Data protection

In the following data protection declaration you will learn more about the collection, processing and use of your personal data if and to the extent that it is collected when you use our websites.

The protection of your data is close to our heart

When handling your data, we act in strict compliance with the relevant statutory data protection regulations and the following principles.

The entity responsible for processing personal data on this website is:

Kolarik im Prater GmbH
Prater 128
1020 Vienna
Austria

Email: office@kolarik.at
Phone: +43 1 729 49 99
Website: https://kolarik.at

We process personal data only to the extent that there is a legal basis for doing so. Depending on the specific purpose, processing is based in particular on:

  • Your consent pursuant to Article 6(1)(a) of the GDPR,
  • to take steps prior to entering into a contract or to perform a contract pursuant to Article 6(1)(b) of the GDPR,
  • to comply with legal obligations pursuant to Article 6(1)(c) of the GDPR, or
  • to protect our legitimate interests or the legitimate interests of third parties pursuant to Article 6(1)(f) of the GDPR, provided that your interests or fundamental rights and freedoms do not take precedence.

The following sections explain what personal data we process, for what purposes, and what legal basis applies in each specific case.

If processing is based on your consent, you may withdraw that consent at any time with future effect. The lawfulness of the processing carried out up to the time of withdrawal remains unaffected. Withdrawal of consent does not necessarily result in the immediate deletion of all data if another legal basis or a statutory retention requirement permits or requires continued storage.

To withdraw your consent, you can contact us by email at office@kolarik.at or by mail at Kolarik im Prater GmbH, Prater 128, 1020 Vienna. For cookies and similar technologies that require your consent, you can also change or withdraw your selection at any time by clicking “Manage Consent” at the bottom of the website.

Server Logs

When you visit our website, our hosting provider ALL-INKL.COM – Neue Medien Münnich, owned by René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany, processes server log data that is technically necessary. This includes, in particular, the page or file accessed, the date and time of access, the access status, the amount of data transferred, the referrer URL, and information about the browser and operating system. IP addresses are stored in the log data exclusively in truncated form.

Data is processed to ensure the functionality and security of our website, in particular for error analysis and to detect and prevent unauthorized access. The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure, stable, and trouble-free operation of our website.

Server log data is automatically deleted after 14 days. It is not analyzed for advertising or profiling purposes, nor is it combined with other data.

Our website uses cookies and similar technologies, such as local storage objects, pixels, and scripts.

We use technically necessary technologies to the extent that this is required for the operation of the website and for explicitly requested functions. The legal basis, to the extent that personal data is processed, is Article 6(1)(f) of the GDPR; access to the end device is governed by Section 165(3) of the TKG 2021.

Statistical and marketing technologies are used only with your prior consent. The legal basis is Article 6(1)(a) of the GDPR in conjunction with Section 165(3) of the TKG 2021.

You can change or revoke your selection at any time, effective for the future, by clicking the "Manage Cookie Consent" button.

For details on services, cookies, storage technologies, purposes, and retention periods, please see our Cookie Policy.

We use Google Ads and the associated conversion tracking on our website. The service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. As part of the provision of this service, data may also be processed by Google LLC and other Google companies.

If you arrive at our website via a Google ad and then perform an action we have defined—such as successfully completing a reservation—Google can recognize that viewing or clicking the ad led to that action. In particular, the following data may be processed: ad and click identifiers, pages visited, the time of the visit and the conversion, referrer information, browser and device information, IP address, cookie identifiers, and other online identifiers.

We use this information to measure the success of our Google Ads campaigns and to optimize our advertising efforts. We generally receive statistical reports from Google and cannot directly identify individual website visitors through this data.

Data processing and storage on your device take place exclusively with your prior consent in accordance with Article 6(1)(a) of the GDPR and Section 165(3) of the TKG 2021. You may revoke or modify your consent at any time with future effect by clicking “Manage Cookie Consent.”

When using Google services, the possibility of data processing in the United States cannot be ruled out. Google LLC is certified under the EU-U.S. Data Privacy Framework. Where necessary, the European Commission’s Standard Contractual Clauses may also be used as the basis for data transfers.

For more information, please see Google's Privacy Policy, the information on data usage on websites, and our Cookie Policy.

Once you have given your consent, we will use the Meta Pixel on our website. For users in the European Economic Area, the provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Meta-Pixel allows us to track whether people visit specific pages on our website or perform certain actions after viewing or clicking on an ad. This enables us to measure the effectiveness of our ads and create target audiences for advertising campaigns.

In particular, the following data may be processed: page views, time of access, referrer information, browser and device information, IP address, Facebook/Meta identifiers, cookie identifiers, and other online identifiers.

Activation occurs only with your consent. The legal basis is Article 6(1)(a) of the GDPR in conjunction with Section 165(3) of the TKG 2021. You may revoke or change your consent at any time via “Manage Cookie Consent.”

Processing in the United States cannot be ruled out. Where the conditions are met, transfers may be based on the EU-U.S. Data Privacy Framework or appropriate safeguards under Article 46 of the GDPR, in particular standard contractual clauses.

For more information: https://www.facebook.com/privacy/policy/

Our website contains links to our profiles on social media networks and platforms, specifically Facebook, Instagram, and YouTube. These links are standard external links and not social media plugins.

Simply visiting our website does not establish a connection to the servers of the respective platform through these links. Only when you click on such a link do you leave our website, and your browser establishes a direct connection to the respective provider. In particular, your IP address, the date and time of access, browser and device information, and the page you previously visited may be transmitted.

If you are logged in to the respective platform, the provider may be able to associate your visit with your user account. The purpose and scope of any further data processing are governed by the privacy policy of the respective provider:

  • Facebook and Instagram: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland – Meta Privacy Policy
  • YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland – Google Privacy Policy

We generally have no control over data processing that takes place after you access the external platform. For more information, please refer to the privacy policies of the respective providers.

Whenever social media content or videos are embedded on our website, they are described separately and—if necessary—are loaded only after you have given your consent.

For online reservations and the management of reservation requests, we use the service provided by tablex Gastro Software GmbH, Lassersdorf 10, 4201 Gramastetten, Austria. The reservation form is embedded as content on our website.

When you access and use the reservation form, technical connection data—including, in particular, your IP address, the date and time of access, browser and device information, and referrer information—may be transmitted to Tablex. When you make a reservation, the data you enter will also be processed. This may include, in particular, your name, phone number, email address, desired reservation date, number of guests, length of stay, and any voluntary comments.

Reservation data is processed to handle your reservation request, to carry out pre-contractual measures, and to process the reservation in accordance with Article 6(1)(b) of the GDPR. The technically necessary processing involved in loading and providing the reservation service is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in providing a secure and user-friendly online reservation option.

Tablex processes the data on our behalf based on an agreement in accordance with Article 28 of the GDPR. Subprocessors engaged by Tablex may be involved in this process.

Reservation data is stored for as long as necessary to process and fulfill the reservation. It is then deleted, unless there are legal retention requirements or further storage is necessary to assert, exercise, or defend legal claims. In such cases, the data is retained only for the specific purpose and for the duration necessary to achieve that purpose.

Any information you provide in the comments field should be limited to what is necessary for the reservation. Please do not enter any specific categories of personal data there—particularly health-related data—unless it is absolutely necessary for the reservation.

For more information on data processing, please see Tablex's Privacy Policy.

For certain inquiries and orders, we provide online forms on our website. For this purpose, we use Gravity Forms, a form software integrated into our WordPress website. The personal data processed is specified in the respective form. This may include, in particular, your name, contact information, billing and shipping details, information regarding the requested service or order, voluntary comments, and technical details related to the submission process.

Data is processed to handle your inquiry, to carry out pre-contractual measures, and to fulfill the order or provide the service you have requested, in accordance with Article 6(1)(b) of the GDPR. To the extent that data must be stored due to statutory retention obligations—in particular those under tax or corporate law—processing is carried out in accordance with Article 6(1)(c) of the GDPR.

We use Stripe’s services to process online payments. The contractual partners for Stripe services in the European Economic Area are, in particular, Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, and—depending on the specific payment service—Stripe Technology Europe Limited, 1 Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland.

When you make a payment, the data required for payment processing is transmitted directly to Stripe. This may include, in particular, your name, email address, billing address, payment amount, currency, the time and status of the transaction, payment method, technical device and connection data, as well as the payment information required to process the selected payment method.

Full credit card or other payment information is processed by Stripe. We generally receive only the information necessary to assign and document the payment, such as a transaction ID, the payment status, and, if applicable, truncated details about the payment method used. We do not store full credit card numbers.

Data is transferred to Stripe for payment processing and contract fulfillment in accordance with Article 6(1)(b) of the GDPR. To the extent that Stripe processes data for fraud prevention, to comply with regulatory obligations, or for its own legally permissible purposes, Stripe may itself be the data controller under data protection law.

Stripe may transfer personal data to affiliated companies, payment service providers, credit institutions, card organizations, and other recipients necessary for processing the payment. In doing so, processing may take place in countries outside the European Economic Area, particularly in the United States. According to Stripe, it relies on applicable adequacy decisions, the EU-U.S. Data Privacy Framework, and/or the European Commission’s Standard Contractual Clauses for this purpose.

Order, billing, and payment data are stored in accordance with statutory retention requirements. Other form data is deleted as soon as it is no longer necessary for processing and completing the respective transaction and there are no statutory retention requirements or legitimate reasons for further storage.

For more information, please see Stripe's Privacy Policy and the Stripe Privacy Center.

On our website, we provide links to external platforms or integrate services from third-party providers through which certain orders, reservations, and purchases are processed. These include, in particular:

  • Wolt and Foodora for food orders and deliveries,

  • Rentware, offered by Betterware Software UG (limited liability), Ernst-Augustin-Straße 12, 12489 Berlin, Germany, for rentals and children's party bookings, as well as

  • Incert, provided by INCERT eTourismus GmbH & Co KG, Leonfeldnerstraße 328, 4040 Linz, Austria, for the purchase and management of gift certificates.

When you click on a standard external link, you will leave our website. Any further collection and processing of personal data will then take place within the respective service. In particular, the following data may be processed: name, contact information, shipping or billing address, details regarding the requested service, booking or order information, payment information, and technical connection and device data.

If an external service is integrated into our website as embedded content or an iFrame, a connection to the respective provider may be established as soon as the embedded content is loaded. In particular, the IP address, the date and time of access, browser and device information, and referrer information may be transmitted.

The data you provide when placing an order, making a reservation, or purchasing a gift certificate is processed for the purpose of taking pre-contractual measures and fulfilling the respective contract in accordance with Article 6(1)(b) of the GDPR. To the extent that storage technologies not required for technical purposes are used, they will only be activated after you have given your consent in accordance with Article 6(1)(a) of the GDPR and Section 165(3) of the TKG 2021.

In the case of external platforms, the respective provider may itself be the data controller under data protection law for the processing carried out within its platform. To the extent that a provider processes personal data exclusively on our behalf, this is done on the basis of an agreement pursuant to Article 28 of the GDPR.

The privacy policy of the respective provider also applies:

The data processed in each system is stored in accordance with the retention periods described therein or for as long as necessary to carry out the transaction, to comply with statutory retention requirements, or to assert, exercise, or defend legal claims.

Our website is not specifically intended for children, and we do not encourage children to provide us with personal information on their own.

We provide an invitation generator to help you design invitations for a children's party. You can enter the name and date of birth of the child hosting the party, the names of the invited children, and, optionally, the email address or phone number of a contact person.

The data entered is processed exclusively locally in the user's browser. The print-ready PDF is generated directly in the browser using JavaScript. The data entered is not transmitted to our web server or to any external service provider. We do not store it, include it in the URL, or use it for analytical, advertising, or any other purposes.

After closing or reloading the page, the data entered in the invitation generator will no longer be available. The generated PDF is saved on the device only if the user downloads it. The user is responsible for the further storage, use, and sharing of the downloaded PDF.

Please enter only the information required for the invitation. The person entering other children’s information into the invitation generator must be authorized to use that information. Special categories of personal data—in particular, health information, allergy information, religious information, or other sensitive information—must not be entered.

Since the data entered is processed exclusively on the end device and is not made available to either Kolarik or any contracted service provider, we do not process this data in any way.

To the extent that personal data is provided to us or a booking service provider in connection with a separate inquiry or booking for a children’s party, the relevant sections of this Privacy Policy shall apply.

If you have any questions, please contact office@kolarik.at.

We transfer personal data only if it is necessary for a specific processing purpose, if there is a legal obligation to do so, if you have given your consent, or if another legal basis permits the transfer.

Depending on the specific process, the following recipients or categories of recipients, in particular, may receive personal data:

  • Our hosting provider ALL-INKL.COM – Neue Medien Münnich, owned by René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany,
  • IT, maintenance, and security service providers,
  • Providers of reservation, booking, ordering, and gift card systems, in particular Tablex, Rentware, Wolt, Foodora, and Incert,
  • Newsletter and communications service provider,
  • Payment service providers, in particular Stripe, as well as participating banks, payment organizations, and financial service providers,
  • Marketing and analytics service providers, in particular Google and Meta, provided that you have consented to the relevant processing,
  • Tax advisors, accountants, legal advisors, and other professional advisors, as necessary,
  • Government agencies, courts, and other public bodies, to the extent that there is a legal obligation to disclose information, as well as
  • other recipients, if the disclosure is necessary to assert, exercise, or defend legal claims.

To the extent that service providers process personal data exclusively in accordance with our instructions, we engage them as data processors on the basis of an agreement pursuant to Article 28 of the GDPR. Service providers who determine the purposes and means of processing on their own process the data under their own responsibility under data protection law. For certain services, joint controllership pursuant to Article 26 of the GDPR may also apply; where this is the case, we will provide information about it in connection with the respective service.

Service providers receive only the personal data they need to perform the respective service. They are selected and contracted in accordance with statutory data protection and security requirements.

To the extent that personal data is processed outside the European Economic Area, such transfer takes place only in accordance with the legal requirements set forth in Articles 44 et seq. of the GDPR. Suitable legal bases include, in particular, an adequacy decision by the European Commission, certification of the recipient under the EU-U.S. Data Privacy Framework, or the European Commission’s Standard Contractual Clauses, including any necessary supplementary safeguards. Details are provided in the descriptions of the respective services.

If you apply for a posted position or submit a speculative application through our website, we will process the application data you provide. This may include, in particular, your name, contact information, address, details about the desired position, resume, cover letter, proof of qualifications, application photo, and other documents you voluntarily submit.

The processing is carried out for the purpose of conducting the application process and deciding whether to establish an employment relationship in accordance with Article 6(1)(b) of the GDPR. To the extent that this is necessary to fulfill obligations under labor or social security law, the processing is carried out in accordance with Article 6(1)(c) of the GDPR. The processing of special categories of personal data provided voluntarily takes place only under the conditions set forth in Article 9 of the GDPR.

Please provide only the personal data necessary for the evaluation of your application. In particular, application materials should not contain any unnecessary information regarding health, religion, ethnic origin, political opinion, or other specially protected circumstances.

Within our company, only those individuals involved in processing your application and making the hiring decision will have access to your application data. If technical service providers are used, they will receive this data only to the extent necessary and in accordance with statutory data protection requirements.

If no employment relationship is established, application data will generally be deleted no later than six months after the conclusion of the application process, unless longer retention is necessary to assert, exercise, or defend legal claims.

You will only be added to a candidate or talent pool for future job openings with your separate consent. In this case, we will inform you of the intended retention period. You may revoke your consent at any time, effective for the future.

If an employment relationship is established, the necessary application data will be transferred to the human resources department and processed in accordance with the applicable legal and contractual requirements.

We store personal data only for as long as is necessary for the respective purpose of processing or as required by statutory retention obligations. The specific retention period depends on the type of data, the purpose of processing, and the respective legal basis.

If a specific retention period is specified in the individual sections of this Privacy Policy, that period takes precedence. Otherwise, the following criteria apply in particular:

  • Data from inquiries is generally stored until the inquiry has been fully processed and is then deleted, provided that no contractual relationship results from it and no other legal basis permits further storage.
  • Contract, order, booking, and payment data are stored for the duration of the contract and thereafter in accordance with statutory retention requirements.
  • Accounting records, invoices, and other business documents relevant for tax purposes are generally retained for seven years. Longer retention may be necessary if the documents are relevant to pending administrative or judicial proceedings.
  • Data processed on the basis of consent is generally stored until the consent is revoked or until the purpose of the processing no longer applies, unless another legal basis permits or requires further storage.
  • Server log data is automatically deleted after 14 days, as described in the section “Server Logs and Website Hosting.”
  • Data may be retained for a longer period to the extent necessary to assert, exercise, or defend legal claims. The duration is determined, in particular, by the applicable statutory limitation periods.

Once the respective retention period has expired, the data will be deleted or anonymized. The data will not be deleted as long as it must be retained due to a legal obligation. During such a retention period, processing is limited to the purposes specified by law.

To the extent that personal data is processed by external platforms acting on their own behalf, their respective deletion and retention policies apply in addition.

We take appropriate technical and organizational measures to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. These measures are determined by taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the associated risks.

The measures we have implemented include, in particular, encrypted transmission of our website via TLS, access restrictions and authorization policies, the securing of administrative access, regular updates to the software we use, and data backup and recovery procedures.

Personal data is accessible only to those individuals and service providers who need it to perform their respective duties. Contracted service providers are selected in accordance with legal requirements and are bound by contract.

Despite appropriate security measures, data transmission over the Internet cannot be completely risk-free. Therefore, please do not submit any confidential or special categories of personal data via publicly accessible input fields unless this is expressly required and intended for the specific process.

Should we become aware of a personal data breach, we will investigate it immediately and, if necessary, comply with the legal reporting and notification requirements under Articles 33 and 34 of the GDPR.

If you subscribe to our newsletter, we will process the data you provide—in particular your email address—to send you regular updates about our offers, events, and news. This processing is based on your consent in accordance with Article 6(1)(a) of the GDPR.

We use the newsletter system provided by tablex Gastro Software GmbH, Lassersdorf 10, 4201 Gramastetten, Austria, for the registration, management, and distribution of our newsletter. The data provided during registration—specifically, title, first and last name, date of birth, and email address, as well as the IP address and the time of registration—is transmitted to Tablex and processed there on our behalf.

Registration is confirmed via a double opt-in process. You will receive an email containing a confirmation link. This process is designed to verify your registration and prevent the misuse of other people's email addresses.

To measure and improve our newsletters, Tablex may track whether and when a newsletter is delivered and opened, and which links contained therein are clicked. In particular, the following data may be processed: the time of delivery and opening, the duration of the session, the links clicked, the time of the click, the IP address, and information about the email program and device used. This information enables us to analyze the use of our newsletters and improve their content.

The distribution of the newsletter and the associated performance measurement are based on your consent in accordance with Article 6(1)(a) of the GDPR. To the extent that information is stored on or retrieved from your device for the purpose of performance measurement, this is also based on your consent in accordance with Section 165(3) of the TKG 2021. It may not be technically possible to opt out of performance measurement while continuing to receive the newsletter.

The data processed for sending the newsletter and measuring its effectiveness is generally stored until you revoke your consent or unsubscribe from the newsletter. After you unsubscribe, your data will be removed from the active newsletter distribution list, unless there are legal retention requirements or legitimate reasons for continued, limited storage.

You may withdraw your consent at any time with future effect, specifically by using the unsubscribe link in each newsletter, by email to office@kolarik.at, or by mail to Kolarik im Prater GmbH, Prater 128, 1020 Vienna. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

For more information, please see Tablex's privacy policy.

We review this Privacy Policy regularly and update it if there are changes to the data processing we perform, the services we use, or legal requirements. The most current version is available on this website.

If a change affects consent that has already been given and the law requires renewed consent, we will obtain it separately. Simply continuing to use our website does not constitute consent to the changed data processing practices.

The date of the last update can be found at the end of this Privacy Policy.

If you have any questions about the processing of your personal data, this Privacy Policy, or the exercise of your privacy rights, please contact us:

Kolarik im Prater GmbH
Prater 128
1020 Vienna
Austria

Email: office@kolarik.at
Phone: +43 1 729 49 99

This contact point serves as our company’s general data protection contact. It is not designated as a data protection officer within the meaning of Articles 37 through 39 of the GDPR, unless a data protection officer has been formally appointed.

Please avoid sending highly confidential information or special categories of personal data via unencrypted email whenever possible. If proof of identity is required to process a request, we will notify you separately.

Provided that the relevant legal requirements are met, you have the following rights under the GDPR, in particular:

  • Right to access the personal data we process pursuant to Article 15 of the GDPR,
  • Right to have inaccurate data corrected or incomplete data completed in accordance with Article 16 of the GDPR,
  • Right to erasure of your personal data pursuant to Article 17 of the GDPR,
  • Right to restriction of processing under Article 18 of the GDPR,
  • Right to data portability under Article 20 of the GDPR,
  • Right to object to processing pursuant to Article 21 of the GDPR, as well as
  • The right to withdraw consent at any time, with effect for the future, in accordance with Article 7(3) of the GDPR.

If personal data is processed for the purpose of direct marketing, you may object to this processing at any time. In this case, your personal data will no longer be processed for direct marketing purposes.

To exercise your rights, you can contact us by email at office@kolarik.at or by mail at Kolarik im Prater GmbH, Prater 128, 1020 Vienna.

If you believe that the processing of your personal data violates data protection law, you have the right to file a complaint with a data protection supervisory authority. In Austria, this is:

Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at

The right to appeal is without prejudice to other administrative or judicial remedies.

As of August 2026

Contact

We welcome your questions, requests, suggestions and criticism.

We can only process reservation requests via the reservation form.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I would like to be contacted by email / callback
This field is hidden when viewing the form

Collection

Order via Getsby and choose when you would like to collect the food you have ordered from us.

Delivery

Order via Wolt or Foodora and have our delicacies conveniently delivered to your home.

Newsletter subscription

With our newsletter you will regularly receive news, offers or information about special events. In total we send out 12-14 issues per year.







I agree to receive information about offers and services from Kolarik im Prater according to my preferences selected here. I also agree to the privacy policy. I can revoke this consent at any time.

Kolarik im Prater GmbH offers visitors to the website the opportunity to subscribe to a newsletter in order to receive regular information about Kolarik im Prater, e.g. about news, offers and events by email. The following special terms of use apply to this participation.

The subscription requires that the visitor registers to receive the newsletter, for which the e-mail address must be provided. Only persons who are at least 18 years old and have full legal capacity are permitted to register. Otherwise, a declaration of consent from a parent or legal guardian is required. Kolarik im Prater reserves the right to reject a registration request without giving reasons. The person making the request has no right to participate in our service. Use on behalf of third parties or for third parties is expressly prohibited.

We use Tablex to manage and send our newsletter. By registering, you confirm that you agree to your data being transferred to Tablex for further processing. Learn more about Tablex's privacy policy here.

You can change your mind at any time by clicking on the unsubscribe link found in the footer of every email you receive from us, or by contacting us at luftpost@kolarik.at. We will treat your information with care and respect.



Reservation

Book your table at the world's largest organic restaurant

Mon.–Thu.: 16:00–23:00
Fri.–Sun. & bank holidays: 11:00–23:00
Kitchen until 21:00

We accept
all major
debit & credit cards