Legal
Privacy Policy
Last updated: October 2026
This policy explains how we process your personal data when you use this website and request a table, in line with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Data controller
Restaurante Taj Mahal · NIF X8099640Y · Avenida Benito Pérez Galdós, 41 (ground floor), 03005 Alicante · tajmahalalicante@gmail.com · 965 120 321.
What data we process
The details you give us when you request a table: name, phone number, email (optional), date, time and number of guests, occasion (optional) and special requests (optional). If you mention allergies or intolerances in your special requests, you are voluntarily giving us health data, which we use only to look after your booking. When you visit the site, our hosting provider also processes your IP address and basic browser data in order to serve the pages and keep the site secure.
Purposes and legal basis
- Managing your booking request and contacting you about it (confirmation, changes or cancellation), including the automatic acknowledgement email. Legal basis: steps taken at your request before entering into a contract (Art. 6.1(b) GDPR).
- Taking account of any allergies or intolerances you tell us about. Legal basis: your explicit consent, given by providing them (Art. 9.2(a) GDPR), which you can withdraw at any time.
- Keeping the site secure and preventing abuse (for example, unwanted automated submissions). Legal basis: legitimate interest (Art. 6.1(f) GDPR).
We do not make automated decisions or build profiles, and we do not use your data to send you marketing.
Is providing data compulsory?
Fields marked with an asterisk (*) are needed to handle your booking. If you don't provide them, we can't process your request.
Who receives your data
We do not pass your data to third parties unless the law requires it. To run the service we use technology providers that process data on our behalf: web hosting (Netlify), email and booking spreadsheet (Google) and form delivery (Web3Forms).
International transfers
Some of these providers are based in the United States. Transfers are made with the safeguards required by Chapter V of the GDPR, such as standard contractual clauses or the EU–US Data Privacy Framework.
How long we keep your data
We keep booking data for up to 12 months from the booking date and then delete it, unless the law requires us to keep it for longer.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability, and withdraw your consent, by writing to tajmahalalicante@gmail.com and saying which right you want to use (we may ask you to prove your identity). We will reply within one month. If you believe your rights have not been respected, you can complain to the Spanish Data Protection Agency (AEPD) at www.aepd.es.
Security
We apply reasonable technical and organisational measures to protect your data, such as limiting access to the booking spreadsheet to authorised staff.