Privacy policy
Last updated: 30 September 2026
This translation is provided for information. If there is any discrepancy, the Spanish version prevails. Español
This policy explains how Mana Park processes the personal data of people who visit this website or contact the restaurant through it, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
Basic information
| Controller | Mana Park Ejemplo, S.L. (Mana Park) |
|---|---|
| Purposes | Handling bookings and enquiries, and measuring how the website is used in aggregated form. |
| Legal basis | Steps taken at your request before a booking, your consent when you write to us, and legitimate interest (audience measurement without cookies and website security). |
| Recipients | Processors that provide technical services to the restaurant, including IberiaIntel. We do not share data with third parties unless required by law. There are transfers to the United States covered by the EU and US Data Privacy Framework. |
| Rights | Access, rectification, erasure, objection, restriction of processing and portability, as explained below. |
| Further information | In the following sections of this page. |
Data controller
| Controller | Mana Park Ejemplo, S.L. |
|---|---|
| Tax ID (NIF) | B12345674 |
| Address | Parque de los Tres Jardines, 29670 San Pedro Alcántara, Málaga |
| [email protected] | |
| Trade name | Mana Park |
| Website | manaparkmarbella.com, carta.manaparkmarbella.com |
What data we process and why
- Bookings and enquiries. If you ask for a table or write to us by phone, WhatsApp, email or through a form on this website, we process your name, your contact details, the date, time and number of guests, and whatever you tell us, in order to manage the booking or reply to you.
- Audience measurement without cookies. We count page visits, clicks on buttons, dishes viewed and QR code scans in aggregated form, as explained in the section on audience measurement.
- Website security. The server records technical data about each request (IP address, date, page requested and browser) to protect the website against abuse and attacks.
Legal basis
- Bookings: steps taken at your request before entering into a contract (article 6.1.b GDPR).
- Enquiries: your consent when you write to us (article 6.1.a GDPR).
- Audience measurement and security: the legitimate interest of the restaurant in knowing how its website is used and in keeping it secure (article 6.1.f GDPR). We use the minimum data needed and you can object at any time.
Data required for bookings
Providing your data is not a statutory or contractual requirement. To manage a booking we need your name, a phone number or email address, the date, the time and the number of guests. If you do not provide them, we cannot confirm or manage the booking. Anything else you tell us is optional. To reply to an enquiry we only need a way to contact you.
Automated decisions and profiling
We do not make decisions based solely on automated processing of your data and we do not carry out profiling. Bookings and enquiries are always handled by a member of the restaurant staff.
How long we keep data
- Booking requests and enquiries: 365 days from the request. After that they are anonymised.
- Audience measurement: individual events for 90 days, without any reusable identifier, and aggregated daily counts for 25 months.
- Technical security logs: 30 days at most, unless they are needed to investigate an incident.
- Data we must keep by law: for the periods set by law.
Recipients and processors
- IberiaIntel, which develops, hosts and maintains this website and sends the booking notifications, acting as processor.
- Cloudflare, Inc., which delivers the website through its network and protects it against attacks. It processes IP addresses and technical request data. It is based in the United States and certified under the EU and US Data Privacy Framework.
- The hosting provider of the servers, located in the European Union.
- The email provider we use to send booking notifications and to reply to your messages.
- An artificial intelligence service provider used only to prepare and translate the content of the website (menu texts and descriptions). It does not receive personal data of website visitors.
- If you book on an external platform or write to us on WhatsApp, that company processes your data under its own privacy policy.
- We do not share data with third parties unless required by law.
International transfers
Cloudflare, Inc. may process data in the United States. The transfer is covered by the adequacy decision of the European Commission on the EU and US Data Privacy Framework and, additionally, by standard contractual clauses.
Audience measurement without cookies
To know how this website is used we follow the guidance of the Spanish Data Protection Agency (AEPD) on audience measurement. We do not use cookies and we store nothing on your device.
For each visit we calculate a pseudonymous identifier with a hash function applied to your IP address and browser data combined with a random value (salt) that changes every day. The salt is deleted after 48 hours, so the identifier can no longer be calculated and visits on different days cannot be linked. We do not store your IP address or the full details of your browser.
We record the pages you visit, clicks on the buttons to call, write on WhatsApp, book or open the menu, clicks on links to other websites, language changes, the dishes on the menu that appear on your screen, scans of our QR codes and the sending of a booking request or a message (only the fact that it was sent, not its content).
With each of these we store the identifier of the day, the date and time, the page, the language of the page, the type of device (mobile, tablet or computer), the name of the browser and of the operating system without their version, and the country, which we obtain from the delivery network without keeping the IP address. With each page visit we also store the domain of the website you come from, if your browser provides it (for example, google.com), and the campaign parameters utm_source, utm_medium and utm_campaign, with their value as it appears in the link, if the link you followed includes them.
We only use this data to obtain aggregated statistics for this website. The identifier is calculated separately for each restaurant, so it cannot link visits to the websites of different restaurants. We never combine this data with data from other websites or use it to build profiles. We delete the events after 90 days and keep only the aggregated daily counts, for 25 months.
The legal basis is the legitimate interest of the restaurant in knowing how its website is used (article 6.1.f GDPR). You can object by writing to [email protected].
Your rights
You can request access to your data, its rectification or erasure, restriction of processing and portability, and you can object to processing. You can also withdraw your consent at any time, without affecting earlier processing.
Write to [email protected] or by post to Parque de los Tres Jardines, 29670 San Pedro Alcántara, Málaga, stating the right you wish to exercise. If we cannot confirm your identity, we will ask you for proof of it.
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency.
Security
We apply technical and organisational measures to protect data, such as encrypted connections, restricted access and backups.
Changes to this policy
We may update this policy. The date of the last update appears at the top of this page.
