Ixchel Mexican Restaurant in Chelsea

Privacy Policy

GUEST PRIVACY NOTICE

This Privacy Notice explains how we collect, use, share and protect personal information about guests of our restaurants, bars and private dining spaces.

1. Who We Are
1.1 Alux Hospitality Group Limited (company number 17208033, registered office 33h Kings Road, London, England, SW3 4LX) is the parent company of a group of hospitality businesses. In this notice, "we", "us" and "our" mean Alux Hospitality Group Limited and the group company that operates the venue you book or visit.
1.2 The venues covered by this notice, and the company that operates each of them, are listed in Schedule 1. The operating company of the venue you visit is a controller of your personal data for that visit. Where guest data is held in a shared group booking, CRM or marketing system, the operating company and Alux Hospitality Group Limited act as joint controllers and have agreed between them who is responsible for each obligation. You may exercise your rights against either of them using the contact details in section 20.
1.3 We have appointed a Data Protection Lead who is responsible for overseeing this notice. We are not required to appoint a statutory Data Protection Officer, but our Data Protection Lead performs that role in practice.
1.4 We are registered with the Information Commissioner's Office (ICO) under registration number [ICO REGISTRATION NUMBER].

2. Scope of This Notice
2.1 This notice applies to personal data about people who make, or are named in, a reservation; dine, drink or attend an event at our venues; join a waiting list; buy gift vouchers; enquire about private hire; sign up to our mailing lists; use our guest Wi-Fi; leave feedback or reviews; or contact us by telephone, email, social media or messaging services.
2.2 It does not cover job applicants, employees, contractors or suppliers, who receive separate notices.
2.3 This notice is given under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), each as amended, including by the Data (Use and Access) Act 2025.

3. Key Terms
3.1 Personal data means any information relating to an identified or identifiable living individual, such as a name, telephone number, email address, booking history or CCTV image.
3.2 Special category data means more sensitive personal data, including information about health. Allergy, intolerance and medical dietary information is considered health data.
3.3 Processing means anything done with personal data, including collecting, recording, storing, using, sharing and deleting it.
3.4 Controller means the organisation that decides why and how personal data is processed.
3.5 Processor means a service provider that processes personal data on a controller's instructions, such as a booking system or email platform.

4. Personal data we collect
4.1 We collect only what we need for the purposes in section 7. Depending on how you interact with us, this may include:

Identity information: Title, first name and surname. For events and private hire, this may also include company name and job title.
Contact information: Mobile and landline telephone numbers, email address and postal address where required for vouchers or invoices.
‍Booking information: Date, time, venue, party size, table preferences, booking channel, deposit or pre-payment status, cancellations, no-shows and waiting-list entries.
‍Occasion and preference information: Special occasions such as birthdays and anniversaries, including date of birth if you choose to provide it, seating preferences, drinks and menu preferences, and accessibility requirements you tell us about.
‍Allergy and dietary information: Food allergies, intolerances, coeliac disease and similar medical dietary requirements. Non-medical dietary choices, such as vegetarian or vegan preferences, may also be recorded.
Transaction information: Bills, items ordered, amounts paid, tips and service charge, payment method type, the last four digits of a card, refunds and voucher redemptions. We do not store full card numbers or security codes.
‍Communications information: Emails, calls, messages, social media direct messages, complaints, feedback and survey responses.
‍Marketing information: Your marketing preferences, opt-ins and opt-outs, and whether you open our emails or click links in them.
‍Images: CCTV footage in and around our venues and photographs or video taken at events.
‍Technical information: IP address, device and browser type, and usage information when you use our websites, booking widgets or guest Wi-Fi.
‍Incident information: Accident and first-aid records, records of incidents, refusals of service and exclusions, and information shared with or by the police or licensing authority.

5. Telephone numbers and email addresses

5.1
We ask for a telephone number and email address when you make a reservation because they are needed to administer your booking.We may use these details to:

Send booking confirmations and reminders, or requests to confirm attendance, by email or SMS.
Contact you about changes to your booking, delays, venue closures or problems with your table.
Notify you when a table becomes available if you are on a waiting list.
Take, refund or administer deposits, pre-payments and cancellation charges where the booking terms provide for them.
Send receipts, invoices and private-hire contracts and documents.
Contact you about lost property, an incident during your visit or a food-safety matter affecting your visit.
Respond to enquiries, feedback and complaints.
Send a short post-visit feedback request about your visit.

5.2 These are service messages, not marketing messages. They are sent because they are needed to perform our contract with you or because we have a legitimate interest in running bookings properly. They will not contain promotional content.
5.3 We will only use your telephone number or email address to send you marketing (news, offers, menus, events and invitations) in the circumstances set out in section 9.
5.4 Bookings made for others. If you book for a group, we will usually hold contact details only for the lead booker. If you give us details of other guests (for example a guest's allergy or a surprise birthday), please make sure they are happy for you to do so and point them to this notice.
5.5 Accuracy. Please tell us if your number or email changes. We may ask you to confirm your details when you book or arrive.
5.6 If you do not provide a working telephone number or email address, we may not be able to accept or hold a reservation, particularly for larger parties, peak times or bookings requiring a deposit.

6. How We Collect Your Data
Directly from you, when you book online, by phone, by email, in person, through social media or messaging apps, at the table, or when you sign up to our mailing list or Wi-Fi.
‍From booking platforms, when you book through a third-party platform such as OpenTable, SevenRooms or ResDiary. Some platforms may also act as a separate controller for the account you hold with them and will have their own privacy notice.
‍From other people, such as a friend, colleague, personal assistant, concierge or event organiser who books on your behalf.
‍From payment providers, including confirmation that a payment, deposit or refund has succeeded or failed.
‍From review sites and social media, including public reviews and comments, and messages you send us on sites such as Google, Tripadvisor, OpenTable, Instagram and Facebook.
‍Automatically, through CCTV in our venues and cookies or similar technologies on our websites and Wi-Fi login pages.

7. Why We Use Your Data
7.1 We must have a lawful basis for each use of your personal data. The table below sets out our purposes and the bases we rely on.

To take, confirm, manage and remind you about reservations and waiting-list places.
To take deposits, pre-payments and cancellation or no-show charges, and to process bills and refunds.
To manage private dining, events and private hire, including contracts and invoicing.
To record occasions and preferences in order to personalise your visit and provide a high-quality service. You may ask us not to keep a guest profile.
To record and act on allergy and medical dietary information. Where required, we rely on your explicit consent to process this information.
To send service messages by email and SMS.
To send post-visit feedback requests and handle feedback and reviews.
To send email, SMS and other marketing communications where permitted by law and where you have provided consent or another lawful basis applies.
To send postal marketing and communicate with relevant corporate contacts where we have a legitimate interest in doing so.
To handle complaints, claims and disputes.
To maintain accounting, tax and statutory records where we are legally required to do so.
To meet licensing, health and safety, accident reporting and age verification requirements.
To operate CCTV, maintain security, prevent and detect crime, and manage exclusions.To respond to emergencies and safeguard vulnerable people.
To disclose information to the police, licensing authority or other public bodies where we are legally required or permitted to do so.
To operate our websites, booking widgets and guest Wi-Fi, including analytics and cookies where applicable.
To conduct business analysis, such as analysing booking trends and covers, using aggregated information where possible.
To support a sale, merger or restructuring of our business where necessary.
7.2
Where we rely on legitimate interests (other than a recognised legitimate interest), we have balanced our interests against yours and concluded that the processing is fair. You can ask us for more information about that assessment.
7.3
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. We do not sell your personal data.

8. Allergies and dietary information
8.1
Your safety comes first. If you tell us about an allergy, intolerance or medical dietary requirement, we will record it against your booking and pass it to the team serving you and the kitchen so that your meal can be prepared appropriately.
8.2
Because this is health information, we ask for your explicit consent to record it. You will be asked to confirm this when you book online, by phone or at the table. You may also choose to tell your server on the day rather than recording it in advance.
8.3
We will only keep allergy information in your guest profile for future visits if you ask us to. Otherwise it is deleted from the booking record within 30 days of your visit.
8.4
You may withdraw consent at any time. If you do, we cannot record your requirement in advance, and you should tell your server each time you visit.
8.5
In a medical emergency we may share relevant information with first-aiders and emergency services to protect your life or health.

9. Marketing

9.1
Email and SMS. We will send marketing by email or SMS only if:you have given us your consent, for example by ticking an unticked box when booking or signing up; oryou have booked, bought from or actively enquired with us, we gave you a clear and simple opportunity to opt out when we collected your details, and the marketing is about our own similar hospitality products and services (the "soft opt-in").
9.2
Every marketing email and SMS we send will tell you who it is from and give you a free and simple way to unsubscribe, such as an unsubscribe link or a reply-STOP option.
9.3
Telephone. We will not make marketing calls to you unless you have specifically agreed. We screen numbers against the Telephone Preference Service where required.
9.4
WhatsApp and other messaging apps. We will only send marketing through messaging apps if you have consented to marketing on that channel.
9.5
Group brands. We will only send you marketing about other restaurants in our group (listed in Schedule 1) if you have consented to group marketing. Booking at one venue does not, on its own, mean you will receive marketing from all our venues.
9.6
Third parties. We do not give or sell your contact details to third parties for their own marketing.
9.7 Opting out. You can opt out at any time by using the unsubscribe link, replying STOP, or contacting us (section 20). We will keep a minimal record of your email address or number on a suppression list so that we do not contact you again by mistake.
9.8 Email tracking. Our marketing emails may contain pixels that show us whether an email has been opened and which links were clicked. We use this to improve our communications. [Insert consent or opt-out mechanism as required: see Schedule 6.]

10. CCTV, photography and events
10.1
We operate CCTV in and around our venues for the safety of guests and staff, to prevent and detect crime, and to deal with incidents and claims. Signs are displayed where CCTV operates. CCTV is not used in toilets or changing areas. Footage is normally overwritten after 30 days unless needed to investigate an incident.
10.2
We may occasionally photograph or film our venues or events for marketing. We will make this clear in advance or at the venue, avoid featuring identifiable guests without permission, and remove images on request where possible.
10.3A
t private events, the event organiser may take their own photographs; they are responsible for those images.

11. Websites, cookies and guest Wi-Fi
11.1
Our websites and booking widgets use cookies and similar technologies. Strictly necessary cookies, and certain analytics and functionality cookies permitted under PECR where we give you clear information and a simple way to object, may be set without consent. Advertising, cross-site tracking and social media pixels are only set with your consent. Details and controls are in our Cookie Notice, available on our websites.
11.2
If you use our guest Wi-Fi, we collect the details you enter on the login page and technical information about your device and connection. We use this to provide the service, protect our network and meet any legal requests. Wi-Fi login does not sign you up to marketing unless you tick a separate consent box.

12. Who we share your data with

‍

We share personal data only where necessary. Where we use service providers, we require them to keep your information secure and to use it only in accordance with our instructions. Depending on the circumstances, we may share your personal data with:
Group companies that operate our venues or provide central booking, CRM, finance and marketing functions.
Service providers: booking and table-management platforms, payment processors, point-of-sale and CRM systems, email and SMS platforms, website and IT hosting, guest Wi-Fi providers, CCTV and security contractors, gift-voucher platforms, and survey and review-management tools;
Professional advisers such as solicitors, accountants, auditors and insurers;
Booking and table-management platforms
The police, licensing authority, local authority, HMRC, regulators and courts where we are legally required or permitted to do so;
Event organisers and hosts, limited to the details needed to run their event; and
A prospective buyer, investor or successor in connection with a sale, merger or restructuring of all or part of our business, under confidentiality obligations.
eded to run their event

13. International Transfers

13.1 Some of our service providers store or access data outside the UK. Where this happens we ensure the transfer is lawful: the destination is approved by the UK Government as providing an adequate level of protection (including the EEA and, for certified organisations, the UK Extension to the EU-US Data Privacy Framework), or we use the ICO's International Data Transfer Agreement or Addendum or another approved safeguard. You can ask us for details of the safeguards used.

‍
14. How Long We Keep Your Data

14.1 We keep personal data only for as long as we need it.
Reservation records, including your name, telephone number, email address and booking details, are normally kept for 24 months from your most recent booking or visit, after which they are deleted or anonymised.
Guest profiles containing occasions and preferences are normally kept for 24 months from your most recent booking or visit, or earlier if you request this.
Allergy and dietary information is normally deleted 30 days after your visit unless you ask us to save it to your guest profile.
Marketing information is kept until you unsubscribe. If you do not engage with our marketing for 24 months, we will either ask you to reconfirm your preferences or remove you.
We may retain a minimal marketing suppression record indefinitely where necessary to ensure that we honour your opt-out request.
Bills, payment and accounting records are normally kept for six years from the end of the financial year to which they relate.
Private hire and event contracts are normally kept for six years from the end of the event or contract.
Gift voucher records are normally kept for six years from expiry or redemption.
Complaints and correspondence are normally kept for three years from closure, or six years where a claim is threatened.
Accident and incident records are normally kept for three years from the incident, or longer where a claim is made. For records relating to a child, they may be kept until the child reaches age 21.
CCTV footage is normally kept for 30 days unless it is required for an incident, claim or police request.
Guest Wi-Fi logs are normally kept for 90 days.
Data rights requests and complaints logs are normally kept for three years from closure.
Lost property records are normally kept for three months.
We may retain data for longer where necessary to deal with a legal claim, investigation or legal obligation.

15. How We Keep Your Data Secure
‍
15.1
We use appropriate technical and organisational measures to protect your data, including access controls and unique logins for our systems, encryption of data in transit and on devices where available, role-based access so staff only see what they need, staff training, secure disposal of paper records, and contractual controls over our service providers. Card payments are handled by PCI DSS compliant payment providers.
15.2
If a personal data breach is likely to result in a high risk to you, we will tell you without undue delay.

16. Your Rights
‍

16.1 Depending on the circumstances and subject to applicable legal conditions and exceptions, you have the following rights:
‍Right of access: You can ask for a copy of your personal data and information about how we use it.
‍Right to rectification: You can ask us to correct inaccurate personal data or complete incomplete information.
‍Right to erasure: You can ask us to delete your personal data where there is no good reason for us to continue keeping it.
‍Right to restriction: You can ask us to pause the use of your personal data, for example while the accuracy of the information is being checked.
‍Right to object: You can object to processing based on legitimate interests. You have an absolute right to object to direct marketing.
‍Right to data portability: Where applicable, you can ask to receive personal data you have provided to us in a structured, machine-readable format, or ask us to send it to another organisation.
‍Right to withdraw consent: Where we rely on your consent, you can withdraw it at any time. This will not affect processing that took place before you withdrew your consent.
16.2 To exercise any of these rights, please contact us using the details below.There is normally no fee for making a request. We may need to confirm your identity and, where we hold a large amount of data, ask you to clarify your request.
16.3 We will normally respond within one month. This period may be extended by up to a further two months for complex or numerous requests. If we need to extend the response period, we will tell you within the first month.

17. Complaints
‍

17.1 If you are unhappy with how we have handled your personal data, please complain to us first. You can do so by email to support@ixchellondon.com, or in writing to the postal address in section 20.
17.2
We will acknowledge your complaint within 30 days of receiving it, investigate it without undue delay, keep you informed of progress, and tell you the outcome.
17.3 You may also complain to the Information Commissioner's Office: website ico.org.uk; helpline 0303 123 1113; address Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
‍
‍18. Children
‍

18.1 Our booking services and mailing lists are intended for adults aged 18 and over.We do not knowingly accept bookings from, or send marketing to, children.Where children dine with an adult, we may record information provided by the adult, such as a child's allergy or birthday, on the adult's booking.

19. Changes to This Privacy Notice
‍

We review this Privacy Notice at least annually.The current version, together with its effective date, will always be available on our websites and on request.Where changes materially affect you, we will tell you by email or when you next book with us.

20. Contact Us

If you have questions about this Privacy Notice, want to exercise your data protection rights, or have a data protection enquiry or complaint, please contact our Data Protection Lead.
‍Data Protection Lead: Guery Ferrufino
‍Email: support@ixchellondon.com
‍
Postal address:
Data Protection Lead
Alux Hospitality Group Limited
33H Kings Road
London
SW3 4LX