The protection of our website Users’ privacy is an absolute priority for us.
ANTONINO S.R.L., pursuant to Articles 13 and 14 of EU Regulation 2016/679 (so-called “GDPR” – General Data Protection Regulation), wishes to inform you, pursuant to Article 13 of EU Regulation 2016/679 (hereinafter “GDPR” or “Regulation”) and D. Lgs. 196/2003 (Privacy Code), as amended by D. Lgs. 101/2018 as amended and supplemented, regarding the purposes and methods by which it will process the personal data (hereinafter “Data”) of users who consult the following website: www.cannavacciuolobistrot.it
N.B.: This privacy notice is provided solely for the aforementioned website and not for any other websites that may be accessed by the user via links.
By connecting to the website and, where applicable, providing their data or expressing consent to their processing (when required for specific purposes), the User declares to be over 16 years of age.
If the service is used by minors, or if personal data relating to minors is entered in connection with hotel or restaurant reservation requests, processing shall take place exclusively within the limits of what is necessary for managing the reservation, providing the requested service, and complying with any applicable legal obligations. In such cases, the minor’s data must be provided by the person exercising parental responsibility or by another authorized person, who guarantees that they are authorized to disclose such data to the Data Controller.
A) ENTITIES INVOLVED IN DATA PROCESSING
Data Controller: ANTONINO S.R.L., VAT No. IT02587680030, with registered office at VIALE MARAZZA 4 – 28021 BORGOMANERO (NO), Italy, Tel.: +39 0322 81968, standard e-mail: info@bistrottorino.it, PEC: antoninocsrl@legalmail.it
Data Protection Officer (DPO): Studio Bagaini e Rillo – Viale Marazza 4, 28021 Borgomanero (NO), VAT No. 01699250039, and the company New Sistem s.r.l. – Viale Marazza 4, 28021 Borgomanero (NO), VAT No. 01622410031, in the person of Accountant Maria Silvana Rillo, Fiscal Code RLLMSL61C46H632Y, has been appointed by the Controller as Data Protection Officer (DPO) for CA.PRI S.R.L.
Joint Data Controller: Cannavacciuolo Consulting s.r.l. Unipersonale, with registered office at Viale Marazza 4, 28021 Borgomanero (NO), PEC: cannavacciuoloconsultingsrl@legalmail.it
The complete and updated list of Data Processors is available at the Controller’s registered office.
For information and the management of rights, the data subject may also write to: privacy@cannavacciuologroup.it
B) PERSONAL DATA PROCESSED
Through our website, the following personal data of Users may be collected and processed by the Controller (as well as any appointed Data Processors):
Standard personal data of the User, suitable for identification and for entering into contracts for requested services/products: first and last name, e-mail address, telephone number, tax data (where invoice issuance is required), additional identification data whose transmission to the competent Questura is mandatory pursuant to art. 109 R.D. n. 773/1931 (Testo Unico delle Leggi di Pubblica Sicurezza) and art. 2 of the Technical Annex to D.M. 076.01.2013, as well as any further personal data voluntarily provided by the User for assistance and information.
Payment Information: Information regarding credit cards or other payment instruments used by the User to execute payments will not be processed directly by the Controller, but by the authorized payment service provider through specific and secure protocols. For further information on how such data is processed, the User is invited to consult the privacy policy of the selected payment service provider.
Special Categories of Data: For reservation purposes, special categories of Data may be collected: data concerning health, related to food allergies or intolerances, as well as additional data related to specific dietary requirements followed by the User.
C) PURPOSES, LEGAL BASIS, AND MANDATORY OR OPTIONAL NATURE OF PROCESSING
The purposes for which the data referred to in the preceding section are processed by the Controller are as follows:
Management of reservation requests at the Restaurant;
Management of reservation requests at the Hotel;
Compliance with obligations imposed by applicable legislation (accounting, tax, etc.);
Compliance with obligations imposed by applicable legislation regarding the identification of guests staying at accommodation facilities and reporting their names to the competent local police headquarters (questure) pursuant to art. 109 R.D. n. 773/1931 (Testo Unico delle Leggi di Pubblica Sicurezza) and the regulations cited therein;
Management of requests for assistance or information submitted by the User via e-mail, telephone, or other contact channels provided by the Controller;
Sending newsletters containing commercial offers relating to the Controller’s activities;
Management of website statistics based on non-anonymized data.
Legal Bases
For purposes Nos. 1 and 2: The legal basis consists of the performance of a contract to which the User is party or the performance of pre-contractual measures taken at the User’s request, pursuant to Art. 6(1)(b) GDPR. For the same purposes, should special categories of data concerning health be processed (such as food allergies, intolerances, or specific dietary requirements), the legal basis consists of the User’s free, specific, informed, and unambiguous consent, pursuant to Art. 6(1)(a) GDPR and Art. 9(2)(a) GDPR.
For purposes Nos. 3 and 4: The legal basis consists of compliance with a legal obligation to which the Controller is subject pursuant to applicable law, under Art. 6(1)(c) GDPR.
For purpose No. 5: The legal basis consists of the performance of pre-contractual measures taken at the User’s request or, depending on the content of the request, the Controller’s legitimate interest in providing a response to assistance or information requests received, pursuant to Art. 6(1)(b) and (f) GDPR.
For purposes Nos. 6 and 7: The legal basis consists of the free, specific, informed, and unambiguous consent expressed by the User, pursuant to Art. 6(1)(a) GDPR. With particular reference to sending newsletters and marketing communications, consent is optional, distinct, and separate from other processing purposes, and may be revoked at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Nature of Data Provision
For purposes Nos. 1 and 2: The User has a contractual obligation to provide data: failing which, the Controller will be unable to enter into the contract with the User and execute it, or to provide the requested performance or service.
For purposes Nos. 3 and 4: The User has a legal obligation to provide data: failing which, the Controller will be unable to comply with the obligations imposed upon it by applicable legislation, and the User will be unable to enjoy the requested performance or service.
For purpose No. 5: Providing data is optional; however, failing to provide the necessary data, the Controller may be unable to respond to the request for assistance or information submitted by the User.
For purposes Nos. 6 and 7: Providing data is optional: failing which, depending on the purpose, the User will not be able to receive newsletters and the Controller will not be able to collect statistics based on non-anonymized data.
D) RECIPIENTS
Data processed through this website, and exclusively for the purposes indicated above, may be disclosed to external entities acting on behalf of the Controller (external contractors, service providers, etc.) appointed as Data Processors.
For the purpose referred to in No. 4, data are also disclosed to the authorities identified by applicable law (the territorially competent Questura and the Ministry of the Interior – Department of Public Security).
E) TRANSFERS
Data transfers to third countries that do not satisfy the conditions set forth in Articles 45 et seq. – in particular Article 46 – of the GDPR will never be carried out.
F) DATA RETENTION
Personal data collected or otherwise processed through this website shall be processed in compliance with the principles set forth in Art. 5 GDPR (lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability) using hard copy or electronic means, exclusively for the pursuit of the aforementioned purposes.
Personal data shall be retained for a period no longer than strictly necessary to achieve the stated purposes, unless further retention is required by applicable law, permitted under the Controller’s legitimate interest, or warranted by proven legal grounds.
For purposes Nos. 1 and 2: Data shall be retained for the time necessary to execute the contract and, based on the Controller’s legitimate interest in potential legal defense, until the expiration of the statute of limitations for any actions arising from the contract.
For purposes Nos. 3 and 4: Data shall be retained for the period mandated by applicable law (e.g., accounting records, invoices, and letters/telegrams received and sent must be retained for 10 years pursuant to art. 2220 c.c.).
For purpose No. 5: Data shall be retained for the time necessary to process and respond to the request for assistance or information and, where necessary, for any additional period permitted under applicable legislation to protect the Controller’s rights.
For purposes Nos. 6 and 7: Data shall be retained until the specific purpose is achieved or until consent is withdrawn by the User, whichever comes first.
Upon expiration of the retention period, personal data shall be deleted or permanently anonymized so as to prevent any re-identification of the User. The IT systems employed to manage collected data are pre-configured to minimize the use of data whenever it is not strictly necessary to achieve the specific purpose pursued.
G) YOUR RIGHTS
The Controller hereby informs the User of the rights granted under Arts. 13(2)(b) and (d), 15, 16, 17, 18, 19, and 21 GDPR, specifically the rights of:
Access to data (Art. 15 GDPR);
Rectification (Art. 16 GDPR);
Erasure (Art. 17 GDPR);
Restriction of processing (Art. 18 GDPR);
Data portability (Art. 20 GDPR);
Objection to processing (Art. 21 GDPR);
Withdrawal of consent at any time, where given (Art. 13(2)(c) GDPR).
Requests may be addressed to the “ENTITIES INVOLVED IN DATA PROCESSING” by sending a registered letter with return receipt (raccomandata a.r.) to the registered office of the Data Controller (or Joint Controller or DPO) or an e-mail to: privacy@cannavacciuologroup.it