Legal

Privacy Policy

Last updated: 25/08/2026 · Alpizena, Wien

1. Data Controller

Data controller within the meaning of the GDPR:
Mohamed Hesham Mohamed Eltabei Shamsou
Lorystraße 61/5, 1110 Vienna, Austria
Email: hello@alpizena.at

2. Collection and Processing of Personal Data

2.1 When Visiting the Website

Every access stores technical data (IP address, browser, date/time) in server logs. This data is not combined with other data sources and is deleted after 7 days. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of operations).

2.2 Customer Account

Upon registration we collect: name, email address, password (encrypted), phone number (optional), delivery addresses. Legal basis: Art. 6(1)(b) GDPR (contract performance).

2.3 Orders

To process orders we handle: name, email, phone, delivery address, ordered items, payment information (processed by Global Payments/PayPal — we do not store full payment data). Legal basis: Art. 6(1)(b) GDPR. Retention period: 7 years pursuant to § 132 BAO (Austrian Federal Fiscal Code).

2.4 Table Reservations

Name, email, phone, date, time, party size, optional notes. Legal basis: Art. 6(1)(b) GDPR. Retention: 3 years.

2.5 Contact Form

Details submitted via contact inquiries are used to process your request and deleted afterwards. Legal basis: Art. 6(1)(f) GDPR.

3. Disclosure to Third Parties

We only share your data where necessary to fulfil a contract:

  • Global Payments Europe, s.r.o. (GP webpay) (credit card payment processing) – Privacy policy: globalpayments.com/privacy
  • PayPal (Europe) S.à r.l. et Cie, S.C.A. (payment processing) – Privacy policy: paypal.com/privacy
  • Supabase, Inc. (database hosting, authentication) – Privacy policy: supabase.com/privacy
  • Resend, Inc. (sending order, reservation and account confirmation emails) – Privacy policy: resend.com/privacy
  • Telegram Messenger Inc. (internal notification of our kitchen/delivery staff about new orders — name, order contents, delivery address) – Privacy policy: telegram.org/privacy

All processors are contractually bound to GDPR-compliant processing.

4. Cookies

We use exclusively technically necessary cookies or equivalent storage mechanisms (session management, authentication, shopping cart, storing your cookie choice). We currently do not use analytics or marketing cookies. Should this change, we will obtain your explicit consent in advance via the cookie banner. You can change your choice at any time via the “Cookie Settings” link in the footer or manage cookies in your browser settings.

5. Your Rights (GDPR)

  • Access (Art. 15): What data we hold about you
  • Rectification (Art. 16): Correction of inaccurate data
  • Erasure (Art. 17): Deletion of your data (possible in your customer account under “Settings”)
  • Data portability (Art. 20): Provision of your data in a machine-readable format
  • Objection (Art. 21): Against processing based on legitimate interests
  • Withdraw consent (Art. 7(3)): At any time for consent-based processing

To exercise your rights, please contact: hello@alpizena.at

6. Right to Lodge a Complaint

You have the right to lodge a complaint with the Austrian data protection authority:
Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna
www.dsb.gv.at

7. Data Security

We use SSL/TLS encryption. Passwords are hashed with bcrypt. Payment data is processed exclusively through PCI-DSS certified providers.