BONSAI
HomeCoffeeMenuCocktailsEventsContact
🇪🇸🇬🇧
Book now
HomeCoffeeMenuCocktailsEventsContactBook now

Privacy Policy

At BONSAI LOUNGE & CAFE, S.L. we understand that maintaining a transparent relationship with you is essential. That is why, below, we present our Privacy Policy, so that you are always duly informed about how we collect and securely process any data you provide to us.

Your data will be processed in accordance with applicable legislation and, specifically, in accordance with the provisions of Regulation (EU) 2016/679 of 27 April 2016 (GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Also in accordance with Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights.

A careful reading of our Privacy Policy will give you the information you need to understand what we will do with the data you provide to us.

Who is responsible for processing your data?

If you, or an authorised person, have provided us with your data, we inform you that BONSAI LOUNGE & CAFE, S.L., with Tax ID (CIF): B19772334, is the controller responsible for processing it. This data will be processed in accordance with the provisions of current personal data protection regulations.

There may be other controllers involved in the processing we carry out; in such cases we will always inform you who is responsible for processing the data, as well as their identification details.

The Website may include hyperlinks or links that allow access to web pages of third parties other than https://bonsaicafe.es/, which are therefore not operated by BONSAI LOUNGE & CAFE, S.L. The owners of such websites will have their own data protection policies and will, in each case, be responsible for their own processing and their own privacy practices.

At BONSAI LOUNGE & CAFE, S.L. we are committed to complying with our obligation of confidentiality regarding personal data and our duty to safeguard it. To this end, we adopt the necessary measures to prevent its alteration, loss, processing or unauthorised access, in accordance with the provisions of the Regulation.

Where do we provide this information?

BONSAI LOUNGE & CAFE, S.L. provides this information through the website https://bonsaicafe.es/ in the section corresponding to the privacy policy. More information is available in the "Legal Notice".

What personal data do we process?

The personal data we process is:

  • Data you voluntarily decide to provide to us.
  • Data derived from communications you have with us.
  • Information relating to your own browsing in the case of Online Services (IP address or information derived from cookies or similar devices; you can view our Cookie Policy on the website).
  • Information available in publicly accessible sources to which we may legitimately have access.
  • Data arising from the contractual or pre-contractual relationship you have with us, including your image, always informing you in this case of the possibility of your image being captured.
  • Data provided to us by third parties about you, where there is a legitimate basis for doing so or where we have obtained your consent to do so.
  • Third-party data that you provide to us, with the prior consent of the third party in question. You can find more information in the records of processing activities section of this privacy policy.

How do we process the data?

At BONSAI LOUNGE & CAFE, S.L. we always process your personal data in strict compliance with applicable law. We also inform you that we have appropriate technical and organisational measures in place to guarantee an optimal level of security, thereby ensuring that only authorised persons will have access, that we will keep the data intact, avoiding any intentional or accidental loss, and that we have reinforced our data processing systems and services.

However, since BONSAI LOUNGE & CAFE, S.L. cannot guarantee that the internet is impregnable, nor the total absence of hackers or others who may fraudulently access personal data, we undertake to inform you without undue delay when a personal data breach occurs that is likely to entail a high risk to the rights and freedoms of natural persons. In accordance with Article 4 of the GDPR, a personal data breach is understood to mean any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

The operations, procedures and technical processes we carry out, whether automated or non-automated, that enable the collection, storage, modification, transfer and other actions on personal data, are considered to be personal data processing.

What is the legal basis for processing?

The legal basis for the processing of Personal Data will be that arising from the contractual or pre-contractual relationship, the employment relationship, or any other relationship required for the processing of data, such as express consent.

How do we manage electronic communications?

In accordance with the provisions of Law 34/2002 of 11 July on Information Society Services and Electronic Commerce, and Directive 2002/58/EC, we inform you that you may receive commercial communications and information via this electronic communication system (emails, automated form response messages and other communication systems) when you have given us your consent, or where these are commercial communications relating to products or services similar to those previously provided by the data controller.

Should you not wish to receive such communications and information, you may notify us via the same channel, indicating "UNSUBSCRIBE FROM COMMERCIAL COMMUNICATIONS" in the subject line, so that your personal data can be removed from our database. Your request will be processed within a period of 1 month from when it is sent. Should we not receive an express reply from you, we will understand that you accept and authorise our company to continue making such communications.

Should you receive such communications through these means, please note that the messages are addressed exclusively to their recipient and may contain privileged or confidential information. If you are not the intended recipient, please note that the use, disclosure and/or unauthorised copying of such information is prohibited under applicable law.

How long do we keep your data?

Personal data relating to natural persons that BONSAI LOUNGE & CAFE, S.L. collects by any means will be kept for as long as the data subject does not request its deletion. It will likewise be kept for as long as the relationship that gave rise to the data processing is maintained, in any case respecting the legal retention periods. Once this period has ended, personal data will be deleted from all of BONSAI LOUNGE & CAFE, S.L.'s systems.

Will your data be disclosed to third parties?

There will be no assignment, transmission or transfer of personal data, other than as already disclosed, except as a result of a legal obligation. Should your data be requested by the Public Administration or Regional Institutions within the scope of the functions expressly attributed to them by law, it will be disclosed.

Should there be any assignment, transmission or transfer of personal data outside the cases foreseen above, you will be informed beforehand so that, where applicable, you may give your consent.

However, in order to organise ourselves properly and have good operating procedures that guarantee sound management, BONSAI LOUNGE & CAFE, S.L. may need to engage the services of advisers, professionals, or other service companies to process data under our instructions.

This third-party processing is governed by a contract set out in writing or in another legally admissible form that allows its execution and content to be evidenced, expressly specifying that the data processor will process the data in accordance with our instructions and will not apply or use it for a purpose other than that set out in said contract, nor will it disclose it, even for the purposes of retention, to other parties.

What are your rights?

Data protection regulations grant you the following rights:

  • Right of access: the User's right to obtain confirmation as to whether BONSAI LOUNGE & CAFE, S.L. is processing their personal data and, if so, to obtain information about their specific personal data and the processing carried out or to be carried out by BONSAI LOUNGE & CAFE, S.L., as well as, among other things, information available on the origin of such data and the recipients of any communications made or planned regarding it.
  • Right of rectification: the User's right to have their personal data that is inaccurate or, taking into account the purposes of the processing, incomplete, amended.
  • Right of erasure ("the right to be forgotten"): the User's right, provided applicable legislation does not establish otherwise, to obtain the erasure of their personal data when it is no longer necessary for the purposes for which it was collected or processed; when the User has withdrawn their consent to the processing and there is no other legal basis for it; when the User objects to the processing and there is no other legitimate reason to continue it; when the personal data has been unlawfully processed; when the personal data must be erased in compliance with a legal obligation; or when the personal data was obtained as a result of a direct offer of information society services to a minor under 14 years of age. In addition to erasing the data, the data controller, taking into account available technology and the cost of implementation, must take reasonable measures to inform other controllers processing the personal data of the data subject's request for erasure of any links to that personal data.
  • Right to restriction of processing: the User's right to restrict the processing of their personal data. The User has the right to obtain the restriction of processing when they contest the accuracy of their personal data; when the processing is unlawful; when the controller no longer needs the personal data, but the User needs it to make claims; and when the User has objected to the processing.
  • Right to data portability: where processing is carried out by automated means, the User has the right to receive their personal data from the controller in a structured, commonly used, machine-readable format, and to transmit it to another controller. Wherever technically possible, the controller will transmit the data directly to that other controller.
  • Right to object: the User's right to have the processing of their personal data not carried out, or to have such processing ceased, by BONSAI LOUNGE & CAFE, S.L.
  • Right not to be subject to a decision based solely on automated processing, including profiling: the User's right not to be subject to an individual decision based solely on the automated processing of their personal data, including profiling, unless applicable legislation establishes otherwise.

If you would like more information about the processing of your data, to rectify inaccurate data, to object to and/or restrict any processing you consider unnecessary, or to request the cancellation of processing when the data is no longer necessary, you may write to BONSAI LOUNGE & CAFE, S.L. at C/ RUA DAS GALERAS Nº 34 BAJO LOCAL 12, 15705 Santiago de Compostela (A Coruña), or by email to info@bonsaicafe.es.

Such communication must include the following information: the user's full name, the request itself, their address and supporting identification documents.

The exercise of these rights must be carried out by the user themselves. However, they may be exercised by an authorised person acting as legal representative of the data subject. In such a case, documentation evidencing this representation must be provided. Likewise, we would like to inform you that you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to its withdrawal, by sending your request to the same address indicated in the previous paragraph. In this case, you must include a copy of your ID card or other document proving your identity with your request.

Should you consider that there is a problem or infringement of applicable regulations in the way your personal data is being processed, you have the right to effective judicial protection and to lodge a complaint with a supervisory authority, in particular in the State where you have your habitual residence, place of work, or the place of the alleged infringement. In Spain, the supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos) (https://www.aepd.es/), C/ Jorge Juan, 6, 28001 Madrid. FAX: 914483680. Tel: 901 100 099. Email: ciudadano@agpd.es.

What is the purpose and legal basis for processing the data, and how long will it be kept?

Below we detail the purposes of the data processing carried out by some or all of the data controllers listed above.

  • Employment management: management of personnel for the formalisation of an employment contract, file management, payroll management. Legal basis: contractual relationship. Retention period: 5 years from the end of the contract.
  • Tax and accounting management: processing necessary for compliance with tax and accounting obligations. Legal basis: contractual relationship, legal obligation of the controller, legitimate overriding interests of the controller or third parties. Retention period: 5 years from the end of the contract, or the time necessary to meet legal obligations.
  • Contact management: processing of data in order to maintain communications with data subjects. Legal basis: contractual relationship, legitimate overriding interests of the controller or third parties, express consent of the data subject. Retention period: 5 years from the end of the contract, until cancellation and/or objection by the data subject, or until the data is no longer relevant for use.
  • Customer management: processing of data necessary to maintain the commercial/contractual relationship with customers, invoicing, after-sales service, sending of promotions and advertising, and loyalty programmes. Legal basis: contractual relationship, commercial relationship. Retention period: 5 years from the end of the contract, or the period legally established by specific regulations.
  • Management of potential customers: to be able to carry out necessary communications with potential customers and/or other interested parties, sending of quotes, rates, product costs and other information requested prior to establishing a contractual relationship. Legal basis: commercial relationship. Retention period: until the data is no longer relevant for use.
  • Website management: managing enquiries, contacts and complaints received through the website. Legal basis: express consent of the data subject. Retention period: until cancellation and/or objection by the data subject, or until the data is no longer relevant for use.
  • Invoicing: issuing invoices to customers, direct debit batches, collections and preparation of records. Legal basis: contractual relationship, legal obligation of the controller. Retention period: the time necessary to meet legal obligations.
  • User management: management of the relationship with users within the controller's usual activity. Legal basis: express consent of the data subject. Retention period: until cancellation and/or objection by the data subject.
  • Project management: management of customer and collaborator data necessary for the management and processing of consultancy projects. Legal basis: contractual relationship, express consent of the data subject. Retention period: until cancellation and/or objection by the data subject, or the period legally established by specific regulations.
  • Management of miscellaneous procedures: management of data necessary from customers, or provided by them, in order to manage and process various procedures contracted by them. Legal basis: commercial relationship, express consent of the data subject. Retention period: until cancellation and/or objection by the data subject.

Acceptance and changes to this privacy policy

It is necessary for the User to have read and agreed to the terms regarding the protection of personal data contained in this Privacy Policy, and to accept the processing of their personal data so that the data controller may proceed with it in the manner, for the periods, and for the purposes indicated. Use of the Website implies acceptance of its Privacy Policy.

BONSAI LOUNGE & CAFE, S.L. reserves the right to modify its Privacy Policy, at its own discretion, or motivated by a legislative, case-law or doctrinal change from the Spanish Data Protection Agency. Changes or updates to this Privacy Policy will not be explicitly notified to the User. The User is advised to periodically consult this page to stay informed of the latest changes or updates.

This Privacy Policy was updated to comply with Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), and with Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights.

BONSAI

Brunch · Coffee · Cocktails · Santiago de Compostela

HomeMenuReservationsInstagramWhatsAppLegal noticePrivacyCookies

© 2026 Bonsai Café. All rights reserved.