Transparency · Data protection
Privacy Policy
Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679.
1. Data Controller
The Data Controller is F & B GROUP S.R.L. (the “Controller”), the company responsible for the website www.castellodellaspizzichina.it and its related contact channels.
- Registered office: Via Riccardo Moretti 6, 00123 Rome (RM), Italy
- Operating premises: Via Riccardo Moretti 6, 00123 Rome, Italy
- Italian VAT number and tax code: 10641631006
- Rome REA Economic and Administrative Index no.: RM-1246201
- Privacy email: amministrazione@castellodellaspizzichina.it
- Certified email (PEC): febgroupsrl@pec.it
- Telephone: +39 06 3036 0101
Data protection requests must be sent to the contact details above. If a Data Protection Officer (DPO) is appointed, the relevant contact details will be published in this section.
2. Data we process
Browsing and technical data
During normal operation, the website’s systems may collect IP address, date and time of the request, requested URI, request method and response code, user agent, operating system, browser, referrer, technical identifiers, security logs and diagnostic data. These data are normally processed in aggregate or pseudonymised form, except where security requirements or the investigation of unlawful activity require otherwise.
Data submitted through the form or other channels
The contact form may collect full name, email address, telephone/WhatsApp number, country, proposed event date or flexibility, estimated number of guests or attendees, event type and message content. If you contact us by email, telephone, WhatsApp or social media, we will also process the data contained in your communication and the technical information made available by the relevant service.
Contractual and administrative data
If the enquiry progresses, we may process identification and contact details, billing information, event details, quotations, agreements, payments and any data needed to provide the services and comply with tax and accounting obligations.
Cookies and tracking technologies
The website uses technical tools and, only where a valid legal basis exists, analytics, functionality and marketing tools. Further information is available in the Cookie Policy.
3. Purposes and legal bases
| Purpose | Legal basis | Main data |
|---|---|---|
| Displaying, operating, maintaining and securing the website; preventing misuse and fraud. | Controller’s legitimate interests, Article 6(1)(f) GDPR; for strictly necessary technologies, Article 122 of the Italian Privacy Code. | Technical, browsing and log data. |
| Answering enquiries concerning information, availability, visits and quotations. | Steps taken at the data subject’s request prior to entering into a contract, Article 6(1)(b) GDPR. | Form data and communications. |
| Managing quotations, contracts, events, services and support. | Performance of a contract, Article 6(1)(b) GDPR. | Identification, event, contractual and accounting data. |
| Administrative, tax and accounting obligations and requests from public authorities. | Compliance with a legal obligation, Article 6(1)(c) GDPR. | Contractual, tax and payment data. |
| Establishing, exercising or defending legal claims. | Legitimate interests, Article 6(1)(f) GDPR. | Data relevant to the dispute. |
| Non-essential statistics, personalisation, external content and advertising. | Consent, Articles 6(1)(a) and 7 GDPR and Article 122 of the Italian Privacy Code, collected through the consent management platform. | Online identifiers, browsing events and preferences. |
| Marketing communications or newsletters, if introduced. | Specific, freely given and revocable consent, Article 6(1)(a) GDPR and Article 130 of the Italian Privacy Code. | Name and contact details. |
The website does not use solely automated decision-making that produces legal or similarly significant effects within the meaning of Article 22 GDPR. Analytics and advertising activities do not determine whether an enquiry or quotation request is accepted or rejected.
4. Provision of data
Fields marked with an asterisk are necessary to handle an enquiry; failure to provide them prevents submission or a response. Other information is optional. Consent to non-essential cookies and any marketing communications is freely given. Refusing consent does not prevent use of the website’s essential functions or the submission of an enquiry.
If you provide personal data relating to another person, you confirm that you are authorised to do so and have informed that person, and you accept responsibility for the disclosure.
5. Processing and security
Data are processed by electronic means and, where necessary, in paper form, in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality. The Controller adopts technical and organisational measures appropriate to the risks, including access controls, system updates, backups, communication safeguards and instructions to authorised personnel.
No Internet-connected system can be considered completely secure. If a personal data breach occurs, Articles 33 and 34 GDPR will be applied where the relevant conditions are met.
6. Recipients and processors
Data may be processed by authorised personnel and disclosed, to the extent necessary, to:
- hosting, Joomla/Gridbox maintenance, security, backup and technical support providers;
- email, telephone, messaging, contact-management and organisational service providers;
- administrative, tax and legal advisers, insurers, banks and suppliers involved in an event;
- Cookie-Script for consent management; Google for Analytics, Tag Manager and advertising services; Meta for Pixel, Facebook, Instagram and WhatsApp; Vimeo for embedded video;
- public authorities or other parties where disclosure is required by law.
Providers processing data on behalf of the Controller are appointed as processors under Article 28 GDPR where applicable. Some providers act as independent controllers under their own privacy notices. An up-to-date list of processors is available upon request.
7. Transfers outside the EEA
The use of global services, including Google, Meta, Vimeo and Cookie-Script, may involve processing in countries outside the European Economic Area. Where this occurs, the transfer is based on an adequacy decision, including the EU–US Data Privacy Framework for validly certified recipients, the European Commission’s Standard Contractual Clauses together with any appropriate supplementary measures, or another mechanism under Articles 44–49 GDPR.
You may request information about the safeguards applied by contacting the Controller. Where required, transfers connected with non-essential tools take place only after the user’s choice.
8. Retention periods
- technical and security logs: normally for up to 30 days, unless anomalies, incidents or requests from an authority require longer retention;
- enquiries and quotations that do not result in a contract: up to 24 months after the last contact;
- contractual, tax and accounting data: for the duration of the relationship and generally for 10 years after it ends, subject to longer periods required by law or litigation;
- marketing data: until consent is withdrawn and in any event no longer than 24 months after the last valid consent or meaningful interaction, after which the data are deleted or consent is requested again;
- records of consent and withdrawal: for as long as necessary to demonstrate compliance and handle potential claims;
- cookies: for the periods specified in the Cookie Policy and preference panel.
At the end of the applicable period, data are erased, anonymised or retained separately where required for legal obligations or the defence of legal claims.
9. Your rights
Where the applicable conditions are met, you may exercise the rights provided by Articles 15–22 GDPR: access, rectification, erasure, restriction, portability, objection on grounds relating to your particular situation and objection at any time to direct marketing. You may also withdraw consent without affecting the lawfulness of processing carried out before withdrawal.
Requests may be sent to the Controller’s contact details. We may ask for information strictly necessary to verify your identity and will respond within the time limits set by Article 12 GDPR. If you believe that the processing infringes data protection law, you may lodge a complaint with the Italian Data Protection Authority or the supervisory authority in your country, without prejudice to any other remedy.
10. Children
The website and event-enquiry services are not directed at children. We do not knowingly collect children’s data for marketing or profiling purposes. A parent or legal guardian may contact us to request verification or erasure.
11. Changes to this policy
This policy may be updated to reflect legal, organisational or technological changes. The current version is published on this page together with the date of its last update. If changes materially affect processing based on consent, fresh consent will be requested where necessary.
12. Privacy contact
F & B GROUP S.R.L.
Via Riccardo Moretti 6, 00123 Rome (RM), Italy
Italian VAT and tax code 10641631006 · REA RM-1246201
PEC: febgroupsrl@pec.it
Email: amministrazione@castellodellaspizzichina.it
+39 06 3036 0101
