Privacy Policy

1. Data controller

The data controller is:

The controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Article 37 GDPR do not apply. For any question about your personal data, please use the contact details above.

2. What data we process and where it comes from

The Site is purely informational: it requires no registration and has no contact forms, members' areas, newsletters or payment systems. The data processed is therefore limited to the following categories.

2.1 Browsing data

In the course of their normal operation, the IT systems and software that run the Site collect certain data whose transmission is inherent in the use of Internet communication protocols: IP address, date and time of the request, page requested, server response code, browser type and operating system. This data is processed by the hosting provider (see section 5) in the server logs, is needed to deliver the service and keep it secure, and is not linked to identified individuals. It may be used to establish liability in the event of computer crimes against the Site.

2.2 Data you choose to give us

When you phone the restaurant or email us to book a table or ask for information, you give us the details we need to handle your request: name, phone number or email address, number of guests, date and time, and any dietary requirements (allergies or intolerances). Information about allergies and intolerances may constitute health data under Article 9 GDPR: we process it solely to prepare your order safely and with your consent, which you give by telling us; you are free not to share it.

2.3 Data collected by third parties

The Site embeds third-party content (a Google Maps map and Instagram reels) which, when loaded, creates a direct connection between your browser and the provider's servers. The provider may receive your IP address and set cookies or similar technologies, acting as an independent controller. Details are given in section 4 and in the Cookie Policy.

2.4 Data published on the Site

In the “What people say” section we show reviews posted by users on Google Maps, with the name (or nickname) chosen by the author and the text as they made it public. This processing is based on the controller's legitimate interest in showing its reputation through content that the authors have voluntarily made public. If you wrote one of these reviews and would rather it did not appear on the Site, just write to us and we will remove it, no reason needed.

3. Purposes, legal bases and retention periods

The controller does not carry out profiling, does not make automated decisions within the meaning of Article 22 GDPR and does not use data for direct marketing.

4. Third-party services on the Site

4.1 Google Maps (Google Ireland Limited)

The “Contact” section includes an interactive map provided by Google Maps. When the map loads, your browser connects to Google's servers, which receive your IP address and device information and may set their own cookies. Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) acts as an independent controller. Privacy policy: policies.google.com/privacy. The Site also links to the restaurant's Google Maps listing, where you can read and leave reviews: clicking these links takes you off the Site.

4.2 Instagram and Facebook (Meta Platforms Ireland Limited)

The “From our Instagram” section shows reel previews hosted on our own servers. Only when you click a preview is Instagram's official player (“embed”) loaded in a window on the Site: at that point your browser connects to the servers of Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland), which may receive your IP address, set cookies and, if you are logged in to Instagram, link the view to your profile. Meta acts as an independent controller. Privacy policy: privacycenter.instagram.com/policy. The Site also links to the restaurant's Instagram and Facebook profiles, which open on those platforms.

4.3 Digital menu

The full menu is available at www.lartigianodellapizza.com/menu/, run by the controller on the same hosting as the Site. The “My list” feature, which lets you note down the dishes you like, stores your choices only in your browser (local storage) and does not send them to the controller.

4.4 External links

The Site contains links to other websites (for example 2wins.studio). The controller has no control over those websites and is not responsible for their privacy practices: please read their own privacy notices.

5. Recipients and transfers outside the EU

Data may be processed on the controller's behalf, as processors under Article 28 GDPR, by:

Data may also be disclosed to public and judicial authorities where required by law. Data is never published, passed on or sold to third parties.

Except as described below, the controller keeps data within the European Union. Emails sent to the controller are handled through Gmail and may also be processed on Google servers in the United States. The providers of embedded content (Google, Meta) may transfer the data they collect as independent controllers to the United States: such transfers rely on the European Commission's adequacy decision of 10 July 2023 (EU-US Data Privacy Framework), to which both companies have signed up, and on the standard contractual clauses referred to in Article 46 GDPR.

6. Whether providing data is required

Browsing data is transmitted automatically when you use the Site. Providing your details for a booking is optional, but without them we cannot reserve a table for you. Telling us about allergies and intolerances is optional: if you don't, the restaurant won't be able to take them into account when preparing your food.

7. Security measures

In line with Article 32 GDPR, the controller takes technical and organisational measures appropriate to the risk, including: transmitting data over HTTPS, hosting with a certified provider whose data centres are in Italy, restricting access to data to authorised and trained people only, and not collecting unnecessary data. Phone bookings are noted down on materials accessible only to restaurant staff and destroyed once no longer needed.

8. Your rights

As a data subject, under Articles 15 to 22 GDPR you have the right to:

You can exercise your rights by writing to the contact details in section 1. We will reply without undue delay and in any case within one month of your request, which may be extended by two further months for particularly complex requests, in which case we will let you know. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.

If you believe that the processing breaches data protection law, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy · www.garanteprivacy.it) under Article 77 GDPR, or with the supervisory authority of the EU country where you live or work, or to bring proceedings before the courts under Article 79 GDPR.

9. Children

The Site is not intended for children under 14, and the controller does not knowingly collect data about them. Bookings must be made by adults.

10. Changes to this notice

The controller may update this notice to reflect legal, technical or organisational changes. The version in force is always the one published at this address, with the date of the last update shown at the top. We recommend checking it from time to time.