Privacy Policy
In short: this website sets no cookies, has no analytics or advertising tools, loads no content, fonts or scripts from third parties, and stores nothing on your device. The form in the “Contact” section does not send anything: it copies your text to your device's clipboard. We only receive personal data if you choose to call us or send us an email.
1. Who we are
mezedofolia.gr is the informational website of the “Mezedofolia” taverna. For anything concerning your personal data and this website, you can reach us using the details published in the “Contact” section:
- Address: Leof. Asklipiou 115, Giannouleika 210 52, Greece
- Phone: +30 2753 061552
- Email: ninagewrga83@gmail.com
2. What happens when you simply visit the site
This is a static website hosted on Google's Firebase Hosting. As with any website, delivering a page or file to you means your browser sends a request to the hosting infrastructure. That request includes your IP address and ordinary technical details (such as the address requested, your browser type and the time of the request).
According to Google's official documentation, Firebase Hosting uses the IP addresses of incoming requests “to detect abuse and provide customers with detailed analysis of usage data”, and retains IP data “for a few months”. Google does not publish a more precise period, and we do not invent one here. Google also documents that every request to the site is logged at the content delivery network (CDN) that Firebase Hosting provides automatically.
Purpose: delivering the website securely and correctly, keeping it available and protecting it from abuse. Legal basis: our legitimate interest in operating the site securely (Article 6(1)(f) GDPR).
We have not added any traffic-measurement, advertising or visitor-profiling tools to this website, and we do not receive identifiers from the hosting service that would let us recognise you as a visitor.
3. Cookies and storage on your device
This website sets no cookies and uses no localStorage, sessionStorage, IndexedDB or service workers. There is no optional technology requiring your consent, which is why we show no consent pop-up. The details are on the Cookies & Technologies page.
4. The contact form sends no data
The “Contact” section has a form with a Name and a Message field. That form has no submission address and is not submitted anywhere. The button copies the text you typed to your device's clipboard, so that you can paste it yourself into an email or a messaging app.
In practice this means that whatever you type stays on your device: it is not sent to us, not sent to a form provider or any other third party, and not stored by the website. We do not use a form-handling service.
5. When you contact us by email or phone
If you email or call us, we receive whatever you choose to tell us — for example your name, your email address or the number you are calling from, and the content of your message (such as a reservation date, time and number of guests).
Purpose: to answer you and to handle your reservation or question. Legal basis: performance of the reservation you ask for, or steps preparatory to it (Article 6(1)(b) GDPR) and, for general enquiries, our legitimate interest in replying to people who contact us (Article 6(1)(f) GDPR). We do not use your contact details for newsletters or marketing messages.
The email address we publish is a Gmail address, so messages you send us are held in Google's email infrastructure. We keep correspondence only for as long as we need it to deal with your request and to manage our relationship afterwards, unless a legal obligation requires us to keep it longer.
6. Links to other websites
The site has an “Open in Google Maps” button. It is a plain link: there is no embedded map and no request is made to Google while you are on our pages. A request happens only if you click the link, at which point you are taken to Google's service, which applies its own privacy policy. The same is true for the phone and email links, which open your own apps.
7. Who processes data on our behalf
We use Google's Firebase Hosting to host and deliver the website. According to Google's official documentation, for the end-user data of a website the site operator typically acts as data controller and Google generally acts as data processor, under the Firebase Data Processing and Security Terms. Google expressly names Fastly, Inc. (USA) as the subprocessor that delivers Firebase Hosting content to end users via its CDN.
Site content is distributed through a global CDN, meaning it is served from the edge server closest to the visitor. We do not claim that all technical processing takes place exclusively within the EU, because Google offers no such commitment for Firebase Hosting.
8. International transfers
Because the hosting and CDN operate globally, technical request data may be processed outside the European Economic Area, including in the United States. For such transfers, Google's data processing terms provide for the mechanisms applicable in each case: the EU–U.S. Data Privacy Framework for transfers to a certified Google entity in the US, and/or the European Commission's Standard Contractual Clauses. We do not state that only one of these applies exclusively, because that depends on the contracting Google entity.
9. Retention
- Technical request data at the hosting layer: Google states that Firebase Hosting retains IP data “for a few months”. We do not set that period and we have no access to the infrastructure's internal logs.
- Form data: none exists, because the form sends nothing.
- Email and phone contact: for as long as we need it to answer and handle your request, unless a legal retention obligation applies.
10. Your rights
In relation to personal data we process, you have the right of access, rectification, erasure, restriction of processing, objection to processing based on our legitimate interest, and data portability where applicable. To exercise your rights, contact us using the details in section 1. Please note that for technical request data not linked to an identifiable person, we may be unable to locate data relating to you.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or with the supervisory authority of your country of residence.
11. Security
The website is served exclusively over HTTPS. Because we collect no data through a form and keep no visitor database, the amount of data that could be exposed is minimal by design.
12. Children and sensitive data
This is an informational website for a taverna. It is not directed at children and it does not ask for age or any other detail through a form. Please do not send us sensitive information by email (for example health data) and limit what you send to what your reservation or question requires. If you need to tell us about a dietary restriction or an allergy, simply mention it on the phone when you book.
13. Changes to this policy
If the way the website works changes — for example if traffic measurement, an embedded map, a form that actually transmits data, or a booking system is added — we will update this page before it goes live and, where consent is required, we will ask for it first.
Sources
The hosting statements above are based on Google's official documentation: Privacy and Security in Firebase, Firebase Hosting web request logs, Firebase Data Processing and Security Terms, Firebase Subprocessors.