Legal entity: לילנבלום 1 בע״מ
English name: LILIENBLUM 1 LTD
Company number: 515471415
Registered office: Lilienblum 6, Tel Aviv‑Yafo
Restaurant operating address: Lilienblum 1, Tel Aviv‑Yafo
Controller and scope
The controller is the company identified above. Its registered office is distinct from the restaurant’s operating address. To exercise a data right, use the Contact page and select “Privacy / personal data”. The request is tracked in the administration; identity verification limited to what is necessary may be requested before any action.
Data, voluntary submission and purpose
The forms collect a name, contact method and message. The contact form also collects an enquiry category; the group form collects the requested date and time, guest count and event type. Providing the information is voluntary and it is used only to handle and reply to the enquiry. Without a name and contact method, the team cannot reply.
The concierge records exchanged messages, language, replies and handling status. When a later reply is required, the email address and transactional consent are stored solely to send the approved reply and a secure recovery link, without marketing. For a group enquiry, information is recorded progressively and contact details are requested only at the end of the flow. For a dietary or accessibility requirement, provide only the practical need, without a diagnosis or medical detail.
Do not include a name, email, phone number, payment details, identity documents, medical information or severe allergy details in chat; use the separate form for contact details. The information is not reused for marketing.
Recipients and security
Access is limited to authorised restaurant staff and the necessary providers: OpenAI for ChatGPT Sites and the concierge API, Cloudflare infrastructure and its D1 database, Resend (Plus Five Five, Inc.) for transactional alerts and replies, and Google for the internal Gmail inbox. To generate a reply, the site sends the filtered free-text message and recent context, the language, a pseudonymous technical identifier and only relevant verified public information to the OpenAI API. Separate name, email and phone fields are excluded; detectable contact details in text are rejected before storage. A free-text answer about a dietary or accessibility need is processed once as a message, then its structured value is removed from later model context. The request uses store:false. OpenAI has no access to the administration, Ontopo or unpublished information.
An internal alert contains only the category, urgency, a reference and a restricted administration link; it contains no name, contact details or conversation content.
The site uses HTTPS, restricted administration and delivery logs. No security measure removes all risk; access rights and providers must be reviewed regularly.
Retention and deletion
The active policy applies only to data recorded from its activation on 2 September 2026. It automatically removes free text 30 days after closure, a closed enquiry 90 days after the later of creation or event date, any remaining enquiry after 365 days using the same reference point, and individual analytics events after 90 days. Earlier data is excluded from automated deletion. A technical log keeps only dates, statuses and aggregate counters, without personal content. Temporary recovery copies may remain under Cloudflare D1 technical retention periods; Resend states that it keeps email data for 30 days by default.
Applicable requests for access, correction or deletion may be sent with the “Privacy / personal data” subject on the Contact page. A dispute or separate legal obligation may require longer retention.
For new conversations, messages and structured information are cleared 30 days after resolution or closure; the remaining record — follow-up email, consent proof, alerts, decisions, delivery statuses and recovery links — is deleted after 90 days. An unresolved conversation is deleted after 365 days without an update. The strictly necessary HttpOnly cookie expires after 365 days; a link sent or provided to the guest expires after 90 days. These tokens are cryptographically secure and only their hashes are stored. Abuse-prevention fingerprints are no longer used after 48 hours; they then become eligible for deletion during the first daily cleanup triggered by later activity. No deletion is applied retroactively.
Analytics and transfers
The site code includes no advertising, marketing pixels or third-party analytics. It records individual first-party events limited to action type, language and an approved site location, without names, contact details or messages; only totals are displayed in the administration.
ChatGPT Sites does not guarantee data residency in Israel, so processing outside Israel is possible. By default, the OpenAI API may retain abuse-monitoring logs for up to 30 days and does not use API data to train its models unless the customer explicitly opts in. Resend retains email and log data for 30 days on its standard plans and processes data in the United States; Google may also process the Gmail alert outside Israel. These providers, their contractual safeguards and subprocessors must be reviewed periodically.
Rights and legal framework
Israeli law provides rights including access and correction where data is inaccurate, incomplete, unclear or out of date. Requests are verified before action. This page describes the site’s actual operation; it is not a general legal-compliance guarantee.
Last updated: 3 September 2026