Legal
Privacy Policy
Last updated: 27 August 2026
This policy explains what happens to personal data submitted through this website, under the General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). It covers this website only: the reservation form, the server logs and the analytics described below.
Data controller
The controller of the personal data described in this policy is the operator of Tomodachi Marbella, established at Calle Rosalía de Castro 3, 29660 Marbella (Málaga), Spain.
Enquiries about this policy, and any request relating to your personal data, should be sent to info@restaurantetomodachi.com or made by telephone on +34 671 79 65 34. No separate data protection officer has been designated; these are the contact details for all data protection matters.
What data we collect
One form on this site collects personal data: the reservation request. It asks for your name, an email address and a telephone number, together with the date, time, number of guests and any note you choose to add. Nothing else on the site collects personal data, and there is no newsletter sign-up, no account and no payment.
The note field is free text. Please do not use it to give us health information beyond what the kitchen needs to feed you safely: an allergy is enough, a diagnosis is not.
The server that hosts this site keeps ordinary technical logs of the requests it serves, which include IP addresses. Those logs exist to keep the site running and secure.
What we use it for
A reservation request is used to answer that reservation: to confirm the table, to ask a question about it, or to tell you we cannot seat you. It is not added to a marketing list and it is not used to send you anything you did not ask for.
Technical logs are used to operate the site and to investigate faults and abuse. Aggregate visitor statistics are used to understand which pages are read.
Legal basis
A reservation request is processed on the basis of steps taken at your request prior to entering into a contract (GDPR art. 6.1.b). Technical logs and aggregate statistics are processed on the basis of the legitimate interest in running a secure and usable website (GDPR art. 6.1.f).
How long we keep it
A reservation request reaches the restaurant as an email and lives in that mailbox. It is kept for as long as is needed to seat you and to deal with anything arising from the visit, and no longer than the law requires. If you would like your request deleted from the mailbox, write to info@restaurantetomodachi.com and ask.
This website itself keeps no database. Nothing you type into the form is stored on this site after the email has been sent.
Who we share it with
Your data is not sold, and it is not shared with other restaurants or with advertisers. It passes only through the providers needed to run the site and deliver the email: the hosting platform this site is deployed on and the transactional email service that carries the reservation to the restaurant, each acting as a processor on the operator's instructions.
Your rights
You have the right to access your personal data, to have it rectified, to have it deleted, to limit how it is processed, to object to processing carried out on the basis of legitimate interest, and to have your data ported to another controller. To exercise any of these rights, write to info@restaurantetomodachi.com or call +34 671 79 65 34, identifying yourself and stating the right you wish to exercise.
Complaints to the supervisory authority
Independently of the rights above, and whether or not you have raised the matter with us first, you are entitled under the GDPR to lodge a complaint with a data protection supervisory authority. In Spain that authority is the Agencia Española de Protección de Datos (AEPD), at https://www.aepd.es.
Made by Cherie Software