A Taste of Japan in Gdańsk

Discover modern Japanese cuisine

Book a table


Privacy Policy


1. General provisions
1.1. This Privacy Policy sets out the rules for processing the personal data of persons using the to.gather restaurant and the website available at togathergdansk.pl.
1.2. The controller of personal data is SECRET COMPANY spółka z ograniczoną odpowiedzialnością (a limited liability company under Polish law), with its registered office at ul. Stępkarska 7/U1, 80-859 Gdańsk, entered into the Register of Entrepreneurs of the National Court Register (Krajowy Rejestr Sądowy) kept by the District Court Gdańsk-Północ in Gdańsk, 7th Commercial Division of the National Court Register, under KRS number 0001147401, Tax Identification Number (NIP) 5833529164, Statistical Number (REGON) 540745816, share capital PLN 5,000 (hereinafter: the "Controller" or "to.gather").
1.3. The Controller may be contacted on matters relating to personal data:
by email: kontakt@togathergdansk.com,
by phone: +48 888 333 770,
in writing at the registered office indicated in section 1.2.
1.4. The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and with Polish data protection law.
1.5. The Controller has not appointed a data protection officer. On all matters relating to data processing, the Controller may be contacted using the details indicated in section 1.3.

2. Definitions
Personal data means information about an identified or identifiable natural person.
Processing means any operation performed on personal data, such as collection, storage, use or erasure.
Processor means an entity that processes personal data on behalf of the Controller.
Guest means a person using the services of to.gather or the website.

3. Purposes, legal bases and scope of processing
3.1. Table reservation
In the reservation process, the Controller processes: first name, phone number, email address (if provided), the date and time of the visit, the number of guests, and the content of any remarks provided by the Guest.
Purpose: accepting and handling the reservation and contacting the Guest regarding the reservation. Legal basis: Article 6(1)(b) GDPR (activities necessary to perform the contract or to take steps prior to entering into it) and Article 6(1)(f) GDPR (legitimate interest consisting in confirming and organizing visits).
If, in the remarks field, the Guest voluntarily provides information about food allergies or dietary requirements that may constitute data concerning health, such data is processed solely for the proper performance of the reservation, on the basis of consent expressed by providing it (Article 9(2)(a) GDPR). Providing such information is voluntary.
3.2. Prepayments, deposits and settlements
For reservations with a pre-order of dishes or drinks, as well as reservations of larger groups on specified dates, the Controller collects a deposit. In connection with this, it processes the data necessary to settle the payment and issue accounting documents.
Purpose: performing the reservation with a deposit, settling amounts due, and fulfilling tax and accounting obligations. Legal basis: Article 6(1)(b) GDPR (performance of the contract) and Article 6(1)(c) GDPR (legal obligations of the Controller, including those arising from tax and accounting regulations).
3.3. Vouchers and gift cards
When a voucher is purchased, the Controller processes the data necessary to issue, redeem and settle it. Purpose: sale and redemption of the voucher. Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR with respect to accounting obligations.
3.4. Organization of events and private reservations
For inquiries regarding the organization of events, room reservations or hire of the entire venue, the Controller processes contact data and information necessary to prepare and carry out the event. Purpose: handling the inquiry and organizing and carrying out the event. Legal basis: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR (legitimate interest consisting in handling inquiries).
3.5. Complaints
Complaints may be submitted by email to kontakt@togathergdansk.com. When handling a complaint, the Controller processes contact data and information relating to the report. Purpose: examining the complaint. Legal basis: Article 6(1)(b) and (c) GDPR and, with respect to defense against potential claims, Article 6(1)(f) GDPR.
3.6. Contact by phone and email
When contacting to.gather, the Controller processes the data provided by the Guest, such as first name, phone number, email address and the content of the message. Purpose: responding to and handling the matter. Legal basis: Article 6(1)(f) GDPR (legitimate interest consisting in conducting correspondence and handling inquiries).
3.7. Video monitoring (CCTV)
Video monitoring is carried out on the premises of to.gather. Purpose: ensuring the safety of persons and property and establishing, pursuing or defending claims. Legal basis: Article 6(1)(f) GDPR (legitimate interest of the Controller). Scope: the image of persons present in the monitored area. Recordings are stored for 30 days and then deleted or overwritten, unless a recording constitutes evidence in proceedings or the Controller has become aware that it may constitute such evidence. The monitored area is marked with appropriate information.
3.8. Use of the website
During the use of the togathergdansk.pl website, technical data is processed, such as the IP address, browser and device data, data on how the website is used, and information stored in cookies and similar technologies. Details of cookies and tools are described in section 11.
Purpose: ensuring the correct and secure operation of the website, carrying out statistics and analytics, and marketing activities, including remarketing. Legal basis: Article 6(1)(f) GDPR (legitimate interest consisting in ensuring the operation, security and continuity of the website) with respect to necessary files, and Article 6(1)(a) GDPR (consent) with respect to statistical, analytical and marketing cookies.
3.9. Guest Wi-Fi
An open Wi-Fi network is available on the premises. Connecting to it does not require registration or the provision of personal data.
3.10. Marketing
The Controller may carry out marketing activities, including sending information about its offer and events, solely on the basis of separately given consent. Purpose: providing marketing information. Legal basis: Article 6(1)(a) GDPR (consent) and, with respect to electronic communication, the consent required by the provisions on the provision of electronic services and by telecommunications law. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before its withdrawal.
3.11. Social media profiles
The Controller maintains profiles on Facebook and Instagram. In connection with maintaining them, it processes the data of persons who interact with the profiles, including those who follow a profile, react to posts, comment, share content or make contact via messages.
Purpose: maintaining the profiles, communicating with the audience and providing information about the offer and events. Legal basis: Article 6(1)(f) GDPR (legitimate interest consisting in maintaining the profiles and communicating with the audience).
With respect to the statistics made available by Facebook, the Controller and Meta Platforms Ireland Limited are joint controllers. The rules for the processing of data by these services are set out in the terms and privacy policies of their operators, which the Controller does not influence to the extent that the operators process data independently.
3.12. to.gather CLUB loyalty program
The Controller operates the to.gather CLUB loyalty program, under which the Guest receives a regular guest card added to Apple Wallet or Google Wallet and benefits from cashback and privileges that depend on the membership level. The program is operated on the Syrve platform.
Within the program, the Controller processes: first name, phone number, date of birth, bill and transaction history, cashback balance and membership level (CLOSER or INSIDER).
Purpose: operating the loyalty program, including participant registration, card issuance, cashback accrual, determination of the membership level and granting of privileges, including the birthday discount. Legal basis: Article 6(1)(b) GDPR (performance of the program participation agreement) and, with respect to sending marketing information related to the program, Article 6(1)(a) GDPR (consent).
The membership level is determined automatically on the basis of the total value of bills. The related profiling is described in section 10. The date of birth is used solely to grant the birthday discount.
Participation in the program is voluntary, and the Guest may withdraw from it at any time.
3.13. Take-away and delivery orders
For take-away orders and delivery orders, the Controller processes the data necessary to accept and fulfill the order.
Purpose: accepting and fulfilling the take-away or delivery order.
Legal basis: Article 6(1)(b) GDPR (performance of the contract) and, with respect to accounting obligations, Article 6(1)(c) GDPR.
Orders placed through external platforms (Uber Eats, Glovo) are subject to the privacy policies of those platforms, which act as separate controllers in this respect. In such cases, the Controller processes data to the extent necessary to fulfill the order transmitted by the given platform.

4. Voluntary provision of data
Providing data is voluntary; however, in some cases it is necessary in order to use a service. Failure to provide the data required to make a reservation, examine a complaint, issue a voucher or organize an event will make it impossible to perform the given service.

5. Recipients of data and processors
Personal data may be shared with entities that support the Controller in conducting its business, including:
Syrve, provider of the platform on which to.gather CLUB loyalty program is operated,
Apple Distribution International Ltd, provider of the Apple Wallet service, within which the loyalty program card is issued,
Webflow, Inc. (United States), provider of the hosting and platform on which the website operates, together with the technical tools used by that platform, including the Sentry error-monitoring tool,
Cloudflare, Inc. (United States), provider of content delivery network and security services,
Google Ireland Limited / Google LLC, provider of the Google Workspace business email, the Google Fonts service, the Google Wallet service, and analytical and marketing tools, including Google Analytics, Google Tag Manager and Google Ads,
Meta Platforms Ireland Limited, operator of the Facebook and Instagram services and provider of the Meta Pixel tool,
Stape, provider of server-side tag management (server-side Google Tag Manager),
ipapi, provider of IP-based geolocation,
providers of accounting, legal and IT services, to the extent necessary to provide their services,
entities authorized to obtain data under applicable law, where they submit such a request on an appropriate legal basis.
Data processing agreements meeting the requirements of Article 28 GDPR are concluded with entities processing data on behalf of the Controller.

6. Transfer of data outside the European Economic Area
Some of the recipients and tools referred to in section 5 (including Webflow together with the Sentry tool, Cloudflare, Google with respect to the Google Workspace, Google Fonts, Google Wallet, Google Analytics, Google Tag Manager and Google Ads services, Meta with respect to the Meta Pixel tool, Apple, Stape and ipapi) have their registered office or process data in the United States or in other countries outside the European Economic Area, which may involve the transfer of data outside that area. Such transfers take place using the appropriate safeguards provided for in Articles 44 et seq. GDPR, in particular the standard contractual clauses approved by the European Commission or on the basis of an adequacy decision, including participation in the Data Privacy Framework where the given recipient has joined it.
The operators of the social media services (Facebook, Instagram) may transfer data outside the European Economic Area under the rules set out in their own privacy policies, which the Controller does not influence.

7. Data retention period
Personal data is stored for the period necessary to achieve the purposes for which it was collected:
reservation data for the period necessary to perform the reservation and then until the limitation period for potential claims expires,
data contained in accounting documents, including data relating to deposits, vouchers and settlements, for the period required by law, as a rule 5 years counted from the end of the calendar year in which the tax obligation arose,
data related to complaints for the period of their examination and until the limitation period for claims expires,
video monitoring recordings for 30 days, subject to section 3.7,
data processed on the basis of consent until it is withdrawn,
data processed on the basis of a legitimate interest until an effective objection is raised or that interest ceases.

8. Rights of data subjects
The data subject has the right to:
- access their data and obtain a copy of it,
- rectify the data,
- erase the data,
- restrict processing,
- data portability,
- object to processing based on a legitimate interest,
withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise these rights, please contact the Controller in the manner indicated in section 1.3.

9. Complaint to the supervisory authority
The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, if they consider that the processing of their data infringes data protection law.

10. Automated decision-making and profiling
Within the to.gather CLUB loyalty program, profiling takes place, consisting of the automatic determination of the membership level on the basis of the total value of bills and in tailoring privileges and offers. This profiling does not produce legal effects concerning the Guest, nor does it similarly significantly affect the Guest.
Apart from the case indicated above, personal data is not subject to automated decision-making producing legal effects concerning the Guest or similarly significantly affecting the Guest.

11. Cookies and similar technologies
11.1. The togathergdansk.pl website uses cookies and similar technologies to the extent necessary for its correct and secure operation and for statistics.
11.2. The website uses:
necessary (technical) files, including a file set by Cloudflare, ensuring the operation and security of the website,
analytical and statistical files, including Google Analytics and Google Tag Manager, also in the server-side variant operated by Stape,
marketing files and tools, including Google Ads and Meta Pixel, used among other things for remarketing,
an IP-based geolocation service (ipapi),
the Google Fonts service, within which the IP address may be transferred to the provider in order to display fonts,
the Sentry tool used to diagnose website errors.
11.3. Cookies and analytical, statistical and marketing tools are used on the basis of the Guest's consent expressed through the consent management mechanism available on the website. Consent may be withdrawn at any time, or the settings changed. Files necessary for the operation of the website do not require consent.
11.4. Cookie settings may be changed in the browser settings. Restricting the use of cookies may affect some functions of the website.

12. Data security
The Controller applies appropriate technical and organizational measures ensuring protection of the processed personal data appropriate to the risks and the categories of data protected; in particular, it protects data against being made available to unauthorized persons, loss or damage.

13. Data of minors
The services of to.gather, including the sale of alcoholic beverages and events marked as intended for adults, are not directed at persons under 18 years of age. The Controller does not knowingly collect the data of minors for the purpose of providing such services.

14. Changes to the Privacy Policy
The Controller may update this Privacy Policy. The current version is published on togathergdansk.pl together with the date of its entry into force.

Popularne kategorie