Vai al contenuto
Atelier Doria — Osteria Contemporanea
HomeMenuChi siamoGalleriaRecensioniContatti Prenota

Trasparenza

Privacy Policy

Informativa ai sensi degli articoli 13 e 14 del Regolamento (UE) 2016/679.

Ultimo aggiornamento: 8 agosto 2026.

1. Titolare del trattamento

Il titolare del trattamento è Appia Food S.R.L.S., con sede legale in Corso Roma 32, 72100 Brindisi (BR), iscritta al Registro delle Imprese di Brindisi, REA BR-166650, capitale sociale € 1.000,00 (2026), partita IVA e codice fiscale 02717510743, e-mail atelierdoria@libero.it, PEC appiafoodsrls@pec.it.

2. Dati trattati

Il server tratta dati tecnici di navigazione, come indirizzo IP, data e ora, risorsa richiesta, user agent ed eventuali log di sicurezza. La pagina di prenotazione prepara nel browser nome, data, ora, numero di persone e note: questi dati non vengono inviati al server del sito e sono trasferiti a WhatsApp soltanto quando l’utente sceglie di proseguire e invia il messaggio. Le note possono contenere allergie o intolleranze alimentari, ossia dati relativi alla salute.

I collegamenti e-mail, telefonici e verso siti esterni attivano il servizio scelto dall’utente; il sito non legge il contenuto delle comunicazioni effettuate tramite applicazioni esterne.

3. Finalità e basi giuridiche

  • Fornire il sito, garantirne sicurezza e continuità e prevenire abusi: legittimo interesse del Titolare, art. 6, par. 1, lett. f) GDPR.
  • Gestire richieste di informazioni e prenotazioni inviate volontariamente tramite e-mail, telefono o WhatsApp: misure precontrattuali richieste dall’interessato, art. 6, par. 1, lett. b) GDPR.
  • Trattare allergie o intolleranze comunicate nelle note: consenso esplicito, art. 9, par. 2, lett. a) GDPR.
  • Adempiere obblighi legali o richieste dell’autorità: art. 6, par. 1, lett. c) GDPR.

Il sito non effettua marketing, profilazione, analytics o decisioni automatizzate.

4. Conferimento e minimizzazione

I dati necessari alla prenotazione sono indicati come obbligatori. Le note sono facoltative. Non inserire nelle note informazioni sanitarie diverse da allergie o intolleranze alimentari necessarie alla gestione della prenotazione. Il consenso ai dati relativi alla salute è separato, facoltativo e non preselezionato; senza tale consenso le note sanitarie non possono essere inoltrate.

5. Destinatari e responsabili del trattamento

I dati possono essere trattati da persone autorizzate e da fornitori tecnici nei limiti necessari. Il servizio di hosting è fornito da Aruba Hosting. I fornitori che trattano dati per conto del Titolare devono essere designati responsabili del trattamento ai sensi dell’art. 28 GDPR, ove applicabile. Il Titolare deve mantenere aggiornato l’elenco completo dei responsabili e renderlo disponibile su richiesta.

Quando l’utente sceglie WhatsApp, la comunicazione coinvolge WhatsApp Ireland Limited e le società del gruppo Meta secondo i rispettivi ruoli e informative. I collegamenti a Google Maps, Instagram, Facebook e TheFork portano a servizi esterni che trattano i dati secondo le proprie informative; Google Maps incorporato è bloccato fino all’attivazione volontaria.

6. Trasferimenti fuori dallo SEE

I fornitori esterni possono comportare trasferimenti verso Paesi non appartenenti allo Spazio economico europeo. Tali trasferimenti devono basarsi su una decisione di adeguatezza o su garanzie appropriate previste dagli articoli 45 e 46 GDPR, incluse, ove applicabili, le clausole contrattuali standard. Il sito evita richieste automatiche verso tali fornitori, fatta eccezione per quelle avviate volontariamente dall’utente.

7. Conservazione

I dati di prenotazione e contatto sono conservati per il tempo necessario a gestire la richiesta e, salvo obblighi legali o contenziosi, non oltre 12 mesi dalla sua chiusura. I dati relativi alla salute sono cancellati quando non più necessari alla specifica prenotazione. I log tecnici sono conservati secondo i tempi configurati dal fornitore di hosting e limitati alle esigenze di sicurezza.

8. Diritti e richieste di cancellazione

L’interessato può esercitare i diritti di accesso, rettifica, cancellazione, limitazione, portabilità e opposizione e può revocare il consenso senza pregiudicare i trattamenti già effettuati. La cancellazione dei dati comunicati per una prenotazione può essere richiesta con un messaggio WhatsApp o una chiamata al numero +39 329 896 2703. Le richieste possono essere inviate anche a atelierdoria@libero.it o alla PEC indicata sopra. Per evitare cancellazioni riferite alla prenotazione sbagliata, il Titolare può chiedere le sole informazioni necessarie a identificare la richiesta. È possibile proporre reclamo al Garante per la protezione dei dati personali.

9. Aggiornamenti

Questa informativa viene aggiornata quando cambiano trattamenti, fornitori o funzionalità. La versione vigente è identificata dalla data riportata in alto.

Last updated: 8 August 2026.

1. Data controller

The data controller is Appia Food S.R.L.S., with registered office at Corso Roma 32, 72100 Brindisi (BR), registered with the Brindisi Companies Register, REA BR-166650, share capital €1,000.00 (2026), VAT number and tax code 02717510743, email atelierdoria@libero.it, certified email (PEC) appiafoodsrls@pec.it.

2. Data processed

The server processes technical browsing data, such as IP address, date and time, requested resource, user agent and any security logs. In the booking page, the browser prepares the name, date, time, number of guests and notes: this data is not sent to the website server and is transferred to WhatsApp only when the user chooses to continue and sends the message. Notes may include food allergies or intolerances, which are health-related data.

Email, telephone and external-site links activate the service chosen by the user; the website does not read the content of communications made through external applications.

3. Purposes and legal bases

  • Providing the website, ensuring its security and continuity, and preventing abuse: the Controller’s legitimate interest, Article 6(1)(f) GDPR.
  • Managing information and booking requests voluntarily sent by email, telephone or WhatsApp: steps taken at the data subject’s request prior to entering into a contract, Article 6(1)(b) GDPR.
  • Processing allergies or intolerances entered in the notes: explicit consent, Article 9(2)(a) GDPR.
  • Complying with legal obligations or requests from authorities: Article 6(1)(c) GDPR.

The website does not perform marketing, profiling, analytics or automated decision-making.

4. Provision and data minimisation

Data required for booking is marked as mandatory. Notes are optional. Do not enter health information other than food allergies or intolerances necessary to manage the booking. Consent to processing health-related data is separate, optional and not preselected; without this consent, health-related notes cannot be forwarded.

5. Recipients and processors

Data may be processed by authorised persons and technical providers to the extent necessary. Hosting is provided by Aruba Hosting. Providers processing data on behalf of the Controller must be appointed as processors under Article 28 GDPR, where applicable. The Controller must keep the complete list of processors up to date and make it available upon request.

When the user chooses WhatsApp, the communication involves WhatsApp Ireland Limited and Meta group companies according to their respective roles and privacy notices. Links to Google Maps, Instagram, Facebook and TheFork lead to external services that process data under their own privacy notices; embedded Google Maps content is blocked until voluntarily activated.

6. Transfers outside the EEA

External providers may involve transfers to countries outside the European Economic Area. Such transfers must be based on an adequacy decision or appropriate safeguards under Articles 45 and 46 GDPR, including standard contractual clauses where applicable. The website avoids automatic requests to these providers, except for those voluntarily initiated by the user.

7. Retention

Booking and contact data is retained for the time required to handle the request and, unless legal obligations or disputes require otherwise, for no longer than 12 months after its closure. Health-related data is deleted when it is no longer required for the specific booking. Technical logs are retained for the periods configured by the hosting provider and limited to security requirements.

8. Rights and deletion requests

The data subject may exercise the rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent without affecting processing already carried out. Deletion of data provided for a booking may be requested by sending a WhatsApp message or calling +39 329 896 2703. Requests may also be sent to atelierdoria@libero.it or to the certified email address listed above. To prevent deletion of the wrong booking, the Controller may request only the information needed to identify the request. A complaint may be lodged with the Italian Data Protection Authority.

9. Updates

This notice is updated whenever processing activities, providers or features change. The current version is identified by the date shown above.

Atelier Doria — Osteria Contemporanea

Corso Roma, 32 · Brindisi

Contatti

+39 329 896 2703
atelierdoria@libero.it

Seguici

Instagram
Facebook
TheFork

Dati legali

Appia Food S.R.L.S.

P. IVA / C.F. 02717510743

Registro Imprese di Brindisi · REA BR-166650

Sede legale · Corso Roma 32, 72100 Brindisi (BR)

Privacy Policy
Cookie Policy

© 2026 Atelier Doria · Appia Food S.R.L.S. · P. IVA / C.F. 02717510743 · REA BR-166650