01
Data controller
The Data Controller is DECA S.r.l., VAT no. 05117161009, with registered office at Piazza Navona 80, 00186 Rome, Italy.
Privacy contact: decabarocco@legalmail.it.
02
Data and purposes
When you browse the website, we process necessary technical data such as your IP address, pseudonymous visit identifier, language and any service errors to operate and secure the website and prevent abuse.
First-party analytics may process pages visited, device and browser information, the external referring origin and privacy-filtered campaign labels contained in the URL (UTM parameters or our internal ctl code). Marketing attribution may also process advertising click identifiers. For internal statistics, these identifiers are converted into a keyed HMAC digest and are not stored or displayed in clear text in those tables. Optional processing through Meta, described below, uses a separate flow. Campaign parameters are not appended to links you open from the website.
In consent mode, optional analytics and marketing categories remain disabled until a choice is made and can be enabled separately. The initial panel lets you accept, reject or customize; Privacy preferences in the footer lets you change or withdraw your choices. Declining does not prevent browsing or booking. Any CMP_MODE=dev is a first-party technical environment override: it is not a choice by, or recorded consent from, the user and does not enable Meta tools. Simulation mode does not contact Meta.
When you contact us or make a reservation, we may process your name, contact details, date, time, number of guests, requests and any other information you voluntarily provide in order to reply and manage the service.
The legal bases are taking steps at your request or performing a contract, compliance with legal obligations, our legitimate interest in the security and proper operation of the service and, where required, consent. Information marked as mandatory is needed to provide the service.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects.
03
Reservations and external services
Reservations are managed through DECA S.r.l.'s proprietary system. We may process your first and last name, telephone number, email address, date, time, number of guests, service, room preference, notes and the information needed to manage, change or cancel the booking.
Group requests may include contact details, number of guests, preferred date and time and a message.
Any allergy or dietary information voluntarily provided is processed, with your explicit consent, solely to provide the requested service.
Where a card guarantee is required, card details are collected directly by Stripe. DECA S.r.l. does not store the full card number or CVC.
Google Maps is loaded only when you choose to view the map. Google may then receive technical data under its own privacy policy.
When you open the technical /recensioni page, the official Tripadvisor widget is loaded. Tripadvisor may receive technical device and connection data and process it under its own privacy policy.
Only with your marketing consent and when the service is active, we use Meta Pixel and Conversions API to measure campaigns and connect visits and confirmed reservations with advertising. The Pixel may send Meta the page visited, technical browser and connection data, and browser and click identifiers (_fbp, _fbc, fbclid). The server confirmation may include normalized email and telephone details transformed using SHA-256 for matching: this does not make them anonymous. Browser and server share an event identifier to avoid counting the same reservation twice.
We do not send Meta card details, notes, allergies, booking codes or private links. Automatic matching of form fields is disabled. Visits starting on /recensioni and reservation management or card verification pages are excluded from this tracking. Details of Meta’s processing are available in its privacy policy and cookie policy. The website does not load Google Analytics.
04
Technical tools and retention
The website uses technical tools and first-party measurements. We retain:
- the initial visit path and duplicate-event markers for the browser-tab session; with marketing consent, click identifiers needed for matching. Meta Pixel may also use its _fbp and _fbc cookies under the policy linked above; withdrawal removes those accessible to the website from the browser and stops new transmissions;
- the pseudonymous visit identifier and, where needed across an automatic language redirect, the external referring origin for the browser-tab session; that origin is used for measurement only when analytics is active;
- the language preference until browser data is deleted;
- the technical security cookie for up to 60 days;
- the signed, HttpOnly consent cookie for up to 180 days;
- technical events and pseudonymised statistics for up to 90 days;
- the consent decision audit, containing categories, configuration version, source, timestamp and pseudonymous visit and device identifiers, for up to 395 days;
- requests and reservations for up to 24 months after the last interaction, unless legal obligations or the establishment, exercise or defence of legal claims require otherwise.
05
Recipients and transfers
Data may be processed by authorised staff and by service providers needed to operate the service, including hosting, security and email providers, Stripe and Google, depending on the service used, and Meta for optional advertising measurement.
Where a provider processes data outside the European Economic Area, the transfer is made using the safeguards set out in Articles 44 and following of the GDPR. Data may also be disclosed to public authorities where required by law. We do not sell personal data.
06
Your rights
Where applicable, you may request access, rectification, erasure, restriction and portability of your data and object to its processing. You may also withdraw consent without affecting processing already carried out.
To exercise your rights, write to decabarocco@legalmail.it. You may also lodge a complaint with the Italian Data Protection Authority, www.garanteprivacy.it.