhatsApp
We usually reply by email. If we can't reach you that way, we get in touch by phone, text message or WhatsApp. If we write to you on WhatsApp, WhatsApp Ireland Limited (Merrion Road, Dublin 4, Ireland) receives your phone number and the content of the message; data may also be transferred to its parent company Meta Platforms, Inc. in the USA. If you don't want to be contacted via WhatsApp, tell us by phone or in the special requests field of the form on the homepage.
Allergies and intolerances
Information about allergies or intolerances in the special requests field is voluntary. If you provide it, we process it with your explicit consent (Art. 9(2)(a) GDPR) solely to prepare for your visit. You can withdraw your consent at any time, e.g. by phone.
Saving your details for future bookings
If you tick “Save my details for my next reservations”, your browser stores your name, phone number and email address in this device’s local storage so the form is already filled in next time. This copy never reaches us. If you untick the box on a later booking, we delete it again; you can also delete it via your browser data.
5. Offers by email (double opt-in)
We only send offers and news by email with your consent (Art. 6(1)(a) GDPR, Section 7(2) no. 2 of the German Unfair Competition Act, UWG). The box in the booking form is voluntary; you can book just the same without it. If you tick it, we send you an email with a confirmation link (double opt-in). Only once you confirm there is your consent given. If you don't confirm within 30 days, the link expires and you won't receive any offers.
- Data
- Email address, name, language and, as proof of your consent, the time of sign-up (booking) and of confirmation.
- Withdrawal
- At any time with effect for the future, e.g. with a short reply to any of our emails or by phone. We then keep the proof of consent only as long as we need it to defend against claims, at most until it is anonymised after 2 years.
- Sending
- Via Resend (see below). We do not send offers by text message.
6. Reservation emails (Resend)
We send the emails about your reservation – the confirmation of receipt, our reply and, if applicable, the confirmation email for offers – through the email service Resend. Our team also receives a notification about each new request containing your reservation details. If you reply to one of our emails, your message arrives in our inbox.
- Provider
- Resend, Inc., USA
- Data
- Email address, name, date, time, party size, requests and the text of our reply, plus delivery logs (time, delivery status).
- Legal basis
- Art. 6(1)(b) GDPR (handling your reservation); for the confirmation email about offers, Art. 6(1)(a) GDPR. Resend processes the data on our behalf (Art. 28 GDPR).
- Third country
- Resend stores account and delivery data in the USA. Resend is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).
- Retention
- At Resend according to its retention period for delivery logs ; in our inbox until your request has been dealt with, at most 2 years.
7. Database (Supabase)
Reservations, the menu and our team’s sign-in to the admin area run on Supabase, a database and authentication service of Supabase Inc. Supabase processes the data on our behalf (Art. 28 GDPR).
Your browser loads menu photos directly from Supabase’s servers. Supabase then receives technically necessary connection data such as your IP address, the image requested and details about your browser. The legal basis is our legitimate interest in a complete, fast-loading menu (Art. 6(1)(f) GDPR). Supabase sets no cookies for this.
- Server location
- Frankfurt am Main, Germany (AWS eu-central-1)
- Data processing agreement
8. Map (Google Maps)
On the “Visit” page we show our location with Google Maps, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map only loads once you choose “Load map” or allow “External content” in the cookie settings. Your browser then sends Google your IP address among other data, and Google may set cookies. Data may be transferred to Google LLC in the USA; Google is certified under the EU-US Data Privacy Framework.
- Legal basis
- Your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time in the cookie settings.
- Google’s privacy policy
- policies.google.com/privacy
Without consent you see our address instead. The “Get directions” link only opens Google Maps when you click it.
9. Cookies & storage
We use strictly necessary cookies and storage entries without consent under Section 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act), because the website would not work as intended without them. We only load optional services with your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Declining optional services does not limit the website or booking. You can change or withdraw your choice at any time.
Essential
Keep the website and table reservations working. These are always active. On the public website, visitors only receive the cookie for the cookie settings and – only if you tick the box when booking or switch language – your saved contact details in local storage or the language cookie. Sign-in cookies exist only for our team in the admin area.
- Cookie settingsAuréa (this website)
Stores your choice in this dialog so we don't ask on every visit.
Storage: Cookie aurea_consent
Duration: 12 months
- Team sign-in (Supabase Auth)Supabase Inc.
Keeps staff signed in to the admin area. Guests have no accounts.
Storage: Cookie sb-<project-id>-auth-token (possibly split into .0, .1 …)
Duration: until sign-out, at most 400 days
Applies: only for our team in the admin area (separate subdomain)
- Reservations & menuSupabase Inc.
Stores your reservation request (name, phone, email, date, time, party size, requests, your choice about offers by email and, if given, its confirmation) and serves the menu.
Storage: — (no cookies)
Duration: until deleted at your request; 2 years after the reservation date, the personal data is anonymised automatically
- Saved contact detailsAuréa (this website)
Fills in name, phone and email for your next reservation on this device. The data stays in your browser and is not sent to us.
Storage: Local storage aurea_guest_contact
Duration: until you untick the box when booking or clear your browser data
Applies: only if you tick “Save my details for my next reservations”
- Language preferenceAuréa (this website)
Remembers that you chose German or English in the language switcher and opens the website in that language on your next visit.
Storage: Cookie aurea_lang
Duration: 12 months
Applies: only after using the language switcher
- Language switchAuréa (this website)
When you switch language, passes the scroll position, the open menu tab and the date, time and party size of the booking form to the page in the other language. Name, phone and email are not passed on.
Storage: Session storage aurea_locale_switch
Duration: deleted as soon as the new page has loaded
Applies: only when switching language
- Dashboard sidebarAuréa (this website)
Remembers whether the sidebar is expanded or collapsed.
Storage: Cookie sidebar_state
Duration: 7 days
Applies: only for our team in the admin area
Statistics · optional
Help us understand how the website is used, e.g. which pages are visited.
We currently use no services in this category.
Marketing · optional
Advertising and social media pixels that recognise you on other websites.
We currently use no services in this category.
External content · optional
Content embedded from other providers, e.g. maps, videos or booking widgets, which send data to those providers when loaded.
- Google MapsGoogle Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Shows our location on an interactive map (“Visit” page). When the map loads, your browser sends Google your IP address among other data; Google may set cookies and transfer data to the USA (EU-US Data Privacy Framework).
Storage: Cookies from google.com (e.g. NID), set by Google
Duration: according to Google, e.g. NID 6 months
Applies: only if you allow external content or choose “Load map”
10. Fonts
We serve the fonts Cormorant Garamond and Manrope from our own server. No connection to Google Fonts is made when you visit the website.
11. Your rights
You have the right at any time to
- access the data we hold about you (Art. 15 GDPR),
- have incorrect data corrected (Art. 16 GDPR),
- have your data deleted (Art. 17 GDPR),
- restrict processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on our legitimate interest (Art. 21 GDPR),
- withdraw consent with effect for the future (Art. 7(3) GDPR) – for cookies via the cookie settings.
Please use the contact details above. For deletion, the email address or phone number you booked with is enough; we then delete all reservations linked to it and confirm this to you. You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. the authority responsible for us: Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany.