Back to Site
🍽️ Vilhena · RO · BrazilPrivacy · LGPD · Restaurant · Health Authority · Rondônia

Privacy Policy.

Ltda Cippola & Maurer Restaurante e Petiscaria Ltda · CNPJ 48.278.689/0001-47

Company

Cippola & Maurer Restaurante e Petiscaria Ltda

CNPJ

48.278.689/0001-47

Last updated

January 2025

Legislation

LGPD · Lei 13.709/2018 · ANVISA · CDC

This Privacy Policy describes how Cippola & Maurer Restaurante e Petiscaria Ltda ("we," "our" or "the Restaurant") collects, uses, stores and protects personal data of our guests, website visitors and all persons whose data we process in connection with our restaurant and bar activities in Vilhena, Rondônia, Brazil.

As a registered limited liability company (Ltda) operating in the restaurant and food services sector, we are committed to full compliance with LGPD (Lei nº 13.709/2018), the Brazilian Consumer Protection Code (CDC — Lei nº 8.078/1990), ANVISA regulations and the Vilhena Health Authority for food services, and the tax obligations of ISS of the Municipality of Vilhena and SEFAZ-RO.

01

Introduction and Scope

This Policy applies to all personal data processed in connection with our restaurant and bar activities — including guests who make reservations, guests who request invoices, website visitors and any person whose data we process. The restaurant business involves personal data primarily at three moments: the table reservation, the invoice when requested, and registration if the guest opts into loyalty programmes or promotions. Most guests dine anonymously — without a reservation or an identified invoice — and that is the default we respect.

02

Identity of the Controller

Company name: Cippola & Maurer Restaurante e Petiscaria Ltda
Type: Sociedade Limitada (Ltda)
CNPJ: 48.278.689/0001-47
Activity (CNAE): Restaurants and Similar Services
Address: Av. Pres. Tancredo Neves, 4846, Sala 24, Jardim Eldorado, Vilhena — RO, CEP 76987-097, Brazil
Email: privacy@cippola-maurer.com.br
03

Personal Data We Collect

  • Anonymous dining (default): Most guests dine without any data collection — cash or card payment without identification, no prior reservation. No data is collected or retained. Anonymous dining is our default.
  • Reservation data: Name, WhatsApp and date/time when making a table reservation — to confirm the booking and communicate any changes. Deleted after the meal or after 30 days if not used for a repeat booking.
  • Invoice data (NF-e / NFC-e — when requested): CPF or CNPJ when the guest requests an identified invoice — for corporate meal reimbursement, business travel expenses or personal record-keeping. Optional: the NFC-e can be issued without identifying the consumer.
  • Dietary restrictions (when provided for a reservation): Allergies or food intolerances shared by the guest so the kitchen can accommodate safely. Treated as health data (LGPD Art. 5º, II) under Art. 11, II, "f" (provision of health / food services).
  • Website contact data: Name, WhatsApp and message when using the reservation or contact form.
  • Technical website data: IP address, browser type and pages visited.
04

Purpose and Legal Basis

PurposeLegal Basis (LGPD)
Managing reservations and restaurant serviceContract performance (Art. 7º, V)
Dietary restrictions for safe meal preparationArt. 11, II, "f" — provision of health / food services
Issuing NF-e or NFC-e when requestedContract performance; Legal obligation (Art. 7º, II)
ISS Vilhena — fiscal bookkeepingLegal obligation (Art. 7º, II)
SEFAZ-RO — ancillary tax obligationsLegal obligation (Art. 7º, II)
Website analytics and improvementLegitimate interest; Consent (cookies)
05

Sharing of Data

Dietary restrictions — absolute kitchen confidentiality: Information about allergies and food intolerances shared for a reservation is communicated to the kitchen team exclusively for safe meal preparation. It is never stored permanently in a system without consent, never shared with third parties and deleted after the meal.
  • SEFAZ-RO / Receita Federal: NF-e or NFC-e with identification — mandatory electronic transmission. Anonymous dining generates no personal data transmission.
  • ISS / Prefeitura de Vilhena: ISS bookkeeping on food services rendered.
  • Vigilância Sanitária de Vilhena / SESAU-RO: During health inspections — institutional data of the restaurant is shared with the competent authority. Guest personal data only under formal, documented legal requirement.
  • PROCON-RO / Senacon: When required in consumer disputes under the CDC.
  • Legal authorities: When required by court order or administrative authority.
06

International Transfers

Our operation is based in Vilhena, RO. All guest data is processed in Brazil. Any reservation or communication platforms operating on international servers do so under the guarantees of Art. 33 of the LGPD. Tax records (NF-e) are processed exclusively in systems certified by the Receita Federal and SEFAZ-RO, in Brazil.

07

Retention Periods

  • Anonymous dining: No personal data collected or retained — anonymous dining is the default.
  • Reservation data (no return visit): Deleted 30 days after the reservation date.
  • Dietary restrictions: Deleted at the end of the meal — not retained beyond what is required for the sitting.
  • NF-e and NFC-e (ISS Vilhena / SEFAZ-RO): Minimum 5 years as required by Brazilian federal and state tax legislation.
  • Contact data without a completed reservation: Up to 3 months from the date of contact.
  • Website analytics: Aggregated and anonymised after 12 months.
08

Security Measures

  • Anonymous dining as the default — no data collected for guests who do not make reservations or request invoices;
  • Dietary restrictions communicated to the kitchen verbally or via an internal notepad used exclusively by the kitchen team, without permanent digital storage;
  • NF-e issued using a certified digital certificate (A1/A3) approved by the Receita Federal;
  • Reservation data received via WhatsApp handled with discretion;
  • Website encrypted (HTTPS);
  • Incident response procedures in accordance with LGPD Art. 48.
09

Your Rights under the LGPD

  • Confirmation and Access (Art. 18, I–II): Confirm whether we hold your data and receive a copy.
  • Deletion (Art. 18, IV): Request deletion — subject to mandatory invoice retention (5 years under tax law).
  • Withdrawal of consent (Art. 8º, §5º): Withdraw from loyalty programmes at any time without affecting future service.
  • Complaint to the ANPD (Art. 18, §1º): Lodge a complaint at www.gov.br/anpd.

We respond within 15 business days.

10

Cookies and Tracking

Our website may use cookies for essential functionality and aggregated performance analytics. We do not use behavioural tracking or advertising cookies. Cookie preferences can be managed through your browser settings.

11

Minors

Restaurants and bars serve families with children. When a reservation is made by an adult including children, we process only the adult's data. We do not collect data from minors via the website. Regarding alcoholic beverages at the bar, Cippola & Maurer complies with the prohibition on selling alcohol to persons under 18 years of age under Brazilian Law nº 9.294/96 and the Statute of the Child and Adolescent (ECA). Identification may be requested when there is reasonable doubt about a consumer's age. Any document presented for age verification is checked visually only — it is not copied, photographed or recorded in any system.

12

Health Authority, Food Safety and Invoice

Vigilância Sanitária / SESAU-RO / ANVISA — RDC 216/2004: Restaurants and food services in Brazil are regulated by ANVISA (RDC 216/2004 — Good Practices for Food Services) and by the state (SESAU-RO) and municipal (Vilhena) health authorities. The Cippola & Maurer health permit is fully compliant with food handling, temperature control, kitchen hygiene and food handler training requirements. During health inspections, the health authority may request temperature control records, food handler files and other operational documents — which contain data about staff, not guests. Guest personal data is not part of mandatory health records and is not shared with the health authority except in the event of a formally declared food safety emergency or public health outbreak.
Dietary restrictions as health data — LGPD Art. 11: When a guest shares a food allergy (peanuts, gluten, lactose, shellfish, etc.) or intolerance at the time of booking or ordering, they are sharing health data as defined by LGPD Art. 5º, II. Cippola & Maurer processes this data under Art. 11, II, "f" (provision of health services) and with maximum discretion: (a) the information is shared only with the kitchen team responsible for preparation; (b) it is not stored in a digital system without express consent; (c) it is deleted after the meal; (d) it is never shared with third parties. Sharing a food allergy at a restaurant is an act of self-protection — we treat this information with the seriousness it deserves.
NF-e and NFC-e for restaurant meals — ISS Vilhena / SEFAZ-RO: Restaurant and bar activities are subject to ISS from the Municipality of Vilhena and to ICMS from the State of Rondônia depending on the specific activity. The NFC-e (consumer electronic invoice) can be issued with or without identifying the consumer: (a) without identification — the default for most guests; (b) with CPF — for guests who want the invoice for personal records or personal expense tracking; (c) with CNPJ — for companies whose staff dine on business and need a formal invoice for corporate reimbursement, daily allowance or business travel expense recording. The invoice issued by Cippola & Maurer Ltda to corporate clients is a valid fiscal document for reimbursement and accounting purposes. The CPF or CNPJ on the invoice is retained for the mandatory 5-year period under Brazilian tax legislation.

Alcohol and age verification: When a guest presents an identity document for age verification, the document is checked visually by the team — it is not copied, photographed, scanned or recorded in any system. The act of presenting a document does not result in any personal data being stored.

13

Updates to this Policy

This Policy may be updated to reflect changes in our activities, in the LGPD, in ANPD guidance, in ANVISA food service regulations or in Rondônia tax legislation. Material changes will be communicated via our website.

14

Contact and Data Protection Officer

All privacy requests should be directed to our Data Protection Officer (LGPD Art. 41):

🍽️

Cippola & Maurer — Privacy

CompanyCippola & Maurer Restaurante e Petiscaria Ltda
CNPJ48.278.689/0001-47
AddressAv. Pres. Tancredo Neves, 4846, Sala 24, Jardim Eldorado, Vilhena — RO, CEP 76987-097, Brazil
WhatsApp+55 (69) 9 0000-0000
HoursMon–Fri: 11:00–23:00 · Sat–Sun: 11:00–23:00
ResponseWithin 15 business days of receipt.
You also have the right to lodge a complaint with the Brazilian national data protection authority:
ANPD — Autoridade Nacional de Proteção de Dados
www.gov.br/anpd