Privacy Policy
In accordance with GDPR (EU) 2016/679 and BDSG
1. Data Controller
Data Controller according to GDPR:
Dylan Darel Kamdem
Dinavora Digital
Rudolf-Breitscheid-Straße 58
67655 Kaiserslautern
Germany
Email: hello@dinavora.com
Telephone: +4915751737936
2. Principles of Data Processing
Dinavora Digital
takes the protection of your personal data very seriously. This privacy policy explains what data is collected on our websitedigital.dinavora.com
, how it is used and what rights you have.
No tracking, no advertising
This website does not use any analytics tools, Google Analytics, advertising cookies or third-party tracking pixels. No data is collected or passed on for advertising purposes.
3. Hosting and Technical Operation
Hosting provider
This website is hosted on the infrastructure of Railway (Railway Corp., San Francisco, CA, USA). Railway is a cloud hosting provider that ensures the technical operation of the website.
When you visit this website, the hosting provider automatically records so-called server log files. These contain technically necessary information:
- IP address of the requesting device (anonymised after 7 days at the latest)
- Date and time of access
- URL accessed
- Browser type and operating system
- HTTP status code
This data is processed solely for the purposes of ensuring technical operation, troubleshooting and defending against attacks. It is not combined with other data sources.
Legal basis: Article 6(1)(f) of the General Data Protection Regulation (DSGVO) (legitimate interest in the secure operation of the website).
Further information on data protection at Railway: https://railway.app/legal/privacy
Rate limiting (Upstash)
To protect against misuse and automated requests (e.g. spam via the contact form), we use server-side rate limiting via the service Upstash (Upstash, Inc., USA). In doing so, your IP address is processed for the duration of the respective time window in order to limit the number of requests. No further storage or analysis takes place.
Legal basis: Article 6(1)(f) of the General Data Protection Regulation (DSGVO) (legitimate interest in the secure operation of the website). Information on data protection at Upstash can be found on the provider’s website.
4. Making contact (email, telephone, contact form)
If you contact us by email (hello@dinavora.com) or by telephone, the data you provide (name, email address, telephone number, content of your message) will be processed solely for the purpose of dealing with your enquiry.
This data will not be passed on to third parties and will be deleted once your enquiry has been fully resolved, provided there are no statutory retention obligations to the contrary.
Legal basis: Article 6(1)(b) of the General Data Protection Regulation (DSGVO) (pre-contractual measures) or Article 6(1)(f) of the General Data Protection Regulation (DSGVO) (legitimate interest).
Contact form
If you use the contact form on our website, we will process the data you provide (subject, name, restaurant name, email address, message) solely for the purpose of handling your enquiry. You can only submit the form once you have confirmed that you accept this privacy policy.
To transmit your enquiry to us by email, we use the service provider Resend (Resend, Inc., USA) as a data processor. A data processing agreement is in place with Resend; data is transferred to the USA on the basis of the EU Standard Contractual Clauses (Article 46 DSGVO). To protect against automated spam, the form uses a technical protection mechanism (honeypot) as well as server-side rate limiting (see Section 3).
Legal basis: Article 6(1)(b) DSGVO (pre-contractual measures) or Article 6(1)(f) DSGVO (legitimate interest in responding to enquiries). The data will be deleted as soon as your enquiry has been fully resolved and provided there are no statutory retention obligations to the contrary.
5. Appointment Booking via Calendly
On our website, we offer the option to book a free initial consultation (Discovery Call) via an external link. This service is provided by:
Calendly
LLC
271 17th St NW, Ste 1000
Atlanta, GA 30363, USA
Privacy policy: https://calendly.com/pages/privacy
Purpose of the appointment
The appointment you have booked is exclusively a non-binding initial consultation (Discovery Call) to analyse your restaurant’s digital situation and to introduce our services. There is absolutely no obligation to purchase.
Data processed
When booking an appointment viaCalendly
, the following data is collected and processed byCalendly
:
- First name and surname
- Email address
- Optional details in the booking form (e.g. restaurant name, message)
- Technical data (IP address, browser, timestamp)
This data is stored byCalendly
on servers in the USA.
Dinavora Digital
receives your name, email address and, where applicable, any optional details as part of the booking process in order to prepare for and carry out the appointment.
External platform
TheCalendly
booking link opens an external website (calendly.com), where the privacy policy ofCalendly
LLC applies.Dinavora Digital
has no influence over the data processing carried out byCalendly
on its platform.
Legal basis: Article 6(1)(b) of theDSGVO
(pre-contractual measures at the request of the data subject).Calendly
LLC is certified under the EU-US Data Privacy Framework; data transfers to the USA are carried out on the basis of the EU Commission’s adequacy decision (Article 45DSGVO
).
6. Contact via WhatsApp
A link to contact us via WhatsApp is provided on our website. The use of WhatsApp is voluntary. If you contact us via WhatsApp, your messages and phone number will be processed by WhatsApp LLC (Meta Platforms).
We have no influence over data processing by WhatsApp. The privacy policy of WhatsApp applies: https://www.whatsapp.com/legal/privacy-policy
We exclusively use the data you provide via WhatsApp to process your inquiry.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in communicating with prospective clients).
7. Cookies
This website does not use cookies.
Neither proprietary cookies nor third-party cookies (e.g., Google, Facebook, marketing tools) are set. Therefore, a cookie banner is not required.
8. Data Sharing with Third Parties
As a general rule, your personal data will not be disclosed to third parties. Exceptions apply only in the following cases:
- Invoicing via external payment service providers (e.g. Ruul), provided a contract is concluded — only the data necessary for invoicing will be transmitted
- A legal obligation to disclose data to public authorities or courts
- Technical operation of the website via Railway (server logs, see Section 3)
- Sending emails via Resend (transmission of contact form enquiries, see Section 4)
- Rate limiting via Upstash (protection against misuse, see Section 3)
All service providers who process personal data on behalf of Dinavora Digital are contractually obliged to comply with the General Data Protection Regulation (DSGVO).
9. Storage Duration
Personal data is only stored for as long as necessary for the respective purpose:
- Email or phone inquiries: deletion after full processing, no later than 12 months.
- Calendly booking data: according to Calendly's privacy policy (usually 12 months after the appointment).
- Server log files (Railway): automatic anonymization after 7 days at the latest.
- Contract data for customer relationships: retention in accordance with statutory retention periods (up to 10 years according to § 147 AO / § 257 HGB).
10. Your Rights as a Data Subject
You have the following rights regarding your personal data with Dinavora Digital:
- Right to access (Art. 15 GDPR) — what data we have stored about you
- Right to rectification (Art. 16 GDPR) — to have incorrect data corrected
- Right to erasure (Art. 17 GDPR) — to request the deletion of your data
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR) — against the processing of your data based on legitimate interests
To exercise your rights, please contact: hello@dinavora.com
You also have the right to lodge a complaint with the competent data protection authority. The supervisory authority for Rhineland-Palatinate is:
Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34
55116 Mainz
Website: https://www.datenschutz.rlp.de
11. Data Security
This website is delivered via an encrypted HTTPS connection (TLS/SSL). The technical infrastructure is operated by Railway on modern cloud servers with current security standards.
Despite all technical and organizational measures, absolute security of data transmission over the Internet cannot be guaranteed.
12. Error and Fault Monitoring (Sentry)
To detect and rectify technical errors, we use the Sentry service provided by Functional Software, Inc., 45 Fremont Street, San Francisco, CA 94105, USA. If a technical error occurs whilst accessing the website, information relating to this – including the IP address, browser type, operating system and the time of the error – is transmitted to Sentry and processed there for error analysis. The data is used exclusively to ensure the technical stability of this website and is not combined with any other data.
Legal basis: Article 6(1)(f) of the GDPR (legitimate interest in the error-free and secure operation of the website). Functional Software, Inc. is certified under the EU-US Data Privacy Framework; data transfers to the USA are carried out on the basis of the EU Commission's adequacy decision (Article 45 of the GDPR).
13. Updates to this Privacy Policy
This privacy policy is currently valid as of July 2026. Dinavora Digital reserves the right to adjust this policy in the event of changes to the website or legal frameworks. The current version is available at digital.dinavora.com/datenschutz.
Dinavora Digital · Dylan Darel Kamdem
Rudolf-Breitscheid-Straße 58 · 67655 Kaiserslautern · Germany
hello@dinavora.com · +4915751737936 · digital.dinavora.com
As at July 2026 · Version 1.1 This document does not constitute legal advice. For legal enquiries, Dinavora Digital recommends consulting a qualified solicitor.