Last updated: September 17, 2025
1. Introduction to Your GDPR Rights
As a personal data subject, you have fundamental rights guaranteed by the General Data Protection Regulation (GDPR) of the European Union and Spanish data protection legislation.\n\nEnigma Cocina Con Alma is committed to facilitating the exercise of these rights in a transparent, free and efficient manner. This document explains in detail each of your rights and how you can exercise them.\n\nALL RIGHTS ARE FREE except in cases of manifestly unfounded or excessive requests. We respond to all requests within a maximum period of 30 days (extendable to 60 days in complex cases).\n\nTo exercise any right, contact us at: reservas@enigmaconalma.com indicating in the subject GDPR - [Type of right]
2. Right of Access (Art. 15 GDPR)
DESCRIPTION OF THE RIGHT\nYou have the right to obtain free information about what personal data we process, how we use it, with whom we share it and for how long we keep it.\n\nINFORMATION WE PROVIDE\nWhen you exercise this right, we will provide you with:\n• Copy of all your personal data that we process\n• Purposes of processing for each category of data\n• Categories of recipients who may access your data\n• Retention period or criteria to determine it\n• Information about your other GDPR rights\n• Source of data if we did not obtain it directly from you\n• Existence of automated decisions or profiling\n\nHOW TO EXERCISE THIS RIGHT\n1. Send email to: reservas@enigmaconalma.com\n2. Subject: GDPR - Right of Access\n3. Include: Full name, email, contact phone\n4. Attach copy of identity document\n5. Specify what specific information you want to know\n\nRESPONSE TIME\n• Response: Maximum 30 days from request\n• Complex cases: Up to 60 days (with prior notification)\n• Format: Secure PDF sent to your verified email
3. Right of Rectification (Art. 16 GDPR)
DESCRIPTION OF THE RIGHT\nYou have the right to obtain rectification of inaccurate personal data and to complete incomplete data, including by means of additional statement.\n\nWHEN TO APPLY THIS RIGHT\n• Your contact details have changed\n• You detect errors in your personal information\n• Your food preferences or allergies have changed\n• Incorrect billing information\n• Any data that does not reflect your current situation\n\nRECTIFICATION PROCESS\n1. Clearly identify what data is incorrect\n2. Provide the correct information\n3. Attach supporting documentation if necessary\n4. We send confirmation of changes made\n5. We notify third parties if we shared that data\n\nHOW TO EXERCISE THIS RIGHT\n• Email: reservas@enigmaconalma.com\n• Subject: GDPR - Data Rectification\n• Include: Current incorrect data and correct data\n• Justification: Documents supporting the changes\n• Identification: Copy of identity document\n\nEFFECTS OF RECTIFICATION\n• Immediate update in our systems\n• Notification to third parties who processed incorrect data\n• Written confirmation of changes made\n• No cost to you except for unfounded requests
4. Right of Erasure Right to be Forgotten (Art. 17 GDPR)
DESCRIPTION OF THE RIGHT\nYou have the right to obtain erasure of your personal data when any of the circumstances provided for in the GDPR occur.\n\nWHEN YOU CAN EXERCISE THIS RIGHT\n• The data is no longer necessary for the original purpose\n• You withdraw your consent and there is no other legal basis\n• Your data has been processed unlawfully\n• Erasure is necessary to comply with a legal obligation\n• Data was obtained in relation to digital services to minors\n\nLIMITATIONS OF THE RIGHT TO BE FORGOTTEN\nWe CANNOT erase data when necessary for:\n• Exercise the right to freedom of expression and information\n• Comply with legal obligations (invoices: 6 years)\n• Public interest in public health\n• Archiving, scientific research or statistical purposes\n• Exercise or defend claims\n\nERASURE PROCESS\n1. We evaluate the appropriateness of your request\n2. We verify applicable legal limitations\n3. We proceed to secure technical erasure\n4. We notify third parties who processed the data\n5. We confirm complete erasure\n\nHOW TO EXERCISE THIS RIGHT\n• Email: reservas@enigmaconalma.com\n• Subject: GDPR - Right to be Forgotten\n• Justification: Reason why you request erasure\n• Scope: Specify what data you want to delete\n• Identification: Identity document for verification
5. Right to Restriction of Processing (Art. 18 GDPR)
DESCRIPTION OF THE RIGHT\nYou have the right to obtain restriction of processing when certain circumstances occur. This means we keep your data but do not process it.\n\nWHEN YOU CAN REQUEST RESTRICTION\n• You contest data accuracy (during verification)\n• Processing is unlawful but you prefer restriction to erasure\n• We no longer need the data but you require it for claims\n• You have exercised right of objection (while we verify prevalence)\n\nEFFECTS OF RESTRICTION\nDuring restriction:\n• Your data is preserved but not processed\n• Only processed with your consent\n• To exercise or defend claims\n• To protect rights of third parties\n• For reasons of important public interest\n\nRESTRICTION PROCESS\n1. We evaluate the appropriateness of your request\n2. We mark your data as restricted in systems\n3. We restrict access only to authorized personnel\n4. We notify you before lifting the restriction\n5. We maintain record of applied restriction\n\nHOW TO EXERCISE THIS RIGHT\n• Email: reservas@enigmaconalma.com\n• Subject: GDPR - Processing Restriction\n• Reason: Circumstance justifying restriction\n• Scope: What specific data you want to restrict\n• Duration: If temporary, indicate estimated duration\n\nEND OF RESTRICTION\n• We will notify you before resuming processing\n• You can request lifting at any time\n• Automatically lifted when resolving the original cause
6. Right to Data Portability (Art. 20 GDPR)
DESCRIPTION OF THE RIGHT\nYou have the right to receive your data in structured, commonly used and machine-readable format, and to transmit it to another controller when technically possible.\n\nREQUIREMENTS TO EXERCISE THIS RIGHT\n• Processing is based on consent or contract\n• Processing is carried out by automated means\n• Does not adversely affect rights of third parties\n\nDATA INCLUDED IN PORTABILITY\nWe can provide in portable format:\n• Profile and contact data\n• Reservation history and preferences\n• Allergy and dietary restriction information\n• Communications and correspondence (emails)\n• Billing and transaction data\n\nAVAILABLE FORMATS\nWe provide data in:\n• JSON (standard structured format)\n• CSV (for spreadsheets)\n• XML (exchange with other systems)\n• PDF (for human review)\n\nDIRECT TRANSMISSION\nWhen technically possible, we can directly transmit your data to:\n• Other restaurants or gastronomic platforms\n• Customer management systems\n• Personal management applications\n\nHOW TO EXERCISE THIS RIGHT\n• Email: reservas@enigmaconalma.com\n• Subject: GDPR - Data Portability\n• Format: Specify preferred format\n• Destination: If you want direct transmission, indicate recipient\n• Verification: Identity document
7. Right to Object (Art. 21 GDPR)
DESCRIPTION OF THE RIGHT\nYou have the right to object to processing of your data for reasons related to your particular situation, or when processing is for direct marketing purposes.\n\nTYPES OF OBJECTION\n\nGENERAL OBJECTION\n• For reasons related to your particular situation\n• When processing is based on legitimate interest\n• We must demonstrate compelling legitimate interests\n• Applies unless our legitimate interests prevail\n\nOBJECTION TO DIRECT MARKETING\n• Absolute right without required justification\n• Includes profiling for marketing\n• Immediate effect after request\n• No exceptions or limitations\n\nHOW TO EXERCISE OBJECTION\nFor general objection:\n• Email: reservas@enigmaconalma.com\n• Subject: GDPR - Processing Objection\n• Justification: Specific reasons for your situation\n• Scope: Specific processing you object to\n\nFor marketing objection:\n• Email: reservas@enigmaconalma.com\n• Subject: GDPR - Marketing Objection\n• Unsubscribe links in commercial emails\n• Account settings on website\n\nEFFECTS OF OBJECTION\n• Immediate cessation of objected processing\n• Maintenance only if we demonstrate legitimate interests\n• Written confirmation of processing your objection\n• Update of communication preferences
8. Rights on Automated Decisions and Profiling (Art. 22 GDPR)
DESCRIPTION OF THE RIGHT\nYou have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or significantly affects you.\n\nAUTOMATED DECISIONS AT ENIGMA\nWe currently DO NOT use:\n• Fully automated decision systems\n• Algorithms that significantly affect customers\n• Profiling for important decisions\n• AI to reject reservations or services\n\nLIMITED USE OF AUTOMATION\nWe do use basic automation for:\n• Automatic reservation confirmation by email\n• Upcoming reservation reminders\n• Aggregated and anonymous statistical analysis\n• Security and fraud prevention systems\n\nYOUR RIGHTS IN CASE OF AUTOMATION\nIf we implemented automated decisions, you would have the right to:\n• Obtain human intervention\n• Express your point of view\n• Contest the decision\n• Obtain explanation of applied logic\n\nADDITIONAL GUARANTEES\nIn case of implementing automation:\n• Mandatory human review for important decisions\n• Complete transparency about criteria used\n• Possibility to request manual reconsideration\n• Regular audits of algorithms\n\nHOW TO EXERCISE THIS RIGHT\n• Email: reservas@enigmaconalma.com\n• Subject: GDPR - Automated Decisions\n• Description: Specific decision you consider automated\n• Request: Human review or logic explanation
9. Procedure to Exercise Your Rights
REQUIRED INFORMATION FOR ALL REQUESTS\n\nMANDATORY DATA:\n• Full name\n• Contact email\n• Phone number\n• Scanned copy of identity document (DNI/NIE/Passport)\n• Clear description of right you want to exercise\n• Specific justification when required\n\nIDENTITY VERIFICATION\nTo protect your data, we verify your identity through:\n• Official identity document\n• Email verification (we send confirmation code)\n• Additional data only you would know\n• In doubtful cases: phone verification\n\nCONTACT CHANNELS\n\nPRIMARY: Email\n• Address: reservas@enigmaconalma.com\n• Subject: GDPR - [Type of right]\n• Guaranteed response within 72 hours\n\nSECONDARY: Postal mail\n• Address: Enigma Cocina Con Alma\n Carrer Justicia 6A\n 03710 Calpe, Alicante, Spain\n• Mark envelope: CONFIDENTIAL - GDPR\n\nTERTIARY: In person\n• Schedule: During restaurant hours\n• Request prior appointment by phone\n• Bring original identity document\n\nRESPONSE TIMES\n• Acknowledgment: 72 hours\n• Complete response: 30 days (maximum 60 days complex cases)\n• Urgent requests: 5 business days\n• Delay notification: Within 30 days if we need more time
© 2025 Enigma Cocina Con Alma. Document version 1.0.0 effective from September 17, 2025.