Privacy Policy
The controller within the meaning of data protection laws, in particular the EU General Data Protection Regulation (GDPR), is:
culinarosa AG
Poststrasse 103, CH-7050 Arosa
+41 81 377 83 00
info@lebistroarosa.ch
General notice
Based on Article 13 of the Swiss Federal Constitution and the data protection provisions of the Swiss Confederation (Data Protection Act, DSG), every person has the right to protection of their privacy as well as protection against misuse of their personal data. The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
In cooperation with our hosting providers, we make every effort to protect the databases as well as possible against unauthorized access, loss, misuse, or falsification. We point out that data transmission over the Internet (e.g., communication by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.
By using this website, you consent to the collection, processing, and use of data in accordance with the following description. This website can generally be visited without registration. Data such as pages accessed or names of files retrieved, date, and time are stored on the server for statistical purposes without this data being directly related to your person. Personal data, in particular name, address, or e-mail address, are collected on a voluntary basis wherever possible. No data is passed on to third parties without your consent.
Processing of personal data
Personal data is any information relating to an identified or identifiable person. A data subject is a person about whom personal data is processed. Processing includes any handling of personal data, regardless of the means and procedures used, in particular the storage, disclosure, acquisition, deletion, saving, modification, destruction, and use of personal data.
We process personal data in accordance with Swiss data protection law. Furthermore — insofar and to the extent that the EU GDPR is applicable — we process personal data in accordance with the following legal bases in connection with Art. 6 (1) GDPR:
- Consent (Art. 6 (1) sentence 1 lit. a GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6 (1) sentence 1 lit. c GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Protection of vital interests (Art. 6 (1) sentence 1 lit. d GDPR) – Processing is necessary in order to protect the vital interests of the data subject or of another natural person.
- Legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.
- Application procedure as a pre-contractual or contractual relationship (Art. 9 (2) lit. b GDPR) – Insofar as special categories of personal data within the meaning of Art. 9 (1) GDPR (e.g., health data, such as severely disabled status or ethnic origin) are requested from applicants as part of the application procedure so that the controller or the data subject can exercise the rights arising from employment law and the law on social security and social protection and fulfil the respective obligations, their processing is carried out in accordance with Art. 9 (2) lit. b GDPR, in the case of the protection of vital interests of the applicants or other persons pursuant to Art. 9 (2) lit. c GDPR, or for the purposes of preventive health care or occupational medicine, for the assessment of the employee's ability to work, for medical diagnostics, care or treatment in the health or social sector, or for the administration of systems and services in the health or social sector pursuant to Art. 9 (2) lit. h GDPR. In the case of a communication of special categories of data based on voluntary consent, their processing is carried out on the basis of Art. 9 (2) lit. a GDPR.
We process personal data for the duration required for the respective purpose or purposes. In the case of longer-term retention obligations due to legal and other obligations to which we are subject, we restrict processing accordingly.
Relevant legal bases
In accordance with Art. 13 GDPR, we inform you of the legal bases of our data processing. If the legal basis is not mentioned in the privacy policy, the following applies: The legal basis for obtaining consent is Art. 6 (1) lit. a and Art. 7 GDPR; the legal basis for processing to fulfil our services and carry out contractual measures as well as to respond to inquiries is Art. 6 (1) lit. b GDPR; the legal basis for processing to fulfil our legal obligations is Art. 6 (1) lit. c GDPR; and the legal basis for processing to safeguard our legitimate interests is Art. 6 (1) lit. f GDPR. In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) lit. d GDPR serves as the legal basis.
Security measures
In accordance with legal requirements and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing as well as the varying probability of occurrence and the extent of the threat to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
The measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, safeguarding of availability, and its separation. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to data threats. We also take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection through technology design and through data-protection-friendly default settings.
Transfer of personal data
As part of our processing of personal data, it may happen that the data is transferred to other bodies, companies, legally independent organizational units, or persons, or that it is disclosed to them. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.
Table reservations
Table reservations for New Year's Eve (31.12.2024) are only valid if a valid credit card has been provided. Reservations for New Year's Eve can be cancelled in full until 23.12.2024. In the event of a cancellation from 23.12.2024, the full menu price will be charged.
Data processing in third countries
If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if the processing takes place in the context of the use of third-party services or the disclosure or transfer of data to other persons, bodies, or companies, this is done only in accordance with the legal requirements. Subject to express consent or transfer required by contract or law, we process data only in third countries with a recognized level of data protection, contractual obligation through so-called standard protection clauses of the EU Commission, in the presence of certifications, or binding internal data protection regulations (Art. 44 to 49 GDPR, information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).
Privacy policy for cookies
This website uses cookies. Cookies are text files that contain data from visited websites or domains and are stored by a browser on the user's computer. A cookie primarily serves to store information about a user during or after their visit within an online offering. The stored information may include, for example, the language settings on a website, the login status, a shopping cart, or the position where a video was watched. We also include other technologies that fulfil the same functions as cookies under the term cookies (e.g., when user information is stored using pseudonymous online identifiers, also referred to as "user IDs").
The following cookie types and functions are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offering and closed their browser.
- Permanent cookies: Permanent cookies remain stored even after the browser is closed. For example, the login status can be saved, or preferred content can be displayed directly when the user visits a website again. Likewise, the interests of users used for reach measurement or marketing purposes can be stored in such a cookie.
- First-party cookies: First-party cookies are set by us.
- Third-party cookies: Third-party cookies are mainly used by advertisers (so-called third parties) to process user information.
- Necessary (also: essential or absolutely required) cookies: Cookies may be absolutely necessary for the operation of a website (e.g., to save logins or other user input, or for security reasons).
- Statistics, marketing, and personalization cookies: Furthermore, cookies are generally also used in the context of reach measurement and when the interests of a user or their behaviour (e.g., viewing certain content, using functions, etc.) on individual websites are stored in a user profile. Such profiles serve, for example, to show users content that corresponds to their potential interests. This procedure is also referred to as "tracking", i.e., following the potential interests of users. Insofar as we use cookies or "tracking" technologies, we will inform you separately in our privacy policy or in the context of obtaining consent.
Notes on legal bases: The legal basis on which we process your personal data with the help of cookies depends on whether we ask you for consent. If this applies and you consent to the use of cookies, the legal basis for processing your data is your declared consent. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (e.g., in the commercial operation of our online offering and its improvement) or, if the use of cookies is necessary, to fulfil our contractual obligations.
Retention period: Unless we provide you with explicit information on the retention period of permanent cookies (e.g., in the context of a so-called cookie opt-in), please assume that the retention period can be up to two years.
General information on revocation and objection (opt-out): Depending on whether the processing is based on consent or legal permission, you have the option at any time to revoke any consent given or to object to the processing of your data by cookie technologies (collectively referred to as "opt-out"). You can initially declare your objection using your browser settings, e.g., by deactivating the use of cookies (whereby this may also restrict the functionality of our online offering). An objection to the use of cookies for online marketing purposes can also be declared by means of a variety of services, especially in the case of tracking, via the websites https://optout.aboutads.info/ and https://www.youronlinechoices.com/. In addition, you can receive further objection notices in the context of the information on the service providers and cookies used.
Processing of cookie data on the basis of consent: We use a cookie consent management procedure in which the consent of users to the use of cookies, or the processing operations and providers named in the cookie consent management procedure, can be obtained as well as managed and revoked by users. The declaration of consent is stored so that it does not have to be requested again and consent can be proven in accordance with the legal obligation. Storage can take place server-side and/or in a cookie (so-called opt-in cookie, or with the help of comparable technologies) in order to be able to assign the consent to a user or their device. Subject to individual information on the providers of cookie management services, the following notes apply: The duration of the storage of consent can be up to two years. A pseudonymous user identifier is created and stored with the time of consent, information on the scope of the consent (e.g., which categories of cookies and/or service providers), as well as the browser, system, and end device used.
- Types of data processed: usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
- Data subjects: users (e.g., website visitors, users of online services).
- Legal bases: consent (Art. 6 (1) sentence 1 lit. a GDPR), legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR).
Privacy policy for SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, such as the inquiries you send to us as the site operator, this website uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Data transmission security (without SSL)
Please note that data transmitted over an open network such as the Internet or an e-mail service without SSL encryption can be viewed by anyone. You can recognize an unencrypted connection by the fact that the address line of the browser shows "http://" and no lock symbol is displayed in your browser line. Information transmitted over the Internet and content received online may be transmitted via third-party networks. We cannot guarantee the confidentiality of communications or documents transmitted via such open networks or third-party networks. If you disclose personal information via an open network or third-party networks, you should be aware that your data may be lost or that third parties may potentially access this information and consequently collect and use the data without your consent. Although in many cases the individual data packets are transmitted in encrypted form, the names of the sender and recipient are not. Even if the sender and recipient live in the same country, data transmission via such networks often takes place without controls, even via third countries, i.e., also via countries that do not offer the same level of data protection as your country of domicile. We assume no responsibility for the security of your data during transmission over the Internet and disclaim any liability for direct and indirect losses. We ask you to use other means of communication should you consider this necessary or reasonable for security reasons. Despite extensive technical and organizational security precautions, data may be lost or intercepted and/or manipulated by unauthorized persons. Where possible, we take appropriate technical and organizational security measures to prevent this within our system. However, your computer is outside the security perimeter we can control. It is your responsibility as a user to inform yourself about the necessary security precautions and to take appropriate measures in this regard. As the website operator, we are in no way liable for damages that you may incur as a result of data loss or manipulation. Data that you enter in online forms may be passed on to commissioned third parties for the purpose of order processing and may be viewed and, where applicable, processed by them.
Privacy policy for server log files
The provider of this website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
This data cannot be assigned to specific persons. This data is not merged with other data sources. We reserve the right to check this data retrospectively if we become aware of specific indications of unlawful use.
Third-party services
This website may use Google Maps for embedding maps, Google Invisible reCAPTCHA for protection against bots and spam, and YouTube for embedding videos. These services of the American Google LLC use, among other things, cookies, and as a result, data is transferred to Google in the USA, whereby we assume that no personal tracking takes place in this context solely through the use of our website. Google has committed itself to ensuring appropriate data protection in accordance with the American-European and American-Swiss Privacy Shield. Further information can be found in Google's privacy policy.
Copyrights
The copyright and all other rights to content, images, photos, or other files on the website belong exclusively to the operator of this website or the specifically named rights holders. Prior written consent from the copyright holder is required for the reproduction of any files. Anyone who commits a copyright infringement without the consent of the respective rights holder may be liable to prosecution and possibly to damages.
General disclaimer
All information on our website has been carefully checked. We make every effort to keep our information offering up to date, correct, and complete. Nevertheless, the occurrence of errors cannot be completely ruled out, which means we cannot guarantee the completeness, correctness, and timeliness of information, including journalistic-editorial information. Liability claims for damages of a material or immaterial nature caused by the use of the information provided are excluded, unless there is demonstrably intentional or grossly negligent fault.
The publisher may change or delete texts at its own discretion and without notice and is not obliged to update the contents of this website. The use of or access to this website is at the visitor's own risk. The publisher, its clients, or partners are not responsible for damages such as direct, indirect, incidental, consequential, or damages to be specifically determined in advance, which allegedly arose from visiting this website, and therefore assume no liability for such damages.
The publisher also assumes no responsibility or liability for the content and availability of third-party websites that can be accessed via external links on this website. The operators of the linked pages are solely responsible for their content. The publisher thus expressly distances itself from all third-party content that may be relevant under criminal or liability law or that violates common decency.
Changes
We may amend this privacy policy at any time without prior notice. The current version published on our website applies. Insofar as the privacy policy is part of an agreement with you, we will inform you of the change by e-mail or other suitable means in the event of an update.
Questions for the data protection officer
If you have any questions about data protection, please send us an e-mail or contact the person responsible for data protection in our organization listed at the beginning of this privacy policy.