Privacy policy
This page says what happens to your personal data when you use this website. It is written in the same plain terms as everything else here, because a privacy policy that has to be decoded is not really telling anybody anything.
The short version: we collect what we need to answer you, hold your table or sell you a ticket, we keep it for as long as we have a reason to, and we do not sell it to anybody. The long version is below, form by form, because "we may collect certain information" is worth nothing to a reader.
Who is responsible for your data
The data controller is Maiya Nepali Kitchen, CVR 37671533, Højdevej 59, 2300 København S, Denmark. We trade as Maiya Party Hall.
Write to info@maiya.dk or call +45 21 95 92 92 with anything about this policy or about your own data. We do not have a data protection officer, because a business of this size is not required to appoint one, so those messages come to the people who run the place.
What we collect, and on which form
When you send an enquiry about hiring the hall, we collect your name, your email address, your phone number, the number of guests, the kind of event and the date you have in mind, along with whatever you write in the message box.
When you book a viewing, we collect your name, your email address, your phone number, the date and time you chose and the size of your party.
When you buy a ticket to one of our events, we collect your name, your email address, your phone number, what you bought, the seat or table if the event has them, and the names of the people attending when the event asks for them. We also hold a payment reference from MobilePay and a random token that lets you open your own tickets from the link in your confirmation email. We never receive or store your card number or your bank details.
When you join a waiting list for a sold out event, we collect your name, your email address, your phone number and how many seats you want.
We do not ask for anything we do not use, and there is no account to create anywhere on this site.
Why we are allowed to hold it
For a ticket order or a viewing, the legal basis is performance of a contract, Article 6(1)(b) of the GDPR. We cannot sell you a seat and get you into the room without knowing who you are and how to reach you.
For an enquiry about hiring the hall or a booked viewing, the basis is also Article 6(1)(b), because both are steps taken at your own request before a contract exists. You asked us for a price and a date, and answering means holding your message and your address until that conversation is finished.
For the names of other people attending, which some events ask the buyer to supply, the basis is our legitimate interest under Article 6(1)(f) in issuing named admission and in stopping tickets being resold to somebody we never sold them to.
For accounts and receipts, the basis is a legal obligation under Article 6(1)(c). Section 12 of the Danish bookkeeping act, bogføringsloven, requires us to keep the records behind a sale.
Where we use Google Ads and Google Analytics, the basis is your consent under Article 6(1)(a), which you give or refuse in the consent banner and can change at any time.
Our own analytics, which are unusual and worth explaining
We count visits to this website ourselves, and the way we do it is deliberately unlike the normal arrangement. No cookie is set. No IP address is stored. No user agent string is stored. This part of the site writes nothing to your device, and no identifier is sent from your browser at all.
What we keep is a visitor hash. It is calculated on our own server, once, from your IP address, your browser string, the site you are on and a secret salt that is replaced every day at midnight. The IP address and the browser string go into that one calculation and are then dropped: neither of them is written down anywhere. Because the salt changes daily, yesterday's hash cannot be recomputed or matched to today's, so a visit cannot be followed from one day to the next.
We are being precise rather than modest here. While a day's salt is current, a hash does tell one visitor apart from another, so we treat it as personal data and describe it as such. What we mean by the word anonymous is narrower and more useful: we cannot identify you from it, we cannot reverse it, and after the salt rotates nobody can, including us.
We do this because we want to know which pages are worth writing and which advertisements are worth paying for, and neither of those questions requires knowing who you are. The legal basis is our legitimate interest under Article 6(1)(f). Since nothing is stored on or read from your device, this part of the site does not need cookie consent under the Danish rules, which is why it works whether or not you accept the banner. It also honours Global Privacy Control: if your browser sends that signal, nothing is counted at all.
Cookies, Google Ads and Google Analytics
This site also uses Google Ads conversion tracking and Google Analytics, which do set cookies and do collect data about your visit. They are loaded with Consent Mode defaults set to denied, which means that until you consent no advertising or analytics cookie is written and Google receives only anonymous, aggregated signals.
If you consent, Google receives information about your visit and can connect it to advertising it has shown you. If you refuse, or ignore the banner, that connection is not made. You can change your mind whenever you like: "Cookie settings" at the foot of every page reopens the banner, and you can clear the cookies from your browser as well.
Two things are kept in your browser's own storage, and it would be easy to leave them out of a page like this, so here they are. `maiya-cookie-consent` remembers the answer you gave the banner, which is the whole point of asking. `maiya-attribution` is written when you arrive from an advertisement and holds the campaign tags in the link you clicked, such as `utm_source` and `gclid`, so that if you go on to send an enquiry we can tell which advertisement paid for it. It is written before the banner is answered, it stays for 90 days, it contains nothing you typed and nothing that identifies you, and clearing your site data removes it.
Who else sees your data
We use four suppliers, and each of them processes data on our instructions under a data processing agreement:
Supabase runs our database, our sign-in for staff, our file storage and the small server functions behind the booking forms. Everything you submit is stored there, in their `eu-west-1` region in Ireland, so it does not leave the European Union.
Vipps MobilePay takes the payments. They receive the amount, the booking reference and whatever their own app needs to complete a payment. We receive back a payment reference and nothing more.
Netlify serves this website today. The venue's own provider simply.com runs the mail server that sends your confirmations and our notifications, and will take over the web hosting as well when the domain moves.
Google provides the advertising and analytics described above.
Nobody else receives your data. We do not sell it, we do not rent it, and we do not pass it to anyone for their own marketing. We will hand over data if a Danish authority or a court legally requires it, and only then.
Only one of those four involves a country outside the EU and the EEA. Google is Google LLC in the United States, and that transfer relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework, with the Commission's standard contractual clauses behind it. Vipps MobilePay is Norwegian, which is inside the EEA, and simply.com is Danish, so neither is a transfer to a third country.
One more thing, because it would be easy to leave out. The web server that serves you this page keeps ordinary access logs at simply.com, and those logs contain IP addresses in the normal way that every web server's do. That is separate from our own analytics described above, which genuinely stores none, and we would rather say so than let a careful reader find the gap themselves.
How long we keep it
An enquiry or a viewing that does not turn into a booking is kept while the conversation is live and for a reasonable period afterwards, and is then deleted. If you ask us to delete it sooner, we will.
A ticket order, and the accounting record behind it, is kept for five years from the end of the financial year it belongs to. That is not our choice: Danish bookkeeping law, bogføringsloven, sets that period, and it takes priority over deleting data we would otherwise not keep.
A waiting list entry is deleted once the event it belongs to has passed.
Our own analytics records carry no identifier that survives the daily salt rotation, so after a day they are counts and nothing else.
Your rights
You can ask us for a copy of the data we hold about you, and we will send it. You can ask us to correct anything that is wrong. You can ask us to delete it, and we will unless bookkeeping law requires us to keep that particular record. You can ask us to restrict what we do with it, ask for it in a portable form, or object to us processing it on the basis of legitimate interest.
Where you have given consent, you can withdraw it at any time, and withdrawing it does not affect anything that was done while it was in force.
Write to info@maiya.dk. We answer within a month, and usually within a few days. There is no charge.
If you want to complain
Tell us first if you can, because most things are quicker to fix directly. If you would rather not, or if you are not satisfied with our answer, you have the right to complain to the Danish Data Protection Agency.
Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby. Telephone 33 19 32 00, email dt@datatilsynet.dk, website datatilsynet.dk.
We may update this policy. The current version is always the one on this page.
Last updated: 28 July 2026.
Rooms for hire
Choose your guest count, menu and drinks, and the total updates as you go. Then send it to us and we will confirm availability.