GDPR Compliance
Last updated: 11/30/2025
Introduction
Bary's Sky Lounge ("we," "our," or "us") is committed to protecting your personal data and ensuring compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This page explains your rights under GDPR and how we handle your personal data in accordance with these regulations.
What is GDPR?
The General Data Protection Regulation (GDPR) is a European Union regulation that came into effect on May 25, 2018. It provides individuals with greater control over their personal data and requires organizations to be transparent about how they collect, use, and protect personal information.
While GDPR is an EU regulation, we apply these principles globally to ensure all our users receive the same level of data protection regardless of their location.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: You have given clear consent for us to process your personal data for specific purposes (e.g., analytics, advertising cookies)
- Legitimate Interests: Processing is necessary for our legitimate interests (e.g., website security, fraud prevention)
- Legal Obligation: Processing is necessary for compliance with a legal obligation
- Contract Performance: Processing is necessary for the performance of a contract with you
Consent Management: We use a cookie consent banner that allows you to provide granular consent for different types of data processing. You can withdraw your consent at any time by updating your cookie preferences.
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
1. Right to Access (Article 15)
You have the right to obtain confirmation as to whether or not we process your personal data and, if we do, to access that data and receive information about how it is being processed.
2. Right to Rectification (Article 16)
You have the right to have inaccurate personal data corrected and incomplete personal data completed.
3. Right to Erasure / "Right to be Forgotten" (Article 17)
You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the original purpose or when you withdraw your consent.
4. Right to Restrict Processing (Article 18)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
5. Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
6. Right to Object (Article 21)
You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
7. Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
8. Right to Withdraw Consent (Article 7)
When processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
How to Exercise Your Rights
To exercise any of your GDPR rights, you can:
- Contact us through our contact page
- Update your cookie preferences through our consent banner
- Use your browser settings to manage cookies
- Send a written request to our data protection contact (see Contact Information below)
We will respond to your request within one month (or two months for complex requests). We may need to verify your identity before processing your request to ensure the security of your personal data.
Data We Collect and Process
We collect and process the following categories of personal data:
Personal Data You Provide
- Name and email address (when subscribing to newsletters or contacting us)
- Contact information (when using contact forms)
- Cookie consent preferences
Automatically Collected Data (With Consent)
- IP address (anonymized when possible)
- Browser type and version
- Device information
- Pages visited and time spent on website
- Referring website addresses
- Cookies and tracking technologies (see our Cookie Policy)
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Cookie consent preferences: Stored in your browser's localStorage until you clear it
- Contact form submissions: Retained for up to 2 years or until you request deletion
- Newsletter subscriptions: Retained until you unsubscribe
- Analytics data: Aggregated and anonymized data may be retained for longer periods for statistical purposes
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (HTTPS/SSL)
- Secure hosting infrastructure
- Regular security assessments
- Access controls and authentication
- Data anonymization where possible
Data Transfers
Some of our third-party service providers (such as Google Analytics, Google AdSense, and Yandex Metrica) may process your data outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Privacy Shield Framework (where applicable)
These transfers only occur with your explicit consent through our cookie consent banner.
Third-Party Processors
We use the following third-party processors that may process your personal data:
- Google Analytics: Website analytics (requires your consent)
- Yandex Metrica: Website analytics (requires your consent)
- Google AdSense: Advertising services (requires your consent)
- Hosting Providers: Website hosting and infrastructure
All third-party processors are required to comply with GDPR and have appropriate data protection measures in place. We only share data with processors that have your consent or are necessary for the operation of our website.
Consent Management
We use a cookie consent banner that complies with GDPR requirements. This banner:
- Provides clear information about the types of cookies we use
- Allows you to provide granular consent for different cookie categories
- Enables you to accept all, reject all, or customize your preferences
- Stores your preferences for future visits
- Allows you to change your preferences at any time
Google Consent Mode v2: We implement Google Consent Mode v2 to ensure that Google services respect your privacy choices. When you reject certain cookie categories, these services operate in a privacy-preserving mode that limits data collection while still providing basic functionality.
Right to Lodge a Complaint
If you believe that we have not adequately addressed your concerns or that we are processing your personal data in violation of GDPR, you have the right to lodge a complaint with your local data protection authority.
For EU residents, you can find your local data protection authority at: European Data Protection Board
Children's Privacy
Our website is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately, and we will delete such information.
Changes to This GDPR Compliance Statement
We may update this GDPR Compliance Statement from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated statement on this page and updating the "Last updated" date.
Contact Information
If you have any questions about this GDPR Compliance Statement, wish to exercise your GDPR rights, or have concerns about how we handle your personal data, please contact us:
- Through our contact page
- By updating your cookie preferences through our consent banner
For more information about our data practices, please also review our Privacy Policy and Cookie Policy.