Schmiedehafen · Portenschmiede

Privacy policy

Here we inform you about which personal data are processed when visiting our website and when using our contact, reservation and application offers.

Status: 2. October 2026

1. Accountable person

Restaurant Schmiedehafen
Owner: Wena Traeger
Krölpaer Straße 25, 07387, Krölpa
E-mail: hallo@schmiedehafen.de
Telephone: 0176 61266600

2. Principles of processing

We process personal data only insofar as this is necessary for the operation of the website, the processing of inquiries, the initiation or execution of a contract, the organization of reservations and events or the processing of applications. Legal bases are in particular Art. 6 Abs. 1 lit. a, b, c and f GDPR.

Automated decision making, including profiling, does not take place.

3. Hosting and server protocols

This website is provided through Cloudflare Workers and the associated infrastructure. When called up, technically required log data can be processed, in particular IP address, time, page called up, referrer, browser and operating system. The processing serves the secure and stable provision of the website (Art. 6 Abs. 1 lit. f DSGVO).

For individual website functions, we also use services for the provision of the reservation and administration application, for database processing, for the secure delivery of content and for the storage of publicly integrated images. This includes in particular Cloudflare for technical delivery, administrative data and file storage as well as Supabase for the reservation database and individual publicly available website image files. Information about the suppliers used can be found in the section "Technical service providers and international processing".

Optional statistics and your choices

Only with your voluntary consent do we collect page views, clicks and steps in booking and request forms. Our own statistics use a random session identifier and the public page address without URL parameters; if applicable, only the hostname of a referring website is collected. Names, e-mail addresses, telephone numbers, form content and private access links are not transmitted to the statistics. The statistics are not used for advertising or cross-site user profiles. Technical processing: Cloudflare (see service providers and international processing below). The legal basis is Art. 6 Abs. 1 lit. a GDPR and § 25 Abs. 1 TDDDG for the optional storage and access in the browser.

With “Only necessary” you can reject the statistics. “Accept all” allows the described optional statistics. The selection is valid on this website and in its embedded booking area; another website requires its own selection. Via "Privacy Settings" you can change or revoke them at any time. As of the revocation, no further statistical events are recorded; the lawfulness of prior processing remains unaffected. A random statistic identifier is only in the browser’s session memory. The selection together with the version and time is in the local browser memory. We consider them for 180 days and remove them after expiration at the next call. The necessary storage of the selection takes place in accordance with § 25 Abs. 2 No. 2 TDDDG; the proof of an actually granted consent is stored with statistical events. Statistical events and related evidence are regularly removed after 400 days in the regular cleanup run. Combined SaaleSpa pedometers do not contain session identifiers.

Bookings, requests and necessary functions are possible without statistics. Technically necessary protection against duplication, temporary form designs, private access links and secure team login remain separate. For contract processing, Art. 6 para 1 lit. b, for required security functions, if applicable, lit. f GDPR and for required storage § 25 para 2 no. 2 TDDDG apply. Advertising pixels, Google Analytics and external analysis scripts are not used.

5. Contact, reservations and events

In the case of contact, reservation, catering or event inquiries, we process the information you have entered, such as name, contact data, appointment, number of people and message. The processing takes place for the processing of your request and for the initiation of a contract or fulfillment of the contract in accordance with Art. 6 Abs. 1 lit. b GDPR; in addition, Art. 6 Abs. 1 lit. f GDPR may apply.

Online reservation form: The form is integrated via our web application at restaurant-schmiedehafen.de/buchen/. The technical provision is made via Cloudflare; Supabase is used for the reservation database. When called up, technically required access data, in particular the IP address, browser information, time and requested resource, can be processed. When sending, we process the entered reservation data for processing the request and contract initiation in accordance with Art. 6 Abs. 1 lit. b GDPR; the technically secure provision takes place on the basis of Art. 6 Abs. 1 lit. f GDPR.

We only keep reservation data for as long as they are necessary for processing and legal proof or storage obligations. If no contract is concluded, request data will be deleted regularly as soon as there are no longer any legitimate reasons for the storage.

Applications, staff and recommendation forms

For applications and personnel inquiries, we process the submitted master, contact, qualification and availability data as well as voluntarily submitted documents. The legal basis is § 26 BDSG in conjunction with Art. 6 Abs. 1 lit. b DSGVO. Applications that are not considered will in principle be deleted no later than six months after completion of the procedure, provided that there is no consent to a longer storage period or a legal obligation.

In the case of employee recommendations, the recommending person is responsible for informing the data subject in advance about the disclosure of their contact data. We use this information exclusively for contact and recruitment.

File and document transmission

If documents or photos are uploaded, we process their content exclusively for the specified purpose. Please provide only necessary documents and blacken out unneeded particularly sensitive information.

7. External links and translation function

Links to Instagram, Facebook, Google Maps or other external offers only transfer data to the respective provider when clicking. For their processing, the data protection notices of the respective service apply.

8. Consignee, third country transfer and security

Data is only received by persons and service providers who need it for the respective purpose. In addition, a transfer takes place only in the case of a legal obligation or with consent. Transfers outside the European Economic Area will only take place if the requirements of Art. 44 ff. GDPR.

As far as service providers or their subcontractors process data outside the European Economic Area, this is only done under the conditions of Art. 44 ff. GDPR, in particular on the basis of an adequacy decision or appropriate guarantees such as the standard contractual clauses of the European Commission.

The website uses TLS encryption. Nevertheless, data transmission on the Internet can never be completely risk-free.

Storage period and purpose limitation

Requests and contact data are stored for processing and necessary proof. If the purpose ceases and there are no longer any legal obligations or justified claims, the data must be deleted. Accounting documents, including invoices, are generally kept for eight years; business letters are regularly kept for six years and books or annual financial statements for ten years. In individual cases, ongoing proceedings or other legal obligations may require longer deadlines. The deadlines begin in accordance with the applicable legal rules. A longer period of storage of documents does not justify the flat-rate storage of all forms.

10. Your rights

In accordance with the legal requirements, you have the right to access, rectification, deletion, restriction of processing, data portability and objection. You can revoke a consent at any time with effect for the future.

To exercise your rights, a message to hallo@schmiedehafen.de is sufficient.

Right of appeal

You can complain to a data protection supervisory authority. For Thuringia, the Thuringian state commissioner is generally responsible for data protection and freedom of information.

11. Update

We adjust this privacy policy if the legal situation, website functions or services used change. Relevant is the version published here.

Private Holiday Sites, Day Plans and Travel Wishes

For private plans created voluntarily, we store titles, host names, dates and locations, expiration and personal information. Invited people can add feedback, appointment and activity requests, or their responses for a travel comparison after consent. Voluntary food wishes are only stored with separate consent. The stored Hafenbar preview contains the photo montage you have designed; the original location photo is processed locally in the browser when you design it.

The edit link allows changes to the entire plan; it is intended for the host only. People with the invitation link will see the plan and summarized feedback. Individual names and food wishes remain with the host. When comparing travel, the names and answers of both travelers become visible together as soon as both have responded. The responsible team will only receive access via the administration if the host expressly submits the plan as a request.

For changes or deletion of your own feedback, a personal access is stored in the local browser memory; in addition, the personal feedback link can be secured. Please keep private links confidential. Hosts can delete their plan including feedback and photo. Guests can withdraw their own feedback. Plans expire after at least 180 days or, for later dates, 60 days after the scheduled date; the term for installation or renewal is at most 730 days. The specific expiration date is in the processing area. Expired content is no longer accessible and is regularly deleted. A separately submitted business request will be preserved in accordance with the above rules for requests.

Personal coupon gift link

When designing a digital envelope voluntarily, we store the recipient name and the personal message for the existing voucher. Via the separate gift link, this information as well as product, value, remaining credit and validity of the voucher are available. Order access, contact details of the buyer and payment information are not displayed. The buyer can deactivate the gift link; the underlying voucher remains in place.

Technical service providers and international processing

For website delivery, central administration data and files, we use Cloudflare (Cloudflare, Inc., USA). The restaurant reservation database and parts of the team registration are made via Supabase (Supabase Pte). Ltd.) provided. E-mail communication takes place via the set up STRATO mailboxes (STRATO GmbH, Germany). Recipients within our company are only employees who need the information for their respective task.

Cloudflare and Supabase may also process data outside the European Economic Area. Information about their contractual data protection conditions and planned transmission guarantees can be found at Cloudflares and supabase. Provides information about the mail service STRATO Ready.

Flea market registration for exhibitors

For the organization of the flea market on 18. October 2026 we process name, e-mail address, offered goods, required stand width, processing status and our feedback. A phone number is voluntary. We need the e-mail address for confirmation of receipt and acceptance or cancellation; without the necessary information, online registration is not possible. The legal basis is the processing of the stand request or the implementation of the stand agreement according to Art. 6 Abs. 1 lit. b DSGVO. The confirmation of the standing conditions is not consent in advertising.

The information is stored in our Cloudflare database and is only accessible for management and administration. Emails are sent via the restaurant mailbox and documented in the internal mailbox. To limit abuse, we use a daily changing identifier derived from the IP address; the raw IP address is not stored in the login table. Technical protection against misuse takes place in accordance with Art. 6 Abs. 1 lit. f DSGVO. There is no passing on of exhibitor contacts to other exhibitors, no public publication of the list and no automated stand commitment.

The registration data is required for the organization and follow-up of the event. Thereafter, no longer necessary contact data, free texts and communication copies are to be deleted; documents that are to be kept as business or tax documents are retained for specific purposes according to the statutory deadlines. Information, correction or deletion can be provided under hallo@schmiedehafen.de requests. Please do not submit health data or other particularly sensitive information about the goods field.

Voluntary communication via WhatsApp

A WhatsApp link on the website only opens the service after your click. When a message is sent to our business WhatsApp number, we process the phone number, display name, message content and delivery information to process the request. The communication is handled via the WhatsApp Business Platform of Meta or WhatsApp and with our central administration. Provider information: WhatsApp data protection. Processing outside the European Economic Area is possible. You can alternatively reach us by e-mail or telephone.

If the digital assistant is activated, shortened message texts and a limited conversation history can be processed via Cloudflare Workers AI to formulate non-binding answers. The system makes no binding booking, payment or standing decisions. Please do not submit any health data or other particularly sensitive information via WhatsApp. The processing of contractual inquiries is based on Art. 6 para 1 lit. b GDPR; general communication and protection against abuse on Art. 6 para 1 lit. f GDPR.

Access, rectification and deletion

To exercise your rights, you can contact the above-mentioned contact address of the controllers. We check the authorization for the request and answer it in principle within one month; in the case of a legally permissible extension, we will inform you in good time. Legally preserved documents remain stored for this purpose and are no longer used for advertising. You can object to a processing according to Art. 6 Abs. 1 lit. f DSGVO for reasons of your special situation. Consent to voluntary publications can be revoked at any time with effect for the future. You can go to the Thuringian State Commissioner for Data Protection and Freedom of Information Complaint.