Last update: June 2026
Privacy Policy
This Privacy Policy is provided pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR) to users visiting this website and/or making an online reservation.
Data Controller
The Data Controller is the entity indicated in the Contacts section of this website. To exercise the rights granted by the GDPR or for any privacy-related communication, you may write to the email address provided in the Contacts section.
Types of Data Processed
Navigation Data
The IT systems and software procedures used to operate this website may collect certain personal data during their normal operation, the transmission of which is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified individuals, but by their nature, could—through processing and association with data held by third parties—allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (success, error, etc.), and other parameters related to the user’s operating system and IT environment.
Cookies and Tracking Technologies
This website uses technical cookies necessary for the operation of the pages and session management. Cookie consent is managed via the Complianz plugin (free version), which allows users to accept, reject, or customize their preferences. No third-party profiling cookies are installed without prior user consent.
Voluntarily Provided Data for Reservations
The online reservation service (Reservino) collects the following personal data when requesting or confirming a table:
- Surname – to identify the reservation
- Email address – to send confirmation and reservation-related communications
- Phone number – to contact the customer if necessary
- Number of guests – to manage availability
- Date and time slot – for service planning
- Payment data – if paying a deposit online, transaction data is managed by PayPal Inc. The website does not store credit card or payment instrument details
An OTP (One-Time Password) system is used to verify the user’s identity, sent to the provided email address.
Purposes and Legal Basis for Processing
- Reservation management – legal basis: contract performance (Art. 6(1)(b) GDPR)
- Sending reservation-related communications (confirmation, changes, cancellations) – legal basis: contract performance
- Compliance with legal obligations (e.g., tax, accounting) – legal basis: legal obligation (Art. 6(1)(c) GDPR)
- System security and abuse prevention – legal basis: legitimate interest of the controller (Art. 6(1)(f) GDPR)
- Sending promotional communications – legal basis: explicit consent of the data subject (Art. 6(1)(a) GDPR), where applicable
Processing and Storage Methods
Personal data is processed using electronic means and stored on secure servers. Reservation data is retained for the time strictly necessary to manage the relationship and fulfill legal obligations, and in any case no longer than 10 years for tax and accounting purposes.
Navigation data is retained for the time strictly necessary and in any case no longer than 90 days, except in cases where evidence of crimes needs to be established.
Disclosure to Third Parties
Personal data is not disclosed or transferred to third parties for commercial purposes. It may be communicated to:
- Technical service providers necessary for the operation of the website and reservation service (hosting, email servers)
- PayPal Inc. – for managing online payments, limited to data necessary for the transaction. PayPal’s privacy policy applies, available at www.paypal.com
- Competent authorities – in case of requests from public authorities or to fulfill legal obligations
Transfer of Data Outside the EU
Data may be transferred to third countries (e.g., email or payment service servers) only if adequate safeguards are in place pursuant to Articles 44-49 of the GDPR, including Standard Contractual Clauses approved by the European Commission.
Data Subject Rights
Pursuant to Articles 15-22 of the GDPR, data subjects have the right to:
- Access their personal data
- Request rectification or erasure
- Request restriction of processing
- Object to processing
- Request data portability
- Withdraw consent at any time, without affecting the lawfulness of prior processing
- Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it)
To exercise these rights, you may contact the Data Controller using the contact details provided in the website’s Contacts section.
Updates
This Privacy Policy may be updated at any time. The updated version is always available on this page, with the last modification date indicated.