Privacy Policy

Last updated: [August 14, 2026]

This Privacy Policy describes how Ziblo (hereinafter, the “Service”) processes the personal data of users (hereinafter, the “Data Subject” or “User”) interacting with the website and platform Ziblo, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable laws.

1. Data Controller

The Data Controller is [Alessandro Matta], with registered office at [Via Leopoldo Pellas, 43 – 50141 Florence], VAT/tax ID [01681880496], PEC [matta@pec.alessandromatta.it] (hereinafter, the “Controller”).

To exercise their rights or for any requests related to data processing, the Data Subject may write to: servizioclienti@ziblo.it.

[If appointed, indicate the Data Protection Officer (DPO) and relevant contacts. Otherwise, remove this line.]

2. Types of Data Processed

The Controller may process the following categories of data:

  • Navigation data: data transmitted implicitly during the use of internet protocols (e.g., IP addresses, browser and device type, visited pages, access times).
  • Data voluntarily provided by the User: data communicated to register for the Service, subscribe to the newsletter, or contact the Controller (e.g., email address, name, business data).
  • Data inserted into the Service by Restaurateurs: data necessary for using the management system (e.g., customer records, menus, reservations), processed in accordance with the Terms and, where applicable, a specific data processing agreement.
  • Cookies and tracking tools: as described in the Cookie Policy and managed via the consent banner.

3. Purposes and Legal Bases for Processing

  • Service provision and account management — legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
  • Responding to information/contact requests — legal basis: performance of pre-contractual measures or legitimate interest (Art. 6(1)(b) / 6(1)(f) GDPR).
  • Sending newsletters and informational communications about Service launches and updates — legal basis: User consent (Art. 6(1)(a) GDPR), revocable at any time.
  • Statistical analysis and measurement (audience, advertising campaigns) — legal basis: consent, where required for non-technical cookies (Art. 6(1)(a) GDPR).
  • Compliance with legal obligations (e.g., tax and accounting obligations for paid forms) — legal basis: legal obligation (Art. 6(1)(c) GDPR).
  • Security and abuse prevention — legal basis: Controller’s legitimate interest (Art. 6(1)(f) GDPR).

4. Processing Methods

Data is processed using IT and telematic tools, with technical and organizational measures in place to ensure security, confidentiality, and integrity, and to prevent unauthorized access, loss, or destruction.

5. Providers and Data Recipients

To provide the Service, the Controller uses third-party providers that process data as either Data Processors or independent Controllers. These include:

  • [Hosting provider, e.g., Aruba S.p.A.] — hosting and infrastructure for the website and Service.
  • Brevo (Sendinblue SAS) — managing subscriptions and sending newsletters. Processing in accordance with Brevo’s privacy policy.
  • Google (Google Ireland Ltd / Google LLC) — navigation statistics (Google Analytics 4) and advertising campaign measurement (Google Ads), activated after consent for the relevant cookies.
  • [Any other providers: payment processors for paid forms, etc. — to be listed.]

Data is not disclosed. It may be communicated to competent authorities where required by law.

6. Transfer of Data Outside the EU

Some providers (e.g., Google) may process data outside the European Economic Area. In such cases, transfers comply with GDPR safeguards (e.g., adequacy decisions or Standard Contractual Clauses). Further details are available in the respective providers’ privacy policies.

7. Retention Period

Data is retained for the minimum time necessary for the purposes for which it was collected, specifically:

  • account and Service data: for the duration of the relationship and, subsequently, as required by law;
  • newsletter data: until consent is revoked (unsubscription);
  • data for tax/accounting obligations: for the statutory periods (typically 10 years);
  • statistical/measurement data: as indicated in the Cookie Policy.

[Verify and adapt retention periods to actual processing activities.]

8. Data Subject Rights

The Data Subject may exercise the rights under Arts. 15-22 of the GDPR at any time, including:

  • right to access their data;
  • right to rectification and erasure (“right to be forgotten”);
  • right to restriction and objection to processing;
  • right to data portability;
  • right to withdraw consent at any time, without affecting the lawfulness of processing based on consent given prior to withdrawal.

Requests should be sent to servizioclienti@ziblo.it. The Data Subject also has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

9. Nature of Data Provision

Providing data necessary for Service provision is optional, but refusal may make it impossible to use the Service or specific features. Providing data for the newsletter is optional and subject to consent.

10. Cookies

The Service uses cookies and similar tools. Detailed information (types, purposes, duration, and consent management) is available in the Cookie Policy.

11. Changes to this Privacy Policy

The Controller reserves the right to update this Privacy Policy at any time, with notice on this page including the update date. Users are advised to review it periodically.

12. Contacts

For any questions about this Privacy Policy or data processing: servizioclienti@ziblo.it.

How can I help you? Click here!