Skip to content
The original caféThe bakeryVisit usMenus
DE/EN
← Back to our venues

Café Diglas

Privacy

How we process personal data on diglas.at, wollzeile.diglas.at and in our menu management system.

Legal notice ↗Privacy policy ↗Cookies ↗

We are happy to help with your questions.

office@diglas.at+43 1 512 57 65

Who is responsible for this website

This notice applies to diglas.at and wollzeile.diglas.at: the directory of the Diglas family’s establishments, the Stammhaus and bakery pages, and the protected menu management system. The controller responsible for processing personal data on this website is:

Café Diglas e.U.
Wollzeile 10, 1010 Vienna, Austria
office@diglas.at
+43 1 512 57 65

You can also use these contact details for privacy questions and to exercise your rights.

Website delivery and hosting

The public pages can be visited without an account. Access to the menu management system requires a separate, authorised account on this website.

The website is hosted by Vercel. The provider is Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel delivers the pages and handles the technical processing of requests. Uploaded menu files are stored in private Vercel Blob storage in Frankfurt. Unpublished files can only be accessed after a server-side authorisation check.

Menu text, editing history and menu management account data are stored in a PostgreSQL database provided through Neon. The published Neon Platform Terms identify Databricks, Inc., the parent company of Neon, LLC, as the provider. Databricks’ address is 160 Spear Street, 15th Floor, San Francisco, CA 94105, USA.

Technical connection data is processed to deliver the website, particularly the IP address and requested URL. Depending on the browser, information about the browser, operating system and previously visited page may also be transmitted. The time, status and technical errors of a request may be logged to operate the website securely.

Website delivery, access protection and troubleshooting serve our legitimate interest in a functioning and secure website under Article 6(1)(f) GDPR. Technical service providers receive data to the extent that they participate in delivering and securing the website.

The retention of technical operational data depends on the duration of service delivery, the investigation of errors and security incidents and, where applicable, statutory retention obligations or the handling of legal claims. The duration varies according to the type of data and the purpose of processing.

International processing

The providers used may process data outside the European Economic Area, particularly in the United States. A European storage location alone does not rule this out. In its privacy and security documentation, Vercel identifies the EU Standard Contractual Clauses as a basis for such transfers. The published provisions are available in Vercel’s Data Processing Addendum. The Neon Platform Terms refer to the Databricks Data Processing Addendum, which also provides for Standard Contractual Clauses. Please use the contact details above if you have questions about the applicable safeguards.

When you contact us

You can contact us by email or telephone. We process the contact details you provide and the content of your enquiry in order to respond. The website has no contact form and does not itself store these enquiries.

Where an enquiry concerns a contract or pre-contractual information you have requested, the legal basis is Article 6(1)(b) GDPR. For other enquiries, the basis is our legitimate interest in responding to your message under Article 6(1)(f) GDPR.

Retention depends on the reason for your enquiry and its handling and, where applicable, statutory retention obligations or the need to address legal claims. Please only send information that is necessary for your enquiry.

The Diglas family newsletter

With your voluntary consent, we record your registration for stories, news and offers from the Diglas family’s establishments. Café Diglas e.U. is the data controller. Processing to manage your registration is based on your consent under Article 6(1)(a) GDPR.

We store your email address, selected language, registration time and source, and the wording and version of your consent in the Neon database described above. Addresses are accessible only through a separately protected private administration account. The menu management account has no access.

The email delivery service will be set up later. Until then, registrations are marked as unconfirmed; neither confirmation emails nor newsletters are sent. A stored registration does not yet verify ownership of the email address. Unconfirmed registrations are excluded from the mailing export.

We keep your registration for the planned newsletter launch and management of your subscription for as long as you wish to subscribe. To withdraw your consent or request removal, contact office@diglas.at. Your registration will then be removed from the active mailing list, subject to any further retention required for legal obligations or claims. Withdrawal does not affect the lawfulness of processing before withdrawal.

Sign-in and menu management for our team

Menu management is accessible only to authorised accounts. A name and email address are stored when an account is created. The Better Auth sign-in system stores passwords as cryptographic hashes. Sign-in is checked on the server; the email address must also be authorised for menu management.

For sign-in, we store session records with a user identifier and expiry time and, where applicable, an IP address and browser identifier. A session is valid for eight hours and may be renewed during active use. Technical access counters are also stored to limit abusive sign-in attempts. This processing serves our legitimate interest in protected administration under Article 6(1)(f) GDPR.

When a menu is saved, we record its content, date, editing time and the editor’s user identifier. For uploaded files, we also store the file name, type, size, upload time and user identifier. This allows menus to be managed and earlier versions to be restored. The basis is our legitimate interest in maintaining a traceable editing process under Article 6(1)(f) GDPR.

Published menu text and the released file are publicly visible. Drafts, previous versions and unpublished files can only be accessed by authorised administrators. User identifiers are not displayed on the public menu.

Retention

Menu versions and uploaded files remain in the history for traceability and restoration. They are not deleted automatically; hiding or replacing a menu does not remove earlier versions or files from storage. Retention depends on the needs of the editing process and, where applicable, legal obligations or claims. Deletion is performed separately, outside the menu editing interface.

Accounts, session records, upload registrations and technical access counters are held in the database. Account data is used to manage access, while session data and access counters support sign-in and abuse prevention. Expired sessions are no longer valid; expiry does not automatically delete every associated database record. Retention depends on whether the data is still needed to manage the account, investigate a security incident or meet legal obligations. Deletion requests can be sent to the contact details above.

Menu text and files should contain only food and menu information intended for guests. Guests’ personal information or confidential team documents do not belong in a daily menu.

English daily menu

Our team can enter and publish an English version manually. Automatic translation through DeepL is currently disabled. No menu text is therefore sent to DeepL through this function.

Cookies, fonts and images

This website does not use advertising trackers. Our own usage statistics do not set cookies or save identifiers in your browser’s local storage or session storage. The daily menu language is selected only for the current view; this choice is not stored persistently in the browser.

The protected menu management system uses the strictly necessary session cookie __Secure-diglas.session_token. It cannot be accessed by JavaScript, is transmitted securely over HTTPS and is valid for eight hours. It may be renewed during active use. It enables sign-in and links the session to the authorised account.

Images, the logo and font files are served with the website. No font files are loaded from Google Fonts or comparable external font servers. Google Maps, social media content and external videos are not embedded in the pages.

Our own usage statistics without analytics cookies

Our own statistics count venue directory views after a deliberate interaction and 15 seconds with the page visible and active, or immediately on a venue click. For these qualified views, we record visible venue tiles and venue clicks to understand how the directory is used. A tile counts as visible when at least half of it has been displayed for half a second. During the current page view, browser memory keeps track of events and tiles already counted; this information is not stored persistently. Visits to venues and purchases are not recorded.

For our own statistics, our Neon database stores only aggregate daily counts: the date in Vienna time, language, event type, venue, image and tile position. These statistics do not assign persistent visitor identifiers, recognise people across page views or count unique visitors or sessions. Our own statistics do not use device fingerprinting. A/B comparisons showing different images or orders are currently disabled.

Known automated requests are filtered using technical browser information; this cannot guarantee detection of every bot. “Do Not Track” and “Global Privacy Control” browser signals are respected: no analytics events are sent when either signal is present. To prevent abuse, a cryptographic value is briefly derived from the IP address. It changes every minute and remains in server memory for no longer than two minutes. Neither this value nor raw IP addresses or user-agent headers are stored in the database for these statistics. Technical connection data and logs required to operate the website are described in the hosting section.

The daily counts are accessible only through a separately protected analytics account and are retained for long-term comparisons. Previous daily counts are archived separately and are not combined with the new series of qualified views. Previous analytics cookies are removed when the venue directory is opened.

Existing data from the previous analytics system

The previous analytics system could record the time, language, random browser, session and page-view identifiers, image, position and comparison variant with your consent under Article 6(1)(a) GDPR and Section 165(3) of the Austrian Telecommunications Act 2021. Where such data has already been stored, it remains in our Neon database and is accessible only through the protected analytics account. Individual events containing random identifiers are deleted after 13 months by a daily cleanup. Daily aggregate counts without visitor identifiers are retained.

Please use the contact details above for questions about previously collected data, withdrawal of earlier consent or deletion. Your rights are described in the “Your rights” section. Withdrawal does not affect the lawfulness of processing before withdrawal.

Vercel Web Analytics

Public pages also use Vercel Inc.’s Web Analytics, excluding backoffice and private analytics. Without analytics cookies, it records page paths, referrers, timestamps, approximate location and device/browser information. Visitor assignment through a request-derived hash expires after 24 hours; aggregate statistics remain. We exclude form inputs and newsletter addresses and remove URL parameters and fragments. “Do Not Track” and “Global Privacy Control” prevent transmission. Reports are accessible only through our Vercel account. Vercel’s privacy information.

Links to other websites

This website links to services including Google Maps for directions, other family establishments and menus on the existing Stammhaus website. Your browser accesses a destination and sends the connection data necessary for that request to its provider only when you open the link. The respective operator’s privacy information applies there. Linking to a map or an establishment’s website does not embed that external service in this page.

Your rights

Subject to the applicable legal conditions, you may exercise the following rights:

  • Access to information about the processing of your personal data,
  • rectification of incorrect or incomplete data,
  • erasure or restriction of processing,
  • objection to processing based on legitimate interests on grounds relating to your particular situation,
  • data portability, where its legal conditions are met,
  • withdrawal of consent with effect for the future, where processing is based on your consent.

Please write to office@diglas.at. Where necessary, we will ask for appropriate information to confirm your identity. Our application code does not perform automated decision-making, including profiling, that produces legal or similarly significant effects.

You also have the right to complain to a data protection supervisory authority if you consider processing of your personal data to be unlawful. In Austria, this is the Austrian Data Protection Authority.

Date of this notice

10 October 2026. This version describes the public website and its protected menu management system. The notice will be updated to reflect changes to hosting, access or functionality.

A little Vienna. A lot of heart.All our family’s venues
Café Diglas e.U. · Wollzeile 10 · 1010 Vienna
Original caféBakeryLegal noticePrivacyCookiesBackoffice