Skip to main content

Your data, your privacy

Privacypolicy

Last updated: June 8, 2026

Le Bistrot de Nino (PANTAI SAS) places particular importance on the protection of your personal data. This policy aims to inform you about how we collect, use and protect your data when you browse this site and interact with us.

It complies with the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and the amended French Data Protection Act.

1. Data controller

The data controller is:

PANTAI (SAS, capital 5 000 €)
1 Quai Jean-Jacques Barthélemy, 13260 Cassis
SIRET: 897 849 972 00020
Email: marine@lebistrotdenino.com
Phone: 04 42 01 74 32

For any question relating to the protection of your data, you can contact Marine TAÏEB, Managing Director and head of processing.

2. Data we collect

We only collect data that is strictly necessary for the purposes described below.

2.1 Via the contact form

  • First and last name
  • E-mail address
  • Phone number (optional)
  • Free-form message

2.2 Via the booking form

  • First and last name
  • E-mail address
  • Phone number
  • Date, time slot and number of guests
  • Special requests (dietary needs, occasion…)

2.3 Via audience-measurement cookies

  • Pages visited, time spent
  • Device type, operating system, browser
  • Visit origin (referer)
  • IP address (anonymised for analytics tools)

3. Purposes & legal bases

Your data is processed in strict accordance with the GDPR, for the following purposes:

PurposeLegal basisRetention
Reply to your messageLegitimate interest3 years after last contact
Handle your bookingContract performance3 years after the service
Measure website audienceConsent (cookies)13 months maximum
Accounting / tax obligationsLegal obligation10 years

4. Data recipients

Your data is intended exclusively for the internal services of PANTAI (Le Bistrot de Nino), authorised to process it.

It may also be transmitted to:

  • Our hosting provider: OVH CLOUD FRANCE (France, Clermont-Ferrand)
  • Our transactional e-mail provider: Amazon SES via Mail Hub Jarvis (DIGIFLOW)
  • Our online booking provider: Be-Book (where applicable)
  • Our audience-measurement provider: Elfsight (Instagram / Google Reviews widgets)

No data is sold, rented or transferred to third parties for commercial purposes.

5. Transfers outside the European Union

Some of our technical providers (Amazon Web Services for e-mail, Google services where applicable) may operate outside the European Union. These transfers are governed by the standard contractual clauses adopted by the European Commission, in accordance with articles 46 et seq. of the GDPR.

6. Your rights

Under the GDPR, you have the following rights at any time:

  • Right of access to your data
  • Right of rectification in case of inaccuracy
  • Right to erasure (« right to be forgotten »)
  • Right to restriction of processing
  • Right to object to processing
  • Right to portability of your data
  • Right to withdraw consent at any time

To exercise these rights, write to us at marine@lebistrotdenino.com specifying your request and attaching a copy of an ID document.

You also have the right to lodge a complaint with the CNIL: www.cnil.fr.

7. Cookies & trackers

A cookie is a small text file placed on your device when you visit our website. It allows certain information to be stored (preferences, audience measurement).

7.1 Strictly necessary cookies

Essential for the proper functioning of the site (session, security, forms). They do not require your consent.

7.2 Third-party cookies (external widgets)

Our site includes the following widgets:

  • Elfsight — display of the Instagram feed and Google reviews
  • Google Maps — directions to the restaurant
  • Be-Book — online booking system (where applicable)

These third-party services may set their own cookies. You can refuse them via your browser settings or via their respective policies.

7.3 Cookie management

You can at any time configure your browser to accept or refuse cookies, either globally or on a case-by-case basis:

8. Data security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration or disclosure: hosting with OVH CLOUD FRANCE (datacenter located in France), HTTPS (TLS) encrypted connections, internal access limited to authorised personnel, strong passwords and regular backups.

9. Changes to this policy

This policy may be updated at any time to reflect legal, regulatory or technical changes. The last update date is shown at the top of this page.