Privacy Policy

Last Updated: December 22, 2024

Effective Date: December 22, 2024

1. Overview

Restaurant Krong Thai is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit our website, contact us, or use our services.

We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Law 25, and other applicable privacy laws in Canada. For visitors from the European Union, we also comply with the General Data Protection Regulation (GDPR).

By using our website or services, you consent to the collection and use of your personal information as described in this policy.

2. Contact Information

**Restaurant Name:** Krong Thai

**Address:** 205 Rue Bellehumeur, Gatineau, QC J8T 8H3

**Phone:** (819) 243-5000

**Privacy Officer:** Restaurant Manager

**Privacy Contact:** [email protected]

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us using the information above.

3. Information We Collect

3.1 Information You Provide Directly

  • **Contact Form Submissions:** Name, email address, phone number, inquiry type, and message content
  • **Phone Communications:** Call details, customer service requests, and reservation information
  • **Email Communications:** Your email address when you contact us directly

3.2 Information Collected Automatically

  • **Website Analytics:** IP address, browser type, device information, pages visited, time spent on site, and referral sources (via Google Analytics)
  • **Cookies and Similar Technologies:** Session cookies, preference cookies, and analytics cookies
  • **Location Data:** General geographic location based on IP address for service area verification

3.3 Third-Party Platform Information

  • **Online Ordering:** When you use our third-party ordering platform (krongthai.order-online.ai), your information is collected and processed according to their privacy policy
  • **Social Media:** If you interact with us on social media platforms, we may receive information according to those platforms' terms

4. How We Use Your Information

4.1 Primary Business Purposes

  • Responding to your inquiries and providing customer service
  • Processing reservations and managing restaurant operations
  • Communicating about our services, hours, and special offers
  • Improving our website and services based on usage patterns

4.2 Analytics and Website Improvement

  • Understanding how visitors use our website through Google Analytics
  • Identifying popular content and improving user experience
  • Analyzing traffic patterns and optimizing website performance

4.3 Legal and Safety Purposes

  • Complying with applicable laws and regulations
  • Protecting our business interests and preventing fraud
  • Responding to legal requests and law enforcement when required

5. Information Sharing and Disclosure

5.1 Third-Party Service Providers

  • **Google Analytics:** For website analytics and performance monitoring
  • **Online Ordering Platform:** krongthai.order-online.ai processes orders independently
  • **Email Services:** For business communications and customer service
  • **Website Hosting:** Netlify for website hosting and content delivery

5.2 Business Operations

  • **Staff Training:** Anonymous feedback data may be used for staff training purposes
  • **Business Analytics:** Aggregated, non-personal data for business decision-making

5.3 Legal Requirements

  • We may disclose your information when required by law, court order, or regulatory authority
  • In case of emergency situations to protect health and safety

5.4 Business Transactions

  • In the event of a sale, merger, or transfer of our business, personal information may be transferred to the new owner under the same privacy protections

6. Cookies and Tracking Technologies

6.1 Types of Cookies We Use

  • **Necessary Cookies:** Essential for website functionality, security, and accessibility
  • **Analytics Cookies:** Google Analytics to understand website usage and improve performance
  • **Preference Cookies:** Remember your language and accessibility preferences

6.2 Third-Party Cookies

  • **Google Analytics:** Tracks website usage with anonymized data
  • **External Platforms:** Third-party ordering and social media platforms may set their own cookies

6.3 Your Cookie Choices

  • You can control cookie preferences through our cookie banner when you first visit
  • Browser settings allow you to block or delete cookies
  • Disabling certain cookies may limit website functionality

6.4 Cookie Consent Management

  • We use a consent management system compliant with GDPR and Canadian privacy laws
  • You can withdraw consent at any time by clearing your browser cookies
  • Essential cookies cannot be disabled as they are necessary for basic website operation

7. Data Retention

7.1 Retention Periods

  • **Contact Form Data:** Retained for 2 years for customer service and follow-up purposes
  • **Analytics Data:** Google Analytics data is retained for 26 months
  • **Email Communications:** Business emails retained for 7 years as per business record requirements
  • **Phone Records:** Call logs retained for 1 year for customer service quality

7.2 Deletion Criteria

  • Data is automatically deleted after retention periods expire
  • Data is immediately deleted upon valid deletion requests
  • Business-critical data may be retained longer for legal compliance

7.3 Secure Deletion

  • All deleted data is securely destroyed using industry-standard methods
  • Backup systems are also purged according to retention schedules

8. Your Privacy Rights

Under Canadian privacy laws (PIPEDA and Quebec Law 25) and GDPR, you have the following rights:

8.1 Access and Information

  • Right to know what personal information we have about you
  • Right to receive a copy of your personal information
  • Right to know how your information is being used

8.2 Correction and Updates

  • Right to correct inaccurate personal information
  • Right to update outdated information
  • Right to complete incomplete information

8.3 Deletion and Erasure

  • Right to request deletion of your personal information
  • Right to be forgotten (subject to legal retention requirements)
  • Right to have data erased when no longer necessary

8.4 Consent Management

  • Right to withdraw consent for data processing
  • Right to object to processing based on legitimate interests
  • Right to restrict processing in certain circumstances

8.5 Data Portability

  • Right to receive your data in a structured, machine-readable format
  • Right to transfer your data to another service provider

8.6 How to Exercise Your Rights

  • Call us at (819) 243-5000 during business hours
  • We will respond within 30 days as required by law
  • Identity verification may be required for security purposes

9. Data Security

9.1 Technical Safeguards

  • SSL/TLS encryption for all website communications
  • Secure hosting with regular security updates and monitoring
  • Regular security assessments and vulnerability testing
  • Access controls and authentication for staff systems

9.2 Organizational Safeguards

  • Staff training on privacy and data protection practices
  • Limited access to personal information on a need-to-know basis
  • Regular privacy policy reviews and updates
  • Incident response procedures for data breaches

9.3 Data Breach Response

  • Immediate containment and assessment of any security incident
  • Notification to privacy authorities within 72 hours as required by law
  • Direct notification to affected individuals without undue delay
  • Documentation and analysis to prevent future incidents

10. Third-Party Services

10.1 Online Ordering Platform

  • **Service:** krongthai.order-online.ai
  • **Data Processing:** Orders are processed independently by this platform
  • **Privacy Policy:** Subject to their own privacy policy and terms
  • **Data Sharing:** We do not control or access customer data from this platform

10.2 Google Analytics

  • **Purpose:** Website traffic analysis and performance monitoring
  • **Data Collected:** Anonymized usage statistics and website behavior
  • **Privacy Policy:** Subject to Google's Privacy Policy
  • **Opt-Out:** Available through Google Analytics opt-out browser add-on

10.3 Website Hosting

  • **Service:** Netlify
  • **Data Processing:** Website hosting and content delivery
  • **Security:** Industry-standard security measures and data protection
  • **Location:** Data may be processed in various global locations

10.4 Third-Party Links

  • Our website may contain links to external websites
  • We are not responsible for the privacy practices of external sites
  • We encourage you to review the privacy policies of any external sites you visit

11. International Data Transfers

11.1 Service Providers

  • Some of our service providers (Google Analytics, Netlify) may process data outside Canada
  • These transfers are protected by appropriate safeguards including:

- Standard Contractual Clauses approved by privacy authorities

- Adequacy decisions by Canadian and European authorities

- Certification schemes and codes of conduct

11.2 Cross-Border Processing

  • Data may be processed in the United States and European Union
  • All transfers comply with applicable privacy laws and regulations
  • We ensure appropriate legal protections are in place before any transfer

12. Children's Privacy

12.1 Age Restrictions

  • Our website and services are not directed to children under 13 years of age
  • We do not knowingly collect personal information from children under 13
  • If we discover we have collected information from a child under 13, we will delete it immediately

12.2 Parental Rights

  • Parents have the right to review and request deletion of their child's information
  • Parents can contact us to exercise these rights on behalf of their children

12.3 Family Dining

  • When families dine with us, we only collect information from adults who make reservations or provide contact details

13. Policy Updates

13.1 Notification of Changes

  • We may update this Privacy Policy to reflect changes in our practices or legal requirements
  • Material changes will be posted prominently on our website
  • We will notify you via email if you have provided your email address to us
  • The 'Last Updated' date at the top of this policy indicates when it was last revised

13.2 Continued Use

  • Your continued use of our website and services after policy updates constitutes acceptance
  • If you do not agree with updated terms, please discontinue use and contact us about data deletion

13.3 Version History

  • Previous versions of this policy are available upon request
  • We maintain records of policy changes for transparency and compliance

14. Privacy Complaints and Disputes

14.1 Internal Complaint Process

  • We will acknowledge your complaint within 5 business days
  • We will investigate and respond within 30 days
  • If you are not satisfied with our response, you may escalate to privacy authorities

14.2 Privacy Authority Contacts

  • **Federal (PIPEDA):** Office of the Privacy Commissioner of Canada

- Website: priv.gc.ca

- Phone: 1-800-282-1376

  • **Quebec (Law 25):** Commission d'accès à l'information du Québec

- Website: cai.gouv.qc.ca

- Phone: 1-888-528-7741

  • **EU Residents:** Your local Data Protection Authority

- List available at: edpb.europa.eu

Contact us about privacy

Contact Information

Phone: (819) 243-5000
Email: [email protected]
Address: 205 Rue Bellehumeur, Gatineau, QC

Privacy Authorities

Federal: priv.gc.ca
Quebec: cai.gouv.qc.ca
EU: edpb.europa.eu