Amida Group
Home
Weddings
Private Events
MICE
Catering
Venues
Wedding Planner
Contact
English
Spanish
English
Amida Group
Home
Home
Weddings
Private Events
MICE
Catering
Wedding Planner
Venues
Contact
Spanish
English

Privacy Policy

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD), Grupo Amida Restaurantes 2025, S.L. hereby informs users about the processing of their personal data.

1. Data Controller

Registered name: Grupo Amida Restaurantes 2025, S.L.
‍Tax ID: B75868265
‍Registered address: Carrer Gremi de Cirurgians i Barbers, 25, A.3.2, 07009 Palma de Mallorca (Balearic Islands), Spain
‍Companies Register: Registered with the Companies Register of the Balearic Islands (Palma de Mallorca) — registration details pending update
‍
Email: legal@grupoamida.com
‍Data Protection Officer: Grupo Amida Restaurantes 2025, S.L. has not appointed a Data Protection Officer (DPO). Data protection queries or requests are handled by the administration department via legal@grupoamida.com.

2. Scope of Application

This policy applies to the processing of personal data carried out through the websites and digital channels of the establishments operated by Grupo Amida Restaurantes 2025, S.L.:

  • BàrBar (barbarmallorca.com) — Palma de Mallorca
  • La Bodeguilla (la-bodeguilla.com) — Palma de Mallorca
  • Periplo Portixol (periploportixol.com) — Palma de Mallorca
  • Bar Nicolás (barnicolas.com) — Palma de Mallorca
  • Room Service (room.grupoamida.com) — Palma de Mallorca
  • Nura (nuramallorca.com) — Palma de Mallorca

Catering, wedding planning and estate management services are provided by AMIDA EVENTS S.L. (B57145898), a legally independent entity with its own privacy policy available at grupoamida.com/es/terms/politica-de-privacidad

3. Purposes of Processing

3.1. Technical website management

Purpose: To ensure the correct technical operation, security and accessibility of the websites.
‍Data processed: Identifying and technical data (IP address, browser type, device, pages visited).
‍Legal basis: Legitimate interest of the controller (Art. 6(1)(f) GDPR).
‍Retention period: The time strictly necessary for the active session, or up to 24 months for aggregated technical analytics data.

3.2. Reservation management

Purpose: To manage table reservations received through the web forms and the booking platform integrated into the websites.
‍Data processed: First name, surname, email address, phone number, desired date and time, number of diners, selected restaurant, and any observations or special requests.
‍Legal basis: Performance of pre-contractual measures at the data subject's request (Art. 6(1)(b) GDPR).
‍Retention period: Up to 24 months from the date of the reservation, unless an earlier erasure request is submitted.
‍Tool: Cover Manager — restaurant reservation management platform.

3.3. Health data: allergens and food intolerances

Purpose: To record and manage the dietary restrictions, allergies and food intolerances reported by diners in order to ensure food safety during service, in accordance with Regulation (EU) No 1169/2011 on food information.
‍Data processed: Food allergies, intolerances and dietary restrictions.
‍Data category: Health data — special category subject to enhanced protection (Art. 9 GDPR).
‍Legal basis: Explicit consent of the data subject (Art. 9(2)(a) GDPR). In emergencies affecting a diner's physical safety, protection of vital interests (Art. 9(2)(c) GDPR).
‍Retention period: For the duration of the service and up to 12 months after the visit date, for food-safety liability purposes. After this period, the data will be deleted.
‍Tool: Cover Manager and direct communication with the restaurant team.
‍
‍Note: Providing this data is voluntary but necessary to ensure diners' food safety. Grupo Amida Restaurantes 2025, S.L. applies enhanced technical and organisational measures to the processing of this data category.

3.4. Operational communications with customers

Purpose: To manage communications relating to active reservations, confirmations, changes, and any incidents arising during service.
‍Data processed: Name, email address, phone number, reservation details.
‍Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
‍Retention period: For the duration of the service relationship and up to 24 months from the last interaction.

3.5. Web analytics and online advertising

Purpose: To analyse user behaviour on the websites in order to improve the browsing experience and measure advertising campaign performance through conversion-event tracking.
‍Data processed: Website behaviour data, traffic source, device type, approximate geographic location, and conversion events (without direct personal identification for advertising purposes).
‍Legal basis: User consent given through acceptance of analytics or marketing cookies in the consent panel (Art. 6(1)(a) GDPR).
‍Retention period: Up to 14 months for analytics data (Google Analytics); up to 24 months for advertising data (Google Ads).
‍Tools: Google Analytics 4, Google Ads, Meta Pixel, Google Tag Manager (individual containers per establishment).

3.6. Video surveillance (CCTV)

Purpose: To ensure the safety of people, property and premises at the establishments of Grupo Amida Restaurantes 2025, S.L.
‍Data processed: Images of individuals captured in monitored areas.
‍Premises: All restaurant establishments operated by Grupo Amida Restaurantes 2025, S.L.
‍Legal basis: Legitimate interest of the controller (Art. 6(1)(f) GDPR) and Art. 22 LOPDGDD.
‍Retention period: A maximum of 30 days from capture (Art. 22(3) LOPDGDD), unless the footage is needed as evidence of unlawful acts, in which case it will be kept until the proceedings are resolved.
‍Additional information: Monitored areas are marked with the legally required information pictogram. Footage is not disclosed to third parties except at the request of the competent authorities.

3.7. Shared administrative services

Purpose: To manage the group's administrative, accounting and invoicing functions, provided internally by Balikan Family 2025, S.L. (B75868257), the group's parent company, acting as intra-group processor under Art. 28 GDPR.
‍Data processed: Identifying data of customers and suppliers, transaction data, accounting and tax data.
‍Legal basis: Performance of a contract (Art. 6(1)(b) GDPR); legal obligations in tax and commercial matters (Art. 6(1)(c) GDPR).
‍Retention period: Tax and accounting records: 10 years (Art. 30 Spanish Commercial Code; Art. 70 General Tax Law).

3.8. Compliance with legal obligations

Purpose: To comply with applicable legal obligations in tax, labour, commercial and health matters.
‍Data processed: Identifying and financial data necessary for regulatory compliance.
‍Legal basis: Compliance with a legal obligation (Art. 6(1)(c) GDPR).
‍Retention period: As established by the applicable regulations in each case.

3.9. Direct marketing communications (Newsletter and SMS)

Purpose: To send commercial communications by email (newsletter) and SMS about restaurant news, offers and promotions.
‍Data processed: Name, email address and phone number provided by the user when making a reservation, as well as interaction data with the communications sent (opens and clicks) collected by the sending tool itself.
‍Legal basis: Explicit consent of the data subject (Art. 6(1)(a) GDPR), given through a specific, non-pre-ticked checkbox on the reservation form (e.g., "I consent to receiving commercial communications from the restaurant by email and/or SMS"). This consent is separate from, and additional to, the processing described in section 3.2: managing the reservation and guaranteeing the table are based on the performance of pre-contractual measures (Art. 6(1)(b) GDPR) and do not depend on this checkbox. If the user does not tick it, their reservation data continues to be processed as normal under section 3.2, but they will not receive commercial communications.
‍Tool: Sendinblue SAS (Brevo) — CRM and marketing platform connected via API to Cover Manager. When this consent is given at the time of booking, the data is automatically transmitted from Cover Manager to Brevo.
‍Retention period: Until the user withdraws consent or unsubscribes. Grupo Amida Restaurantes 2025, S.L. may periodically clean up inactive contacts in accordance with data-minimisation criteria.
‍Unsubscribing: At any time, via the unsubscribe link included in each communication or by writing to legal@grupoamida.com. Unsubscribing does not affect operational communications relating to an active reservation (section 3.4).

3.10. In-store card payment (Card Terminal)

Purpose: To process payment by bank card on the premises as a means of payment for the service provided.
‍Data processed: Payment card data, processed on an encrypted basis between the card terminal and the relevant financial institution, plus the transaction amount and date. Grupo Amida Restaurantes 2025, S.L. does not access or store the full card number.
‍Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
‍Retention period: The transaction receipt is kept in accordance with accounting and tax regulations (section 3.7). Card data itself is managed and retained by the financial institution under its own applicable rules (PCI-DSS and banking regulations).
‍Tool: Card terminals provided by Banca March, Banco Sabadell and Revolut.

4. Data Processors

The data collected may be processed by the following providers acting as data processors, pursuant to Art. 28 GDPR:

  • Webflow, Inc. — Website development and hosting platform — USA
  • Cloudflare, Inc. — Content delivery network and perimeter security — USA
  • Cover Manager — Restaurant reservation management — Spain (EU)
  • Sendinblue SAS (Brevo) — CRM platform and commercial communications (newsletter and SMS) — France (EU)
  • Agora TPV — Restaurant management and point-of-sale system (orders, dishes ordered, and supplier management: delivery notes, invoices and purchase orders) — Spain (EU). It does not currently link tickets to a diner's identity or process customers' personal data.
  • Banca March, Banco Sabadell and Revolut — Card terminal providers — Spain / EU. Card data is processed on an encrypted basis directly between the terminal and the financial institution; these entities may act as independent controllers with respect to their own regulatory obligations regarding payments, fraud prevention and anti-money laundering.
  • Google LLC (Google Workspace) — Productivity suite and corporate email — USA
  • Google LLC (Google Analytics 4) — Website traffic analytics — USA
  • Google LLC (Google Business Profile) — Business listing, review and search/maps presence management — USA
  • Google LLC (Google Maps) — Geolocation and display of locations on the website — USA
  • Google LLC (Google Tag Manager) — Tag and tracking script management — USA
  • Google LLC (Google Ads) — Advertising management and conversion tracking — USA
  • Meta Platforms Ireland Ltd. — Meta Pixel — website behaviour tracking — Ireland (EU)
  • Balikan Family 2025, S.L. — Shared intra-group administrative and accounting services — Spain (EU)

All processors have signed the corresponding data processing agreement pursuant to Art. 28 GDPR and apply security measures appropriate to the risk involved.

Grupo Amida Restaurantes 2025, S.L. does not sell or share personal data with third parties for those third parties' own commercial purposes. Access by the processors listed is strictly limited to providing the contracted service.

5. International Data Transfers

Several data processors are based in the United States. Transfers are carried out with the safeguards required by Art. 46 GDPR:

Google LLC and Meta Platforms Ireland Ltd.: transfers covered by the EU-U.S. Data Privacy Framework, adopted by European Commission Adequacy Decision of 10 July 2023 (Decision 2023/1795/EU).
Webflow, Inc. and Cloudflare, Inc.
: transfers carried out under the Standard Contractual Clauses (SCCs) adopted by the European Commission.
Sendinblue SAS (Brevo)
: as a processor established in, and hosting data in, France (European Union), this processing does not require the additional international-transfer safeguards under Chapter V GDPR.

6. Data Subject Rights

Data subjects may exercise the following rights recognised under the GDPR and the LOPDGDD:

  • Access (Art. 15): to obtain confirmation of the data processed and to access it.
  • Rectification (Art. 16): to request correction of inaccurate or incomplete data.
  • Erasure (Art. 17): to request deletion of data once it is no longer necessary or consent is withdrawn.
  • Restriction (Art. 18): to request restriction of processing in the circumstances provided by law.
  • Portability (Art. 20): to receive data in a structured, machine-readable format.
  • Objection (Art. 21): to object to processing based on the controller's legitimate interest.
  • Withdrawal of consent: at any time, with no retroactive effect.
  • Rights of deceased persons (Art. 3 LOPDGDD): persons connected to the deceased by family ties or de facto relationships, as well as their heirs, may contact the controller to request access to, and, where applicable, rectification or erasure of, the deceased's personal data, unless the deceased expressly prohibited this or the law provides otherwise.

Grupo Amida Restaurantes 2025, S.L. does not carry out automated decision-making, including profiling, that produces legal effects on the data subject or similarly significantly affects them.

Exercising your rights:

Email: legal@grupoamida.com
Postal address: Grupo Amida Restaurantes 2025, S.L., Carrer Gremi de Cirurgians i Barbers, 25, A.3.2, 07009 Palma de Mallorca

The request must include the requester's full name, a copy of their national ID or equivalent document, and a specific description of the request. The response period is one month, extendable by up to two further months in cases of particular complexity.

If a data subject believes their rights have been infringed, they may file a complaint with the Spanish Data Protection Agency (AEPD) — www.aepd.es

7. Data Security

Grupo Amida Restaurantes 2025, S.L. applies appropriate technical and organisational measures pursuant to Art. 32 GDPR, including encryption of communications, role-based access control, robust authentication, and incident-management procedures.

In the event of a security breach likely to affect data subjects' rights, the AEPD will be notified within a maximum of 72 hours of becoming aware of it (Art. 33 GDPR).

8. Minors

The services of Grupo Amida Restaurantes 2025, S.L. are not directed at persons under 14 years of age. Should the data of minors be found to have been collected without the consent of their legal representative, it will be deleted immediately.

9. Amendments

Grupo Amida Restaurantes 2025, S.L. may update this policy in response to regulatory or technical changes. The update date appears at the beginning of the document.

Last updated: 13 July 2026

Contact Us ↗
Carrer Gremi de Cirurgians i Barbers, 25,
A.3.2, 07009 - Balearic Islands
Ca Na Melis Street, 17
07007 - Illes Balears, Spain
What We Do
WeddingsPrivate EventsMICE
How We Do
CateringVenuesWedding Planner
Our Restaurants
BàrBarLa BodeguillaPeriplo PortixolBar NicolasNuraRoom Service
Social
InstagramFacebookLinkedInPinterest
Terms
Legal NoticePrivacy PolicyCookie Policy
Service TermsCatering Extras
© 2001–2026 Grupo Amida™. All rights reserved.

We use cookies to improve navigation and analyze site usage. You can manage your consent or see more details in our Privacy Policy.

RefuseAccept
Preferences
Privacy Preference Center
When you visit websites, they may store or retrieve data in your browser. This storage is often necessary for the basic functionality of the website. The storage may be used for marketing, analytics, and personalization of the site, such as storing your preferences. Privacy is important to us, so you have the option of disabling certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may impact your experience on the website.
Allow all cookiesReject all cookies
Manage Consent Preferences by Category
Essential
Always Active
These items are required to enable basic website functionality.
Marketing
These items are used to deliver advertising that is more relevant to you and your interests. They may also be used to limit the number of times you see an advertisement and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the website operator's permission.
Personalization
These items allow the website to remember choices you make (such as your user name, language, or the region you are in) and provide enhanced, more personal features. For example, a website may provide you with local weather reports or traffic news by storing data about your current location.
Analytics
These items help the website operator understand how its website performs, how visitors interact with the site, and whether there may be technical issues. This storage type usually doesn't collect information that identifies a visitor.
Confirm my preferences and close