1. Controller and contact
The controller is Roma ugostiteljstvo d.o.o., društvo s ograničenom odgovornošću, registered at Žabica 1, 51000 Rijeka, OIB 71883304715, VAT ID HR71883304715. Business contact: catering.elrio@gmail.com. Privacy requests: catering.elrio@gmail.com.
2. Catering inquiries
The form collects your name, at least one contact method (email or phone), event date, city/postcode, delivery and staff choices, and any optional address or message. An address is required only if delivery is requested. We process this to answer a request or prepare a quotation under Article 6(1)(b) GDPR. Submitting the form does not create a reservation, order, contract, or payment obligation.
Relevant dietary or allergy requirements may be included so that we can prepare a suitable proposal. Please do not send unrelated medical details or other sensitive personal data.
3. Delivery and retention
The website stores a temporary database recovery copy and sends every entered field to the restaurant mailbox through an external transactional email provider.
The website copy is deleted automatically after 30 days. A deleted record may remain in an encrypted rotating backup for up to 14 additional days. An inactive inquiry email is deleted from the restaurant mailbox within 12 months. This is mailbox retention only; the website does not create customer, booking, payment, invoice, or accounting records.
4. Providers and international transfers
External providers of hosting, encrypted backups, mailboxes, transactional email, and authorised support may process personal data on our instructions and only to the extent needed to provide their services. Production infrastructure and off-site backups are located in the EU/EEA, with access limited to authorised people.
Current transactional email processor:
- Postmark (AC PM LLC) — delivers catering inquiries and may retain message content and metadata for 45 days. Processing may take place in the United States and is covered by a data-processing agreement and Standard Contractual Clauses. Postmark EU privacy details.
5. Automatically received technical data and maps
For security and abuse prevention, the server receives ordinary request data such as IP address, timestamp, browser information, and requested URL. Pseudonymised abuse-prevention data is deleted after seven days.
The footer map uses OpenFreeMap to display OpenStreetMap data. OpenFreeMap receives the visitor’s IP address and technical request information needed to return map tiles, styles, fonts, and sprites. The website does not use map requests for analytics or advertising and does not create non-essential browser storage. See the OpenFreeMap privacy notice.
The catering form loads Cloudflare Turnstile to detect automated abuse. Cloudflare receives technical request, browser, device, page, and interaction information needed to validate the challenge. The result is used only to accept or reject the submission. See Cloudflare’s Turnstile Privacy Addendum.
6. Recipients, security, and legal obligations
Data is available only to authorised restaurant staff and the providers needed to host, back up, secure, support, and deliver email. It may also be disclosed when law requires it or to establish, exercise, or defend legal claims. We use access controls, encrypted transport, backups, retention limits, and security monitoring appropriate to the risk. There is no automated decision-making that produces legal or similarly significant effects.
7. Your rights
Subject to the GDPR, you can request access, correction, deletion, restriction, data portability, or object to processing. Send a request to catering.elrio@gmail.com. We may verify identity and normally respond within one month. You may complain to the Croatian Personal Data Protection Agency (AZOP): azop.hr.