Skip to content
echtasien

Privacy policy

The following information explains, pursuant to Article 13 GDPR, which personal data we process in connection with this website and the services offered through it. What counts is what is actually used on this website.

Controller within the meaning of the General Data Protection Regulation (GDPR)

Sangai GmbH (trading as "Echtasien"), Blankeneser Landstraße 1, 22587 Hamburg, Germany, represented by its managing director Santosh Kumar Lama. Phone +49 40 53008876 (Winterhude) and +49 40 18011932 (Blankenese), email verwaltung@echtasien.de. We operate the restaurants Echtasien Winterhude (Alsterdorfer Straße 85, 22299 Hamburg) and Echtasien Blankenese (Blankeneser Landstraße 1, 22587 Hamburg).

Please send data protection enquiries to verwaltung@echtasien.de. You may also send them to info@tasteclick.de; Tasteclick receives them on our behalf and forwards them to us without delay.

This website and its reservation, voucher, ordering, enquiry and newsletter functions are provided and operated on our behalf by Tasteclick, owner Julian Mertens, Habichtsplatz 8, 22307 Hamburg, Germany, as a processor (Article 28 GDPR); a data processing agreement is in place. We remain the controller responsible for the processing of your data.

Scope of this policy

This policy covers your visit to this website and the services offered through it: table reservations, voucher purchases, contact and job enquiries, and the newsletter. For each of these we describe below which data we process, why, on which legal basis, who receives it and how long we keep it.

Legal bases

We process personal data on the basis of Article 6(1)(a) GDPR (consent), (b) (contract and pre-contractual measures), (c) (legal obligation) and (f) (legitimate interest; the interest concerned is stated in the relevant section). The storage of information on your device and access to it are additionally governed by § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG).

Hosting and server logs

This website is hosted, delivered and image-optimised by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Server-side functions run, according to our configuration, in the EU region of Frankfurt am Main; delivery takes place via Vercel's globally distributed edge network. Build processes and product-related log data are partly processed by Vercel in regions in the USA.

When you access the website, technically necessary connection data is processed: IP address, date and time, requested addresses and HTTP status, amount of data transferred, the previously visited page, and browser type and operating system. The purposes are the secure and stable provision of the website, protection against misuse and error analysis; the legal basis is Article 6(1)(f) GDPR.

Vercel retains the logs of our server-side functions for 24 hours in the plan we use; they are then deleted automatically. Individual connection data is retained for longer only where necessary to defend against a specific attack or to investigate a fault.

A data processing agreement is in place with Vercel. For transfers to the USA it incorporates the EU Commission's standard contractual clauses (Implementing Decision (EU) 2021/914); Vercel Inc. is also certified under the EU-U.S. Data Privacy Framework.

Database and application backend

The content, master and transaction data of this website, namely page content, reservations, orders, vouchers, enquiries, newsletter sign-ups and our guest directory, are processed in a database of the Supabase service. Our contractual partner is Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Data is stored in a database region within the EU (Ireland); separation from the data of other businesses is enforced at database level.

The images and videos of this website are also stored there. Photographs, however, are not delivered directly from there: our hosting provider Vercel retrieves them from that storage, converts them into a space-saving image format (AVIF or WebP), keeps the converted version in its delivery network for up to one year and delivers it from there to your browser; your IP address is transmitted to Vercel in the process. The purpose is faster display with a smaller volume of data; the legal basis is Article 6(1)(f) GDPR. The provider, the place of processing and the third-country safeguards are set out in the section "Hosting and server logs". Videos and graphics in SVG format continue to be delivered directly from that storage to your browser; your IP address is transmitted to Supabase in the process.

The purpose is the provision and management of the website content and functions; the legal basis is Article 6(1)(f) GDPR and, where necessary for the performance of a contract, Article 6(1)(b). A data processing agreement is in place. Where administrative access from third countries cannot be ruled out, it is based on the EU Commission's standard contractual clauses (Article 46 GDPR); this provider is not certified under the EU-U.S. Data Privacy Framework.

Protection against misuse

To protect our forms and ordering channels against automated submissions, we limit their number per time window. For this purpose we store, for every reservation, order, voucher order, enquiry and newsletter sign-up, a cryptographic hash of your IP address (the IP address itself is not stored) and, on the next submission, count how many transactions with the same hash fall within the time window. We do not keep a separate counter; the hash is stored for as long as the transaction it belongs to. The purpose is the security of our systems; the legal basis is Article 6(1)(f) GDPR.

Error and stability monitoring

To detect and fix technical errors we use the Sentry service of Functional Software, Inc. (d/b/a Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, in its EU region (data centre in Frankfurt am Main). When a technical error occurs, diagnostic data is transmitted: the error message and the technical call stack, the address concerned, the time, and browser and device information.

Before transmission, automatic filtering removes information that could identify a person, in particular access keys, email addresses, IP addresses in the message text, cookies and the query parameters of requested addresses. No deliberate transmission of personal data takes place; that such information may occasionally be included by chance cannot be entirely ruled out technically.

The purposes are error analysis and the stability and security of this website; the legal basis is Article 6(1)(f) GDPR. Error event data is processed in the EU region and deleted after 90 days. A data processing agreement is in place; where administrative access takes place from the USA, the adequacy decision on the EU-U.S. Data Privacy Framework and, in addition, the EU Commission's standard contractual clauses apply.

Error reports from your browser

If a technical error occurs in your browser, for example while displaying a page, an error report is sent directly from your device to Sentry; the provider, data location and retention are the same as in the section "Error and stability monitoring". The data transmitted comprises technical error data (the error message and call stack, the requested address without its query parameters, the time, and browser and device information) and, unavoidably because it is part of every internet connection, your IP address.

We have deliberately limited this function to the minimum: there is no session recording, so your screen is not recorded. Visits are not counted and the loading times of your visit are not transmitted. Your actions before the error are recorded only as a technical position in the page structure (which button, which page), not with what you entered or read.

No information is stored on your device and no information stored there is read. This is therefore not a case under § 25 TDDDG, and no consent is required. The purpose and legal basis correspond to the section "Error and stability monitoring" (Article 6(1)(f) GDPR); here too, the incidental capture of personal information cannot be entirely ruled out technically.

Fonts

The fonts used on this website are served from our own server. No connection to third-party servers is established, in particular no retrieval of Google Fonts via a Google CDN.

Table reservation

When you reserve a table through this website, we process the details you enter in the reservation form: your name, your email address or phone number (at least one of the two), the desired location, date, time and number of guests, and optionally your seating preference, the occasion and a note. Your IP address is processed only as a cryptographic hash for protection against misuse.

We use these details to accept your reservation, assign a table to it, confirm and manage it. Reservations for smaller groups are confirmed automatically; larger groups are reviewed and confirmed personally. You receive a confirmation by email and, if you have provided a phone number, possibly by phone; about 24 hours before the appointment we send a reminder. Via a personal link in these messages you can change or cancel your reservation yourself; this link contains a random identifier and is addressed to no one else. The legal basis is Article 6(1)(b) GDPR (performance of the reservation); for the assignment to our guest directory, Article 6(1)(f) GDPR (orderly management of our guests).

The note field is intended for organisational information such as a high chair or a terrace request. We do not ask you to provide information about your health there; intolerances and allergies are best discussed with our team on site. If you nevertheless voluntarily enter such information, we use it solely to accommodate it during your visit and treat it like the other reservation details.

Your reservation data is linked to your entry in our guest directory (see "Guest directory"); once its contact details are anonymised, only the date, time, number of guests and table remain of the reservation, without any personal reference.

Voucher purchase

When you buy a gift voucher in our voucher shop, we process your name and email address, the chosen amount, design and delivery method, optionally the name of the recipient and a dedication, and, for postal delivery, the delivery address. The purposes are the conclusion and performance of the purchase contract, creation of the voucher as a PDF, its delivery by email or post, management of the remaining balance and redemption; the legal basis is Article 6(1)(b) GDPR. On redemption we process the voucher code, the amount, the remaining balance and the redemption history.

We retain purchase, receipt and payment data for up to ten years under § 147 AO and § 257 HGB (Article 6(1)(c) GDPR). If you request erasure earlier, we anonymise the details identifying you (name, email address, recipient name, dedication, delivery address); the receipt data required for accounting is retained without personal reference. Details of the contract are set out in the voucher terms and conditions and the cancellation policy.

Online payment (Mollie)

Payment in the voucher shop and, where offered, for online orders is handled by the payment service provider Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. When paying, you are redirected to Mollie; there you enter your payment details, which we ourselves neither receive nor store. Mollie processes the data required for the chosen payment method, your IP address and the transaction details (amount, order number) as an independent controller, including to fulfil anti-money-laundering obligations. We receive the payment confirmation and payment status from Mollie. The legal basis is Article 6(1)(b) GDPR. Mollie's privacy policy is available at https://www.mollie.com/en/privacy.

Contact and job enquiries

When you write to us via the contact form, we process your subject, name, email address, optionally your phone number and your message in order to handle your enquiry. Your message is additionally delivered to us by email; the provider of our mailbox processes it as a recipient (see "Email mailbox and domain"). The legal basis is Article 6(1)(b) GDPR where your enquiry is aimed at a contract (for example an event or celebration), otherwise Article 6(1)(f) GDPR (orderly handling of enquiries). We store enquiries until they have been fully dealt with and then delete them in accordance with our deletion concept; statutory retention obligations remain unaffected.

Job applications: via the application form we additionally process the desired position and the desired location. If you attach a CV, this file is not stored in our website database; it is attached solely to the notification email sent to us and afterwards exists only in our email mailbox. The confirmation sent to you contains no attachment. The legal basis is Article 6(1)(b) GDPR in conjunction with § 26(1) of the German Federal Data Protection Act (BDSG), and Article 6(1)(a) GDPR for voluntary additional information. If your application is unsuccessful, we delete the application data no later than six months after the end of the procedure, unless a longer retention period is required by law or you have expressly agreed to longer storage. If you are hired, we transfer the data to the employment relationship.

Newsletter

You can subscribe to our newsletter via the sign-up form on the website or by ticking a box when reserving or buying a voucher. The box is always optional and never pre-ticked; the consent text reads: "Yes, I would like to receive the echtasien newsletter." For this we process your email address and the time of your sign-up in order to send you news and offers. The legal basis is your consent under Article 6(1)(a) GDPR. Sign-up uses the double opt-in procedure: you first receive an email with a confirmation link, and only after your confirmation do we add you to the mailing list.

To prove your consent we store the time of sign-up and confirmation, the version of the consent text, the place of sign-up (form, reservation, voucher, order) and a cryptographic hash of your IP address, never the IP address itself. You can withdraw your consent at any time with effect for the future: via the unsubscribe link at the end of every newsletter email or informally via the contact details above. After withdrawal we process your details only insofar as necessary to prove the earlier consent and to ensure that you are not contacted again. Technical dispatch takes place via the email delivery service named below.

Our newsletter issues contain no tracking pixel and no redirected links; we do not record whether or when you open an issue or click a link. The issue sent is retained together with the technical dispatch data for as long as the associated campaign exists in our system. If delivery is permanently refused or you object to receipt, we additionally store a hash of your address on a suppression list so that you are not contacted again; this list contains no plain-text addresses and remains in place even after your other data has been deleted.

Guest directory

Reservations, orders, voucher purchases and newsletter sign-ups create an entry in our guest directory containing your contact details, the origin of the entry, the time of the last contact and the associated transactions (for example your previous reservations with date, number of guests and notes). The purpose is the orderly management of our guests and the assignment of your transactions; the legal basis is Article 6(1)(f) GDPR and, for sending the newsletter itself, your consent under (a).

An automatic process checks every hour which entries are due and irreversibly anonymises the contact details they contain. An entry without a purchase or order transaction becomes due 90 days after the last recorded contact; an entry with a purchase or order transaction 24 months after the last transaction. Proof of newsletter consent and receipt data that we are obliged to retain remain unaffected.

Unsubscribing from the newsletter ends dispatch but does not by itself delete your entry in the guest directory. If you wish to be deleted before the stated period expires, an informal message to the contact details above suffices; we then anonymise the entry without delay unless a retention obligation prevents this.

Sending emails

For the technical dispatch of our emails (reservation confirmations and reminders, order and voucher confirmations, acknowledgements from the forms, confirmation and newsletter emails) we use Amazon Simple Email Service (SES) of Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, in the Europe (Stockholm) region. Sender and recipient details, dispatch times, subject and message content, and technical delivery data such as delivery status and bounce notifications are processed; the content is passed through for dispatch and not stored there permanently.

The purpose is reliable delivery; the legal basis is Article 6(1)(b) or (f) GDPR. A data processing agreement is in place as part of the provider's service terms; for any transfers to the USA, the adequacy decision on the EU-U.S. Data Privacy Framework and, in addition, the EU Commission's standard contractual clauses apply.

Email mailbox and domain

We receive, store and process incoming messages, form notifications and application documents in our business email mailbox. The purposes are the receipt and handling of business messages; the legal basis is Article 6(1)(f) or (b) GDPR. Data is stored until the matter has been fully dealt with, plus statutory retention periods.

[TO BE COMPLETED: name, address and processing location of the provider hosting the mailbox verwaltung@echtasien.de; sentence on the data processing agreement with this provider.]

Photos of persons

This website may contain images in which persons are recognisable, for example members of our team. The legal basis for such publication is the consent of the person depicted (Article 6(1)(a) GDPR, §§ 22, 23 of the German Art Copyright Act, KUG), and for minors the consent of the persons with parental responsibility; it can be withdrawn at any time with effect for the future without affecting the lawfulness of publication up to that point. If you appear in an image and do not or no longer wish it to be published, an informal message to the contact details above suffices; we will then promptly remove the image from the website.

External maps (Google Maps)

The maps on our location pages are only loaded once you explicitly request them. Before that, no connection to Google is established, which is why no consent banner appears when you access this website. After you give your consent, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, processes in particular your IP address, browser and device information and the previously visited address; processing in the USA cannot be ruled out, and Google sets its own cookies.

The legal basis for loading the map is your consent under § 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. You can withdraw it at any time: for all providers at once via "External content" on this page and in the footer, or for Google only via "Privacy settings" in the footer. For transfers to the USA, Google LLC is certified under the EU-U.S. Data Privacy Framework; in addition, the EU Commission's standard contractual clauses apply. Google's privacy policy is available at https://policies.google.com/privacy. The "Get directions" button is a simple link to Google Maps that opens in a new tab; no data flows before you click it.

How we remember your consent and for how long is explained in the section "External content (videos, maps, booking areas)" at the end of this page. There you can also withdraw a consent you have given directly.

Linked services without embedding

Our Instagram profile is only linked and opens in a new tab. Merely visiting our website transmits no data to Instagram: it is a simple link, not embedded content, and no connection is established before you click. Only when you follow the link do you leave our area of responsibility; from then on the privacy policy of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, applies.

Recipients of personal data

The recipients are the following service providers, insofar as necessary for the respective function. Data processing agreements under Article 28 GDPR are in place with processors.

Tasteclick, owner Julian Mertens (Hamburg, Germany): operation of the website and of the reservation, ordering, voucher, enquiry, newsletter and guest management functions on our behalf; data location EU.

Vercel Inc. (USA): hosting, delivery and image optimisation; data location: server-side functions in the EU region of Frankfurt am Main, delivery worldwide, build processes and logs partly in the USA.

Supabase Pte. Ltd (Singapore): database, application backend and storage of this website's images and videos, as well as their direct delivery where it does not run through Vercel's image optimisation; data location EU (Ireland).

Amazon Web Services EMEA SARL (Luxembourg): email dispatch; data location Sweden (Europe/Stockholm region).

Functional Software, Inc. d/b/a Sentry (USA): error and stability monitoring; data location EU (Frankfurt am Main).

Mollie B.V. (Netherlands): payment processing in the voucher shop and for online payment of orders, as an independent controller; data location EU.

Google Ireland Limited (Ireland): map display, only after your consent; data location worldwide.

In addition, the provider of our business email mailbox, see the section "Email mailbox and domain". For postal delivery of vouchers, the postal service provider we engage receives your delivery address. We pass data on to public authorities only where legally obliged to do so; receipt and payment data is also received by the parties entrusted with our bookkeeping and tax returns.

Transfers to third countries

Where personal data is processed outside the EU and the EEA, this is based on the safeguards of Articles 44 et seq. GDPR: on the adequacy decision on the EU-U.S. Data Privacy Framework (Article 45 GDPR) where the US provider concerned is certified (Vercel, Amazon Web Services, Sentry, Google), and otherwise, in particular for Supabase, on the EU Commission's standard contractual clauses under Implementing Decision (EU) 2021/914 (Article 46(2)(c) GDPR). Where data is processed exclusively within the EU and the EEA, no transfer to a third country takes place.

Cookies and similar technologies

No consent banner appears when you access this website, because no third party is contacted without your consent. For visitors, this website sets only one cookie of its own per provider you have approved, and only once you explicitly approve an external content. It stores solely the day of your approval for exactly that provider, is valid for 180 days and is strictly necessary under § 25(2) no. 2 TDDDG, because without it you would have to decide again on every page view. Details and how to withdraw are given in the section "External content (videos, maps, booking areas)" at the end of this page.

You can withdraw your approvals in two ways: "External content" in the footer and on this page resets all stored approvals with one click. Under "Privacy settings" in the footer you see each provider individually and can switch it off individually; exactly the one associated cookie is then deleted while the others remain. Every change takes effect immediately, without reloading the page.

After approval, Google (maps) additionally sets its own cookies within the embedded frame. When paying, you are redirected to Mollie; on Mollie's page its own notices apply. Beyond this, no cookies, local storage or comparable technologies are used on this website for advertising or tracking purposes; in particular, reach measurement and error monitoring work entirely without access to your device. For both, there is therefore no consent you could withdraw; "Privacy settings" merely explains them and shows no switch for them. Reservation, ordering and voucher purchase work without cookies; the personal link for managing your reservation carries its identifier in the address itself.

A further cookie named "__Host-tc_preview" does not concern guests: it is set only when a person who maintains our website clicks a preview link sent to them in order to review an as yet unpublished draft. It contains only a random string without personal reference, is restricted to this website, becomes invalid after 72 hours at the latest and can be deleted at any time via "End preview"; it is technically necessary (§ 25(2) no. 2 TDDDG), and no third party is involved.

Retention period and deletion

We store personal data only for as long as necessary for the purposes stated or as long as statutory retention obligations exist; the specific periods are given in the respective sections. Tax and commercial retention periods are generally six, eight or ten years (§ 147 AO, § 257 HGB). Once the purpose no longer applies, the data is deleted or anonymised. Upon termination of our cooperation with Tasteclick, the data is returned to us and deleted at the service provider.

Your rights

You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20), the right to object to processing based on Article 6(1)(f) GDPR (Article 21), and the right to withdraw consent at any time with effect for the future (Article 7(3)). To exercise these rights, contact Sangai GmbH, Blankeneser Landstraße 1, 22587 Hamburg, Germany, by email at verwaltung@echtasien.de or at info@tasteclick.de (forwarded to us), or by phone on the numbers above. We respond without undue delay and at the latest within one month. Erasure is carried out by us; no data is deleted through the website alone, for example by unsubscribing from the newsletter or cancelling a reservation.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit), Ludwig-Erhard-Straße 22, 7th floor, 20459 Hamburg, Germany, phone +49 40 428 54-4040, email mailbox@datenschutz.hamburg.de, www.datenschutz-hamburg.de.

Automated decision-making

No automated decision-making with legal effect and no profiling within the meaning of Article 22 GDPR take place. The automatic confirmation of smaller reservations checks only the availability of a table at the desired time and does not evaluate any personal characteristics.

Currency of this privacy policy

We update this privacy policy as soon as the functions used on this website or the legal requirements change. The version available on this page is always the authoritative one. In case of doubt, the German version prevails.

Last updated: September 2026

External content (videos, maps, booking areas)

Third-party external content, such as videos, maps and booking areas, only loads once you explicitly agree in the placeholder shown. If you agree, we store your decision for that specific provider in a small text entry (cookie) on your device, together with the time of your consent. Its sole purpose is to spare you from agreeing again on your next visit. No reach measurement and no profiling take place.

The stored decision is valid for 180 days. After that it expires and the placeholder reappears.

This website shows no consent banner on arrival, because no third party is contacted without your agreement.

You can withdraw your consent at any time using the “External content” item, directly below this paragraph and in the footer of all pages that can embed external content (videos, maps, booking areas). One click resets all stored consents.