Legal
Privacy Notice
Version: 2026-03-20-draft-1
1. Who We Are
Mila Modern Greek Restaurant ("Mila", "we", "us", or "our") respects your privacy and is committed to processing personal information lawfully and responsibly.
This notice explains how we collect, use, store, share, and protect personal information when you:
- visit our website
- make or manage a reservation
- contact us by email, telephone, WhatsApp, or online forms
- sign up to receive news, offers, and other marketing communications
- visit or interact with us in person
Mila is operated by:
- Trading name: Mila Modern Greek Restaurant
- Address: LXX Sandhurst, 70 Rivonia Rd, Sandhurst, Sandton, 2196, South Africa
- Email: info@milamoderngreek.co.za
- Telephone: +27 10 746 5599
2. This Notice Applies To
This notice applies to personal information processed in connection with:
- website browsing and enquiries
- reservation requests, confirmations, reminders, amendments, cancellations, and no-show handling
- guest relationship management
- special requests, dietary notes, and service preferences
- direct marketing by email and WhatsApp where you have opted in or where another lawful basis applies
- compliance, fraud prevention, security, and record-keeping
3. Personal Information We Collect
Depending on how you interact with us, we may collect:
- Identity and contact details, such as your name, email address, and phone number
- Reservation details, such as booking date, time, party size, booking source, and reservation reference
- Guest preferences and service information, such as seating requests, special occasions, dietary notes, allergies, and other booking notes you choose to share
- Communication records, such as emails, WhatsApp messages, call notes, customer service records, and marketing preferences
- Technical and website information, such as IP address, device/browser information, user agent, and basic website usage information
- Consent and audit records, such as whether you accepted booking terms, whether you opted in to marketing, the version of the legal notices shown to you, and the date/time of your consent interaction
- Payment or deposit information, if deposits or prepayments are introduced in the future, but we should avoid storing full card details unless handled by an approved payment provider
We ask that you do not provide sensitive personal information unless it is necessary for your booking or service request. If you share health-related information, such as allergy or dietary information, we will use it only for service and safety purposes.
4. How We Collect Personal Information
We may collect personal information:
- directly from you when you complete forms, make reservations, contact us, or opt in to marketing
- from your communications with us by email, phone, WhatsApp, or in person
- from service providers acting on our behalf, such as booking, CRM, notification, hosting, analytics, or payment providers
- automatically through website and system logs when you use our digital services
5. Why We Process Personal Information
We process personal information for the following purposes:
- to receive, confirm, and manage reservations
- to contact you about your booking, including confirmations, reminders, changes, and cancellations
- to accommodate special requests and improve guest experience
- to keep internal reservation, guest, and audit records
- to detect abuse, duplicates, fraud, misuse, or security incidents
- to comply with legal, regulatory, and operational obligations
- to send marketing communications by email and WhatsApp where you have opted in or where we are otherwise permitted by law
- to improve our services, website performance, and operational reporting
6. Lawful Grounds For Processing
Under POPIA, we may process personal information where:
- processing is necessary to conclude or perform a contract with you, such as managing your reservation
- processing is required to comply with a legal obligation
- processing protects a legitimate interest of yours or ours, such as security, fraud prevention, and service continuity
- you have consented to the processing, especially for direct marketing by electronic communications
Where we rely on your consent, you may withdraw that consent at any time for future processing, subject to applicable law.
7. Direct Marketing
We will keep transactional booking communications separate from marketing communications.
- Booking confirmations, reminders, and service messages are not treated as marketing where they relate directly to your reservation.
- Email and WhatsApp marketing will only be sent where you have opted in or where we are otherwise permitted by applicable law.
- You may opt out of marketing at any time by following the unsubscribe instructions in the message, replying with an opt-out request, or contacting us directly.
8. Sharing Of Personal Information
We may share personal information with:
- booking and reservation system providers
- customer relationship management providers
- email, SMS, and WhatsApp notification providers
- website hosting, cloud, analytics, and security providers
- payment or deposit processing providers, if applicable
- professional advisors, auditors, insurers, or regulators where reasonably necessary
- public authorities or law enforcement where disclosure is required by law
We do not sell personal information.
Where an operator processes personal information on our behalf, we will require that operator to process it only on our instructions and to apply appropriate security safeguards.
9. Cross-Border Transfers
Some of our service providers may store or process personal information outside South Africa.
Where cross-border transfers occur, we will take reasonable steps to ensure that the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection, or that the transfer is otherwise permitted by POPIA.
10. Retention
We keep personal information only for as long as necessary for the purpose for which it was collected, unless a longer retention period is required or permitted by law.
In general:
- reservation and service records may be retained for operational, reporting, dispute-resolution, and compliance purposes
- consent and audit records may be retained for as long as necessary to demonstrate compliance and manage objections or complaints
- marketing preference records may be retained to ensure we honour your opt-in or opt-out choices
Detailed retention schedules should be finalised internally and reflected in operational policy.
11. Security
We take reasonable technical and organisational steps to secure personal information against loss, misuse, unauthorised access, disclosure, alteration, or destruction.
These measures may include:
- access controls and role-based permissions
- secure hosting and encrypted connections
- audit logging and monitoring
- service-provider controls
- incident response procedures
No method of transmission or storage is completely secure, but we take reasonable steps to reduce risk and respond appropriately to security incidents.
12. Your Rights
Subject to applicable law, you may have the right to:
- request access to personal information we hold about you
- request correction of inaccurate, incomplete, or outdated personal information
- request deletion or destruction of personal information where retention is no longer authorised
- object, on reasonable grounds, to certain processing
- object to direct marketing and withdraw marketing consent
- lodge a complaint with the Information Regulator
To exercise any of these rights, contact us using the details in this notice.
13. Complaints
If you have a privacy concern or complaint, please contact us first so that we can try to resolve it.
You also have the right to lodge a complaint with the Information Regulator (South Africa):
- Website: inforegulator.org.za
- Email: enquiries@inforegulator.org.za
- Telephone: 010 023 5200
14. Updates To This Notice
We may update this notice from time to time to reflect legal, operational, or service changes. When we do, we will publish the updated version on our website and update the effective date and version number.
15. Effective Date And Version
- Effective date: [To be confirmed]
- Version: 2026-03-20-draft-1