Lena

18 days to goOct 17

Lena

18 days to goOct 17

Privacy policy


Lena is the Mediterranean restaurant at Kerkplein 9 in Alkmaar. This privacy policy explains which personal data we process when you visit our website lena.casa, book a table, buy a gift card, send a group enquiry, apply for a job or get in touch with us. We explain why we do so, who we share data with, how long we keep it and what your rights are.

Who is responsible

The controller is WK Hospitality B.V., Kerkplein 9, 1811 KL Alkmaar, the Netherlands (Chamber of Commerce no. 99429357). Lena is a trade name of WK Hospitality B.V.

Do you have a question about your data, or do you want to exercise one of your rights? Email [email protected] or call +31 72 792 0063.

What data we process

You do not need to share anything with us to read the website. We process data that you give us yourself, and to a limited extent technical data that arises when you use the website.

Visiting the website

On every visit, our hosting provider and Cloudflare process the technical data needed to show the website and keep it secure: your IP address, the type of browser and device, the page requested and the time. We do not use this data to recognise or follow you.

Website usage statistics

We use Umami, a statistics service we host ourselves, to understand how the website is used. Umami works without cookies and does not follow you across other websites. We record:

  • which pages are viewed, which website you came from, your browser, operating system, type of device, screen size and language;
  • an approximate location (country, region and city), derived from your IP address. Your IP address itself is not stored;
  • how quickly pages load and whether a technical error occurs on a page (only the first line of the error message);
  • which buttons and links are used: calling, emailing, directions, our Instagram and Facebook pages, opening the booking widget and the gift card widget, and returning from the gift card payment page;
  • that a booking, group enquiry, job application or gift card purchase has been completed. For a booking we note the number of guests, the chosen service and how you found us; for a group enquiry the number of guests; for a gift card the amount and currency.

These statistics contain no names, email addresses, phone numbers or other data that would let us recognise you. They stay on our own server and never go to an advertising network. Would you rather not be counted? Decline the statistics in the notice you see on your first visit. You can reopen that notice at any time through “Cookie information” at the bottom of every page.

Bookings

Bookings are made through the Guestplan widget. There you enter your name, email address, phone number, the date, the time, the number of people and any comments. Guestplan receives this data directly and manages the booking on our behalf. We do not ask for a deposit.

Gift cards

Gift cards are sold through Gifty. Your order details, such as your name and email address, and your payment are processed by Gifty and Gifty’s payment provider. Your payment details never reach us. We receive the data needed to deliver and redeem the gift card.

Group enquiries

If you enquire about a group booking or one of our rooms, we process your name, email address, phone number, the number of guests, the preferred date, the room or option you chose and your message.

Job applications

If you apply through the website, we process your name, email address, phone number, your motivation, the language you apply in and your CV if you attach one. To protect the form from spam, Cloudflare Turnstile checks that you are a person; this processes technical data such as your IP address and browser characteristics.

Contact by email or phone

If you email or call us, we process your contact details and what you tell us, so that we can help you.

Allergies and other sensitive data

In comments or messages you can let us know that you have an allergy, intolerance or dietary requirement. That is data about your health, a special category of personal data. We only use it to make your visit safe and suitable, and only because you give it to us yourself. Keep it to what we need to know, for example: “nut allergy”.

Why we use your data, and on what legal basis

  • Handling bookings and group enquiries: contacting you, making arrangements, confirming, changing or cancelling. Legal basis: the performance of a contract or steps we take at your request before entering into one (Article 6(1)(b) GDPR).
  • Delivering and redeeming gift cards. Legal basis: the performance of a contract (Article 6(1)(b) GDPR).
  • Assessing job applications and keeping in touch with you about the position. Legal basis: your consent, which you give when you send the form and can always withdraw (Article 6(1)(a) GDPR).
  • Answering questions you ask by email or phone. Legal basis: our legitimate interest in being reachable for guests (Article 6(1)(f) GDPR), or the performance of a contract if your question is about one.
  • Running and securing the website and preventing misuse such as spam. Legal basis: our legitimate interest (Article 6(1)(f) GDPR).
  • Using anonymous statistics to understand how the website is used and where it can be improved. Legal basis: our legitimate interest (Article 6(1)(f) GDPR). You can always object by declining the statistics.
  • Using allergies and dietary requirements for your visit. Legal basis: your explicit consent, given by passing them on to us yourself (Article 9(2)(a) GDPR).
  • Complying with legal obligations, such as the statutory retention period for our accounts. Legal basis: a legal obligation (Article 6(1)(c) GDPR).

We do not use your data for marketing unless you ask for it, we do not sell it, we do not build profiles of you and we do not make decisions about you that are taken by a computer alone.

Who we share your data with

We only share data with parties we need in order to provide our services, and only what they need for that. These parties process your data on our instructions and may not use it for their own purposes.

  • Guestplan (eTender B.V.): our booking system. Guestplan receives the details you enter when booking and sends you the confirmation and any messages about your booking.
  • Gifty: the sale and handling of gift cards, including payment.
  • OVHcloud: hosting of this website, the database, our statistics (Umami) and the backups.
  • Cloudflare: delivers the website quickly and securely to your browser, protects it against attacks, checks the job application form for spam (Turnstile) and hosts the system in which we handle group enquiries and job applications, including attached CVs.

We do not keep group enquiries and job applications on the website itself. When you send them, they go straight to our own system for group enquiries and applications, which only our team can access.

All of these parties process your data within the European Union. We do not transfer personal data to countries outside the EU.

If the law requires us to, for example at the request of the police or the tax authorities, we may provide data to a government body.

Cookies and similar technologies

This website does not place any tracking or advertising cookies of its own. What does end up in your browser:

  • Your choice about the statistics, which we keep in your browser’s local storage (under the name “lena.analytics”), so that we do not have to ask you again on every visit.
  • Functional cookies or browser storage from Guestplan (the booking widget loads on every page) and from Gifty (on the gift card page), which their services need in order to work, for example to hold a booking or order while you fill it in.
  • Possibly a strictly necessary security cookie from Cloudflare, which distinguishes visitors from automated traffic.

If you click through to our pages on Instagram or Facebook, or to Google Maps for directions, you leave our website. From that moment on, the privacy rules of those services apply.

How long we keep your data

We do not keep data longer than necessary for the purpose we received it for:

  • Group enquiries: up to 12 months after our last contact about the enquiry. After that they are deleted automatically.
  • Job applications and CVs: up to 4 weeks after the application procedure has ended. An application we have not responded to is deleted no later than 90 days after receipt. This happens automatically.
  • Bookings: as long as needed for your visit and its handling, and after that for up to 12 months, for questions and any complaints.
  • Email correspondence: up to 24 months after our last contact.
  • Website usage statistics: up to 12 months.
  • Technical server logs: briefly, for security and to resolve faults.
  • Backups: 7 days; after that they are overwritten.
  • Data we are legally required to keep, such as our financial records: 7 years.

Your rights

Under the GDPR you have the right to ask us:

  • for access to the data we hold about you;
  • to correct inaccurate data;
  • to delete your data;
  • to do less with your data (restriction of processing);
  • to transfer your data to you or to another party;
  • to stop a processing activity that we base on our legitimate interest (objection).

If you have given consent, for example with a job application, you can always withdraw it. This does not affect what we did with your data before you withdrew it.

Send your request to [email protected]. We may ask you to show that the data is yours, so that we do not give it to the wrong person. We respond within one month. If your request is complex or we receive many, this may take up to two months longer; we will let you know within the first month.

Are you unhappy with how we handle your data or your request? Let us know first and we will look for a solution together. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

Young people

Are you under 16? Then ask a parent or guardian for permission before you send us personal data, for example with a job application.

Security

We take appropriate technical and organisational measures to protect your data against loss and unlawful use. All connections to the website are encrypted (HTTPS), only staff who need the data can access it, CVs are stored in a place that is not publicly accessible, and data that has reached its retention period is deleted automatically.

Changes

We update this privacy policy when our website, our services or the law change. The latest version is always on this page; the date below shows when we last changed it.


September 27, 2026