General Privacy Notice

This Privacy and Data Protection Policy applies to any individual (hereinafter “Data Subjects”) whose Personal Data is processed by WE ARE ONA, in compliance with the General Data Protection Regulation (GDPR) adopted on April 27, 2016, by the European Parliament and the Council.

When you visit our website, WE ARE ONA (hereinafter “we”) collects your Personal Data to use in various automated processing activities.

Definitions

  • Personal Data: Refers to any information relating to an identified or identifiable natural person (hereinafter “Personal Data”);
  • DPO: The Data Protection Officer (DPO) is responsible for ensuring compliance with the GDPR within the organization; and
  • Data Controller: The Data Controller is the natural or legal person who determines the purposes and means of processing. Typically, this is the legal entity represented by its legal representative. The Data Controller is WE ARE ONA.

Our Commitments

We process your Personal Data in accordance with Regulation (EU) 2016/679 of the European Parliament and Council, known as the GDPR.

We are committed to safeguarding your Personal Data. Only authorized personnel trained in confidentiality rules participate in the management of the weareona.co website.

WE ARE ONA implements the relevant technical and organizational measures in order to comply with the applicable regulations and, more specifically, to protect Personal Data against any accidental or illicit destruction, loss, alteration, disclosure or unauthorized access.

In the event of a data security breach affecting your Personal Data, WE ARE ONA will inform you within the timeframes and under the conditions specified by applicable legal and regulatory provisions.

Information Obligations

Article 13 of the GDPR requires us to inform you about:

  • The identity and contact details of the Data Controller and, where applicable, the Data Controller’s representative;
  • The purposes of the processing for which the Personal Data is intended and the legal basis for the processing;
  • The recipients or categories of recipients of the Personal Data, if any; and
  • The period for which the Personal Data will be stored or, if that is not possible, the criteria used to determine that period.

The Personal Data We Process

We collect and process the following Personal Data:

Data collected to send our newsletter

Personal Data collected Purpose Legal Basis Retention Period
Email address Newsletter management Consent 3 years since your last contact with us

Data collected to manage your reservation

Personal Data collected Purpose Legal Basis Retention Period
First name, last name, email address, dietary requirements Reservation management Legitimate interest 3 years since your reservation

Data collected when you browse our website

Personal Data collected Purpose Legal Basis Retention Period
IP address Managing visitor browsing information Legitimate interest 3 years

Data recorded when you receive our email communications

Personal Data collected Purpose Legal Basis Retention Period
IP address, last name, first name, email address Pixel placement for: analysis of email open rates for deliverability purposes; analysis of email open rates to measure and optimize campaign performance Consent 13 months

To find out more about data processing through the use of cookies, you can view our cookie policy by clicking here.

Recipients of Personal Data

Personal Data collected on the weareona.co website is primarily intended for WE ARE ONA. However, it may be shared with our partners, service providers or subcontractors.

To facilitate website maintenance, reservation management and newsletter management, some of your data may also be shared with our subcontractors.

The list of our partners, service providers and subcontractors that may process your Personal Data is set out below:

Partner / Service Provider / Subcontractor Purpose
Tock Reservation management
Infomaniak Website hosting
XXXX XXXX

We ensure that all our partners and subcontractors are subject to adequate Personal Data protection mechanisms and comply with GDPR requirements, and that data is processed only by authorized personnel bound by a confidentiality agreement or equivalent contractual document.

Exercising Your GDPR Rights

Right of access and rectification of your data. You have the right to obtain from the Data Controller confirmation as to whether or not Personal Data concerning you is being processed and, where that is the case, the right to access and/or have such data rectified (see Articles 15 and 16 of the GDPR).

Right to erasure of your data. In accordance with Article 17 of the GDPR, you have the right to request the erasure of your Personal Data without undue delay, in the cases provided for therein.

Right to restriction of processing. You have the right to request the restriction of the processing of your Personal Data in the cases provided for in Article 18 of the GDPR.

Right to object to processing. In accordance with Article 21 of the GDPR, you have the right to object to the processing of Personal Data concerning you where the processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data, in particular where the Data Subject is a child.

Right to data portability. You have the right to the portability of your Personal Data, which allows you to receive the Personal Data you have provided to us in a structured, commonly used and machine-readable format, as well as the right to transmit that data to another Data Controller. The exercise of this right is subject to the conditions set out in Article 20 of the GDPR.

Right to withdraw your consent. In accordance with Article 7 of the GDPR, where processing is based on consent, you have the right to withdraw your consent at any time. This will terminate the processing of your data.

Right to define post-mortem directives. You have the right to define instructions regarding the retention, erasure and disclosure of your Personal Data after your death, by appointing a trusted third party, duly certified and responsible for ensuring compliance with the deceased’s wishes in accordance with the applicable legal framework (Article 85 of French Law No. 78-17 of 6 January 1978 relating to data processing, files and freedoms).

How to Exercise Your Rights

You may exercise your rights by sending your request to the following email address: hello@weareona.co, or by post accompanied by a copy of an identity document, addressed to WE ARE ONA at the following address: 68 rue RenĂ© Boulanger, 75010 Paris, France.

You may also lodge a complaint with the CNIL.

Updates to This Policy

In order to comply with regulatory changes and to reflect our practices, we reserve the right to amend this policy. Any changes will be published in this document; we recommend that you consult our privacy policy regularly.


Updated: 12 August 2026