Privacy Policy
Privacy Policy
1. Controller and Data Protection Officer
Controller within the meaning of the GDPR:
100 Gramm GmbH
Weinbergsweg 25
10119 Berlin, Germany
E-mail: claudius@100gramm.berlin
Phone: 030 896 52057
Represented by the Managing Director: Claudius-Roman Wiehe
External Data Protection Officer:
Simon Pokrony
DLx Media
Badstraße 49
13357 Berlin, Germany
E-mail: 100grammvino@dlx-media.com
Web: www.dlx-media.com
2. General Information on Data Processing
Protecting your personal data is important to us. We process your data exclusively on the basis of the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
You can generally use our website without providing personal data. Where personal data is collected on our pages, this is done on a voluntary basis or where legally required. Our website operates without the use of consent-requiring cookies or tracking technologies.
3. Hosting and Server Log Files
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located exclusively in Germany. The technical administration of the website is carried out by DLx Media, Badstraße 49, 13357 Berlin, Germany.
We have concluded data processing agreements in accordance with Art. 28 GDPR with both service providers, obliging them to process data in a manner that follows our instructions and complies with data protection law.
When you access our website, the hosting provider automatically stores general technical access data in so-called server log files. This includes:
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
- Date and time of access
- IP address (anonymized)
- Internet service provider
This data is processed exclusively to ensure technical operation, for error analysis and to defend against attacks. It is not merged with other personal data.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the website).
Storage period: The log files are automatically deleted after no later than 30 days.
4. Website Analytics with DLx Analytics
To analyze usage behavior on our website, we use the service DLx Analytics provided by DLx Media, Badstraße 49, 13357 Berlin, Germany (www.dlx-analytics.com).
DLx Analytics is a privacy-compliant analytics solution based in Germany. The service works without cookies, without fingerprinting and without collecting personal data. Only anonymized, aggregated usage statistics are recorded (e.g. page views, time on site, country of origin). Identification of individual persons is technically impossible.
Since no information is stored on or read from your device, neither consent under Section 25 TDDDG nor consent under the GDPR is required. No data is transferred to third countries outside the EU.
5. Local Provision of Fonts and Resources
To ensure a consistent and appealing presentation of our content, we integrate fonts as well as other resources required for display (e.g. scripts, images, icons) exclusively locally from our own server.
No connection to third-party servers – such as Google Fonts or external content delivery networks (CDNs) – takes place in the process. As a result, no personal data (in particular, not your IP address) is transmitted to third parties.
6. Contact Form
You can send us a message via a contact form on our website. The data you enter (e.g. name, e-mail address, message) is used exclusively to process your request and is not passed on to third parties.
Legal basis: Art. 6(1)(b) GDPR (initiation of a contract or pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).
Storage period: Your data will be deleted once your request has been fully processed and no statutory retention obligations apply.
7. Table Reservations via SevenRooms
For table reservations, we use the service SevenRooms provided by SevenRooms Inc., 228 Park Ave S, PMB 73540, New York, NY 10003, USA.
The reservation function is integrated in a data-minimizing way: simply accessing our website does not yet transmit any data to SevenRooms. A connection to SevenRooms' servers and a transfer of your data only take place once you actively click the "Reserve" button and start the reservation process.
As part of the reservation, the data you provide is processed, in particular your name, e-mail address, phone number, date, time, number of guests, and any additional information (e.g. special requests). This data is used exclusively to carry out and manage your reservation and for related confirmation and reminder messages. SevenRooms acts as a processor on our behalf; a data processing agreement in accordance with Art. 28 GDPR has been concluded.
SevenRooms Inc. is based in the USA. Any transfer of personal data to the USA takes place on the basis of the European Commission's adequacy decision for the EU-US Data Privacy Framework, under which SevenRooms is certified (Art. 45 GDPR). In addition, SevenRooms has implemented the European Commission's Standard Contractual Clauses (Art. 46 GDPR).
Legal basis: Art. 6(1)(b) GDPR (performance of pre-contractual or contractual measures to provide the reservation you have expressly requested). The reservation tool is only loaded as a result of your active click on "Reserve" (Section 25(2) no. 2 TDDDG).
Storage period: Your reservation data will be deleted once it is no longer required for the stated purposes and no statutory retention obligations apply.
For further information on how SevenRooms handles data, please see sevenrooms.com/privacy-policy.
8. Newsletter
You can subscribe to our newsletter on our website. We use the double opt-in procedure: after signing up, you will receive a confirmation e-mail through which you must actively confirm your subscription. Only then will your e-mail address be added to our distribution list.
At the time of registration, we store your e-mail address and the timestamp of your confirmation. This data is used exclusively to send the newsletter and is not passed on to third parties. The newsletter is sent via our own, self-operated infrastructure.
You can unsubscribe from the newsletter at any time. Every newsletter contains a corresponding unsubscribe link. After you unsubscribe, your e-mail address will be deleted from our distribution list without delay.
Legal basis: Art. 6(1)(a) GDPR (consent).
9. Your Rights as a Data Subject
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR): You can request information about which data we have stored about you at any time.
- Rectification (Art. 16 GDPR): You have the right to have inaccurate data corrected.
- Erasure (Art. 17 GDPR): You can request the deletion of your data, provided no statutory retention obligations apply.
- Restriction of processing (Art. 18 GDPR): You can request that the processing of your data be restricted.
- Data portability (Art. 20 GDPR): You have the right to receive your data in a common, machine-readable format.
- Objection (Art. 21 GDPR): You can object to the processing of your data based on legitimate interests at any time.
- Withdrawal (Art. 7(3) GDPR): You can withdraw any consent you have given at any time with effect for the future.
- Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59-61, 10555 Berlin.
To exercise your rights, please contact our Data Protection Officer (contact details in Section 1).
10. Applicant Data
You have the option to apply to us via the application form on our website (including file upload for your CV and other documents) or by e-mail. We process the personal data you submit (e.g. name, contact details, CV, references) exclusively for the purpose of carrying out the application procedure. The data is processed internally only and is not passed on to third parties.
The transmission of your application documents via our form is encrypted (HTTPS). Uploaded files are stored on our own servers and are accessible only to the persons involved in the application procedure.
Legal basis: Section 26 BDSG in conjunction with Art. 6(1)(b) GDPR.
Storage period: In the event of a rejection, your application documents, including uploaded files, will be deleted no later than 6 months after the conclusion of the application procedure. In the event of hiring, the data will be transferred to your personnel file.
If you expressly consent to longer storage in our applicant pool, we will retain your data for up to 2 years on the basis of Art. 6(1)(a) GDPR. You can withdraw this consent at any time.
11. Data Security
We use technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security measures are continuously improved in line with technological developments.
Data is transmitted on our website in encrypted form via the HTTPS protocol.
12. Currency of this Privacy Policy
This privacy policy is currently valid and is dated July 2026. As our website develops or due to changes in legal requirements, it may become necessary to amend this privacy policy. The current version is available on this page at any time.