Privacy Policy – Notice on the Processing of Personal Data
This notice is provided to users visiting the website www.bbpiazzafratti.it pursuant to Art. 13 of EU Regulation 2016/679 – GDPR (hereinafter referred to as the “GDPR” for brevity) and describes the methods for managing and processing the personal data relating to them; the term “data processing” refers to any operation or set of operations performed on personal data, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1. DATA CONTROLLER
The Data Controller for personal data is Augusto Cataldi, Tax Code CTLGST74L03C773A.
For any information regarding the processing of personal data or to exercise the rights granted by the GDPR, the data subject may contact the Data Controller at the following details:
Registered office: Piazza Antonio Fratti 18, 00053 Civitavecchia (RM)
Email: info@bbpiazzafratti.it
2. TIPOLOGIA DI DATI TRATTATI
2.1 Dati di navigazione
I sistemi informatici e le procedure software preposte al funzionamento del sito acquisiscono, nel corso del loro normale esercizio, alcuni dati personali la cui trasmissione è implicita nell'uso dei protocolli di comunicazione Internet.
Tra tali dati rientrano, a titolo esemplificativo:
• indirizzi IP o nomi a dominio dei dispositivi utilizzati dagli utenti;
• indirizzi URI delle risorse richieste;
• stringhe identificative del browser, sistema operativo o il bot utilizzato;
• orario della richiesta;
• metodo utilizzato nel sottoporre la richiesta al server;
• dimensione del file ottenuto in risposta;
• codice numerico indicante lo stato della risposta fornita dal server;
• informazioni relative al sistema operativo e al browser utilizzato.
Tali dati vengono trattati esclusivamente per garantire il corretto funzionamento del sito, ottenere informazioni statistiche aggregate e anonime sull'utilizzo dei servizi e accertare eventuali responsabilità in caso di illeciti informatici.
I log tecnici sono conservati dal provider Aruba S.p.A. nell'ambito dell'erogazione del servizio di hosting e sono accessibili al Titolare esclusivamente nei casi necessari alla sicurezza del sito, alla manutenzione tecnica o per l'accertamento di eventuali illeciti.
2.2 Data voluntarily provided by the user
Voluntarily sending communications via the contact forms on the site—specifically on the pages named “Contact”, "Reservations", and "Guestbook"—entails the collection of data provided by the user, such as: • First and Last Name; • Email Address; • Telephone Number (the latter is optional and only applicable to the reservation request form); • any additional data included in the message that was not explicitly requested. Users are advised not to transmit data belonging to special categories pursuant to Art. 9 of the GDPR (e.g., data concerning health, religious beliefs, or political opinions) via the contact form, unless strictly necessary for the purpose of the request being made.I dati saranno utilizzati esclusivamente per rispondere alle richieste formulate dall'utente o per fornire i servizi richiesti. Providing the data marked as mandatory on the form is necessary to process the request; failure to provide this information makes it impossible to submit or handle the request.
2.3 Social Networks
The site may contain links to third-party social media platforms and provide related features, such as—by way of example but not limitation—page-sharing buttons. The use of such services is governed by the respective privacy policies of the relevant providers. Any installation of non-essential cookies or tracking technologies—i.e., those not required to ensure site navigation and access to content—associated with the use of third-party components will take place only with the user's prior consent (where required by applicable law), which the user may modify or revoke.2.4 Cookies
The site uses only technical cookies necessary for its operation.
3. PURPOSES AND LEGAL BASIS FOR PROCESSING
"Legal basis" refers to the legal grounds authorizing an organization or individual to process personal data; it constitutes the fundamental requirement under the GDPR (EU Regulation 2016/679) to ensure the lawfulness of any data collection, use, or storage.
Personal data are processed for the following purposes:
a) to enable browsing and the proper functioning of the website;
Legal basis: legitimate interest of the Data Controller (Art. 6, para. 1, letter f, GDPR).
Retention period: for the period specified by the hosting service provider and, in any case, no longer than necessary for security purposes and the investigation of unlawful acts.
b) respond to requests sent by the user via the contact form or other communication channels (e.g., email);
Legal basis: performance of pre-contractual measures taken at the request of the data subject (Art. 6, para. 1, letter b, GDPR).
Retention period: For the time strictly necessary to process the request and, in any case, no longer than 24 months from the last contact in the absence of subsequent professional relationships, unless further retention is required to handle related requests, protect the Data Controller's rights, or comply with legal obligations.
c) comply with legal obligations, regulations, or requests from competent authorities;
Legal basis: legal obligation (Art. 6, para. 1, letter c, GDPR).
Retention period: For the duration prescribed by the specific applicable regulations (e.g., 10 years for tax/accounting documentation).
d) collect aggregated and anonymous statistics on site usage;
Legal basis: the Data Controller’s legitimate interest (pursuant to Art. 6(1)(f) of the GDPR) in compiling site usage statistics using aggregated and minimized data. If non-anonymized statistical cookies are used, the legal basis is the user's explicit consent pursuant to Art. 6(1)(a) of the GDPR.
Retention period: no retention period applies, as third-party cookies of this type are not installed.
4. PROCESSING METHODS AND SECURITY
Personal data is processed using electronic and digital tools in compliance with the principles of lawfulness, fairness, transparency, data minimization, and confidentiality set forth in the GDPR.
The Data Controller implements appropriate technical and organizational measures to ensure the security of personal data and to prevent unauthorized access, disclosure, alteration, or accidental destruction.
5. DATA DISCLOSURE
Personal data may be disclosed to third parties providing services essential to the operation of the website or the professional activities of the Data Controller.
6. DATA CONCERNING MINORS
The website is not intended for minors, and the Data Controller does not intentionally collect personal data relating to them unless the conditions set forth by applicable law are met. Should a user submit data concerning a minor, the processing shall be lawful only if and to the extent that consent is given or authorized by the holder of parental responsibility. In the event that data concerning minors is found to have been collected without such consent, the Data Controller shall proceed to delete it immediately.
The rights provided for by the GDPR may be exercised, in the minor's interest, by the person exercising parental responsibility or legal representation.
7. DATA RETENTION
The data are retained for the periods indicated in paragraph 3 above and subsequently deleted or anonymized, subject to further legal obligations.
8. RIGHTS OF THE DATA SUBJECT
The data subject may exercise the rights provided for in Articles 15-22 of the GDPR at any time, including:
• right of access to personal data: to know which data are being processed and to receive a copy thereof;
• right to rectification of inaccurate data: to demand the correction of inaccurate, incomplete, or outdated data (e.g., email addresses or contact details that are no longer active or in use);
• right to erasure of data: to request and obtain the removal of data in the cases provided for by law;
• right to restriction of processing: to temporarily suspend processing in the event of disputes;
• right to data portability (where applicable): to request and obtain one's data in a structured and readable format;
• right to object to processing: to object at any time to processing based on legitimate interest or for marketing purposes, in the cases provided for by Art. 21 of the GDPR;
• right to withdraw consent given at any time, without affecting the lawfulness of processing carried out prior to the withdrawal;
• right to lodge a complaint with the Personal Data Protection Authority if the user believes that the data processing violates the GDPR.
Guarantor for the Protection of Personal Data
Piazza Venezia n. 11, 00187 Rome
Website: www.garanteprivacy.it
The Data Controller does not employ automated decision-making processes or profiling activities pursuant to Art. 22 of the GDPR. To exercise their rights or request information regarding the processing of personal data, the data subject may contact the Data Controller at the following addresses:
Augusto Cataldi
Piazza Antonio Fratti 18
00053 Civitavecchia (RM)
Email: info@bbpiazzafratti.it
Requests will be processed within the timeframes established by Regulation (EU) 2016/679.
9. Transfer of data outside the EU
Personal data processed directly by the Data Controller are stored on servers located within the European Union and are not transferred to countries outside the European Economic Area (EEA).
However, this website uses tools provided by social media platforms, interactive maps (Google Maps), and sharing buttons. Interaction with these elements may result in the transfer of certain technical data (e.g., IP addresses, cookies) to third-party servers located outside the EEA, including in the United States.
These third-party providers process the data as independent data controllers and are required to carry out such transfers in compliance with Articles 44-49 of the GDPR, specifically through:
• European Commission adequacy decisions (such as the EU-US Data Privacy Framework);
• Standard Contractual Clauses.
Users are encouraged to consult the privacy policies of the respective third-party providers (e.g., Google, Meta) to learn the details of their processing methods and data transfers.
Last update of this notice: July 2, 2026.





