RESERVATION

Book a table

Book a table

Privacy Policy

This Privacy Policy explains how Lopatar restaurant (“we”, “us”, “the Controller”) collects, uses and protects the personal data you provide when using the lopatar.bg website and when contacting us. Processing is carried out in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and the Bulgarian Personal Data Protection Act (PDPA).

1. Data Controller

Lopatar restaurant
Sofia, Ovcha Kupel district, Bulgaria
Email: lopatar@petrus.bg
Phone: +359 876 643 137

[Legal entity name and company number (EIK) to be completed by the Controller.]

2. What personal data we collect

  • Through the contact form: name, email address, subject and message content.
  • For reservations: name, phone, email, date/time and number of guests.
  • Automatically on your visit: IP address, browser and device type, pages visited — via cookies and similar technologies.

3. Purposes and legal bases

  • Responding to enquiries and communicating with you — based on legitimate interest (Art. 6(1)(f)) and/or consent (Art. 6(1)(a)).
  • Receiving and managing reservations — based on Art. 6(1)(b) (steps taken at your request).
  • Maintenance, security and improvement of the website — based on legitimate interest.
  • Compliance with legal obligations — based on Art. 6(1)(c).

4. Cookies

The website uses cookies necessary for its operation, as well as (with your consent) analytics cookies for statistics. You can manage cookies through your browser settings. Third-party services (e.g. Google) may set their own cookies.

5. Retention period

We keep your personal data only for as long as necessary for the relevant purpose: enquiry correspondence — up to 12 months; reservation data — until the event is completed plus a reasonable period; data required by law — for the statutory periods.

6. Recipients and processors

We may share data with providers that help us operate the site and services: hosting provider, email service provider, reservation system and analytics providers. They process the data on our instructions and under appropriate safeguards.

7. Your rights

Under the GDPR you have the right to: access your data; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection to processing; and the right to withdraw consent at any time. To exercise your rights, contact us using the details above.

8. Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or disclosure.

9. Supervisory authority

You have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP): 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, website: cpdp.bg.

10. Changes to this policy

We may update this policy from time to time. The current version is always published on this page.

Last updated: June 2026.