Server logs
Each access to our website automatically generates information at our web server:
- Lawful basis
- GDPR Art. 6(1)(f) (legitimate interest: operational security, error analysis)
- Retention
- 7 days
Last updated · 06 May 2026
This policy applies to tablario.com and the restaurant portal. The separate per-restaurant privacy notice — the one callers hear on the phone — lives at tablario.com/datenschutz/<restaurant-id>.
Controller within the meaning of GDPR is Staqmind UG. No data protection officer is appointed — the conditions of § 38 BDSG are not met.
Each access to our website automatically generates information at our web server:
For form requests we collect name, email and optionally phone/restaurant name.
For contract performance we store restaurant master data and payment information (Stripe).
Tablario processes caller data on behalf of the restaurant (phone number, audio, transcript, reservation details). Tablario is a processor under GDPR Art. 28; the controller is the respective restaurant. Call audio is stored for up to 30 days and then automatically anonymised.
We use only strictly necessary cookies (session cookies, CSRF protection). For web analytics we use Plausible Analytics — cookie-less, no personal data, no cross-site tracking. No consent banner required. Data transfer encrypted via SSL/TLS.
We use the following service providers. DPAs (GDPR Art. 28) are in place with all of them. Data transfers to the USA rest on the EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs).
| Provider | Purpose | Location | Third-country basis |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Cloud hosting, compute, DB, CDN, Cognito auth, SES email | eu-central-1 · Frankfurt | — |
| Telnyx Ireland Limited | Telephony routing, numbers, SMS | Dublin, Ireland | SCCs (EU/USA flow possible) |
| LiveKit, Inc. | Voice orchestration (WebRTC/SIP) | USA / EU | DPF / SCCs |
| Deepgram, Inc. | Speech-to-text (STT) · default provider | USA | DPF / SCCs |
| Soniox Inc. | Speech-to-text (STT) · alternative | USA | SCCs |
| ElevenLabs Inc. | Text-to-speech (TTS) | EU residency / USA | DPF / SCCs |
| Anthropic, PBC | AI language model (Claude) | USA | DPF / SCCs |
| Stripe, Inc. | Payment processing | USA / Ireland | DPF / SCCs |
| ImprovMX (Reflexion Networks) | Inbound email forwarding | USA | SCCs |
| Functional Software (Sentry) | Error monitoring & stability analysis | USA | DPF / SCCs |
| Plausible Analytics | Web analytics (cookie-less) | EU | — |
LiveKit, Deepgram, Soniox, ElevenLabs and Anthropic only process data within the AI phone assistant on behalf of our restaurant customers.
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Contact us at:
datenschutz@tablario.comYou have the right to lodge a complaint with a supervisory authority. Our competent authority is:
No profiling under GDPR Art. 22 occurs. The AI makes no legally binding decisions; the restaurant retains full control over reservation rules at all times and can manually adjust bookings.
We take appropriate measures under GDPR Art. 32:
We commit to detecting, investigating and reporting personal data breaches without undue delay. For notifiable breaches under GDPR Art. 33 we notify the supervisory authority within 72 hours. Where high-risk breaches affect data subjects we inform them without delay (Art. 34 GDPR). Restaurant customers also receive a processor notification.
We update this policy whenever our services or legal requirements change. The current version is always available here.
Drop us a message — we reply within one business day.