Privacy Policy
This Privacy Policy explains how personal data are collected and processed when you visit www.ristoranteborsa.it, contact Ristorante Alla Borsa, request information or make a reservation through the communication channels made available on the Website.
The processing of personal data is carried out in accordance with Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR), the applicable provisions of Italian Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018, and the applicable rules concerning cookies and electronic communications.
1. Data Controller
The Data Controller is:
Ristorante Alla Borsa di Pasquali Alceste & C. S.n.c.
Via Goito 2
37067 Valeggio sul Mincio (VR), Italy
VAT No. IT02401690231
Email: info@ristoranteborsa.it
Telephone: +39 045 795 0093
For any request concerning the processing of your personal data or the exercise of your rights under the GDPR, you may contact the Data Controller using the contact details above.
2. Personal Data We Process
Depending on how you use the Website and interact with the restaurant, we may process the following categories of personal data.
2.1 Browsing and technical data
When you visit the Website, the systems used to operate it may automatically collect certain technical information, including:
- IP address;
- browser type and version;
- device and operating system information;
- date and time of access;
- pages and resources requested;
- referring page or website;
- technical logs required for the operation and security of the Website.
These data are generally processed automatically and are necessary for the correct functioning, security and technical administration of the Website.
2.2 Data provided when contacting us or making a reservation
The Website does not currently provide an online purchasing system. Reservations and enquiries may instead be made through the contact methods displayed on the Website, including email, telephone and WhatsApp.
When you contact us, we may process information such as your name, telephone number, email address, number of guests, requested reservation date and time, the content of your message and any other information you voluntarily provide.
Only the data necessary to answer your request, manage your reservation or provide the requested service will be processed.
2.3 Information concerning allergies, intolerances and dietary requirements
The restaurant invites guests to inform us in advance of allergies, food intolerances, coeliac disease or other dietary requirements that may be relevant to the preparation and service of meals.
Some of this information may constitute data concerning health and therefore a special category of personal data within the meaning of Article 9 GDPR.
Such information will be processed only where voluntarily provided for the purpose of managing the guest’s dietary requirements and where the conditions required by Article 9 GDPR, including explicit consent where applicable, are satisfied.
Health-related information will not be used for marketing, profiling or purposes unrelated to the requested restaurant service.
2.4 Cookie preference data
If you use the Website’s cookie preference management system, information concerning your choices may be stored in order to remember and document your preferences.
3. Purposes and Legal Bases of Processing
Website operation and security
Technical and browsing data are processed to operate the Website, ensure its security, prevent misuse, diagnose technical problems and protect the Website and its infrastructure.
Legal basis: Article 6(1)(f) GDPR – legitimate interests of the Data Controller in operating and protecting the Website.
Enquiries and communications
Personal data provided by email, telephone, WhatsApp or other communication channels are processed to answer questions, provide information and manage communications with users.
Legal basis: Article 6(1)(b) GDPR where the communication concerns a reservation or measures requested before entering into a contract, or Article 6(1)(f) GDPR where the communication concerns a general enquiry.
Reservations and restaurant services
Personal data are processed where necessary to receive, confirm, modify and manage table reservations and provide the requested restaurant services.
Legal basis: Article 6(1)(b) GDPR – performance of a contract or steps taken at the request of the data subject prior to entering into a contract.
Allergies, intolerances and other health-related dietary information
Where guests voluntarily provide information concerning allergies, intolerances, coeliac disease or other health-related dietary requirements, such information is processed exclusively to manage the requested dietary arrangements and help provide the restaurant service safely.
Legal basis: Article 9(2)(a) GDPR – explicit consent of the data subject, where required, in conjunction with the applicable legal basis under Article 6 GDPR.
Compliance with legal obligations
Personal data may be processed where necessary to comply with obligations imposed by applicable legislation, regulations, court orders or competent authorities.
Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation.
Establishment, exercise or defence of legal claims
Where necessary, certain personal data may be retained or otherwise processed to establish, exercise or defend legal claims or to protect the rights of the Data Controller.
Legal basis: Article 6(1)(f) GDPR – legitimate interests of the Data Controller.
Optional third-party content and cookies
Where the Website uses non-essential third-party services or technologies requiring consent, they will be activated only after the user has made the corresponding choice through the cookie preference system.
Legal basis: Article 6(1)(a) GDPR – consent, together with the applicable rules governing cookies and similar technologies.
4. Cookies and Similar Technologies
The Website uses cookies and similar technical mechanisms where necessary for its operation and may use third-party services where enabled by the user.
Necessary cookies
Necessary cookies are used to provide essential Website functions. They may, for example, maintain the browsing session, remember the selected language and store the user’s cookie preferences.
These cookies are required for the Website to function correctly and therefore do not require prior consent where they meet the requirements applicable to strictly necessary technical cookies.
Third-party content
The Website contains or may contain content supplied by external providers. Where the activation of such content requires consent, it must remain disabled until the user enables the relevant category through the cookie preferences.
Users may accept, reject or subsequently change their choices at any time using the Cookie Preferences link available on the Website.
5. Google Maps
The Contact page includes an embedded Google Maps map.
When Google Maps is activated, the user’s browser establishes a connection with Google. Google may consequently receive technical information such as the user’s IP address and may use cookies or similar technologies in accordance with its own privacy and cookie policies.
Where required under applicable law, the map is activated only after the user has consented to third-party content through the Website’s cookie preference system.
Consent may be withdrawn at any time by changing the Cookie Preferences.
6. YouTube Content
Some pages of the Website may contain videos embedded from YouTube, a service provided by Google.
When YouTube content is activated, a connection may be established with Google’s servers and technical information, including the user’s IP address and information concerning the browser or device, may be transmitted to Google. Google may also use cookies or other identifiers in accordance with its own privacy practices.
Where consent is required, YouTube content will be loaded only after the user has enabled the relevant third-party content category.
7. Embedded Menu Content
Some menu content available on the Website is displayed through an embedded online viewer hosted on the external domain dm.internetservice.it.
When this content is displayed, technical connection information such as the user’s IP address, browser information and request data may be processed by the provider responsible for delivering the embedded content, insofar as technically necessary to provide and secure the service.
The Data Controller uses such technical services for the legitimate purpose of making restaurant information and menu content available through the Website.
8. WhatsApp
The Website provides a link allowing users to contact the restaurant through WhatsApp.
If you choose to use WhatsApp, your communication is also subject to the privacy terms and technical infrastructure of WhatsApp and its provider. Depending on the information you provide, the restaurant may receive your telephone number, profile information made available through the service, the content of your message and any attachments you choose to send.
WhatsApp is an external service and the Data Controller does not control the processing performed independently by the provider of that service.
You are not required to use WhatsApp and may contact the restaurant by email or telephone instead.
9. Recipients of Personal Data
Personal data may be made available, where necessary and within the limits of their respective functions, to:
- authorised employees and collaborators of the Data Controller;
- hosting, website maintenance and IT service providers;
- email and communications service providers;
- providers involved in the technical operation of the Website and its embedded content;
- Google, where Google Maps or YouTube services are activated;
- WhatsApp and its provider where the user chooses to communicate through that service;
- professional advisers, consultants or legal representatives where necessary;
- public authorities or other entities where disclosure is required by law or by a lawful order.
Where required by the GDPR, service providers processing personal data on behalf of the Data Controller are appointed as processors pursuant to Article 28 GDPR.
Personal data are not sold to third parties.
10. Transfers of Personal Data Outside the European Economic Area
Some third-party technology providers may process personal data in countries outside the European Economic Area.
Where a transfer to a third country takes place, personal data will be transferred only in accordance with Chapter V of the GDPR, including, where applicable, on the basis of an adequacy decision adopted by the European Commission, appropriate contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism recognised by the GDPR.
Users should also consult the privacy information provided by the relevant third-party service provider when choosing to use or activate such services.
11. Data Retention
Personal data are retained only for as long as necessary for the purposes for which they were collected and in accordance with the principle of storage limitation.
In particular:
- technical and security data are retained for the period necessary to operate, secure and troubleshoot the Website and its infrastructure, subject to the retention settings of the relevant technical providers;
- enquiries and reservation communications are retained for the time necessary to answer the request, manage the reservation and, where applicable, for any additional period required by law or necessary for the establishment, exercise or defence of legal claims;
- health-related dietary information is retained only for the time necessary to manage the relevant reservation and restaurant service, unless longer retention is required in connection with a legal obligation, documented incident or legal claim;
- cookie preferences and consent records are retained for the period necessary to remember and document the user’s choices and to comply with applicable legal requirements.
Once the relevant retention period has expired, personal data will be deleted, anonymised or otherwise rendered no longer attributable to the data subject, unless further retention is required by law.
12. Whether Providing Personal Data Is Mandatory
Providing personal data through email, telephone or WhatsApp is generally voluntary.
However, certain information may be necessary to answer a request or manage a reservation. If the necessary information is not provided, the restaurant may be unable to process the request or confirm the reservation.
Providing information concerning allergies, intolerances or other dietary requirements is voluntary. Where such information is necessary for the restaurant to accommodate a specific dietary requirement safely, failure to provide it may prevent the restaurant from guaranteeing that the requested requirement can be met.
Consent to non-essential cookies or third-party content is voluntary and may be refused or withdrawn without preventing access to the essential functions of the Website.
13. Data Security
The Data Controller implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Access to personal data is limited to persons and service providers who require such access for legitimate operational purposes and who are subject to appropriate confidentiality and data-protection obligations.
Nevertheless, no transmission or storage system can guarantee absolute security. Users are therefore encouraged to avoid sending unnecessary personal or sensitive information through electronic communication channels.
14. Automated Decision-Making and Profiling
The Data Controller does not use personal data collected through the Website to make decisions based solely on automated processing that produce legal effects concerning users or similarly significantly affect them within the meaning of Article 22 GDPR.
15. Rights of Data Subjects
Subject to the conditions provided by the GDPR, you may exercise the following rights:
- right of access to your personal data;
- right to rectification of inaccurate or incomplete data;
- right to erasure of personal data where the applicable conditions are met;
- right to restriction of processing;
- right to data portability, where applicable;
- right to object to processing based on legitimate interests, for reasons relating to your particular situation;
- right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
- right to lodge a complaint with the competent supervisory authority.
Requests may be submitted to:
info@ristoranteborsa.it
The Data Controller may request information necessary to verify the identity of the person exercising the rights before responding to the request.
16. Right to Lodge a Complaint
If you believe that the processing of your personal data infringes applicable data-protection legislation, you have the right to lodge a complaint with the competent supervisory authority.
For the Data Controller established in Italy, the supervisory authority is the Garante per la protezione dei dati personali.
This right is without prejudice to any other administrative or judicial remedy available under applicable law.
17. Third-Party Websites and Services
The Website may contain links to websites, social networks or services operated by third parties.
When you follow an external link or voluntarily use a third-party service, the processing performed by that third party is governed by its own privacy information and terms. The Data Controller is not responsible for processing independently carried out by external website or service providers.
18. Changes to This Privacy Policy
The Data Controller may update this Privacy Policy where necessary to reflect changes in legislation, the Website, the services offered or the technologies used.
The updated version will be published on this page together with the date of the latest revision.
Users are therefore encouraged to review this Privacy Policy periodically.