CARAMELLA ESSEN
Privacy policy
1. Controller
Caramella · Anastasios Ilantzidis
Reckhammerweg 2 · 45141 Essen
+49 201 3162339
[email protected]
2. Visiting this website
You can browse our menu and gallery without submitting personal details. To deliver the website securely, the hosting infrastructure processes technical request data such as IP address, requested URL, time and browser information. The purpose is delivery, error diagnosis and protection against misuse, based on our legitimate interests under Article 6(1)(f) GDPR.
Hosting in the Netherlands
The deployment is configured for Railway Corporation (USA), EU West Metal, Amsterdam, Netherlands. The application and its PostgreSQL database are to run in this region. Hosting in the EU does not exclude processing in other countries by the provider’s support, control-plane services or subprocessors. Technical request data is processed to provide and protect the website (Article 6(1)(f) GDPR).
Railway Privacy · Railway data processing agreement
3. Contact enquiries
When you use our contact form, we process your email address, subject, message and optional phone number to answer your enquiry. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual enquiries, or Article 6(1)(f) GDPR for other correspondence. We do not use these details for advertising. Providing details is voluntary, but an email address and the content of your enquiry are needed to reply through this form. Alternatively, you can call us.
4. Email delivery
The form sends messages through Resend (Plus Five Five, Inc., USA) to our contact inbox at [email protected]. These providers process the information needed to deliver and store the email. Processing outside the EU may occur. Resend’s data processing addendum includes transfer safeguards such as EU standard contractual clauses. The applicable arrangements depend on the service contract; copies or information about the safeguards can be requested from us. Amsterdam hosting does not keep email delivery or mailbox storage exclusively in the EU.
Resend privacy policy · Google privacy policy
5. Retention and security
We retain enquiries for as long as needed to handle them and fulfil statutory retention obligations. The application does not store a separate copy of contact messages. For abuse prevention, hashed request identifiers and counters expire after the applicable limit window (3 hours for login and contact); expired counters are removed on a subsequent rate-limit request. The IP address is used for this purpose only behind a configured trusted proxy; otherwise a shared counter is used. Hashing is pseudonymisation, not anonymisation. No analytics or advertising profiles are created.
6. Cookies and external services
Your cookie choice is saved for 180 days. The admin area uses a necessary login cookie for up to 14 days. Fonts, photos and videos are served by this website. The contact page loads Google Maps, provided by Google Ireland Limited, only after your permission. Loading the map transmits your IP address and technical browser information to Google; Google may use cookies and process data according to its privacy policy. Instagram, Facebook and TikTok are external links and load only when you follow them.
Administration and security
For the restricted admin area, we process the admin email, a salted password hash, short-lived hashed email codes and session records. The purpose is access protection and management of the café website (Article 6(1)(f) GDPR). Email codes expire after 10 minutes, sessions after 14 days; expired entries are removed on a subsequent account access. Logout revokes that session; credential changes revoke all sessions. The account remains stored while it is used. No plaintext password is stored. Admin changes create audit entries containing the action, revision and time.
There is no automated decision-making with legal or similarly significant effects and no advertising profiling. Retention by hosting and email providers, including backups, follows the applicable service configuration and contractual deletion rules. Contact us for information about the current retention periods.
7. Your rights
Subject to the applicable legal requirements, you have rights of access, rectification, erasure, restriction, data portability and objection to processing based on legitimate interests. Consent, where given, can be withdrawn for the future. Contact us using the details above. You can also complain to a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
In particular, you may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR (Article 21 GDPR). Send your request to the contact address above. We normally respond to rights requests within one month, subject to statutory extensions.
Last updated: 25 September 2026
