Privacy Policy

Pursuant to EU Regulation 2016/679 (GDPR) — Website: novo-osteria.it

This Privacy Policy describes how the website https://novo-osteria.it/ manages the processing of personal data of users who consult it and use its services. This information is provided in compliance with Art. 13 of EU Regulation 2016/679 (General Data Protection Regulation – GDPR).

1. Data Controller

The Data Controller for the data collected through this website is:

Grand’Impero Srl

Registered Office: Via Nino Bixio 51/B, 29015 Castel San Giovanni (PC), Italy

VAT Number / Tax Code: 01780870331

PEC (Certified Email): grandeimperosrl@legalmail.it

2. Types of Data Collected and Purposes

The processing involves personal data provided voluntarily by the user and technical navigation data necessary for website operations:

  • Contact Form: If the user uses the contact form on the website, identification and contact details such as First Name, Last Name, and Email are collected. This data is processed exclusively to respond to requests for information or support sent by the user.
  • Booking Form (Internal Management): For managing table reservations at the Osteria, First Name, Last Name, Phone Number, Email, and optional Social Media Link are requested and collected. This data is processed exclusively for internal use by authorized personnel to organize, confirm, and manage the booking, as well as to contact the customer regarding any schedule changes or operational needs.
  • Navigation Data and Cookies: The computer systems responsible for running the website acquire certain data required for web navigation (e.g., IP addresses, connection times). The website is built on the WordPress CMS platform and uses the Elementor graphical editor, along with the third-party services listed below.

3. Legal Basis for Processing

The Controller processes personal data based on the following legal grounds:

  • Execution of contractual or pre-contractual measures (Art. 6, par. 1, lit. b GDPR): to manage the Booking Form and respond to requests submitted via the Contact Form.
  • Legitimate interest of the Controller (Art. 6, par. 1, lit. f GDPR): for the proper technical administration of the website, IT security, and performance optimization.
  • Consent of the data subject (Art. 6, par. 1, lit. a GDPR): where explicitly requested for specific tracking or non-anonymized analytical cookies.

4. Third-Party Services and Data Transfer

The website integrates third-party tools and functionalities that may involve the collection or processing of data:

WordPress & Elementor

CMS platform and layout editor used to manage and deliver website content. They do not perform autonomous processing outside the technical scope of publication and optimal website operation.

Google Fonts (Google Ireland Limited)

A typeface optimization service that may display fonts hosted on Google servers. Google may acquire browsing data (such as the IP address) in accordance with its own privacy policy.

Font Awesome (Fonticons, Inc.)

Icon and graphic style visualization services designed to improve the user interface. The integration may involve technical calls to the provider’s servers to load graphic assets.

Google Analytics & Google Search Console (Google Ireland Limited)

Tools used to monitor web traffic trends, perform statistical analysis of website performance, and optimize search engine indexing. Data is collected primarily in an aggregated and anonymized form.

5. Methods of Processing and Data Retention

Data processing is carried out using computer and/or telematic tools, with organizational methods and logic strictly related to the stated purposes, applying appropriate security measures to prevent data loss, illicit use, or unauthorized access.

Data provided for contacts and bookings will be stored only for the time strictly necessary to fulfill the requested service (e.g., until the booking is fulfilled or the contact request is fully handled) and for any period mandatory under tax or applicable legal regulations.

6. Rights of the Data Subject

At any time, pursuant to Articles 15 et seq. of EU Regulation 2016/679, the user can exercise the right to:

  • Obtain confirmation of the existence of personal data concerning them and gain access to it;
  • Obtain the update, rectification, or integration of data;
  • Request the erasure of their data (“right to be forgotten”), transformation into anonymous form, or blocking of data processed unlawfully;
  • Request the restriction of processing or object to it for legitimate reasons;
  • Request data portability in a structured, commonly used format;
  • Lodge a complaint with the Personal Data Protection Authority (www.garanteprivacy.it).

To exercise these rights, requests can be sent directly to the Controller’s PEC email address: grandeimperosrl@legalmail.it.

7. Policy Updates

This Privacy Policy is updated as of July 2026. The Controller reserves the right to make changes at any time to adapt it to new legal provisions or technical updates of the website.

Model Popup