Legal
Privacy policy
Last updated: 11 August 2026
This page is a translation for our English-speaking guests. The German version is the legally binding one.
1. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Kanpai GmbHAlexanderstraße 17, 52062 Aachen
Germany
Represented by the Managing Director: Mezbah Uddin Shaber
Phone: +49 (0) 241 91793702
WhatsApp: +49 (0) 157 55920499
Email: info@kanpaisushi.de
We have not appointed a data protection officer, and we are not required to: fewer than 20 people in our company are permanently engaged in the automated processing of personal data (§ 38 (1) BDSG). For any data protection question, reach us using the contact details above.
2. What this site loads — and what it does not
This website sets no cookies, uses no tracking and no analytics tools, and stores nothing in your browser. There are no web fonts from external servers, no embedded map, no videos and no social media plug-ins. For the same reason this site needs no cookie banner and no consent under § 25 TDDDG.
Text, photos and the menu's search function are served exclusively from our own server. Search terms and filters on the menu page take effect only in the open window; they are neither stored nor transmitted to us.
One single exception: the booking form on the "Book a table" page. It comes from resmio and is loaded only after you click "Load booking form" — see section 5. Until you do, visiting this website establishes no connection to any third party.
The references to our ordering shop, WhatsApp, Google Maps, Instagram and Facebook are ordinary links. They transmit nothing unless you follow them.
3. Server log files
When this page is requested, our hosting provider automatically stores data in what are known as server log files, transmitted by your browser:
- the address requested, and the date and time of the request
- the volume of data transferred and confirmation of a successful request
- browser type and version, operating system used
- the previously visited page (referrer), where transmitted
- IP address
Purpose and legal basis. This data is technically necessary to deliver the page, to ensure its stability and security, and to investigate misuse. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in the secure and trouble-free operation of this site. This data is not combined with other data sources, and we draw no conclusions about individuals from it.
Retention. Log files are deleted after 30 days at the latest, unless they are exceptionally needed for longer to investigate a specific security incident.
4. Hosting
This site is hosted with the following provider:
HOSTINGER INTERNATIONAL LIMITED61 Lordou Vironos str., 6023 Larnaca
Cyprus
The provider processes the data named in section 3 exclusively on our behalf and on our instructions. A data processing agreement under Art. 28 GDPR is in place with them. The servers hosting this site are located in the European Union.
5. Table reservations via resmio
For table reservations we use the service resmio:
resmio GmbHKatzwanger Str. 150, Gebäude 1c, 90461 Nürnberg
Germany
Amtsgericht Nürnberg, HRB 35433
Only on click. On the "Book a table" page you first see only a notice with a
button. The booking form itself is loaded only when you use that button. At that point your
browser connects to resmio's servers (static.resmio.com and
app.resmio.com) and, as is technically necessary, transmits your IP address and the
usual connection data. Until that click, no data is transmitted to resmio.
Legal basis. The form is loaded on your explicit action and serves to prepare the reservation contract; the legal basis is Art. 6 (1) (b) GDPR and, for the access to your device, your consent under § 25 (1) TDDDG, which you give with that click. You can always book by phone instead on +49 (0) 241 91793702, in which case nothing is transmitted to resmio.
What is processed. If you fill in and submit the form, resmio processes the reservation details you provide — typically name, email address, phone number, party size, date and time, and any note — in order to confirm the reservation and pass it to us. resmio acts on our behalf in doing so; a data processing agreement under Art. 28 GDPR is in place for that processing. resmio's own processing is additionally governed by their privacy policy.
We delete reservation data as soon as it is no longer needed to run the restaurant and no statutory retention periods apply.
6. Ordering online
You cannot order directly through this website. We link to two separate ordering channels, each of which is a separate website with its own privacy policy:
- Cash on collection — resmio's ordering module at app.resmio.com
- Paying online by card — our shop on the SumUp platform at kanpai-gmbh.sumupstore.com
Both are links. No data is transmitted unless you click them. As soon as you follow one, you leave this website; what data is collected there — delivery and payment details, for example — is governed by that provider's privacy policy. This policy has no bearing on that processing.
7. Contacting us
If you contact us by email or telephone, we process the information you give us in order to answer your enquiry. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries), or Art. 6 (1) (b) GDPR where your enquiry concerns a contract, such as a reservation. We delete this data once the enquiry has been dealt with conclusively and no statutory retention periods apply. There is no contact form on this website.
Contact via WhatsApp
We offer WhatsApp as an additional way to reach us. The link on this page is an ordinary reference: unless you click it, no connection to WhatsApp is established and no data is transmitted.
If you message us on WhatsApp, we process your phone number, your WhatsApp name and the content of your message in order to answer your enquiry. The legal basis is Art. 6 (1) (f) GDPR, or Art. 6 (1) (b) GDPR where a reservation or order is involved.
The service is operated by:
WhatsApp Ireland LimitedMerrion Road, Dublin 4
Ireland
The service belongs to the Meta group; personal data may in that context also be transferred to and processed in the USA. We have no influence over the nature and extent of WhatsApp's processing. You can find more in WhatsApp's privacy policy.
If you would rather avoid that, you can reach us just as well by phone, by email or in person at the restaurant. Please do not send us health data or other sensitive information over WhatsApp; for allergy questions, please speak to us directly.
We delete messages once the enquiry has been dealt with and no statutory retention periods apply.
8. Recipients of the data and transfers to third countries
Beyond the processors named in sections 4 and 5, we do not pass on personal data arising from the operation of this site. We do not sell data.
Merely visiting this website results in no transfer to a third country outside the EU or EEA. Such a transfer can only arise if you choose the WhatsApp route yourself (section 7) or follow a link to one of the ordering channels or to a social network (section 6).
9. Your rights
You have the following rights against us in respect of your personal data:
- access to the data processed (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing (Art. 21 GDPR)
An informal message to the address or email address given above is enough to exercise them.
Right to object
Where we process data on the basis of Art. 6 (1) (f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
Right to lodge a complaint
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2–4, 40213 Düsseldorf
www.ldi.nrw.de
10. Encryption
This site is delivered over an encrypted connection (TLS/HTTPS). You can recognise this by the padlock symbol in your browser's address bar. It means the data you send us cannot be read by third parties.
11. Changes to this policy
We will amend this privacy policy as soon as the underlying processing changes — for instance if we introduce a contact form, an analytics function or an embedded map in future. The version published on this page, bearing the date given above, is the one that applies.