Privacy Policy

Last updated: October 2026

This Privacy Policy explains how personal data are collected and processed through the website www.homerestaurantlabarbarella.it, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Italian data protection legislation.

1. Data Controller

The Data Controller is:

SCALI DAINELLI ALESSANDRO
VAT No. IT01548160520
Località Sant’Andrea 6
53037 San Gimignano (SI), Italy

Email: alescda96@gmail.com

2. Personal Data We Process

Depending on how you use the website, we may process:

  • name and surname;

  • email address;

  • telephone number;

  • selected experience;

  • booking date and time;

  • number of participants;

  • booking status;

  • information voluntarily entered in booking forms, contact forms or messages;

  • dietary requirements, food allergies or intolerances, where voluntarily provided;

  • technical information relating to website access and navigation;

  • referring website, referral source or campaign information;

  • communications exchanged in connection with a booking or enquiry.

3. Booking Management and Provision of Services

Personal data are processed in order to:

  • receive and manage reservations;

  • confirm, modify or cancel bookings;

  • communicate with customers;

  • organise and provide cooking classes and related food experiences;

  • manage participant numbers and dietary requirements;

  • respond to customer requests;

  • manage administrative matters connected with the service.

The legal basis is the performance of a contract or steps taken at the customer’s request prior to entering into a contract pursuant to Article 6(1)(b) GDPR.

4. Online Booking System – Amelia

The website uses Amelia to manage online reservations.

When a customer completes a booking, information entered into the booking form is stored in the website’s WordPress database.

This may include:

  • name and surname;

  • email address;

  • telephone number;

  • selected experience;

  • selected date and time;

  • number of participants;

  • booking status;

  • additional information voluntarily provided by the customer.

Bookings successfully submitted through the website may be automatically confirmed according to the availability configured in the booking system.

These data are used to manage the reservation and provide the requested service.

5. Contact Forms and Enquiries

If you contact La Barbarella through the website, by email or through a contact form, the information provided will be processed in order to respond to your request.

Where the request relates to a possible booking or service, the legal basis is Article 6(1)(b) GDPR.

For other general enquiries, processing may be based on the legitimate interest of the Data Controller in responding to communications received pursuant to Article 6(1)(f) GDPR.

6. Dietary Requirements, Allergies and Intolerances

Customers may voluntarily provide information concerning allergies, food intolerances or dietary requirements.

Such information may constitute special categories of personal data within the meaning of Article 9 GDPR.

These data are processed only where necessary to organise and provide the requested experience safely and appropriately.

Customers should provide only information relevant to this purpose.

Such information is not used for marketing or unrelated purposes.

7. Payments

No payment-card information is collected through the website as part of the standard booking process.

Unless otherwise expressly stated, payment for the booked experience is made directly to La Barbarella on site.

The website does not store payment-card details.

8. Booking Source and Referral Tracking

The website may record information relating to how a customer reached the website or booking process.

This information may include:

  • referring website;

  • referral domain;

  • campaign or UTM parameters;

  • booking source;

  • referral type.

This information may be associated with the relevant booking.

It is used for internal administrative, statistical and commercial purposes, including:

  • identifying the source of a booking;

  • measuring the effectiveness of referral or promotional channels;

  • identifying, where applicable, the commercial partner associated with a booking;

  • determining commissions or commercial attribution where applicable.

Where technically possible, booking-source information may be transmitted through the booking flow without persistent cookies.

Where the relevant cookie consent has been provided, the website may also use a first-party attribution cookie to remember the booking source across future visits.

This information is not used for behavioural advertising or cross-site profiling.

9. Website Analytics – SlimStat

The website uses SlimStat Analytics to obtain statistical information about website usage.

SlimStat is configured in a privacy-oriented manner.

In particular:

  • IP addresses are masked;

  • browser fingerprinting is disabled;

  • SlimStat does not set its own tracking cookie;

  • statistical information is stored locally in the website’s WordPress database;

  • analytics data are retained for a maximum of 420 days;

  • archived records are not retained after the applicable retention period;

  • geographic information is limited to country-level data.

SlimStat may process information such as:

  • page views;

  • referring websites;

  • browser and device information;

  • operating system;

  • country of origin;

  • technical navigation information.

These data are used to understand website usage, identify technical issues, evaluate traffic sources and improve the website.

10. Hosting – Aruba

The website and its database are hosted through services provided by Aruba S.p.A.

Personal and technical data processed through the website may therefore be stored on the hosting infrastructure used to operate the website.

The hosting provider may process data where necessary for:

  • website hosting;

  • database hosting;

  • security;

  • backups;

  • maintenance;

  • technical operation.

Where applicable, service providers processing personal data on behalf of the Data Controller act as processors pursuant to Article 28 GDPR.

11. Email Communications

The website uses email services to send or receive communications concerning:

  • booking confirmations;

  • booking changes or cancellations;

  • customer enquiries;

  • availability requests;

  • other service-related communications.

The main email address used by the Data Controller is:

alescda96@gmail.com

Email communications may involve the technical infrastructure of the relevant email provider.

12. Technical and Security Data

Technical information may be processed where necessary for:

  • ensuring correct website operation;

  • preventing misuse or unauthorised access;

  • diagnosing technical problems;

  • maintaining website and booking-system security.

The legal basis is the legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR.

13. Legal, Accounting and Administrative Obligations

Personal data may be processed where necessary to comply with applicable legal, accounting, tax or administrative obligations.

The legal basis is Article 6(1)(c) GDPR.

14. Provision of Personal Data

Information marked as mandatory during booking is necessary to manage the reservation and provide the requested service.

Failure to provide required information may make it impossible to complete the booking.

Optional information is provided voluntarily.

15. Recipients of Personal Data

Personal data may be accessed or processed, where necessary, by:

  • persons authorised by the Data Controller;

  • Aruba S.p.A. and other technical hosting providers;

  • website developers and maintenance providers;

  • booking-management software providers;

  • email and communication providers;

  • accountants and professional advisers;

  • competent public authorities where required by law.

Access is limited to what is necessary for the relevant purpose.

Personal data are not sold to third parties.

16. International Data Transfers

Some technical or email service providers may process personal data outside the European Economic Area.

Where personal data are transferred outside the European Economic Area, such transfers are carried out in accordance with Chapter V GDPR using, where applicable:

  • European Commission adequacy decisions;

  • Standard Contractual Clauses;

  • other safeguards recognised under applicable law.

17. Data Retention

Personal data are retained only for as long as necessary for the purposes for which they were collected.

In particular:

  • booking information is retained for the period necessary to manage reservations and subsequent administrative, accounting or legal requirements;

  • accounting documentation is retained for the periods required by Italian law;

  • contact requests that do not result in a booking are retained only for the period reasonably necessary to respond;

  • SlimStat analytics data are retained for a maximum of 420 days;

  • booking-source information may remain associated with the relevant booking where necessary for administrative, statistical or commercial-attribution purposes;

  • security and technical logs are retained for the period reasonably necessary for security purposes.

Data may be retained longer where necessary for the establishment, exercise or defence of legal claims.

18. Cookies and Similar Technologies

The website uses cookies and similar technologies for technical, booking-related, statistical and other purposes.

SlimStat is configured not to set its own tracking cookie.

Booking-source information may, where technically possible, be transmitted without persistent cookies.

Where the relevant consent is provided, a first-party attribution cookie may be used to remember a booking source for future visits.

Where consent is required for a particular technology, it will be activated only after the relevant consent has been provided.

Further information is available in the website’s Cookie Policy.

19. Embedded Content and Third-Party Services

The website may include third-party content such as:

  • maps;

  • review widgets;

  • external media;

  • other embedded content.

Such providers may process technical information or use cookies or similar technologies.

Where consent is required, non-essential third-party technologies should only be activated after the user has provided the relevant consent.

20. Automated Decision-Making

The website does not carry out automated decision-making producing legal effects or similarly significant effects within the meaning of Article 22 GDPR.

21. Rights of Data Subjects

Under Articles 15 to 22 GDPR, where applicable, users may have the right to:

  • access their personal data;

  • request correction;

  • request erasure;

  • request restriction of processing;

  • object to processing based on legitimate interests;

  • request data portability;

  • withdraw consent where processing is based on consent.

Requests may be sent to:

alescda96@gmail.com

22. Right to Lodge a Complaint

Users have the right to lodge a complaint with the competent supervisory authority.

In Italy, this is:

Garante per la Protezione dei Dati Personali

23. Changes to this Privacy Policy

This Privacy Policy may be updated to reflect changes to the website, services, technologies, providers or applicable law.

The latest version will always be published on this page.