Privacy Policy
SEL by ÓX is committed to protecting your personal data and respecting your right to privacy. This Privacy Policy explains what personal data we process when you use our website, contact us, make a reservation, or use our services.
Personal data is processed in accordance with Act No. 90/2018 on Data Protection and the Processing of Personal Data and Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation (“GDPR”).
1. Data Controller
The data controller responsible for the processing of personal data under this policy is:
SEL by ÓX ehf.
Icelandic ID No. 670515-0790
Laugavegur 55
101 Reykjavík
Iceland
Email: sel@ox.restaurant
Phone: +354 779 0333
If you have any questions about the processing of personal data or wish to exercise your rights under this policy, you can contact us by email at sel@ox.restaurant.
2. What personal data do we process?
We only process personal data that is necessary in relation to the purpose of the processing. Depending on how you interact with us, the following information may be processed:
- Contact information: name, email address, phone number, and other information you provide when contacting us.
- Enquiries and messages: the content of enquiries, message subject lines, and other information you send through the website, by email, or by phone.
- Reservation information: information relating to table reservations, such as name, email address, phone number, reservation date and time, number of guests, and comments you provide when making a reservation.
- Information about allergies or special requirements: if you choose to inform us of allergies, intolerances, or other dietary requirements, we use such information solely to prepare for and provide you with safe and appropriate service.
- Technical information: IP address, browser type, device, operating system, visit time, pages viewed, and similar information that may be collected through web servers, security systems, and cookies.
- Consent settings: information about your consent or refusal regarding cookies and similar technologies.
3. Purpose and legal basis for processing
| Purpose | Personal data | Legal basis |
|---|---|---|
| To respond to enquiries and communications | Name, email address, phone number, message content | Steps taken prior to entering into a contract or our legitimate interests in responding to enquiries |
| To receive and manage table reservations | Reservation information, contact information, and comments | Contract or steps taken prior to entering into a contract |
| To take account of allergies, intolerances, or special requirements | Information you voluntarily provide about allergies or dietary requirements | Your explicit consent or processing necessary to protect vital interests, as applicable |
| To ensure website security and functionality | Technical information, IP address, security logs | Our legitimate interests in operating a secure website |
| To use necessary cookies | Technical cookie information | Necessary to provide the website service and ensure website functionality |
| To use analytics, marketing, or performance cookies | Usage data, consent settings, and technical information | Your consent |
| To comply with legal obligations | Data that may relate to invoices, accounting, complaints, or legal claims | Legal obligation |
4. Table reservations through Dineout
When you click “Book a table” on our website, you may be redirected to the Dineout reservation system. Personal data may be entered there in connection with your reservation, for example your name, email address, phone number, number of guests, date, time, and reservation comments.
Dineout may process personal data as an independent data controller or as a processor, depending on the nature of the processing. We recommend that you review Dineout’s privacy policy when using the reservation system.
5. Cookies and consent
The website uses cookies and similar technologies. Cookies are small text files stored in your browser and may be necessary for the website to function or used, with your consent, for purposes such as analytics, performance measurement, or marketing.
- Necessary cookies: used to ensure that the website functions properly, to maintain security, and to remember your consent settings. These cookies cannot be disabled in the consent banner.
- Functionality and preference cookies: may remember your choices, such as language or other settings, where such functionality is active on the website.
- Analytics and performance cookies: help us understand how the website is used and how it can be improved. These cookies are only used with your consent.
- Marketing cookies and third-party cookies: may be used to display or measure third-party content. Such cookies are only used with your consent.
You can manage your consents at any time by clicking the fingerprint button in the bottom left-hand corner of the screen. There you can accept, reject, or change your choices for different categories of cookies.
You can also configure your browser to reject or delete cookies. However, such settings may affect the functionality of the website.
6. Withdrawal of consent
Where processing is based on your consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
To change or withdraw your cookie consent, click the fingerprint button in the bottom left-hand corner of the screen and update your preferences.
7. Who has access to personal data?
We do not sell your personal data. However, we may share or provide access to personal data to the following parties where necessary:
- staff and service providers who need the information to respond to enquiries or provide services;
- reservation service providers, such as Dineout, when you make a table reservation;
- hosting providers, website administrators, WordPress plugins, and other technical service providers;
- email and communication systems used to respond to enquiries;
- accountants, payment service providers, or advisers where necessary for business, invoicing, or legal obligations;
- public authorities, where required by law or where necessary to protect our rights.
Service providers that process personal data on our behalf must only process the information according to our instructions and in accordance with appropriate confidentiality and data protection obligations.
8. Transfers of personal data outside the EEA
We aim, where possible, to use service providers that store data within the European Economic Area (“EEA”). If personal data is transferred to a country outside the EEA, we ensure that appropriate safeguards are in place, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or other lawful safeguards under the GDPR.
9. Retention period
We do not retain personal data for longer than necessary in relation to the purpose of the processing, unless the law requires or permits a longer retention period.
- Enquiries and general communications: retained for as long as necessary to respond to and follow up on the enquiry, generally no longer than 12 months unless ongoing communication, a contractual relationship, or legitimate interests require longer retention.
- Reservation information: retained for as long as necessary to manage the reservation, service, changes, complaints, or potential claims.
- Information about allergies or special requirements: retained only for as long as necessary to prepare for and provide the service, unless you request continued registration or a legitimate reason requires otherwise.
- Consent settings: retained to demonstrate consent or refusal and to remember your preferences.
- Technical security logs: retained for a reasonable period to ensure security, traceability, and troubleshooting.
- Accounting records: retained in accordance with statutory retention periods, generally for 7 years from the end of the relevant financial year where accounting records are concerned.
10. Security of personal data
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. Such measures may include access controls, encrypted connections, updates to website systems, limited staff access, and agreements with service providers.
11. Your rights
You have the following rights under data protection law, as applicable in each case:
- The right to information about how we process your personal data.
- The right of access to the personal data we process about you.
- The right to rectification if information is inaccurate or incomplete.
- The right to erasure in certain circumstances.
- The right to restriction of processing in certain circumstances.
- The right to data portability where processing is based on consent or contract and carried out by automated means.
- The right to object where processing is based on legitimate interests.
- The right to withdraw consent at any time where processing is based on consent.
To exercise your rights, you can email us at sel@ox.restaurant. We may request confirmation of your identity before handling your request, to ensure that personal data is not disclosed to the wrong person.
12. Complaint to the Icelandic Data Protection Authority
If you believe that our processing of personal data violates data protection law, you have the right to lodge a complaint with Persónuvernd, the Icelandic Data Protection Authority.
Persónuvernd
Email: postur@personuvernd.is
Website: www.personuvernd.is
13. Children
The website and our services are not specifically intended for children. We do not knowingly collect personal data from children without the consent of a parent or guardian where such consent is required by law.
14. Changes to this Privacy Policy
We may update this Privacy Policy as needed, for example due to changes to the website, our services, technical solutions, or legal obligations. A new version takes effect when published on the website.