PRIVACY POLICY
NOTICE PURSUANT TO REGULATION (EU) 2016/679
Benedicta S.r.l. La Ristorazione, Via Benedetta 12R, 50123 Florence, VAT no. 05795070480, respects the privacy of all individuals who visit its website, and any information collected is used first and foremost to respond to the requests submitted, and secondly to improve the service provided.
Data Controller (hereinafter: Ristorante Benedicta) Benedicta S.r.l. La Ristorazione, Via Benedetta 12R, 50123 Florence, VAT no. 05795070480 Email: info@ristorantebenedicta.it
Types of Data collected
The details of the data that may be collected and processed by the Controller are set out below:
Identification data (first name, last name, telephone number, email, tax code, date of birth, residential address, company details, name of guests and beneficiaries).
How and where the Data collected is processed
Such data will be processed by Ristorante Benedicta for the sole purpose of carrying out the requested service or one or more requested operations, specifically:
- Providing the User with information/clarifications on the services offered
- Online booking of the on-site restaurant service
- Informing the User in the event of website maintenance or any service disruptions
- Sending commercial communications – only with further explicit consent
Processing methods
The Controller adopts appropriate security measures to prevent unauthorised access, disclosure, alteration or destruction of Personal Data. Processing is carried out using IT and/or electronic tools, following organisational procedures and logic strictly related to the purposes indicated. In addition to the Controller, in some cases other parties involved in the organisation (administrative staff, sales staff, legal advisors, system administrators) or external parties (such as third-party technical service providers, hosting providers, IT companies, communication agencies) may have access to the Data — these may also be appointed, where necessary, as Data Processors by the Controller. The updated list of Processors may always be requested from the Data Controller.
In any case, specific security measures are observed to prevent data loss, unlawful or improper use, and unauthorised access.
Processing connected with the web services of this site takes place at the operational headquarters located at Via del Corso, 42R – 50122 Florence, and is handled solely by the appointed Data Processor or by technical staff assigned and instructed for this purpose. No data arising from the web service is disclosed or disseminated.
The processing of the data referred to in the previous paragraph is carried out for the purposes set out below:
- Purposes related to contractual obligations and pre-contractual measures adopted at the request of the data subject;
- Obligations provided for by laws, regulations and EU legislation, by provisions issued by authorities legitimately entitled to do so, and by supervisory and control bodies. In particular, compliance with tax or accounting obligations;
- Customer management (communications with the customer; administration of receipts, orders, invoices; selection processes in relation to the company’s needs).
Place
The Data is processed at the Controller’s operational premises and at any other location where the parties involved in the processing are based. For further information, please contact the Controller.
Retention period
Data is retained for a period of time not exceeding what is necessary to fulfil the purposes for which it is processed. The appropriate retention period is defined in relation to the purposes and compliance with applicable legal obligations, or for the Controller’s legitimate interest.
Data relating to browsing logs, where recorded, will be retained by the Controller for a period of 12 months. We also inform you that the data you provide will be processed for the entire duration of the contractual relationship between us, and further retained solely for the period required to comply with legal obligations, unless it is necessary to retain it for longer in order to establish, exercise or defend a legal claim, or to comply with any further legal obligations or orders issued by the Authorities.
At the end of the retention period, the Personal Data will be deleted. Therefore, once this period has expired, the right of access, erasure, rectification and the right to data portability can no longer be exercised.
User Rights
Users may exercise certain rights with regard to the Data processed by the Controller. In particular, the User has the right to:
- Withdraw consent at any time. The User may withdraw previously given consent to the processing of their Personal Data pursuant to Art. 7 of GDPR 679/2016.
- Object to the processing of their Data. The User may object to the processing of their Data when it is carried out on a legal basis other than consent, pursuant to Art. 21 of GDPR 679/2016.
- Access their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing, and to receive a copy of the Data processed, pursuant to Art. 15 of GDPR 679/2016.
- Verify and request rectification. The User may verify the accuracy of their Data and request that it be updated or corrected, pursuant to Art. 16 of GDPR 679/2016.
- Obtain restriction of processing. The User may request the restriction of the processing of their Data pursuant to Art. 18 of GDPR 679/2016, where certain conditions apply, limiting the Controller to merely storing the data.
- Obtain erasure or removal of their Personal Data. Where certain conditions apply, the User may request the erasure of their Data by the Controller pursuant to Art. 17 of GDPR 679/2016.
- Receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another controller, pursuant to Art. 20 of GDPR 679/2016.
- Lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action, pursuant to Art. 13 of GDPR 679/2016.
(Note for internal review: in the source Italian text the right to lodge a complaint is cited as Art. 13 GDPR — the article that normally governs this right is Art. 77. Translated as given; worth a quick check with whoever manages the legal content before publishing.)
How to exercise your rights
Data subjects may exercise their rights at any time by writing to the Data Controller at info@ristorantebenedicta.it, or by using the forms available on the website www.garanteprivacy.it. Requests are processed free of charge and handled by the Controller as soon as possible, and in any case within one month. Should the need actually arise, the data subject may lodge a complaint with the supervisory authority using the forms available on www.garanteprivacy.it.
COOKIE POLICY
To make our website easier and more intuitive to use, we use cookies. Cookies are small pieces of data that allow us to distinguish between new and returning visitors and to understand how users navigate our website. We use the data collected through cookies to make the browsing experience more pleasant and efficient in the future. Cookies do not record any personal information about a user, and no identifiable data will be stored. If you wish to disable the use of cookies, you need to customise your computer’s settings by setting all cookies to be deleted, or by activating a warning message whenever cookies are stored. To proceed without changing how cookies are applied, simply continue browsing. Visit AboutCookies.org for further information on cookies and how they affect your browsing experience.
The types of cookies we use
Strictly necessary cookies
These cookies are essential to allow you to move around the site and use its features fully, such as accessing the various protected areas of the site. Without these cookies, some essential services — such as filling in the booking form — cannot be provided.
Performance cookies
These cookies collect information about how users use a website, for example which pages are visited most often, or whether error messages are received from web pages. These cookies do not collect information that identifies a visitor. All information collected through these cookies is aggregated and therefore anonymous. It is used only to improve how a website works.
Functionality cookies
These cookies allow the site to remember choices made by the user (such as name, language or region) and provide enhanced, personalised features. These cookies may also be used to remember changes made to text size, fonts and other customisable parts of web pages. They may also be used to provide services you have requested, such as watching a video or commenting on a blog. The information collected by these types of cookies may be made anonymous and cannot track your browsing activity on other websites. By using our site, you agree that such cookies may be installed on your device.
Google Analytics
This website uses Google Analytics, a web analytics service provided by Google, Inc. Google Analytics uses cookies, which are text files placed on your computer, to help the website analyse how users use the site. The information generated by the cookie about your use of the website (including your anonymised IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators, and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, but please note that if you do this you may not be able to use the full functionality of this website. By using this website, you consent to the processing of your data by Google in the manner and for the purposes set out above. You can prevent Google from collecting the cookie generated by your use of this website (including your IP address) and from processing that data by downloading and installing the following browser plug-in: http://tools.google.com/dlpage/gaoptout?hl=en
Details of analytics cookies: _ga _gat _utma _utmb _utmc _utmz
These cookies are used to collect information about how users use our site. We use the information to compile reports and to improve the site itself. The cookies collect information in anonymous form, including the number of visitors to the site, where visitors came from before arriving at the site, and which and how many pages they visited. They are used by the Google Analytics service to distinguish unique users by assigning a randomly generated number as an identifier for the client in use. They are included on every page and used to calculate visitor data and thereby generate visit analytics reports. By default they are set to expire after 2 years, although this setting can be customised by the website owner. If you would prefer Google Analytics not to use the collected data in any way, you can use your browser’s Do Not Track (anonymous browsing) option.
cookie_notice_accepted
A cookie that stores the “Ok, continue” or “accept” response given on the cookie notice bar. This cookie’s duration is set to 30 days.
Social network buttons and widgets
Social network buttons and widgets (for example, Facebook and Twitter) allow visitors browsing the site to interact directly with the social platforms. Using these buttons does not install any third-party cookies on the site. Links are nevertheless provided below where the user can view the privacy notice relating to how each social network manages data:
- https://www.facebook.com/help/cookies
- https://support.twitter.com/articles/20170519-uso-dei-cookie-e-di-altre-tecnologie-simili-da-parte-di-twitter
phpsessid
A non-permanent cookie generated by PHP-based applications. This is a general-purpose identifier used to maintain user session variables. It does not contain any information identifying the user. Expiry: at the end of the browsing session.
icl_current_language
A cookie used to manage the browsing session in the language chosen by the user. Expiry: at the end of the browsing session.