Privacy policy
How Burrata Italia d.o.o. collects, uses and protects the personal data of guests and visitors to this site.
This policy explains how Burrata Italia d.o.o. (Ulica i broj 1, 71000 Sarajevo, Bosna i Hercegovina) handles personal data. We process only what we genuinely need in order to take a reservation, answer a question and run the restaurant.
For anything about this policy or your data, write to [email protected].
1. What we collect
We only collect what you give us, or what arises from using the site:
Reservations: name, email address, phone number, date and time, party size, and any note you add (allergies, for example).
Enquiries and job applications: the content of the message you send us and the details in it.
Newsletter: your email address, if you sign up.
Technical data: anonymised visit statistics, if you consented to analytics cookies.
We do not take card details through this site and we do not ask for special categories of data. If you tell us about a health matter in a note (an allergy, say), we use it solely to prepare your food safely.
2. Why we process it, and on what basis
Every processing activity has a clear purpose and legal basis:
Reservations and the messages around them — performance of a contract, or steps taken at your request before entering one.
Answering an enquiry or job application — our legitimate interest in conducting business correspondence.
Newsletter — your consent, which you can withdraw at any time.
Analytics and cookies — your consent, given through the cookie banner.
Legal obligations — keeping accounting records, for example.
3. Who we share it with
We never sell personal data. We share it only with service providers acting on our behalf under a duty of confidentiality:
Hosting and site delivery (Vercel Inc.).
Site content database (Convex Inc.).
Newsletter delivery (Klaviyo Inc.), only if you subscribed.
Visit statistics (Google Analytics) and consent management (Cookiebot), only with your consent.
Some of these providers process data outside Bosnia and Herzegovina and the European Economic Area. Where that happens, the transfer relies on standard contractual clauses or another appropriate safeguard.
4. How long we keep it
We keep data only as long as the purpose requires:
Reservations — up to 12 months after the booking date.
Email correspondence — up to 24 months from the last message.
Job applications — up to 12 months, unless you agree to longer.
Newsletter — until you unsubscribe.
Accounting records — for the periods the law requires.
5. Your rights
In relation to your data you have the right to:
request access to the data we hold about you,
have inaccurate data corrected,
have data erased where there is no longer a basis for processing it,
request restriction of processing, or object to it,
withdraw consent at any time, without affecting processing already carried out,
lodge a complaint with the competent data protection authority.
Send your request to [email protected]. We respond within 30 days at the latest.
6. Security
The site is served over HTTPS only. Reservation data and site content are accessible solely to authorised staff, behind a sign-in with two-factor authentication. Email addresses published on the site are protected against automated harvesting.
7. Changes to this policy
If the way we process data changes, we update this page and its effective date. Significant changes are announced on the site.