This Privacy Policy explains which personal data is processed when you visit this website and when you contact us.
1. Data Controller
Omar Shaar
trading as Eano
Stiftsplatz 5
53111 Bonn
Germany
Email: info@eano.dev
Phone: +49 176 45342588
A data protection officer is not legally required and has not been appointed.
2. General Information and Legal Basis
We only process personal data to the extent necessary to provide the website, handle inquiries, take pre-contractual measures, fulfill a contract, or comply with legal obligations.
- Art. 6(1)(b) GDPR for inquiries related to a possible or existing contract.
- Art. 6(1)(c) GDPR to fulfill legal obligations.
- Art. 6(1)(f) GDPR for the secure, stable and cost-effective operation of the website.
- Art. 6(1)(a) GDPR, where we expressly obtain your consent.
3. Hosting and Server Log Files
This website is hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus (“Hostinger”). The server location depends on the data center booked with Hostinger.
When you visit the website, the hosting provider may process technically necessary data in server log files. This may include IP address, date and time, page accessed, amount of data transferred, referrer, browser, operating system and access status.
This processing takes place to ensure secure delivery, error analysis and defense against abusive access based on Art. 6(1)(f) GDPR.
Server log files are generally deleted automatically after a maximum of 7 days, unless retention is required to investigate a specific security incident.
4. Contact Form and Getting in Touch
When you submit a contact inquiry, we process your name, email address, subject, message and any information voluntarily provided. This data is used to process the inquiry and respond to follow-up questions.
If the inquiry relates to a possible contract, processing is based on Art. 6(1)(b) GDPR. For other inquiries, it is based on our legitimate interest in appropriate communication under Art. 6(1)(f) GDPR.
Providing your name and email address is required so that we can process and respond to your inquiry; all other information is voluntary. Without a name and email address, we cannot process the inquiry.
5. Demo Requests
For a demo request, we process in particular your name, email address, optionally your phone number, restaurant name, information about your current situation and menu, logo and design status, desired start date, an opening date if applicable, and any voluntary messages.
This processing serves to prepare a tailored product presentation and to carry out pre-contractual measures at the request of the data subject under Art. 6(1)(b) GDPR. Submitting the request does not yet create a paid contract.
Providing your name and email address is required so that we can process your demo request; all other information is voluntary. Without a name and email address, we cannot prepare a demo presentation.
6. Technical Spam and Abuse Protection
To protect our forms against automated or excessive requests, we use a hidden honeypot field and a time-limited rate limit. For this purpose, a non-readable check value is generated from the IP address and stored for a maximum of 15 minutes.
The legal basis is our legitimate interest in the security and functionality of our forms under Art. 6(1)(f) GDPR.
7. Contact via WhatsApp
If the WhatsApp link provided is actively used, a connection is established to our WhatsApp Business number +49 176 45342588. The service is provided by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, the Meta entity responsible for the European Economic Area. WhatsApp then processes data under its own responsibility; this may include phone number, message content, device and connection data.
Using WhatsApp is voluntary. Alternatively, you can use the contact form or email at any time. For transfers to third countries, in particular the United States, WhatsApp’s/Meta’s privacy information and transfer mechanisms apply.
8. Cookies and Similar Technologies
As of now, we do not use any analytics, marketing or tracking services on the publicly accessible pages. WordPress may use technically necessary cookies, in particular for logged-in administrators and website functionality.
Should non-essential cookies or external tracking services be used in the future, this information will be updated and, if necessary, consent will be obtained in advance.
9. Recipients and Data Processors
Personal data is only transferred to service providers or other recipients to the extent necessary for the purposes mentioned, where there is a legal obligation, or where valid consent has been given. We currently use in particular the following service providers:
- Hostinger International Ltd. as the hosting provider of the website.
- Google Ireland Limited (Gmail) for sending emails from contact and demo inquiries. The email/SMTP provider used may change in the future; this Privacy Policy will be updated accordingly.
- IT, maintenance or support service providers, where necessary in individual cases.
10. Storage Period
We only store personal data for as long as necessary for the respective purpose. Inquiries are deleted once they have been fully processed and no contractual or legal retention obligations apply.
As a rule, we delete data from contact and demo inquiries no later than 6 months after the inquiry has been fully processed, unless a longer statutory retention obligation applies or the inquiry results in a contractual relationship.
11. Rights of Data Subjects
Subject to the applicable legal requirements, data subjects have, in particular, the following rights:
- Right to access the personal data processed.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure or restriction of processing.
- Right to data portability, where applicable.
- Right to object to processing based on Art. 6(1)(e) or (f) GDPR.
- Right to withdraw consent with effect for the future.
To exercise these rights, a message to the contact address given above is sufficient.
12. Right to Lodge a Complaint with a Supervisory Authority
Data subjects have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of their residence, workplace, or the place of the alleged infringement.
As Eano is based in Bonn, the competent authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (Data Protection Authority of North Rhine-Westphalia): Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
13. Data Security and Updates
We take appropriate technical and organizational measures to protect personal data against loss, unauthorized access and misuse. Data transmitted through the website is encrypted via HTTPS.
We update this Privacy Policy whenever processing activities, the services used, or legal requirements change.
14. Automated Decision-Making
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning data subjects or similarly significantly affects them.