Data controller
The organization responsible for the processing described in this Policy is SOFI CAFE DOO.
SOFI CAFE DOO Šetalište Kapetana Iva Vizina 28Tivat, Montenegro Email: sofitivat@gmail.com Phone: +382 69 16 15 15
Data we may process
- Reservation details: your name, email address, phone number, requested date and time, number of guests, preferences, and special requests.
- Information you choose to provide when you contact us by email, phone, social media, or a messaging service.
- Technical records such as IP address, request time, requested page, response code, referrer, and browser or device type.
- Essential WordPress and security data needed to operate, protect, and administer the site.
Please do not send payment-card details, identity documents, or other unnecessary sensitive information through the free-text field. If you provide dietary or allergy information, we use it only as needed to handle your reservation.
Purposes and legal bases
- Answering enquiries, taking steps requested by you, and managing table reservations.
- Operating, diagnosing, securing, and preventing misuse of the website.
- Complying with applicable legal obligations and resolving disputes.
Depending on the circumstances, processing may be based on your request, our legitimate interests in operating the restaurant and protecting the site, a legal obligation, or your consent where consent is required. Required reservation fields are needed for us to process the request; without them, we may be unable to confirm it. We do not use submitted data for decisions based solely on automated processing that produce legal or similarly significant effects.
Service providers and external content
Providers supporting hosting, server security, backups, and email delivery may access data only to the extent necessary to provide those services. We do not sell personal data.
Some pages load Google Maps, YouTube, Google Fonts, and front-end files from jsDelivr or cdnjs. These providers may receive technical data, including your IP address and browser information, when a resource loads and may use cookies under their own policies. Social buttons for Telegram, WhatsApp, Instagram, and TikTok are external links; the destination service policy applies when you open them. Some providers may process data outside Montenegro subject to their transfer mechanisms and applicable legal requirements.
How long data is kept
Reservation and contact information is kept only as long as needed to answer you, manage the booking, establish or defend legal claims, and meet applicable record-keeping duties. Server logs are retained under the hosting security and rotation schedule. Backup copies remain until they are overwritten or deleted in the normal backup cycle.
Your rights
Subject to applicable law, you may request access to your data, correction, deletion, restriction, or object to certain processing. You may withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing. Contact us at sofitivat@gmail.com. We may request information needed to verify your identity and locate the relevant data.
You may also lodge a complaint with the Montenegrin Agency for Personal Data Protection and Free Access to Information (AZLP).
Children
The site is not designed specifically to collect personal data from children. If you believe a child has provided data without appropriate authorization, please contact us so we can review the request and take appropriate action.
Security
We use reasonable technical and organizational safeguards, including HTTPS, access controls, software maintenance, and backups. No method of transmission or storage can guarantee absolute security.
Changes to this Policy
We may update this Policy when the site, our practices, or applicable requirements change. The current version is published on this page with its revision date.