Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how Maria Food & Service AB processes personal data when you visit the Maria’s Indian Restaurant website, create an account, make a reservation, place an order or contact us.
1. Data Controller
Maria Food & Service AB is the controller responsible for the processing described in this policy.
Organisation number: [ORGANISATION NUMBER]
Address: Mariedalsvägen 51, 217 45 Malmö, Sweden
Email: info@mariasrestaurant.se
Telephone: +46 73 734 04 06
2. Personal Data We May Collect
- Name and contact details, including telephone number and email address.
- Billing, delivery and collection information.
- Account and login information.
- Order history, selected dishes and transaction details.
- Reservation details and special requests.
- Customer-service correspondence and complaints.
- IP address, browser, device and website activity information.
- Cookie preferences and consent records.
- Marketing preferences.
Please avoid including unnecessary health information in order notes. If you provide allergy or dietary information, we process it only as necessary to handle your request safely and in accordance with applicable law.
3. Why We Process Personal Data
We may process personal data to:
- Receive, prepare, deliver and manage orders.
- Process payments and issue receipts or refunds.
- Manage accounts and reservations.
- Answer enquiries and resolve complaints.
- Meet accounting, tax, food-safety and other legal obligations.
- Prevent fraud, abuse and security incidents.
- Maintain and improve our website and services.
- Send marketing where we have valid permission or another lawful basis.
4. Legal Bases
Depending on the situation, processing is based on performance of a contract, compliance with a legal obligation, our legitimate interests or your consent.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing carried out before consent was withdrawn.
5. Who Receives Personal Data
We may share necessary information with trusted providers that help us operate our business, including:
- Payment providers.
- Hosting and technical service providers.
- Email and communications providers.
- Delivery providers.
- Accounting and professional advisers.
- Authorities where disclosure is legally required.
These recipients may only use personal data for authorised purposes and subject to applicable data-protection requirements.
6. International Transfers
If a service provider processes information outside the EU or EEA, we use an applicable legal transfer mechanism and appropriate safeguards where required.
7. Retention
We keep personal data only for as long as necessary for the relevant purpose or to satisfy legal requirements. Accounting and transaction records may be retained for the period required under Swedish law.
Account information is retained while the account remains active and for a reasonable period afterwards. Enquiries, complaints and consent records are retained for as long as necessary to manage the matter and demonstrate compliance.
8. Your Rights
Subject to the conditions in applicable law, you may request:
- Access to your personal data.
- Correction of inaccurate or incomplete data.
- Deletion of personal data.
- Restriction of processing.
- Data portability.
- Objection to certain processing.
- Withdrawal of consent.
To exercise a right, email [PRIVACY EMAIL ADDRESS]. We may need to verify your identity before completing the request.
9. Complaints
If you are dissatisfied with our processing, please contact us first. You also have the right to submit a complaint to Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection.
10. Security
We use reasonable organisational and technical safeguards designed to protect personal data. No internet-based service can, however, guarantee absolute security.
11. Changes to This Policy
We may update this policy when our services, processing activities or legal obligations change. The latest version will be published on this page.