Privacy Policy
Ravessarian Dining Restaurant
Effective date: 1 June 2025
Last reviewed: 1 June 2025
This Privacy Policy explains how collects, uses, discloses and protects personal data obtained through the website at ravessariandining.com (the "Website"). Please read this policy carefully before submitting any information through the Website.
This policy applies solely to personal data collected via the Website. It does not govern data processing activities carried out entirely within our physical restaurant premises beyond what is described here.
1. Data Controller
The data controller responsible for your personal data is:
| Legal entity | |
|---|---|
| Trading name | Ravessarian Dining Restaurant |
| Registered address | |
| Registration number | 1003674928 |
| VAT / Business number | 867492813 RT 0001 |
| Privacy contact email | info@ravessariandining.com |
| Website | ravessariandining.com |
References to "we", "us" or "our" throughout this policy mean
2. Personal Data We Collect
We collect personal data only to the extent necessary for the purposes described in this policy. The categories of personal data we collect through the Website are set out below.
2.1 Contact and Reservation-Request Data
When you submit a reservation request, an enquiry form or a general contact form on the Website, we collect:
- Full name
- Email address
- Telephone number
- Preferred reservation date and time
- Party size
- Occasion or special-arrangement notes you choose to include in free-text fields
- Any other information you voluntarily provide in the message field
2.2 Device and Technical Data
When you visit the Website, our web server and any analytics tools we operate automatically receive certain technical data, including:
- IP address (which may be truncated or pseudonymised depending on your consent choices)
- Browser type and version
- Operating system
- Referring URL
- Pages viewed and time spent on each page
- Date and time of the visit
- Device type (desktop, tablet or mobile)
2.3 Consent and Preference Data
When you interact with our consent management interface, we record:
- The consent choices you make (accepted, declined or granular preferences)
- The date and time of each consent event
- The version of the policy in force at the time of consent
- Cookie identifiers associated with your consent record
2.4 Cookie and Similar-Technology Data
We use cookies and similar technologies on the Website. Details of each category are provided in Section 4 below and in our Cookie Notice, which is presented to you when you first visit the Website.
2.5 Data We Do Not Collect
We do not knowingly collect special-category personal data through the Website. If you voluntarily include such information in a free-text field, we will treat it with heightened care and will not use it for any purpose other than fulfilling your specific request.
The Website is not directed at persons under the age of 18. We do not knowingly collect personal data from individuals under 18. If we become aware that a person under 18 has submitted personal data to us, we will delete that data promptly. Please contact us at info@ravessariandining.com if you have reason to believe this has occurred.
3. How We Use Your Personal Data
The table below sets out each processing purpose, the categories of data involved and the legal basis we rely on under applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation.
| Purpose | Data categories used | Legal basis |
|---|---|---|
| Processing and responding to reservation requests and general enquiries | Contact and reservation-request data | Performance of a contract or pre-contractual steps at your request; or your consent where no contractual relationship exists |
| Sending a confirmation of your reservation request by email | Name, email address, reservation details | Performance of a contract or pre-contractual steps |
| Sending service-related communications (such as reservation reminders or changes) | Name, email address, telephone number, reservation details | Legitimate interest in providing the service you have requested; or performance of a contract |
| Operating and improving the Website (analytics) | Device and technical data; cookie and similar-technology data | Your consent (where required) or our legitimate interest in maintaining a functional and secure website |
| Managing consent records and honouring your preferences | Consent and preference data | Legal obligation and legitimate interest in demonstrating compliance |
| Ensuring Website security, preventing fraud and investigating misuse | Device and technical data; IP address logs | Legitimate interest in protecting our systems and users |
| Complying with legal and regulatory obligations | Any category as required | Legal obligation |
| Establishing, exercising or defending legal claims | Any category as required | Legitimate interest in protecting our legal position |
Where we rely on legitimate interest as a legal basis, we have assessed that our interests are not overridden by your privacy rights. You may request a copy of that assessment by contacting us at the address in Section 10.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawal instructions are provided in Section 9.
5. Disclosure and Recipients of Personal Data
We do not sell, rent or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the following categories of recipients, strictly for the purposes described in this policy.
5.1 Service Providers and Processors
We engage trusted third-party service providers to assist us in operating the Website and delivering our services. These providers act only on our documented instructions and are not permitted to use your data for their own purposes. Categories of service providers include:
- Web hosting and infrastructure providers
- Email delivery and communication platforms
- Website analytics providers
- Consent management platform providers
- IT security and monitoring service providers
5.2 Professional Advisers
We may share personal data with lawyers, accountants, auditors and insurers where necessary in connection with the services they provide to us, subject to appropriate confidentiality obligations.
5.3 Regulatory and Law-Enforcement Authorities
We may disclose personal data to government authorities, regulators or law-enforcement bodies where required by applicable law, court order or other legal process, or where we believe disclosure is necessary to protect our rights or the safety of others.
5.4 Business Transfers
If undergoes a merger, acquisition, restructuring, sale of assets or similar transaction, personal data held by us may be transferred to the relevant parties as part of that transaction, subject to appropriate confidentiality protections. We will notify you of any such change in accordance with applicable law.
6. International Transfers of Personal Data
is based in Canada. Where we engage service providers whose infrastructure is located outside Canada, your personal data may be transferred to and processed in other countries, including countries that may not provide a level of data protection equivalent to that in Canada.
When we transfer personal data outside Canada, we take steps to ensure an adequate level of protection by relying on one or more of the following safeguards:
- Contractual clauses approved or recognised under applicable Canadian privacy law that bind the recipient to appropriate data-protection standards
- A determination that the jurisdiction provides substantially similar protection to that required under PIPEDA
- Your explicit consent to the transfer, where required
You may request further information about the safeguards in place for any specific transfer by contacting us at info@ravessariandining.com.
7. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law. The following retention principles apply.
| Data category | Retention period | Rationale |
|---|---|---|
| Reservation-request and contact data (confirmed reservation) | 2 years from the reservation date | Operational record-keeping and responding to follow-up enquiries |
| Reservation-request data (no-show or cancelled before confirmation) | 90 days from the date of the request | Short-term operational need; no ongoing relationship established |
| General contact enquiries | 1 year from the date of the enquiry | Operational need to refer to prior correspondence |
| Device and technical log data | Up to 13 months | Security monitoring and Website performance analysis |
| Consent and preference records | 3 years from the date the consent record was created or last updated | Demonstrating compliance with consent obligations |
| Data subject rights correspondence | 3 years from the date the request was closed | Legal obligation and defence of potential claims |
At the end of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be associated with you. Where deletion is not immediately possible (for example, because data is held in backup archives), we isolate it from further active processing until deletion is feasible.
8. Security of Personal Data
We implement appropriate technical and organisational measures designed to protect personal data against accidental loss, unauthorised access, disclosure, alteration or destruction. These measures are reviewed and updated periodically in light of evolving threats and best practices.
Our security measures include, without limitation:
- Encrypted transmission of data between your browser and the Website using industry-standard transport layer security (TLS)
- Access controls that limit access to personal data to authorised personnel who require it for a legitimate business purpose
- Regular monitoring of systems for vulnerabilities and potential threats
- Staff training on data-protection obligations and information security practices
- Contractual requirements imposed on service providers to maintain equivalent security standards
No method of electronic transmission or storage is completely secure. While we take the protection of your personal data seriously and apply proportionate safeguards, we cannot guarantee absolute security. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately at info@ravessariandining.com.
In the event of a personal data breach that creates a real risk of significant harm to individuals, we will notify the Office of the Privacy Commissioner of Canada and, where required, affected individuals, in accordance with the mandatory breach-reporting requirements under PIPEDA.
9. Your Rights as a Data Subject
Under PIPEDA and applicable provincial privacy legislation, you have the following rights with respect to your personal data held by us. We will respond to all valid requests within 30 days of receipt, or notify you if an extension is required.
9.1 Right of Access
You have the right to request confirmation of whether we hold personal data about you and, if so, to receive a copy of that data together with information about how it is processed.
9.2 Right to Correction (Rectification)
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or update it.
9.3 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time by:
- Adjusting your cookie preferences via the "Cookie Settings" link in the Website footer
- Sending a written request to info@ravessariandining.com
Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal.
9.4 Right to Request Deletion
You may request that we delete your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent and no other legal basis applies, or where the data has been unlawfully processed. We will comply unless we are required or permitted by law to retain the data.
9.5 Right to Object to Processing
Where we rely on legitimate interest as the legal basis for processing, you have the right to object on grounds relating to your particular situation. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for the establishment, exercise or defence of legal claims.
9.6 Right to Data Portability
Where processing is carried out by automated means and is based on your consent or a contractual relationship, you may request that we provide your personal data in a structured, commonly used and machine-readable format, and transmit it to another controller where technically feasible.
9.7 Right Not to Be Subject to Automated Decision-Making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects in relation to you.
9.8 How to Exercise Your Rights
To exercise any of the rights described above, please submit a written request to:
- Email: info@ravessariandining.com
- Postal address: Privacy Officer, ,
To protect your privacy, we may ask you to verify your identity before processing your request. We will not charge a fee for processing reasonable requests, but reserve the right to apply a reasonable fee for manifestly unfounded or excessive requests.
10. Minimum Age and Protection of Minors
The Website and the associated restaurant and gaming facilities are intended for use by individuals who are 18 years of age or older. We do not knowingly collect, use or disclose personal data from individuals under the age of 18. If you are a parent or guardian and believe that a minor has provided personal data to us through the Website, please contact us at info@ravessariandining.com and we will take prompt steps to delete the information.
11. Links to Third-Party Websites
The Website may contain links to external websites operated by third parties. These links are provided for your convenience only. We have no control over the content of those sites and accept no responsibility for their privacy practices. We encourage you to review the privacy policies of any third-party websites you visit.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or the services offered through the Website. When we make material changes, we will update the "Last reviewed" date at the top of this page and, where appropriate, notify you by email or by a prominent notice on the Website prior to the change taking effect.
We encourage you to review this policy periodically. Your continued use of the Website following the posting of an updated policy constitutes your acknowledgement of the changes.
13. Complaints
If you believe that we have not handled your personal data in accordance with this policy or applicable privacy law, we encourage you to contact us first so that we can investigate and attempt to resolve the matter.
If you are not satisfied with our response, or if you wish to raise a concern directly with a supervisory authority, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada:
- Office of the Privacy Commissioner of Canada
- 30 Victoria Street, Gatineau, Quebec K1A 1H3, Canada
- Website: www.priv.gc.ca
Residents of Ontario may also contact the Information and Privacy Commissioner of Ontario:
- Information and Privacy Commissioner of Ontario
- 2 Bloor Street East, Suite 1400, Toronto, ON M4W 1A8, Canada
- Website: www.ipc.on.ca
14. Contact Us
For any questions, concerns or requests relating to this Privacy Policy or our data-processing activities, please contact our Privacy Officer using the details below.
| Legal entity | |
|---|---|
| Trading name | Ravessarian Dining Restaurant |
| Postal address | Privacy Officer, |
| info@ravessariandining.com | |
| Website | ravessariandining.com |
We aim to acknowledge all privacy enquiries within 5 business days and to provide a substantive response within 30 calendar days of receipt. Where a longer period is required by the complexity of the request, we will inform you of the extended timeline and the reasons for it.