Privacy policy
1. Controller
The controller responsible for processing personal data on this website is:
Maurice Noltin
Bei.Mo Streetfood Catering
Ennepestraße 24
44807 Bochum
Germany
Email: info@beimostreetfood.de
2. Hosting by ALL-INKL.COM
This website is hosted by ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. When the website is accessed, the hosting provider processes technically necessary connection and log data, in particular the IP address, time of access, requested file, access status, data volume transferred, referrer and information about browser and operating system.
Processing is carried out to provide the website securely and reliably on the basis of Art. 6(1)(f) GDPR. ALL-INKL.COM acts as a processor pursuant to Art. 28 GDPR. According to the provider, its data centres are located in Germany.
3. Contact form and catering enquiries
When you contact us using the enquiry form, we process the information you enter. This may include your name, email address, telephone number, requested event date and time, type of occasion, approximate number of guests, event location/postcode, menu preference, budget range, dietary requirements, allergies or intolerances, special wishes, further message and information about how you heard about us. Required fields are marked accordingly.
Processing is carried out to handle your enquiry. Where the enquiry relates to entering into or performing a catering contract, Art. 6(1)(b) GDPR is the legal basis. For other enquiries, processing is based on Art. 6(1)(f) GDPR, our legitimate interest being to process and respond to incoming enquiries.
The form data is sent by email to the mailbox used by Bei.Mo Streetfood. The current website does not provide for additional storage of the enquiry content in a website database. Enquiries are deleted once the relevant matter has been completed unless statutory retention obligations or legitimate interests require longer storage.
4. Protection of the contact form against abuse
Technical security measures are used to protect the contact form against automated spam and misuse. These include CSRF protection, a hidden bot field (honeypot), a minimum completion time and rate limiting. Technical connection data, in particular the IP address and timestamps of form requests/submissions, may be processed for this purpose. For rate limiting, the IP address is not stored in plain text but pseudonymised using a server-side random value.
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to protect the website, communication channels and IT systems against spam and misuse.
5. Local fonts, images and technical resources
Fonts, images, stylesheets and scripts are served locally from our own web space, apart from Cloudflare Turnstile if enabled. Loading these local resources does not establish a connection to external font or content providers.
6. Cookies and similar technologies
This website does not use cookies for advertising, analytics or tracking and does not create user profiles. When the contact form is used, a technically necessary session cookie named BIMOSESSID may be set. It is used only to secure the form, particularly for CSRF protection and one-time form tickets, and is a session cookie without a permanent lifetime.
Under the current technical setup, no other consent-requiring cookies or comparable tracking technologies are used.
7. Recipients
Personal data is generally received only by those parties that need it to process the respective matter. ALL-INKL.COM may have access as the hosting processor.
8. Retention
We retain personal data only for as long as necessary for the relevant purpose or as required by statutory retention obligations. Server logs and technical security data are processed only for periods necessary for system security.
9. Your rights
Subject to the statutory requirements, you have rights including access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Where processing is based on consent, consent can be withdrawn at any time with effect for the future.
10. Right to complain
You also have the right to lodge a complaint with a data-protection supervisory authority. The supervisory authority for a controller based in North Rhine-Westphalia is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
11. Security
We use appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. The website is delivered via HTTPS and additionally uses security headers, a restrictive Content Security Policy and server-side input validation.
12. Updates
This privacy policy will be updated if website functions, service providers or legal requirements change.
