Information pursuant to Section 5 of the German Digital Services Act (DDG)
Barra
Remers & Westhead GbR
Okerstrase 2, 12049 Berlin
Germany
Represented by
Daniel Remers, Owner
Kerry Westhead, Owner
Contact
Telephone: 030 81860757
Email: reservations@barraberlin.com
Website: www.barraberlin.com
Registration Details
District Office of Neukölln
Public Order Office of Berlin-Neukölln
Juliusstraße 67, 12051 Berlin
Germany
VAT Identification Number
VAT identification number pursuant to Section 27a of the German Value Added Tax Act:
DE318755722
Person Responsible for Content pursuant to Section 18 (2) of the German State Media Treaty (MStV)
BarraRemers & Westhead GbR
Okerstrase 2, 12049 Berlin
Germany
Credits
Copywriting and editorial content: Hannah Jaques
Translation: Claudia Sennecke
Concept and web design: Paul Adams
Photography: Marcus Nolan
Consumer Dispute Resolution
We are neither willing nor legally obliged to participate in dispute-resolution proceedings before a consumer arbitration board.
Please verify this wording, as the applicable notice depends on your legal status and current legal requirements.
Liability for Content
As a service provider, we are responsible for our own content on these pages in accordance with general laws. However, we are not obliged to monitor transmitted or stored third-party information or to investigate circumstances indicating illegal activity.
Obligations to remove or block the use of information under generally applicable laws remain unaffected by this.
Liability for Links
Where our website contains links to external third-party websites, we have no influence over their content. We therefore cannot accept any liability for such external content. The respective provider or operator of the linked pages is always responsible for their content.
Validity
This Legal Notice is valid from 22 July 2026.
Last updated: August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Remers & Westhead GbR
Okerstraße 2
12049 Berlin
Germany
Telephone: 030 81860757
Email: kerry@barraberlin.com
Authorized representatives:
- Daniel Remers, owner
- Kerry Westhead, owner
2. Overview of Processing Activities
We process personal data in particular for the following purposes:
- Providing, operating and securing our website;
- Processing contact inquiries;
- Managing and carrying out table reservations;
- Selling and redeeming vouchers;
- Processing payments;
- Communicating with guests and customers;
- Displaying our services and social media content;
- Measuring reach and conducting analysis, where used;
- Fulfilling statutory retention and documentation obligations.
In particular, the following data may be processed:
- Master data, such as names and addresses;
- Contact data, such as email addresses and telephone numbers;
- Reservation data, such as date, time, number of persons, special occasions and requests;
- Payment and transaction data, such as payment status, transaction ID, amount and billing information;
- Technical data, such as IP address, browser and device information, timestamps and security information;
- Usage data, such as pages visited and access times;
- Communication data, such as messages and the content of inquiries;
- Voucher data, such as voucher value, recipient and purchase history.
Data subjects may include, in particular:
- Website visitors;
- Customers, guests and persons making reservations;
- Voucher purchasers and voucher recipients;
- Communication partners;
- Users of our social media services.
3. Legal Bases
We process personal data on the basis of, in particular, the following legal bases:
- Article 6(1)(a) GDPR: consent;
- Article 6(1)(b) GDPR: performance of a contract or implementation of pre-contractual measures, for example in the case of reservations and voucher purchases;
- Article 6(1)(c) GDPR: compliance with legal obligations, such as statutory retention obligations under tax and commercial law;
- Article 6(1)(f) GDPR: protection of legitimate interests, in particular our interest in secure, efficient and properly functioning business operations.
Where we process special categories of personal data, such as health information or information about allergies, this is done only where an appropriate legal basis exists under Article 9 GDPR.
4. Security Measures
We implement appropriate technical and organizational measures pursuant to Article 32 GDPR to ensure a level of protection appropriate to the risk. This includes, in particular, the encrypted transmission of our website using TLS/SSL.
5. Website and Web Hosting by Webflow
Our website is hosted by Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA.
When the website is accessed, the following data may be processed in particular:
- IP address;
- Date and time of access;
- Browser type and version;
- Operating system;
- Referrer URL;
- Amount of data transferred;
- Technical and security-related information.
The processing is carried out to provide, secure and ensure the stability of the website and is based on Article 6(1)(f) GDPR.
Further information:
6. Contact by Contact Form, Telephone or Email
If you contact us via contact form, email or telephone, we process the data you provide, in particular your name, contact details and the content of your message, in order to process and respond to your inquiry.
The legal bases are:
- Article 6(1)(b) GDPR, where the inquiry relates to the preparation or performance of a contract;
- Otherwise, Article 6(1)(f) GDPR, based on our legitimate interest in processing inquiries.
We delete the data once the inquiry has been conclusively dealt with, unless statutory retention obligations apply or continued storage is necessary for the establishment, exercise or defense of legal claims.
7. Email Communication and Gmail/Google Workspace
For our business email communication, we use Google Workspace, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Depending on the configuration used, data may also be processed by affiliated companies of Google, including Google LLC in the USA.
When communicating by email, the following data may be processed in particular:
- Email address;
- Name, if provided;
- Content and attachments of the message;
- Date and time of the communication;
- Technical communication data.
The processing is carried out to process inquiries, implement pre-contractual or contractual measures and fulfill legal obligations. The legal bases are Article 6(1)(b), Article 6(1)(c) and, where applicable, Article 6(1)(f) GDPR.
Google may transfer personal data to third countries.
We use the professional cloud service Google Workspace for our business email communication and office organization. The standard Google Workspace terms of use apply. We have electronically concluded a data processing agreement with the provider, known as the Data Processing Amendment. Transfers of data to the USA are legally safeguarded by the EU-U.S. Data Privacy Framework and, additionally, by the incorporation of the EU Standard Contractual Clauses.
Further information:
https://policies.google.com/privacy?hl=en-US
8. Table Reservations via Tock
For managing table reservations, we use the Tock service provided by Tock, LLC, 320 N. Sangamon St., Floor 6, Chicago, IL 60607, USA.
The following data may be processed in particular as part of a reservation:
- Name;
- Email address;
- Telephone number;
- Date, time and number of persons;
- Special occasions and requests;
- Where applicable, payment or credit card details, particularly for deposits, events or no-show arrangements.
The processing is carried out to handle the reservation and implement pre-contractual or contractual measures pursuant to Article 6(1)(b) GDPR.
Tock may process data in the USA.
Further information:
https://www.exploretock.com/privacy
9. Gift Up Vouchers
We use the Gift Up service, provided by Koan Adventures Ltd., Burnt Ash House, Cirencester Road, Chalford, Stroud, England, GL6 8PE, to sell and redeem digital gift vouchers.
As part of the sale of gift vouchers, the following data may be processed in particular:
- Name and contact details of the purchaser and, where applicable, the recipient;
- Email address and, where applicable, postal address;
- Voucher and order details;
- Payment and transaction information;
- Technical data, in particular IP address and times of use;
- Information concerning voucher redemption and voucher status.
The processing is carried out to perform and administer the voucher contract, in particular to sell, issue, manage, and redeem vouchers, on the basis of Article 6(1)(b) GDPR. Where processing is necessary to comply with statutory retention and documentation obligations, the legal basis is Article 6(1)(c) GDPR. Processing for the prevention and investigation of fraud may be based on Article 6(1)(f) GDPR. Our legitimate interest in this regard is the secure processing of voucher sales and protection against fraudulent transactions.
Gift Up has informed us that, as a SaaS provider, it acts as a data processor with regard to our customers’ personal data and provides an updated Data Processing Agreement (DPA) reflecting the requirements of the GDPR for merchants. According to Gift Up, no individually signed copy of the DPA exists. Processing is therefore carried out on the basis of the DPA provided by Gift Up and the corresponding contractual provisions, insofar as these have been validly incorporated into the contractual relationship.
Gift Up has also informed us that it uses service providers such as Microsoft Azure to provide its services. According to Gift Up, these services are operated almost exclusively in the United Kingdom. Where services outside the European Union or the United Kingdom are used, they are intended to be used only to a limited extent, primarily for resilience and business-continuity purposes. According to Gift Up, such services are not used for the permanent storage of our customers’ personal data.
For transfers of personal data to countries outside the European Union or the United Kingdom, appropriate safeguards under data protection law are used, in particular the EU Standard Contractual Clauses, unless an adequacy decision or another lawful transfer mechanism applies. The former EU-U.S. Privacy Shield is not used as a transfer mechanism, as it is no longer valid.
Further information about data processing by Gift Up and the applicable data protection provisions can be found in Gift Up’s privacy policy and contractual documents: https://help.giftup.com/article/40-privacy-policy
The data will be deleted as soon as it is no longer required for the purposes stated above, unless statutory retention or documentation obligations provide otherwise. Business and tax-related data may be retained for the periods required by law.
10. Payment Processing via Stripe
For payment processing, we use Stripe. Stripe’s payment functions are not directly integrated into our website. Instead, payments are initiated through the platforms we use:
- Gift Up for gift vouchers and gift cards; and
- Tock for payments connected with reservations, bookings, events and similar services.
Depending on the transaction, you may be redirected to a payment page provided by Gift Up or Tock. Payment data may then be transmitted to Stripe through the relevant platform.
The contracting party for the Stripe services is:
Stripe Technology Europe Limited
1 Grand Canal Street Lower
Dublin 2, Ireland
Stripe processes payment-related data for the technical processing of payments, fraud prevention, compliance with legal obligations and the security of the payment infrastructure.
The following data may be processed in particular:
- Name and, where applicable, contact details;
- Payment and billing information;
- Payment method;
- Payment amount and currency;
- Transaction and payment status;
- Transaction or payment reference;
- IP address and technical device and browser data;
- Where applicable, the last four digits of the payment card; and
- Data relating to fraud-prevention and security checks.
Payment data is generally transmitted to Stripe via Tock or Gift Up. We do not necessarily receive complete payment card details. Complete card details are generally processed by Stripe or by the payment service providers used for the respective transaction.
Stripe is used in particular for the following transactions:
- Payments for gift vouchers and gift cards via Gift Up;
- Deposits connected with reservations or bookings;
- Reservation deposits;
- Payments connected with events or other bookings; and
- Where applicable, no-show fees.
The processing is necessary to perform and process the respective contract pursuant to Article 6(1)(b) GDPR. Processing may also be carried out:
- To comply with legal obligations, particularly obligations under tax, commercial, anti-money-laundering and payment law, pursuant to Article 6(1)(c) GDPR; and
- For fraud prevention, payment security, and the establishment, exercise or defence of legal claims, on the basis of Article 6(1)(f) GDPR.
Data Processing Agreement
Stripe has informed us that its Data Processing Agreement (DPA) is available online and forms part of the Stripe Services Agreement. There is therefore no separate, individually signed DPA.
The current Stripe DPA is available at:
<https://stripe.com/legal/dpa>
Transfers to Third Countries
Stripe may process personal data in, or transfer personal data to, countries outside the European Economic Area. According to Stripe’s information, the following transfer mechanisms may be used, depending on the circumstances:
- The EU Standard Contractual Clauses issued by the European Commission;
- The UK Addendum to the International Data Transfer Agreement;
- The EU-U.S. Data Privacy Framework; and
- The UK extension to the EU-U.S. Data Privacy Framework.
The transfer mechanism applicable in an individual case may depend on the type of data, the place of processing and the particular Stripe service involved. Further information is available in Stripe’s Data Transfer Addendum:
Storage Period
Stripe stores personal data for as long as necessary for the relevant processing purposes. In addition, statutory retention obligations—particularly those relating to the prevention of terrorist financing and money laundering, fraud monitoring and prevention, and tax, accounting and financial reporting—may require data to be retained for longer periods.
According to Stripe, identity-verification data is generally retained in the Stripe Dashboard for three years. Different retention periods may apply to other data, depending on the type of data and the purpose of processing.
Further Information
Further information about Stripe’s processing of personal data is available in Stripe’s Privacy Policy:
https://stripe.com/en-de/privacy
Additional information can be found in the Stripe Privacy Center:
https://stripe.com/legal/privacy-center
Stripe’s current privacy policy and contractual documents contain the authoritative information regarding Stripe’s processing activities, retention periods and international data transfers.
11. Payment Processing in the Restaurant via orderbird and Worldline
For processing payments in our restaurant, we use the orderbird point-of-sale system. orderbird is used in particular to record and document orders, invoices and payment transactions.
Payment transactions are processed through the payment service provider Worldline. Worldline is used in particular for card payments and other payment methods offered via the payment terminal.
The following data may be processed in particular as part of cash-register and payment processing:
- Invoice and payment amount;
- Date and time of the payment transaction;
- Payment method used;
- Transaction and receipt data;
- Information about cancellations, refunds and payment changes;
- Where applicable, name and billing address, if provided;
- Technical data relating to the point-of-sale system and payment terminals;
- Where applicable, pseudonymized payment or transaction identifiers.
We use orderbird and Worldline in particular for the following purposes:
- Recording and processing payments in the restaurant;
- Issuing receipts, invoices and, where applicable, hospitality receipts;
- Processing cancellations and refunds;
- Billing and accounting;
- Fulfilling tax, commercial and other legal obligations;
- Payment security and prevention of improper or fraudulent payment transactions.
The processing is based on:
- Article 6(1)(b) GDPR, where processing is necessary to perform the contract for the services you use;
- Article 6(1)(c) GDPR, where processing is necessary to comply with legal obligations, particularly statutory tax and accounting retention obligations;
- Article 6(1)(f) GDPR, where processing is necessary for the secure and proper handling of payments, fraud prevention and the efficient organization of our business operations.
We generally do not store complete payment card numbers or PIN data. Where necessary, this data is processed directly by Worldline, the payment terminal used and the payment service providers involved.
Data processed as part of cash-register and payment processing is deleted as soon as it is no longer required for the stated purposes. Data forming part of business records that must be retained under tax, commercial or other statutory requirements is stored for the applicable statutory retention periods.
The provider of the point-of-sale system is:
orderbird GmbH
Ritterstraße 12, Ste. 3
10969 Berlin
Germany
Payment processing is carried out via:
Worldline
Tour Voltaire, 1 Place des Degrés
CS 81162
92059 Paris La Défense Cedex
France
Further information about data protection is available in the current privacy information of orderbird and Worldline:
https://www.orderbird.com/en/privacy
https://worldline.com/en/compliancy/privacy
12. Instagram Feed via Instafeed.org
On our website, we use Instafeed Social Networking Private Limited, House No. 843, Sector 15, Faridabad, Haryana, 121006, India, to embed content from our Instagram account.
Depending on the technical implementation, a connection to Instafeed.org, Instagram or Meta may already be established when the relevant website is accessed. In particular, the IP address, browser and device information, time of access and technical usage data may be processed. If content is loaded directly from Instagram or Meta, these providers may also process access data for their own purposes.
13. Our Instagram and Facebook Profiles
https://www.instagram.com/barra_berlin/
@barra_berlin
https://www.facebook.com/barraberlin/
@barraberlin
We operate our own profiles on Instagram and Facebook. If you communicate with us through these platforms, we may receive and process the following data in particular:
- Your username and, where applicable, your publicly visible name;
- The content of your message or comment;
- Profile picture and publicly visible profile information;
- Where applicable, information that you voluntarily provide to us;
- Information about the communication history.
We use this data to respond to inquiries, communicate with guests and maintain our social media profiles. Depending on the content, the legal basis is Article 6(1)(b) or Article 6(1)(f) GDPR. Storage may also be necessary to fulfill legal obligations or for the establishment, exercise or defense of legal claims.
Please note that Instagram and Facebook also process data for their own purposes. We have only limited influence over this processing. Meta’s privacy information also applies:
https://www.facebook.com/privacy/policy/
https://privacycenter.instagram.com/policy/
If you use Facebook or Instagram page statistics or “Insights,” it must also be reviewed whether an agreement on joint controllership with Meta and a separate notice concerning Insights are required.
14. Recipients and Data Processing
We transfer personal data only where there is a legal basis for doing so. Recipients may include, in particular:
- Webflow, Inc. – hosting;
- Tock – reservation management;
- Koan Adventures Ltd./Gift Up – voucher processing;
- Stripe – payment processing;
- [Instafeed provider – social media feed; insert exact name];
- Google Ireland Limited or Google Workspace – email communication;
- Instagram and Facebook/Meta – communication and, where applicable, embedded content;
- Tax advisors, banks, payment service providers and other necessary service providers;
- Authorities and other bodies where there is a legal obligation to disclose data.
Where required, data processing agreements pursuant to Article 28 GDPR are concluded with processors. Not every recipient is automatically a processor. Depending on the processing activity, Stripe, Meta and potentially other providers may act partly or entirely as independent controllers.
15. Transfers to Third Countries
Some service providers may transfer data to countries outside the European Economic Area, particularly the USA. Such transfers take place only where the requirements of Articles 44 et seq. GDPR are met, for example on the basis of an adequacy decision, certification under the EU-U.S. Data Privacy Framework or appropriate safeguards such as Standard Contractual Clauses.
16. Data Retention
We delete personal data as soon as the purpose for processing it no longer applies, unless statutory retention obligations apply or continued storage is necessary for the establishment, exercise or defense of legal claims.
Business and tax-relevant documents are retained in accordance with the statutory retention periods.
17. Rights of Data Subjects
Subject to the applicable legal requirements, you have the following rights:
- Right of access pursuant to Article 15 GDPR;
- Right to rectification pursuant to Article 16 GDPR;
- Right to erasure pursuant to Article 17 GDPR;
- Right to restriction of processing pursuant to Article 18 GDPR;
- Right to data portability pursuant to Article 20 GDPR;
- Right to object to processing based on Article 6(1)(e) or Article 6(1)(f) GDPR pursuant to Article 21 GDPR;
- Right to withdraw consent at any time with effect for the future pursuant to Article 7(3) GDPR;
- Right to lodge a complaint with a data protection supervisory authority pursuant to Article 77 GDPR.
18. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy if our website, services or legal requirements change.
This Privacy Policy is dated 5 August 2026.
