Legal
Privacy, cookies and legal notice
What we collect, why we hold it, how long for, and how to make us delete it.
Last updated 09 August 2026.
Legal notice
Published in accordance with Article 10 of Spanish Law 34/2002 on information society services and electronic commerce (LSSI-CE).
- Owner: Simon Griffith
- NIF: X0000000X
- Registered address: [Street], [Postcode] [Town], [Province], Spain
- Email: hello@simongriffith.com
- Telephone: +34 711 070 882
- Activity: private chef and catering services
- Trading name: Simon Griffith
The content of this site belongs to Simon Griffith unless stated otherwise, and may not be reproduced commercially without permission.
Who is responsible for your data
Simon Griffith, NIF X0000000X, of [Street], [Postcode] [Town], [Province], Spain, is the data controller. Contact us about anything on this page at hello@simongriffith.com.
What we collect, and why
| What | Why | Legal basis |
|---|---|---|
| Name, email, telephone or WhatsApp number | To reply to your enquiry, confirm the booking and reach you on the day | Performance of a contract, or steps taken at your request before entering one |
| Villa address, access details, dates, guest numbers | To plan, shop for and deliver the service you booked | Performance of a contract |
| Allergies, intolerances and dietary requirements | To cook food that is safe for your party. This is health data, which the law treats as a special category | Your explicit consent, given when you supply it, and our legal duty under food information law |
| Payment records and invoices | To take payment and to meet Spanish tax and accounting obligations | Legal obligation |
| Correspondence with you | To keep a record of what was agreed and to handle any complaint | Our legitimate interest in running the business and defending claims |
You do not have to give us allergy information, but if you do not, we cannot guarantee that what we cook is safe for you. You may withdraw that consent at any time, which will normally mean cancelling the booking.
We do not send marketing email unless you have separately asked us to, and every such message carries an unsubscribe link.
Who else sees it
We use a small number of service providers, each acting as a data processor under contract:
- Netlify — hosts this website and runs the booking functions.
- Supabase — stores booking records in the EU.
- Resend — sends your booking confirmation email.
- Stripe Payments Europe Ltd — processes card payments. Your card details go directly to Stripe; we never see or hold them.
- Our email provider — carries correspondence with you.
- Our accountant or gestor — sees invoices and payment records for tax purposes.
Some of these providers are based outside the European Economic Area, or use infrastructure that is. Where data leaves the EEA it is protected by the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell or rent your data to anybody, ever.
How long we keep it
- Enquiries that do not become bookings: twelve months, then deleted.
- Booking and correspondence records: the duration of the contract plus the limitation period for claims.
- Allergy and dietary information: deleted within six months of service, unless we need it to defend a claim.
- Invoices and accounting records: six years, as required by the Spanish Commercial Code and tax law.
Your rights
You may ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it to another provider, or stop processing it where we rely on legitimate interest. Write to hello@simongriffith.com and we will answer within one month.
If you are not satisfied with our response, you may complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (AEPD), or to the supervisory authority in the country where you live.
Cookies
This website sets no advertising, tracking or profiling cookies. There is nothing to accept or reject, which is why you are not being shown a banner.
Your browser may store a small amount of technical data required for the site to work and to be served securely. If we add analytics in future, this page will be updated and a consent banner will appear before any non-essential cookie is set.
Typefaces are served from this domain rather than from a third-party font service, so loading a page discloses your IP address to nobody but us and our host.
Security
The site is served over HTTPS, payment is handled entirely by Stripe, and access to booking records is limited to Simon and, where necessary, our accountant. No system is perfect, but we do not hold card data and we do not hold more about you than the booking needs.
Changes
If this policy changes materially we will say so here and update the date at the top.
