Data Protection
Personal data (hereinafter referred to as “data”) is processed by us only to the extent necessary and for the purpose of providing a functional and user-friendly website, including its content and the services offered therein.
According to Article 4(1) of Regulation (EU) 2016/679 – the General Data Protection Regulation (hereinafter “GDPR”) – “processing” refers to any operation or set of operations performed on personal data, whether or not by automated means. This includes, but is not limited to: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
The following privacy policy provides detailed information, in particular about the type, scope, purpose, duration, and legal basis for the processing of personal data, insofar as we either alone or jointly with others determine the purposes and means of such processing. Furthermore, we also inform you below about the third-party components we use for optimization purposes and to improve the quality of user experience, insofar as such third parties process data under their own responsibility.
Our Privacy Policy is structured as follows:
I. Information about the Data Controller
II. Rights of Users and Data Subjects
III. Information on Data Processing
I. Information about the Data Controller
The responsible provider of this website in terms of data protection law is:
MISIK – Owner: Jungmi Ha
Vogelsangstraße 18
D-70176 Stuttgart
Germany
Phone: +49 711 451 404 47
Email: info@misik-restaurant.de
The Data Protection Officer of the provider is: Jungmi Ha
II. Rights of Users and Data Subjects
With regard to the data processing described in more detail below, users and data subjects have the right:
-
to obtain confirmation as to whether or not personal data concerning them is being processed, access to the processed data, further information about the data processing, and copies of the data (see also Art. 15 GDPR);
-
to request the rectification or completion of inaccurate or incomplete data (see also Art. 16 GDPR);
-
to request the immediate erasure of their personal data (see also Art. 17 GDPR), or, alternatively, where further processing is required under Art. 17(3) GDPR, to request restriction of processing in accordance with Art. 18 GDPR;
-
to receive the personal data concerning them, which they have provided, and to transmit those data to other controllers/responsible parties (see also Art. 20 GDPR);
-
to lodge a complaint with a supervisory authority if they believe that the processing of their personal data violates data protection laws (see also Art. 77 GDPR).
Furthermore, the provider is obligated to inform all recipients to whom personal data has been disclosed of any rectification or erasure of data or restriction of processing carried out in accordance with Articles 16, 17(1), and 18 GDPR. This obligation does not apply if such notification is impossible or involves disproportionate effort. Notwithstanding this, the data subject has the right to be informed about these recipients.
In addition, under Art. 21 GDPR, users and data subjects have the right to object to the future processing of personal data concerning them, provided that the data is processed by the provider based on Art. 6(1)(f) GDPR. In particular, an objection to data processing for the purpose of direct marketing is permissible.
III. Information on Data Processing
Your personal data, as processed when you use our website, will be deleted or blocked as soon as the purpose for storing it no longer applies, provided that there are no statutory retention obligations to the contrary and unless otherwise stated below.
Cookies
a) Session Cookies
We use so-called cookies on our website. Cookies are small text files or other storage technologies that your internet browser stores on your device. These cookies process specific information such as your browser data, location data, or IP address.
This processing makes our website more user-friendly, effective, and secure, for example by enabling the display of the website in various languages or the use of a shopping cart feature.
The legal basis for this processing is Art. 6(1)(b) GDPR, if the cookies are used for contract initiation or fulfillment.
If cookies are not used for this purpose, our legitimate interest lies in improving the functionality of our website. The legal basis in this case is Art. 6(1)(f) GDPR.
Session cookies are deleted when you close your browser.
b) Thrid-Party Cookies
Our website may also use cookies from partner companies (third parties) for purposes such as advertising, analytics, or functional enhancements.
For details, especially concerning purposes and legal bases for such third-party cookie processing, please refer to the information provided below.
c) Cookie Control
You can prevent or limit the installation of cookies by configuring your browser settings accordingly. You can also delete stored cookies at any time. The steps and measures required depend on the browser you are using. Please consult your browser’s help function or user guide, or contact the browser manufacturer or support service.
Flash cookies cannot be blocked via browser settings. Instead, you must change the settings of your Flash player. Refer to its help function or documentation for guidance.
Restricting or blocking cookies may lead to reduced functionality of our website.
Contract Fulfillment
The data you provide to use our goods and/or services is processed for the purpose of fulfilling the contract and is necessary for such purposes. Without this data, concluding and executing the contract is not possible.
Legal basis: Art. 6(1)(b) GDPR.
We delete the data after full contract performance, subject to compliance with statutory tax and commercial retention obligations.
To fulfill the contract, we may forward your data to the logistics company responsible for delivery or the financial service provider processing your payment.
Legal basis for this transfer: Art. 6(1)(b) GDPR.
Serverdaten
For technical reasons, particularly to ensure the stability and security of the website, certain data is transmitted by your browser to us or our web hosting provider. These are known as server log files and include:
-
Browser type and version
-
Operating system
-
Referrer URL
-
Pages visited on our website
-
Date and time of access
-
IP address
These data are stored temporarily and are not combined with other data.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the improvement, stability, functionality, and security of our website.
These data are deleted no later than seven days after collection unless further retention is required for evidence purposes.
Kundenkonto/ Registrierungsfunktion
When you create a customer account on our website, we collect the data you enter during registration (e.g., name, address, email) for pre-contractual services, contract fulfillment, or customer care (e.g., displaying previous orders or using a wishlist).
Additionally, we store the IP address and registration date and time. This data is not shared with third parties.
Your consent to this processing is obtained during registration, and reference is made to this privacy policy.
Legal basis: Art. 6(1)(a) GDPR. If the account is also for pre-contractual or contractual purposes, Art. 6(1)(b) GDPR applies.
You may withdraw your consent at any time with future effect per Art. 7(3) GDPR by notifying us.
We delete the data once processing is no longer necessary, subject to statutory retention obligations.
Newsletter
If you subscribe to our newsletter, we collect your email address and—optionally—your name and address. We also store your IP address and the date and time of registration.
Your consent is obtained, the content described, and reference made to this privacy policy.
We use the data exclusively for newsletter delivery. No data is shared with third parties.
Legal basis: Art. 6(1)(a) GDPR.
You can withdraw your consent at any time per Art. 7(3) GDPR by notifying us or using the unsubscribe link in each newsletter.
Contact Inquiries
When you contact us via form or email, we use your data to respond to your inquiry. Providing this data is necessary—without it, we may not be able to respond fully.
Legal basis: Art. 6(1)(b) GDPR.
Your data is deleted once your inquiry has been fully processed, provided no legal retention obligations apply (e.g., due to a resulting contract).
To promote our products and services and to communicate with interested parties or customers, we operate a company presence on the Facebook platform.
On this social media platform, we are jointly responsible — within the meaning of the GDPR — together with Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Facebook's Data Protection Officer can be contacted via the following contact form:
https://www.facebook.com/help/contact/540977946302970
We have entered into a joint controller agreement with Facebook, which governs our respective responsibilities under the GDPR. This agreement, which outlines the mutual obligations, is available at:
https://www.facebook.com/legal/terms/page_controller_addendum
The legal basis for the data processing described below is Article 6(1)(f) GDPR. Our legitimate interest lies in the analysis, communication, marketing, and sale of our products and services.
In some cases, data processing may also be based on the user’s consent pursuant to Article 6(1)(a) GDPR, which may be withdrawn at any time with future effect in accordance with Article 7(3) GDPR by notifying the platform provider.
When visiting our online presence on Facebook, user data (such as personal information, IP address, etc.) is processed by Facebook Ireland Ltd. as the platform operator within the EU.
This user data is used to provide us with statistical insights regarding the use of our company page on Facebook. Facebook Ireland Ltd. also processes this data for market research and advertising purposes, as well as for the creation of user profiles. Based on these profiles, Facebook Ireland Ltd. can, for example, serve users interest-based advertising both within and outside of Facebook.
If the user is logged into their Facebook account when accessing our page, Facebook Ireland Ltd. can also link this data to the corresponding user account.
If a user contacts us via Facebook, any personal data voluntarily provided in this context will be used to process the inquiry. We will delete the user’s data once the request has been conclusively answered, unless legal retention obligations (e.g., due to a subsequent contractual relationship) prevent deletion.
Facebook Ireland Ltd. may also use cookies in connection with data processing.
If users do not consent to this processing, they can prevent the installation of cookies by adjusting their browser settings. Previously stored cookies can be deleted at any time. The exact steps depend on the specific browser used. Flash cookies cannot be managed through browser settings but must be adjusted in the Flash player settings. Restricting or disabling cookie installation may limit the full functionality of Facebook.
More information on Facebook’s data processing activities, how to restrict them, and how to delete data processed by Facebook can be found in Facebook’s Data Policy:
https://www.facebook.com/privacy/explanation
It cannot be ruled out that data processing by Facebook Ireland Ltd. also takes place via Facebook Inc., 1601 Willow Road, Menlo Park, California 94025, USA.
To promote our products and services and to communicate with interested parties or customers, we operate a company presence on the Instagram platform.
On this social media platform, we are jointly responsible — within the meaning of the GDPR — together with Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Instagram’s Data Protection Officer can be contacted via the following contact form:
https://www.facebook.com/help/contact/540977946302970
We have entered into a joint controller agreement with Facebook, which governs our respective responsibilities under the GDPR. This agreement, outlining the mutual obligations, can be accessed at the following link:
https://www.facebook.com/legal/terms/page_controller_addendum
The legal basis for the data processing described below is Article 6(1)(f) GDPR. Our legitimate interest lies in the analysis, communication, marketing, and sale of our products and services.
In certain cases, processing may also be based on the user’s consent pursuant to Article 6(1)(a) GDPR. Consent can be withdrawn at any time with future effect in accordance with Article 7(3) GDPR by notifying the platform provider.
When visiting our online presence on Instagram, user data (such as personal information, IP address, etc.) is processed by Facebook Ireland Ltd. as the platform operator within the EU.
This user data is used to provide us with statistical information about the use of our company profile on Instagram. Facebook Ireland Ltd. also uses this data for market research and advertising purposes, as well as to create user profiles. These profiles allow Facebook Ireland Ltd. to serve interest-based advertising to users both within and outside of Instagram. If the user is logged into their Instagram account at the time of access, Facebook Ireland Ltd. may also associate the data with the respective user account.
If a user contacts us via Instagram, the personal data voluntarily submitted in that context will be used to process the inquiry. We delete the user’s data once the inquiry has been conclusively answered, provided there are no statutory retention obligations, such as in the case of a subsequent contractual relationship.
Facebook Ireland Ltd. may also use cookies in connection with data processing.
If users do not consent to this processing, they may prevent the installation of cookies by configuring their browser accordingly. Previously stored cookies can also be deleted at any time. These settings vary depending on the browser. Flash cookies cannot be managed through browser settings but must be changed via the settings in the Flash Player. Restricting or disabling cookies may result in limited functionality of the Facebook and Instagram platforms.
Further information on Instagram’s data processing activities, options to restrict them, and how to delete data processed by Instagram can be found in Instagram’s Data Policy:
https://help.instagram.com/519522125107875
It cannot be ruled out that data processing by Facebook Ireland Ltd. is also carried out via Facebook Inc., 1601 Willow Road, Menlo Park, California 94025, USA.
Linking to Social Media via Graphic or Text
We also promote our presence on the following social networks via our website. This integration is done by means of a linked graphic representing the respective network. By using such a graphic link, we ensure that merely visiting a webpage containing social media promotions does not automatically result in a connection to the servers of the respective social network in order to display its logo or embedded content.
A connection to the respective network service is only established once the user actively clicks on the relevant graphic. Only then will the user be redirected to the respective social media platform.
Once the user is forwarded, the respective network may collect information about the user. It cannot be ruled out that such data is processed in the United States.
The types of data typically collected include IP address, date, time, and the specific page visited. If the user is logged into their user account on the respective network at the time, the network operator may link the collected information to the user’s personal account. If the user interacts with a “share” or similar button of the network, such information may be stored in their account and may be published, depending on the settings.
If the user wishes to prevent the automatic association of collected information with their social media profile, they must log out of their account before clicking on the graphic link. Additionally, users can configure their accounts accordingly to restrict such data processing.
The following social networks are linked from our website:
Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, a subsidiary of Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA.
Privacy Policy: https://www.facebook.com/policy.php
Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, a subsidiary of Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA.
Privacy Policy: https://help.instagram.com/519522125107875
“Facebook“- Social-Plug-in
We use plugins of the Facebook social network on our website. Facebook is operated by Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA. Within the EU, the service is operated by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (hereafter collectively referred to as “Facebook”).
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the improvement of the quality of our online presence.
Further details about available Facebook plugins and their functions can be found at:
https://developers.facebook.com/docs/plugins/
If a plugin is embedded on a webpage you visit on our site, your browser will automatically download the plugin from Facebook’s servers in the USA. For technical reasons, your IP address must be transmitted to Facebook during this process. Additionally, the date and time of your visit to our site will be collected.
If you are logged into Facebook while visiting a page with an active plugin, Facebook may recognize the visit and link this information to your personal user account. For example, if you click Facebook’s “Like” button, this interaction may be stored in your user account and potentially made public via the platform.
To prevent Facebook from linking the collected data directly to your account, you must log out of Facebook before visiting our site or use a browser add-on to block the loading of Facebook plugins.
For more information on how Facebook collects and uses data and your rights and settings to protect your privacy, refer to:
https://www.facebook.com/policy.php
Google Analytics
We use Google Analytics, a web analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as “Google”).
Google Analytics is used to analyze how users interact with our website.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in optimizing and economically operating our website.
Usage and user-related information (such as IP address, location, time, or frequency of visits) is transmitted to a Google server in the United States and stored there. However, we use Google Analytics with the so-called IP anonymization feature. Within the EU or EEA, Google shortens the user’s IP address before transmission.
Google uses the collected data to provide us with analytical reports regarding the use of our website and to offer other services related to internet usage.
Google states that it does not associate your IP address with other data. Further privacy information from Google, including how to prevent data usage, is available at:
https://www.google.com/intl/de/policies/privacy/partners
Additionally, Google offers a browser add-on to disable tracking by Google Analytics, which can be downloaded here:
https://tools.google.com/dlpage/gaoptout?hl=de
This add-on can be installed in most common browsers and gives you more control over the data Google collects when visiting our website. It communicates with Google Analytics’ JavaScript (ga.js) to inform it that no data about the website visit should be transmitted. However, this does not prevent data transmission to us or to other web analysis services we may use. Any additional services used will also be described in this privacy policy.
Google-Maps
We use Google Maps on our website to display our location and to create directions. This is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to as “Google.”
To display certain fonts on our website, a connection is established to Google’s servers in the USA when our website is accessed.
If you access the Google Maps component integrated into our website, Google stores a cookie on your device via your internet browser. In order to display our location and create directions, your user settings and data are processed. We cannot exclude the possibility that Google may use servers in the USA.
The legal basis is Art. 6 (1)(f) GDPR. Our legitimate interest lies in optimizing the functionality of our website.
By establishing this connection to Google, Google can determine from which website your request was sent and to which IP address the directions should be sent.
If you do not agree with this processing, you can prevent the installation of cookies by adjusting the settings in your internet browser. See the section "Cookies" above for more details.
The use of Google Maps and the information obtained through Google Maps is subject to the Google Terms of Use and the Google Maps Additional Terms of Service.
Further information is also provided by Google at:
Google Fonts
We use Google Fonts on our website to display external fonts. This is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to as “Google.”
To enable the display of certain fonts, a connection is established to Google's servers in the USA when the website is accessed.
The legal basis is Art. 6 (1)(f) GDPR. Our legitimate interest lies in the optimization and economical operation of our website.
By connecting to Google when our website is accessed, Google can determine from which website your request was sent and to which IP address the font is to be delivered.
Google provides further information at:
This includes, in particular, options for preventing the use of data.
YouTube
We use YouTube on our website. This is a video platform provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to as “YouTube.” We use YouTube in connection with the "Enhanced Privacy Mode" to display videos to you.
If you have given your consent to this processing, the legal basis is Art. 6 (1)(a) GDPR. The legal basis may also be Art. 6 (1)(f) GDPR. Our legitimate interest lies in improving the quality of our online presence.
According to YouTube, the Enhanced Privacy Mode ensures that data as described below is only transmitted to the YouTube server if you actually start a video.
Without "Enhanced Privacy," a connection to the YouTube servers in the USA is established as soon as you visit a web page with an embedded YouTube video.
This connection is necessary to display the video via your browser. In this process, YouTube will at least collect and process your IP address, the date and time, and the page you visited. A connection to the DoubleClick advertising network is also established.
If you are logged into YouTube at the same time, YouTube assigns the connection information to your YouTube account. If you want to prevent this, you must either log out of YouTube before visiting our site or make the appropriate settings in your YouTube account.
To ensure functionality and analyze user behavior, YouTube stores cookies permanently on your device via your browser. If you disagree with this processing, you can prevent the storage of cookies by adjusting your browser settings. More on this under "Cookies."
Further information on data collection, use, and your rights is provided by Google at:
https://policies.google.com/privacy
Mail-Chimp Newsletter
You have the option to sign up for our free newsletter via our website.
We use MailChimp, a service provided by The Rocket Science Group, LLC, 512 Means Street, Suite 404, Atlanta, GA 30318, USA, hereinafter referred to as “The Rocket Science Group.”
Further privacy information is available at:
http://mailchimp.com/legal/privacy/
When you subscribe, the data entered during registration (e.g., your email address, and optionally your name and address) is processed by The Rocket Science Group. Your IP address, registration date, and time are also stored. During the registration process, you will be asked to consent to receiving the newsletter, the content is explained, and this privacy notice is referenced.
The newsletter includes a tracking pixel (web beacon) to analyze whether and when the newsletter is opened and whether links were clicked. Alongside technical data such as device and IP address, this is used to optimize the newsletter and align it with reader preferences.
The legal basis for newsletter delivery and analysis is Art. 6 (1)(a) GDPR.
You can revoke your consent at any time with future effect under Art. 7 (3) GDPR. You can either notify us or use the unsubscribe link included in each newsletter.
WIX
a) Use of WIX Shop Software
We use the WIX shop system from Wix.com Ltd., Namal 40, 6350671 Tel Aviv, Israel to display our products, handle contracts, and host our site.
Legal basis: Contract initiation and/or performance (Art. 6 (1)(b) GDPR).
Due to WIX’s international operations, processing outside the EU may occur. WIX ensures data processing is done only in third countries with adequate data protection (e.g., via EU adequacy decisions or standard contractual clauses).
WIX processes the following user data on our behalf:
Name, email address, delivery and billing address, payment data, company name, phone number (if applicable), IP address, order information, and device/browser information.
b) WIX Web Analytics
WIX also uses cookies for web analytics. Data such as time, location, and frequency of site visits is transmitted to and analyzed on WIX servers.
Legal basis: Art. 6 (1)(f) GDPR – legitimate interest in analyzing and optimizing our website.
Users can prevent or stop cookie installation via browser settings.
More on WIX's data processing is available at:
https://de.wix.com/about/privacy
Payment Providers
To process orders placed in our online shop or to facilitate payment of electronic invoices, we use external payment service providers. The legal basis for processing the personal data collected in this context is your consent (Art. 6 para. 1 lit. a) GDPR) as well as the necessity for the performance of a contract (Art. 6 para. 1 lit. b) GDPR). The following payment methods are available to you:
Paypal
If you choose a payment method offered via the payment service provider “PayPal,” the payment will be processed by PayPal (Europe) S.à r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg. In the course of the payment process, your data—such as name, address, email address, telephone number, and payment amount—will be transmitted to PayPal. PayPal may also transfer your data to third parties insofar as this is necessary to fulfill contractual obligations or if the data is to be processed on PayPal’s behalf. For more information on PayPal’s data protection practices, please refer to: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Stripe (Credit Card)
If you choose a payment method offered via the payment service provider “Stripe,” the payment will be processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The transmission of data collected during the payment process (e.g., name, address, account number, bank sort code, credit card number, invoice amount, etc.) is carried out solely for the purpose of payment processing and only to the extent necessary for this purpose.
You have the option to withdraw your consent to data processing at any time. Such a withdrawal does not affect the lawfulness of data processing carried out prior to the withdrawal. For more information about Stripe’s data protection practices, please refer to:
https://stripe.com/de/privacy#translation
Additional Information Regarding Table Reservations
Server Log Files
The table reservation system automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:
-
Browser type and version
-
Operating system used
-
Referrer URL
-
Host name of the accessing device
-
Time of the server request
This data is not merged with other data sources. The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of the website — for this purpose, server log files must be recorded.
Sample Privacy Policy by the law firm Weiß & Partner