Legal

Privacy Policy

This page explains what personal data Jospereno collects when you use this website or contact us, why we collect it, who we share it with, and the rights you have over it.

Last updated 21 August 2026 · Written against the DIFC Data Protection Law No. 5 of 2020

Who we are

Jospereno is a steakhouse at Al Murooj Complex, Sheikh Zayed Road, DIFC, Dubai, United Arab Emirates. We operate this website at jospereno.com.

For the purposes of data protection law, we are the controller of the personal data described on this page. That means we decide what is collected and why, and we are responsible for it.

Because we operate from the Dubai International Financial Centre, the law that applies to this policy is the DIFC Data Protection Law No. 5 of 2020, together with the DIFC Data Protection Regulations. The DIFC Commissioner of Data Protection supervises it.

What we collect

When you visit this website

Our website does not require you to create an account, and we do not take bookings — Jospereno is walk-in only. So on an ordinary visit we collect very little about you personally:

  • Technical and usage data. Your IP address, browser and device type, operating system, the pages you view, how you arrived, and roughly where you are (city level). This comes from our server logs and from the analytics and advertising tools described below.
  • Identifiers stored on your device. Cookies and similar technologies set by us and by Google and Meta. See Cookies and tracking.

When you contact us

  • By WhatsApp or phone (+971 52 420 6404): your phone number, your name if you give it, and the content of your messages.
  • By email (hello@jospereno.com): your email address and whatever you write to us.
  • Through a form on this site, if and when we publish one: the fields you fill in. We will always tell you at the point of collection what each field is for.

If you join our mailing list or a loyalty programme

We are preparing an email list and a loyalty programme. If and when you choose to sign up, we will collect your email address, the name you give us, and — only if you volunteer it — your birthday, so we can send you something on it. You will be asked to confirm your subscription, and every message we send will carry a one-click unsubscribe. We will not add you to any list because you contacted us about something else.

What we never collect on this website

We do not take payments online, so this website never handles card or bank details. We do not collect passport or ID numbers. We do not ask for, and do not want, any information about your health, religion, ethnicity or any other special category of data.

Why we collect it, and on what basis

What we doWhyOur lawful basis
Serve and secure the websiteTo make pages load, keep the site available, and detect abuse or attacksOur legitimate interests in running a working, secure website
Measure how the site is usedTo understand which pages are useful, and to fix the ones that are notOur legitimate interests in improving what we offer
Advertising and measuring our advertisingTo show our ads to relevant audiences and see whether they workedOur legitimate interests, and your consent where the law requires it
Answer you when you write to usBecause you asked us something and we would like to replyOur legitimate interests in responding to enquiries
Send you marketing emailTo tell you about the menu, offers and what is happening at the restaurantYour consent, which you may withdraw at any time
Run a loyalty programmeTo recognise you as a returning guest and give you what the programme promisesYour consent, and performance of the programme terms

Where we rely on legitimate interests, we have weighed those interests against your rights, and we have kept the data to what is genuinely needed for the purpose. You can object to that processing — see Your rights.

Cookies and tracking

This site uses cookies and similar identifiers for three things: to make it work, to measure how it is used, and to support our advertising.

  • Necessary. Set by our hosting and caching to serve pages correctly and keep the site secure. The site does not work properly without these.
  • Analytics. Google Analytics 4, loaded through Google Tag Manager. These tell us which pages people read and where they arrive from. We do not use them to identify you personally.
  • Advertising. The Meta pixel, which supports our advertising on Facebook and Instagram and tells us whether an ad led to a visit.

You can clear or block cookies in your browser settings at any time. You can opt out of Google Analytics with Google's browser add-on, and you can control how Meta uses your activity in your Facebook or Instagram ad settings. Blocking cookies will not stop you using this website.

Where the law requires your consent before non-essential cookies are set — which includes visitors in the European Economic Area and the United Kingdom — that consent is requested before those tools load.

Who we share it with

We do not sell your personal data. We do not rent it, and we do not trade it. We share it only with the categories of service provider we need to run the business, and only for the purposes above:

  • Our hosting and website security provider — to serve this website and keep it available and protected.
  • Google — analytics and advertising measurement, through Google Analytics and Google Tag Manager.
  • Meta — advertising and measurement on Facebook and Instagram, and WhatsApp if you choose to message us there.
  • Our email delivery provider — only if you sign up to our mailing list, and only to deliver those messages.

We name Google and Meta specifically because their cookies and tags run in your browser on this site, and because you may want to use their own opt-out controls, which we link to in Cookies and tracking. For the other categories, if you want to know exactly which company we use, write to us and we will tell you.

We may also disclose data where the law requires it, or to establish or defend a legal claim.

Where your data goes

Some of the providers above process data outside the DIFC and outside the UAE, including in the United States and the European Union. Where we transfer personal data out of the DIFC, we do so on a basis permitted by the DIFC Data Protection Law — either to a jurisdiction the DIFC recognises as adequate, or under contractual safeguards with the provider.

How long we keep it

  • Server logs: a short rolling window kept by our host for security and troubleshooting.
  • Analytics and advertising data: for the retention period set in the relevant Google and Meta products, which is measured in months, not years.
  • Emails and WhatsApp messages: as long as we need them to deal with what you asked, and a reasonable period afterwards in case you come back to us.
  • Mailing list and loyalty data: until you unsubscribe or ask us to delete it. If you stop opening our emails for a long time, we will remove you rather than keep mailing.

Your rights

Under the DIFC Data Protection Law you have the right to:

  • Access the personal data we hold about you, and get a copy.
  • Correct anything that is wrong or incomplete.
  • Have it erased, where we no longer have a good reason to keep it.
  • Restrict how we use it while a question about it is resolved.
  • Object to processing we base on legitimate interests, including profiling for advertising.
  • Receive it in a portable format, where the processing is based on consent or a contract and is automated.
  • Withdraw consent at any time, where consent is what we relied on. Withdrawing it does not undo what was lawful beforehand.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make any such decisions.

To exercise any of these, email hello@jospereno.com. We will respond within one month. We may ask you to confirm who you are first, so that we do not hand your data to someone else. Exercising these rights is free.

If you are not satisfied with how we have handled your request, you may complain to the DIFC Commissioner of Data Protection at the Dubai International Financial Centre.

Children

This website is meant for adults. We do not knowingly collect personal data from children. Families are very welcome in the restaurant, but if you believe a child has given us personal data through this website, write to us and we will delete it.

Changes to this policy

When we change how we handle personal data, we update this page and change the date at the top. If a change materially affects your rights, and we have a way to reach you, we will tell you directly rather than leave you to notice.

How to reach us

For anything on this page, including a request about your data: