Skip to content
GDPR & TDDDG Compliant

Privacy Policy

Comprehensive privacy policy pursuant to the General Data Protection Regulation (GDPR) and TDDDG

1 Data Controller

The controller responsible for data processing on this website under the General Data Protection Regulation (GDPR) is:

HB Tad GmbH

Breite Str. 48–50, 50667 Cologne, Germany

Managing Director: Mehmet Aytekin

Commercial Register: Amtsgericht Köln, HRB 124696 · VAT ID: DE458040405

Email: info@hbdoner.com

2 Legal Grounds for Processing (Art. 6 GDPR)

  • Art. 6(1)(a) GDPR (Consent): Explicit consent granted for specific features (e.g., interactive maps).
  • Art. 6(1)(b) GDPR (Contractual): Processing required to fulfill orders, reservations, or evaluate franchise inquiries.
  • Art. 6(1)(c) GDPR (Legal Obligation): Statutory accounting and tax retention periods under German law.
  • Art. 6(1)(f) GDPR (Legitimate Interests): IT security, threat prevention, and reliable site operations.

3 Hosting & Server Logs

Our website is hosted on secure enterprise infrastructure in Germany by Hetzner Online GmbH under a Data Processing Agreement (DPA) compliant with Art. 28 GDPR. Server logfiles (IP addresses, request timestamp, browser info) are retained for max 7 days for security protection.

4 Cookies & Local Storage (TDDDG § 25)

We only use strictly necessary cookies for website functionality. External media services (Google Maps) require your explicit consent before loading. You can adjust your consent at any time via the button.

5 Orders & POS System Integration (HBPOS)

Order details submitted through our site are transmitted directly to the point-of-sale system (HBPOS Desktop) of the designated restaurant branch to prepare and fulfill your meal in accordance with Art. 6(1)(b) GDPR.

6 Local Fonts (GDPR Compliant)

Our corporate typography (DM Sans) is 100% self-hosted on our servers. No requests or telemetry are sent to Google servers in the United States.

7 Your Rights & Supervisory Authority

You have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict processing (Art. 18), data portability (Art. 20), and object (Art. 21). The competent supervisory authority is LDI NRW (Düsseldorf, Germany, www.ldi.nrw.de).