Privacy Policy

Privacy Policy

In compliance with the obligations arising from national legislation (Legislative Decree no. 196 of 30 June 2003, Personal Data Protection Code) and European Community legislation (European Regulation on the protection of personal data no. 679/2016, GDPR), as subsequently amended, this website respects and protects the privacy of visitors and users, making every possible effort not to infringe users’ rights.

This privacy policy applies exclusively to the online activities of this website and is valid for visitors/users of the website.

This website processes data on the basis of consent. By using or browsing this website, visitors and users expressly approve this privacy notice and consent to the processing of their personal data in accordance with the methods and purposes described below.
Providing data, and therefore giving consent to its collection and processing, is optional. Users may refuse consent and may withdraw consent already given at any time (by sending an email to the data controller). Users are aware that refusing consent may make it impossible to provide certain services and may compromise the browsing experience of the website.

Data Controller

The data controller under current law is Locanda Rosati, Loc. Buonviaggio, 22 / 05018 Orvieto (TR), who can be contacted at info@locandarosati.it

Data Processor

The data processor is Easymedia srl, Via Angelo Costanzi 98, 05018 Orvieto (TR).

Place of Processing

The data collected by the website is processed at the premises of the Data Controller and the Data Processor.

Data Collected and Purposes

Like all websites, this website uses log files in which information collected automatically during users’ visits is stored. The information collected may include:

Internet Protocol (IP) address;
browser type and parameters of the device used to connect to the website;
name of the Internet Service Provider (ISP);
date and time of visit;
referring page of the visitor (referral) and exit page;
possibly the number of clicks.

The above information is processed automatically and collected exclusively in aggregate form in order to verify the proper functioning of the website and for security reasons (from 25 May 2018 this information will be processed on the basis of the legitimate interests of the controller).
For security purposes (spam filters, firewalls, virus detection), the automatically recorded data may also include personal data such as the IP address, which may be used, in accordance with applicable laws, to prevent any harmful or criminal activity. Such data is never used to identify or profile the user, but only to protect the website and its users (from 25 May 2018 this information will be processed on the basis of the legitimate interests of the controller).

Forms filled in to request information simply send an email to the Controller, and the form data may be automatically recorded together with other data such as the sender’s email, IP address and browser type, in order to offer a better service in the event of a temporary email malfunction. Such data is understood to be voluntarily provided by the user when requesting the service. The data received will be used to provide the requested service and may be used for marketing services at the Controller’s discretion.

Information that website users choose to make public through the services and tools made available to them is provided by the user knowingly and voluntarily, and this website is exempt from any liability for any violations of the law. It is the user’s responsibility to verify that they have permission to enter third parties’ personal data or content protected by national and international regulations.

The data collected by the website during its operation is used exclusively for the purposes indicated above and is retained for the time strictly necessary to carry out the specified activities, until the user deems it appropriate and (exclusively for data recorded through contact forms) for a maximum of 365 days. In any case, the data collected by the website will never be provided to third parties for any reason, unless there is a legitimate request from the judicial authority and only in the cases provided for by law.

Data used for security purposes (blocking attempts to damage the website) is retained for 7 days.

User Rights

Pursuant to European Regulation 679/2016 (GDPR) and national legislation, the User may, in the manner and within the limits provided by current legislation, exercise the following rights:

request confirmation of the existence of personal data concerning them (right of access);
know its origin;
receive it in an intelligible form;
obtain information about the logic, methods and purposes of the processing;
request the updating, rectification, supplementation, erasure, or blocking of data processed in violation of the law, including data no longer necessary for the purposes for which it was collected;
where processing is based on consent, receive, at the mere cost of any medium used, the data they have provided to the controller, in a structured form readable by a data-processing device and in a commonly used format for electronic devices;
the right to lodge a complaint with the supervisory authority (Garante Privacy – link to the Garante’s page);
as well as, more generally, exercise all the rights granted to them by applicable legal provisions.

Requests should be addressed to the Data Controller.

Where data is processed on the basis of legitimate interests, the rights of data subjects are nevertheless guaranteed (except for the right to data portability, which is not provided for by law), in particular the right to object to the processing, which can be exercised by sending a request to the data controller.

This document was last updated on 23/05/2018.

Scroll to Top