Skip to the policy
Camillo a Piazza Navona Back to site

Privacy · personal data

Privacy policy.

Clear information about the data we process, why we use it and the rights you can exercise.

Updated 14 August 2026

01

Data controller

The Data Controller is DECA S.r.l., VAT no. 05117161009, with registered office at Piazza Navona 80, 00186 Rome, Italy.

Privacy contact (certified email): decabarocco@legalmail.it.

02

Data and purposes

When you browse the website, we process necessary technical data such as your IP address, pseudonymous visit identifier, language and any service errors to operate and secure the website and prevent abuse.

First-party analytics may process pages visited, device and browser information, the external referring origin and privacy-filtered campaign labels contained in the URL (UTM parameters or our internal ctl code). Marketing attribution may also process advertising click identifiers. These identifiers are sent only to our first-party backend, immediately converted into a keyed HMAC digest and not stored or displayed there in clear text. Campaign parameters are not appended to links you open from the website.

When analytics is not active, optional aggregate, behavioural and performance measurements are not sent. Any strictly technical event contains only the page path without query parameters, the consent status and essential service markers: it contains no referrer, client or device details, campaign attribution or advertising click identifiers. The tracker does not read or use the referring origin before analytics is active; a later grant starts a new measurement window and does not recover or backfill earlier referrer, activity or performance data.

In the current development configuration, CMP_MODE=dev is a first-party technical environment override that enables analytics and marketing; it is not a choice by, or recorded consent from, the user. No Meta Pixel, Google Analytics or other third-party analytics or advertising tag is loaded. If a consent mechanism is activated, the optional analytics and marketing categories will remain disabled until a choice is made. Once a decision has been verified by the server, tabs on the same origin use BroadcastChannel to exchange only a refresh signal; they do not exchange consent categories or other data, and each tab reloads the server state.

When you contact us or make a reservation, we may process your name, contact details, date, time, number of guests, requests and any other information you voluntarily provide in order to reply and manage the service.

The legal bases are taking steps at your request or performing a contract, compliance with legal obligations, our legitimate interest in the security and proper operation of the service and, where required, consent. Information marked as mandatory is needed to provide the service.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects.

03

Reservations and external services

Our public reservation channel is OctoTable. When you select the booking button, you leave our website and access the external platform. DECA S.r.l. uses the information it receives to organise and manage your reservation; OctoTable also processes data under its own privacy policy.

Ordinary reservations made through the public OctoTable flow do not require a deposit, card guarantee or pre-authorisation and do not carry financial penalties. Legacy internal booking and card-verification pages are not operational on the public website.

For separately agreed groups of more than 10 guests, a deposit or a card pre-authorisation or guarantee may be required. Before confirmation, the applicable terms and, where used, the payment service provider and relevant data-processing information will be communicated.

Google Maps is loaded only when you choose to view the map. Google may then receive technical data under its own privacy policy.

When you open the technical /recensioni page, the official Tripadvisor widget is loaded. Tripadvisor may receive technical device and connection data and process it under its own privacy policy.

The website does not use Meta Pixel, Google Analytics or third-party advertising profiling tags and does not send events collected by the first-party tracker to Meta.

04

Technical tools and retention

The website uses technical tools and first-party measurements. We retain:

  • the pseudonymous visit identifier and, where needed across an automatic language redirect, the external referring origin for the browser-tab session; that origin is used for measurement only when analytics is already active and is deleted after refusal or revocation;
  • the language preference until browser data is deleted;
  • the technical security cookie for up to 60 days;
  • the signed, HttpOnly consent cookie for up to 180 days;
  • technical events and pseudonymised statistics for up to 90 days;
  • the consent decision audit, containing categories, configuration version, source, timestamp and pseudonymous visit and device identifiers, for up to 395 days;
  • requests and reservations for up to 24 months after the last interaction, unless legal obligations or the establishment, exercise or defence of legal claims require otherwise.

05

Recipients and transfers

Data may be processed by authorised staff and by service providers needed to operate the service, including hosting, security and email providers, OctoTable and Google, depending on the service used.

Where a provider processes data outside the European Economic Area, the transfer is made using the safeguards set out in Articles 44 and following of the GDPR. Data may also be disclosed to public authorities where required by law. We do not sell personal data.

06

Your rights

Where applicable, you may request access, rectification, erasure, restriction and portability of your data and object to its processing. You may also withdraw consent without affecting processing already carried out.

To exercise your rights, write to the certified email address decabarocco@legalmail.it. You may also lodge a complaint with the Italian Data Protection Authority; its institutional website is garanteprivacy.it.