WEBSITE PRIVACY POLICY

    (European Regulation on the protection of personal data no. 2016/679)

    This is an English translation provided for your convenience. The Italian version is the authoritative text: in case of discrepancy, the Italian wording prevails.

    L'Officina S.r.l., which operates "L'Officina ristorante culturale", takes the user's privacy seriously and is committed to respecting it. This privacy policy ("Privacy Policy") describes the personal data processing activities carried out by L'Officina S.r.l. through the website www.lofficinaristorante.it and the related commitments undertaken by the Company.

    The Company, acting as Data Controller, may process the user's personal data when the user visits the Site and uses its services and features.

    In the sections of the Site where the user's personal data is collected, a specific notice pursuant to art. 12/15 of EU Reg. 2016/679 is normally published. Where required by EU Reg. 2016/679, the user's consent will be requested before processing their personal data. If the user provides personal data of third parties, the user must ensure that the disclosure of such data to L'Officina S.r.l. and its subsequent processing for the purposes specified in the applicable privacy notice complies with EU Reg. 2016/679 and related legislation.

    1. Identifying details of the Data Controller

    L'Officina S.r.l., in the person of its legal representative pro tempore, with registered and operating office at Borgo XX Giugno, 56, 06121 Perugia, Italy — VAT no. 03853840548 — REA PG 357550.

    2. Categories of data processed

    Visiting and browsing the Site does not generally involve the collection and processing of the user's personal data, except for navigation data and cookies as specified below.

    In addition to so-called "navigation data", personal data voluntarily provided by the user when interacting with the Site's features or requesting the services offered on it may also be processed.

    Special categories of data (art. 9 GDPR) — allergies and intolerances. The "Notes" field in the Site's forms — table booking, event booking and private event enquiry — allows the user to voluntarily report any food allergies or intolerances. Such information constitutes health data: it is processed exclusively on the basis of the explicit consent given by the user through the dedicated checkbox that appears in the form when the "Notes" field is filled in (art. 9(2)(a) GDPR), for the sole purpose of safely managing the booking and the serving of food. Providing it is optional: alternatively, such information may be communicated directly to staff, in person or by telephone. The content of the notes is not disclosed to any third-party recipient and follows the retention periods of the request it relates to, as set out in section 7.

    3. Cookies and navigation data

    The Site uses "cookies". Cookies are small files stored on the hard disk of the user's computer. There are two broad categories of cookies: technical cookies and profiling cookies. Technical cookies are necessary for a website to function properly and to allow the user to browse it. Without them, the user may be unable to display pages correctly or to use certain services. Profiling cookies are designed to create user profiles in order to send advertising messages in line with the preferences expressed by the user while browsing.

    Cookies may also be classified as:

    • "session" cookies, which are deleted immediately when the browser is closed;
    • "persistent" cookies, which remain in the browser for a set period of time. They are used, for example, to recognise the device connecting to a site, making authentication easier for the user;
    • "first-party" cookies, generated and managed directly by the operator of the website the user is browsing;
    • "third-party" cookies, generated and managed by parties other than the operator of the website the user is browsing.

    4. Cookies used on the Site

    The website www.lofficinaristorante.it uses technical cookies only, necessary for the operation of the site. There are no profiling cookies, advertising cookies or tracking systems (no implementation of Google Analytics, Facebook Pixel or similar tools).

    The only exception: the interactive Google Maps map in the Contacts section is not loaded automatically, but only after an explicit action by the user (clicking "Load the interactive map"). Only in that case may Google Ireland Ltd. / Google LLC set its own third-party cookies, in accordance with its own privacy policy.

    Below is the complete list of cookies and data stored locally by the Site:

    NameTypePurposeDurationDomain
    __cf_bmTechnical (cookie)Distinguishes human requests from automated ones, to protect the Site from bots and malicious traffic. Set by Cloudflare, which serves the Site30 minutesFirst-party
    __dplTechnical (cookie)Identifies the version of the Site being served, so that browsing stays consistent when an update is published. Contains no data attributable to the userSessionFirst-party
    sb-*-auth-tokenTechnical (localStorage)Supabase session token for administrative authenticationSessionFirst-party

    The Site also contains links to external pages (Instagram, Facebook, Google Maps for directions). By clicking on such links, the user accesses third-party sites which may set their own cookies in accordance with their respective privacy policies.

    There are no implementations of Google Analytics, Facebook Pixel or other tracking systems.

    Since the Site sets technical cookies only and local storage strictly necessary to deliver the service requested by the user, no consent banner is required: pursuant to art. 122 of Italian Legislative Decree 196/2003 and the Guidelines of the Italian Data Protection Authority of 10 June 2021, consent is not due for such cookies. The third-party content that would require consent — the Google map alone — is not loaded automatically and remains subject to an explicit action by the user.

    5. The Site may contain links to other sites (so-called third-party sites)

    L'Officina S.r.l. has no access to and exercises no control over cookies, web beacons and other user-tracking technologies that may be used by the third-party sites the user can reach from the Site;

    L'Officina S.r.l. exercises no control over content and materials published by or obtained through third-party sites, nor over the related processing of the user's personal data, and expressly disclaims any liability in this respect.

    The user is required to check the privacy policy of the third-party sites accessed through the Site and to obtain information about the conditions applicable to the processing of their personal data. No user profiling system has been implemented.

    Please note that the site uses Supabase as its data management backend. Supabase is an open-source platform operating as a "backend as a service", providing a PostgreSQL database, authentication, storage, serverless and real-time functions, removing the need to write complex backend code; as regards privacy, it handles data securely with granular controls (RLS) and JWT tokens. A payment system (Stripe) is also in place for gift card purchases. Data is encrypted and sent securely to Stripe. E-mail notifications concerning the outcome of booking requests and online purchases are sent and managed through the Resend platform, a service for sending transactional e-mail reliably and at scale, simplifying configuration and ensuring high performance through optimised servers and active delivery management.

    For internal operational management, notifications about new bookings and requests are forwarded to restaurant staff via Telegram. Such notifications contain no personal data: they report only non-identifying information such as date, time and number of guests. The full details of the request remain in the Controller's systems and are accessible only to authorised staff.

    The site also provides links to the restaurant's Instagram and Facebook pages.

    This Privacy Policy applies only to the Site as defined above.

    How to disable cookies in browsers

    Cookies on websites can be disabled by downloading dedicated software such as Ghostery (https://www.ghostery.com) for the browser in use and disabling individual cookies. Alternatively, "private browsing" mode can be enabled: a feature that allows browsing without leaving navigation data in the browser. Cookies can also be disabled or deleted through the browser's settings panel.

    6. Retention of personal data

    Personal data is stored and processed on IT systems owned by L'Officina S.r.l. and managed by third-party technical service providers; for further details please refer to the section "Scope of disclosure and access to data" below. Data is processed exclusively by specifically authorised personnel, including staff responsible for extraordinary maintenance operations. Such data will be deleted once it is no longer necessary for the purposes indicated above, save for further retention obligations provided for by law.

    7. Purposes and methods of processing

    L'Officina S.r.l. may process the user's personal data for the following purposes:

    • Table bookings at the restaurant "L'Officina", including the management of confirmations and cancellations — legal basis: performance of pre-contractual measures at the data subject's request (art. 6.1.b GDPR).
    • Gift card sales: online purchase of gift cards redeemable at the restaurant, delivered by e-mail to the designated recipient — legal basis: performance of the sales contract (art. 6.1.b GDPR).
    • Event bookings at the restaurant premises. The Company organises food-and-wine events and culinary tastings — legal basis: performance of pre-contractual measures at the data subject's request (art. 6.1.b GDPR).
    • Management of private event enquiries (ceremonies, corporate dinners, anniversaries), including the preparation of the related quotation — legal basis: performance of pre-contractual measures at the data subject's request (art. 6.1.b GDPR).

    The IP address of anyone submitting a form on the Site is also processed, for the sole purpose of limiting automated submissions and abuse (anti-spam protection of the booking, event and gift card forms) — legal basis: the Controller's legitimate interest in the security of its own systems (art. 6.1.f GDPR). The IP address is not associated with the other data of the request and is retained only for the duration of the anti-abuse window, equal to one hour, after which it is automatically deleted by a procedure that runs every five minutes.

    Personal data is processed both in paper and electronic form and entered into the company information system in full compliance with EU Reg. 2016/679, including security and confidentiality requirements, and in accordance with the principles of fairness and lawfulness of processing.

    Data is retained for the time strictly necessary for the purposes indicated, according to the following periods:

    • Table bookings: automatically deleted 7 days after the booking date.
    • Event bookings: automatically deleted 7 days after the event date.
    • Unpaid gift card orders: automatically deleted 30 days after the order date, the term beyond which the order is deemed to be of no effect pursuant to the Terms of Sale.
    • Issued gift cards and the related orders: retained for 10 years, corresponding to the limitation period of the credit embodied in the voucher (art. 2946 of the Italian Civil Code) and to the civil and tax obligations to retain accounting records (art. 2220 of the Italian Civil Code, art. 22 of Presidential Decree 600/1973).
    • Private event enquiries: retained until the enquiry is settled and, where a contract is concluded, for the duration of the accounting and tax obligations indicated above. In practice: rejected enquiries are automatically deleted 30 days after rejection; those left without follow-up for 12 months are automatically deleted at the end of that period; confirmed ones follow the accounting and tax periods.
    • IP addresses collected for anti-abuse purposes: 1 hour (deletion checked every five minutes upon expiry).

    Once these periods have elapsed, data is deleted, unless its retention is necessary for the establishment, exercise or defence of legal claims or to comply with a legal obligation.

    8. Security and quality of personal data

    L'Officina S.r.l. undertakes to protect the security of the user's personal data and complies with the security provisions laid down by applicable legislation in order to prevent data loss, unlawful or unauthorised use of data and unauthorised access to it. Furthermore, the information systems and software used by L'Officina S.r.l. are configured so as to minimise the use of personal and identifying data; such data is processed only to achieve the specific purposes pursued from time to time. L'Officina S.r.l. uses a range of advanced security technologies and procedures designed to help protect users' personal data; for example, personal data is stored on secure servers located in protected and controlled-access facilities.

    The user can help L'Officina S.r.l. keep their personal data accurate and up to date by notifying any change concerning their address, position, contact details, etc.

    9. Scope of disclosure and access to data

    The user's personal data may be disclosed:

    • to all parties entitled to access such data by virtue of legal provisions;
    • to our collaborators and employees, within the scope of their duties;
    • to the web agency that maintains the Site on behalf of the Controller, acting as data processor pursuant to art. 28 GDPR, limited to what is necessary for technical support;
    • to all natural and/or legal persons, public and/or private, where disclosure is necessary or instrumental to the performance of our business and in the manner and for the purposes described above.

    10. Transfer of data to third countries

    In order to deliver its services, the Company relies on providers that may process personal data in countries outside the European Union or the European Economic Area, in particular in the United States of America. The providers concerned are:

    • Supabase Inc. (USA) — backend, database and authentication. Data is protected by the Standard Contractual Clauses (SCC) approved by the European Commission and by the Data Processing Agreement entered into with the provider.
    • Stripe Inc. (USA) — online payment processing. Stripe adheres to the EU-US Data Privacy Framework and is certified under the European Commission's adequacy decision of 10 July 2023. Payment data is processed in accordance with PCI-DSS standards.
    • Resend Inc. (USA) — sending of transactional e-mail (booking confirmations, gift card delivery). Resend adheres to the EU-US Data Privacy Framework and is certified under the European Commission's adequacy decision. The transfer is further governed by Standard Contractual Clauses (SCC) and a Data Processing Agreement (DPA).
    • Cloudflare, Inc. (USA) — delivery and protection of the Site. It processes the technical connection data (including the IP address) necessary to serve the pages and to filter automated traffic. Cloudflare adheres to the EU-US Data Privacy Framework; processing is further governed by a Data Processing Agreement and Standard Contractual Clauses.
    • Google Ireland Ltd. / Google LLC (Ireland / USA) — solely the interactive map in the Contacts section, which is not loaded automatically: only if the user clicks "Load the interactive map" is their IP address disclosed to Google. Google LLC adheres to the EU-US Data Privacy Framework. No other Google content is loaded by the Site: typefaces are hosted on our own servers and involve no connection to Google.

    The operational notifications sent to staff via Telegram contain no personal data (see section 5) and therefore involve no transfer of personal data to that platform.

    The user may obtain a copy of the appropriate safeguards adopted for the transfer of data by writing to the following e-mail address: lofficina@hotmail.it.

    11. Nature of the provision of personal data

    Providing certain personal data is mandatory in order to allow L'Officina S.r.l. to handle communications and requests received from the user, or to contact the user again to follow up on their request. Such data is marked with an asterisk [*], and in that case its provision is mandatory to allow L'Officina S.r.l. to act on the request, which otherwise cannot be processed. Conversely, the collection of other data not marked with an asterisk is optional: failure to provide it will have no consequences for the user. The Site carries out no processing for marketing purposes: the data provided through the forms is used exclusively to act on the user's specific request.

    For accountability purposes (art. 5(2) GDPR), together with each request submitted through the forms, the confirmation that this notice has been read is recorded and — for the notes field of the forms that provide for it — any consent given pursuant to art. 9(2)(a), with the date and time assigned by the Controller's systems and an indication of the version of the notice published at that moment. Such evidence follows the retention period of the related request.

    12. Rights of the data subject

    Art. 15 (right of access), 16 (right to rectification) of EU Reg. 2016/679

    The data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning them is being processed, and, where that is the case, access to the personal data and the following information:

    1. the purposes of the processing;
    2. the categories of personal data concerned;
    3. the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
    4. where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
    5. the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
    6. the right to lodge a complaint with a supervisory authority;
    7. the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

    Art. 17 of EU Reg. 2016/679 (right to erasure, "right to be forgotten")

    The data subject has the right to obtain from the controller the erasure of personal data concerning them without undue delay, and the controller has the obligation to erase personal data without undue delay where one of the following grounds applies:

    1. the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
    2. the data subject withdraws the consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;
    3. the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
    4. the personal data have been unlawfully processed;
    5. the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
    6. the personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of EU Reg. 2016/679.

    Art. 18 of EU Reg. 2016/679 — Right to restriction of processing

    The data subject has the right to obtain from the controller restriction of processing where one of the following applies:

    1. the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;
    2. the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
    3. the personal data are required by the data subject for the establishment, exercise or defence of legal claims, although the controller no longer needs them for the purposes of the processing;
    4. the data subject has objected to processing pursuant to Article 21(1) of EU Reg. 2016/679, pending the verification whether the legitimate grounds of the controller override those of the data subject.

    Art. 20 of EU Reg. 2016/679 — Right to data portability

    The data subject has the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:

    1. the processing is based on consent pursuant to art. 6(1)(a) or art. 9(2)(a), or on a contract pursuant to art. 6(1)(b);
    2. the processing is carried out by automated means.

    Right to lodge a complaint with the supervisory authority (art. 77 GDPR)

    The data subject has the right to lodge a complaint with the competent supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. For Italy, the supervisory authority is the Garante per la protezione dei dati personali, with offices at Piazza Venezia 11 – 00187 Rome, website: www.garanteprivacy.it.

    13. Withdrawal of consent to processing

    The data subject may withdraw consent to the processing of their personal data at any time by writing to lofficina@hotmail.it. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal and does not affect processing based on a legal ground other than consent (performance of the contract, legal obligations, legitimate interest).

    For more information about the processing of your personal data, or to exercise the rights referred to in point 12 above, you may contact L'Officina S.r.l. at the following e-mail address: lofficina@hotmail.it, or at the postal address Borgo XX Giugno, 56, 06121 Perugia, Italy by registered letter with return receipt.

    The Controller responds to requests without undue delay and in any case within one month of receipt, extendable by two months for particularly complex requests (art. 12.3 GDPR). Exercising these rights is free of charge. Sending identity documents is not required: the Controller may request additional information to confirm the identity of the applicant only where it has reasonable doubts in that respect (art. 12.6 GDPR).

    14. Data Protection Officer (DPO)

    The Controller does not fall within the cases of mandatory designation of a Data Protection Officer provided for by art. 37 of EU Reg. 2016/679 and has therefore not appointed a DPO. For any matter concerning the processing of personal data, the Controller can be contacted directly at the details given in point 1.

    Form: Web Privacy Notice – Rev. 02/2026
    Last updated: 20 August 2026