Datenschutzerklärung
Privacy Policy
Asmar Falafel (Owner: Saeeb Mahfoud)
Bernhard-Ernst-Straße 7
48155 Münster
Germany
Phone: +49 163 3713457
Email: info@asmarfalafel.de
Web: https://asmarfalafel.de
The controller within the meaning of the General Data Protection Regulation (GDPR) is the owner named above. We have not appointed a Data Protection Officer, as the legal requirements are currently not met.
- our website asmarfalafel.de (including online ordering / WooCommerce shop),
- all associated online services (contact forms, catering requests, customer accounts, email contact, WhatsApp contact, phone contact),
- and any future online services such as newsletters or apps, to the extent described in this policy.
External ordering platforms such as Uber Eats, Lieferando, or Wolt operate their own websites/apps and privacy policies and act as separate controllers.
We process personal data only to the extent necessary to provide a functional website and our content and services, process orders, catering requests and other contracts, respond to inquiries, or protect our legitimate interests, and only where a legal basis under Article 6 GDPR applies.
Legal bases include in particular:
- Art. 6(1)(b) GDPR (performance of a contract, e.g., online ordering),
- Art. 6(1)(c) GDPR (legal obligations, e.g., retention obligations under tax and commercial law),
- Art. 6(1)(f) GDPR (legitimate interest in a secure, user-friendly website and efficient communication),
- and where applicable in the future: Art. 6(1)(a) GDPR (consent, e.g., newsletter).
Personal data is stored only as long as necessary for the stated purposes or as long as statutory retention periods apply.
Our website is hosted by:
Hostinger International Ltd. 61 Lordou Vironos Street Larnaca 6023 Cyprus
Hostinger provides the technical infrastructure (servers, storage, security features). We have concluded a data processing agreement pursuant to Art. 28 GDPR with Hostinger.
When you access our website, technical information is automatically stored in server log files, such as:
- IP address
- Date and time of access
- Requested page/file
- Browser type and version
- Operating system
- Referrer URL
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the technical provision and security of the website (e.g., defense against attacks).
Log files are generally deleted automatically after a short period unless longer storage is required, e.g., to investigate security incidents.
Our website currently uses only cookies that are technically necessary for operation, such as:
- WooCommerce cookies for cart and checkout
- Session cookies for login status in customer accounts
- Where applicable, security cookies (e.g., spam protection)
These cookies are required to provide the service you expressly requested and can therefore be set without consent under applicable German law (TTDSG).
Embedded third-party content (e.g., Google Maps) is loaded only after activation; until then, no third-party cookies are set by that content.
You can configure your browser to block or delete cookies. In that case, certain functions (e.g., cart) may not work properly.
If you contact us by email, phone, or contact form, we process your details (name, contact information, message content) to handle your request.
Legal bases:
- Art. 6(1)(b) GDPR (pre-contractual/contractual communication), or
- Art. 6(1)(f) GDPR (legitimate interest in efficient communication).
Data is deleted once the request has been fully processed, unless statutory retention obligations apply.
For catering requests, we use a form on our website (WPForms plugin). The data you enter (e.g., name, contact details, event information, number of guests, preferences) is stored on our web server and sent to us by email.
WPForms processes data on our behalf and only according to our instructions; a data processing agreement exists where required.
Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a catering contract).
Our website contains a link/button to our WhatsApp Business account. When you click it, the WhatsApp app or WhatsApp Web opens depending on your device. Provider: WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
Communication is end-to-end encrypted, but Meta/WhatsApp may process metadata (e.g., who communicates with whom and when). We recommend not sending particularly sensitive information (e.g., health data) via WhatsApp.
Legal basis: Art. 6(1)(b) GDPR (communication regarding orders/inquiries) or Art. 6(1)(f) GDPR (legitimate interest in fast customer contact).
Further information can be found in WhatsApp’s privacy policy.
You may create a customer account voluntarily. In doing so, we process, among other things:
- Name, address, contact details
- Login data (email, password)
- Order history
Legal basis: Art. 6(1)(b) GDPR (provision of account functions as part of the user relationship).
You can delete your customer account at any time via the relevant function in your profile. Upon deletion, profile data is removed from the active system. Order and invoice data will be stored further only to the extent required to comply with statutory retention obligations (see Section 17).
When you place an order, we process the following data depending on payment and delivery method:
- Basic data (name, where applicable company)
- Billing and delivery address
- Contact details (email, phone)
- Order data (products, prices, date)
- Selected payment and delivery method
- Any notes/comments
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
Processing is carried out via the WooCommerce shop system within our WordPress installation. WooCommerce sets technically necessary cookies (e.g., cart identifier).
We currently offer the following payment methods:
- Cash or card payment on pickup/delivery (where available)
- Online payment via PayPal (planned/partially active)
- Additional payment providers in the future where applicable
If you use PayPal or another payment provider, payment information is processed directly between you and the provider. We typically receive only a confirmation of success or failure, not full account or card details.
Legal basis: Art. 6(1)(b) GDPR. Payment providers act as separate controllers; please review their privacy notices.
For deliveries, we may use external logistics partners such as Uber Direct. In this case, we transmit the data required for delivery (name, delivery address, and where applicable phone number) to the relevant provider. The provider processes the data independently for delivery fulfillment.
Legal basis: Art. 6(1)(b) GDPR (performance of the delivery contract).
If you order via external platforms such as Uber Eats, Lieferando, or Wolt, data is initially collected by those companies. We receive only the data necessary to prepare and fulfill the order (e.g., name, delivery address, products).
These platforms act as controllers for their processing. Please review their privacy policies on their websites/apps.
Our legal basis for processing is Art. 6(1)(b) GDPR (performance of contract).
We may offer an email newsletter with offers and updates about Asmar Falafel in the future. For this purpose, we would process your email address and, where applicable, your name.
- Registration will take place via double opt-in (confirmation email with link).
- Legal basis: your consent under Art. 6(1)(a) GDPR.
- You can withdraw your consent at any time with effect for the future (unsubscribe link or email).
- For persons under 16, consent is only valid with parental approval (Art. 8 GDPR).
We will add details (provider, technical implementation) once the newsletter is launched.
We use Google Maps to help you find our location. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Maps is disabled by default. It is only loaded after you actively click “Load map”. Until then, no connection to Google’s servers is established through the map on our website.
When you activate the map, personal data (in particular your IP address and technical device/browser information) may be transmitted to Google. Google may set cookies and process data outside the EU/EEA (e.g., in the USA).
Legal basis: Art. 6(1)(a) GDPR (consent via your activation click). You can avoid this processing at any time by not activating the map and using the “Open in Google Maps / Get Directions” link instead.
More information is available in Google’s privacy policy: https://policies.google.com/privacy.
You may send applications (e.g., for jobs at Asmar Falafel) by email, including your CV and a short message.
We process the data you provide solely to decide whether to establish an employment relationship (Art. 6(1)(b) GDPR in conjunction with Section 26 German Federal Data Protection Act (BDSG)).
If no employment relationship is established, we will delete your application documents no later than six months after completion of the application process, unless you consent to longer storage (talent pool) or statutory retention obligations apply.
Our services are generally intended for adults. Orders by minors may be possible if they can validly act under applicable law. For services based on consent (e.g., newsletter), persons under 16 should provide consent only with parental approval (Art. 8 GDPR in conjunction with German law).
We do not knowingly process children’s personal data for marketing purposes without appropriate consent.
We store personal data only for as long as necessary for the stated purposes or as required by statutory retention periods. Thereafter, data is deleted or anonymized.
Typical examples:
- Contract and order data: retention under commercial and tax law (typically several years).
- Log files: short storage period unless needed to investigate security incidents.
- Inquiry contact data: deletion after final processing unless further purposes apply.
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to certain processing (Art. 21 GDPR)
Where processing is based on consent, you have the right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR). To exercise your rights, an informal notice to the contact details above is sufficient.
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR (Art. 77 GDPR).
The authority generally responsible for us is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
We implement technical and organizational security measures to protect your data against manipulation, loss, destruction, or unauthorized access. This includes encrypted transmission via TLS/SSL (recognizable by “https://” and the lock symbol in your browser).
We may update this privacy policy to ensure it remains compliant with current legal requirements and reflects changes to our services (e.g., introducing new services). The most current version applies when you revisit our website.
Datenschutzerklärung
Verantwortlich im Sinne der Datenschutzgrundverordnung, DSGVO, sind gemeinsam:
Saeeb Mahfoud
Lina von der Ahe
Nieberdingstraße 10
48155 Münster
Deutschland
Telefon: +49 163 3713457
E-Mail: info@chaihut.de
Website: https://chaihut.de
Ein Datenschutzbeauftragter wurde derzeit nicht benannt, da die gesetzlichen Voraussetzungen hierfür aktuell nicht vorliegen.
- Art. 6 Abs. 1 lit. a DSGVO, sofern Sie eine Einwilligung erteilen
- Art. 6 Abs. 1 lit. b DSGVO, soweit die Verarbeitung zur Durchführung vorvertraglicher Maßnahmen oder zur Bearbeitung Ihrer Anfrage erforderlich ist
- Art. 6 Abs. 1 lit. c DSGVO, soweit eine gesetzliche Verpflichtung besteht
- Art. 6 Abs. 1 lit. f DSGVO, soweit wir ein berechtigtes Interesse an einem sicheren, stabilen und nutzerfreundlichen Betrieb unserer Website sowie an effizienter Kommunikation haben
61 Lordou Vironos Street
Larnaca 6023
Zypern
- IP Adresse
- Datum und Uhrzeit des Zugriffs
- aufgerufene Seite oder Datei
- Browsertyp und Browserversion
- verwendetes Betriebssystem
- Referrer URL
- E Mail Adresse, Pflichtfeld
- Vorname, Pflichtfeld
- Status Student oder berufstätig, Pflichtfeld
- Instagram, optional
- Server Logfiles nur für den Zeitraum, der für Sicherheit und technische Stabilität erforderlich ist
- Kontaktanfragen bis zur abschließenden Bearbeitung, soweit keine gesetzlichen Aufbewahrungspflichten bestehen
- Daten aus der Chaihut Circle Registrierung bis zum Wegfall des Zwecks oder bis zu einem Widerruf bzw. einer Abmeldung, soweit keine gesetzlichen Gründe für eine längere Speicherung bestehen
- Recht auf Auskunft nach Art. 15 DSGVO
- Recht auf Berichtigung nach Art. 16 DSGVO
- Recht auf Löschung nach Art. 17 DSGVO
- Recht auf Einschränkung der Verarbeitung nach Art. 18 DSGVO
- Recht auf Datenübertragbarkeit nach Art. 20 DSGVO
- Recht auf Widerspruch nach Art. 21 DSGVO
- Recht auf Widerruf einer erteilten Einwilligung mit Wirkung für die Zukunft
Kavalleriestraße 2 bis 4
40213 Düsseldorf
Deutschland
Telefon: +49 211 38424 0
E-Mail: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de

Our website uses only links/icons to our profiles (Instagram, Threads, TikTok, YouTube, Facebook). A connection to the platform is established only when you click the relevant icon, which may transmit data (e.g., IP address, referrer). The platform operators are responsible for further data processing.