GDPR · Processing of personal data

Privacy Policy.

Short version up front: I know how annoying privacy policies are. I promise: no tracking, no analytics, no advertising cookies. What I collect — and why — is honestly listed below.

Note: The legally binding version is the German original at doernbacher-cafebar.de/datenschutz.html. This English version is provided for convenience.

1. Controller

Maximilian Dörnbach
Dörnbacher Café-Bar
Knickhagen 7
37308 Heilbad Heiligenstadt
Germany
E-mail: anfragen@doernbacher-cafebar.de

For full details see the Imprint (German).

2. Privacy at a glance

This privacy policy informs you about which personal data is processed when you visit this website, on which legal basis, and which rights you have under the General Data Protection Regulation (GDPR).

3. General information & legal bases

The processing of your personal data is generally based on one of the following legal bases:

  • Art. 6 (1) (a) GDPR — you have given consent (e.g. by ticking the checkbox in the request form).
  • Art. 6 (1) (b) GDPR — processing is necessary for the performance of a contract or for pre-contractual measures (e.g. handling your request).
  • Art. 6 (1) (c) GDPR — processing is necessary to comply with a legal obligation (e.g. tax retention periods).
  • Art. 6 (1) (f) GDPR — processing is based on a legitimate interest (e.g. secure provision of the website).

4. Hosting

This website is hosted by:

ALL-INKL.COM · Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68 · 02742 Friedersdorf · Germany
Privacy policy of All-Inkl

A data processing agreement (DPA) under Art. 28 GDPR has been concluded with ALL-INKL.COM. Data processing takes place exclusively on servers in Germany. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure and efficient provision of the online offering).

5. SSL / TLS encryption

This site uses SSL/TLS encryption (Let's Encrypt) for security reasons. You can recognise an encrypted connection by the address bar starting with „https://" and a padlock symbol. All data you transmit to us is thus protected against eavesdropping by third parties.

6. Server log files

When the website is accessed, our hosting provider automatically collects information in so-called server log files. Specifically:

  • IP address of the requesting computer (anonymised after 7 days)
  • Date and time of access
  • Requested page / file
  • HTTP status code & transferred data volume
  • Referrer URL (page from which you came)
  • Browser type and version, operating system

This data is not merged with other data sources. Retention period: maximum 7 days, then automatically deleted. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in security and functionality).

7. Request form

If you use the request form on this website, the following data is transmitted to me:

  • Mandatory fields: first and last name, e-mail address, event date, number of guests, event location
  • Optional: company, phone number, occasion, time, desired package, free-text message

Purpose: processing your request and preparing an individual quote.
Legal basis: Art. 6 (1) (b) GDPR (performance of pre-contractual measures).
Retention period: until you object to storage or the purpose ceases to apply (no booking concluded → 6 months; booking → for the duration of statutory retention periods of up to 10 years under § 147 AO, German Tax Code).

The request is transmitted via encrypted SMTP (port 465, SSL/TLS) to my mailbox server at ALL-INKL.COM. No data is passed on to third parties.

8. Automatic confirmation e-mail

After sending the form, you will receive an automatic confirmation within approx. 15 minutes at the e-mail address you provided. This mail is also sent via my SMTP server at ALL-INKL.COM. Legal basis: Art. 6 (1) (b) GDPR.

9. Contact by e-mail

If you contact me by e-mail (anfragen@doernbacher-cafebar.de or max@doernbacher-cafebar.de), your message including all personal data contained therein is stored for the purpose of handling your enquiry. I do not share this data without your consent.

Legal basis: Art. 6 (1) (b) GDPR for contract-related communication, otherwise Art. 6 (1) (f) GDPR. Your e-mails remain with me until you request deletion or the purpose ceases — subject to mandatory tax retention periods.

10. Cookies

This website sets no cookies — neither first-party nor third-party. I use no tracking, no analytics tools (no Google Analytics, Matomo or similar) and no advertising cookies.

11. Local browser storage (Local Storage & Session Storage)

For convenience, your browser stores some technically necessary data locally on your device (this data never leaves your device and is not transmitted to me):

  • Request form: your entries are temporarily stored in localStorage so you don't have to re-enter them if the page reloads accidentally. The data is deleted as soon as the form is successfully sent — or manually by you through your browser settings.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in usability) or § 25 (2) no. 2 TDDDG (strictly necessary storage, as you have actively requested this).

12. External fonts (Google Fonts)

This website uses web fonts (Lora and Poppins) via the Google Fonts API for consistent typography. When you access the site, your browser loads the required fonts directly from Google servers, transmitting your IP address to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for users in the EEA) or Google LLC (USA) for delivery.
Privacy policy: policies.google.com/privacy

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in consistent, professional typography). Data transfers to the USA are based on an adequacy decision by the EU Commission under the EU-US Data Privacy Framework (DPF). Google LLC is DPF-certified.

Note: Local embedding of the fonts is possible on request — let me know if this is important to you.

13. Links to social networks

This website links to my Instagram profile (@doernbacher_cafe). This is a simple link — no data is transmitted to Instagram when you visit my website. Only when you actively click the link will you be forwarded to the platform. From that moment on, the privacy policy of Meta Platforms Ireland Ltd. applies.

14. Your rights as a data subject

Under the GDPR you have the following rights:

  • Right of access (Art. 15 GDPR) — you can request information about which data I process about you.
  • Right to rectification (Art. 16 GDPR) — correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR) — provided no statutory retention obligations apply.
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR).
  • Right to object (Art. 21 GDPR) — you can object to processing at any time.
  • Right to withdraw consent (Art. 7 (3) GDPR) — the lawfulness of prior processing remains unaffected.

To exercise your rights, a simple e-mail to anfragen@doernbacher-cafebar.de is sufficient.

15. Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the one in your federal state or the authority responsible for me:

Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI)
Häßlerstraße 8 · 99096 Erfurt · Germany
www.tlfdi.de

16. No automated decision-making

I do not use automated decision-making within the meaning of Art. 22 GDPR. Every request is decided by a human (usually Maximilian personally).

17. Data transfer to third countries

A transfer of your data to third countries outside the EU/EEA only takes place as part of the Google Fonts integration (see section 12). No other third-country transfers occur.

18. Updates to this privacy policy

I reserve the right to adjust this privacy policy if legal requirements or changes to my data processing make this necessary. The current version is always available at doernbacher-cafebar.de/datenschutz.html.

As of: May 2026