Privacy Policy
Last updated: 12 November 2025
1. Data Controller
The data controller is: Tutta N'ata Storia di Francesco Palmieri — Largo Umberto I, n 13, Crotone (Italy) — VAT: 03985560790 — [email protected]
2. General information
We process data in compliance with Regulation (EU) 2016/679 (GDPR) and applicable Italian law.
The site is designed to minimise the collection of personal data during normal browsing.
3. Data processed
3.1 Technical data collected automatically
When you access the site we process exclusively the technical information strictly necessary for its operation:
- IP address (stored only temporarily for technical reasons)
- Date, time and URL of requests handled by the server
- Browser type, operating system and device information
These data are used exclusively to ensure the security and operation of the service and are deleted at the end of the session, except for security needs.
3.2 Voluntarily provided data
To make a reservation you will be redirected to WhatsApp or a direct call: communication takes place on services provided by WhatsApp LLC or the telephone operator. The site does not expose forms to fill in and does not store users' phone numbers.
We use exclusively the information you provide during the conversation (e.g. name or booking details) to handle the request and do not store it on the site's systems. Data remains processed by external providers in accordance with their respective privacy policies.
3.3 Analytics and engagement measurement
We use a self-hosted instance of Umami Analytics hosted on the controller's infrastructure. The service does not use cookies or persistent identifiers and respects the browser's Do Not Track preference. We collect exclusively aggregate and anonymised metrics on site usage to understand how visitors use the site and improve its operation.
3.4 Request limiting and perimeter security
To prevent abuse we apply rate limiting policies and perimeter security measures based on network identifiers provided by the requesting client (e.g. IP address or proxy headers). Such identifiers are kept in memory only for the duration of the control window and are not stored or shared with third parties.
4. Purposes and legal bases
We process technical data and usage metrics for legitimate interest (Art. 6(1)(f) GDPR). Data provided for contacts or bookings is processed to fulfil the request (Art. 6(1)(b) GDPR). Any additional communications take place with prior consent (Art. 6(1)(a) GDPR).
5. Data retention
Technical data used for security is deleted at the end of the session, except in case of incidents.
Contact or booking data is retained for the time necessary to handle the request and comply with legal obligations (normally no more than 12 months). Aggregate metrics are retained for a maximum of 12 months and then deleted according to the procedure scheduled by the controller.
6. Data sharing
We do not sell or disclose personal data to third parties, except in the following cases:
- Requests from competent authorities or legal obligations
- Protection of our rights or defence in legal proceedings
- Corporate operations or business reorganisations
7. Rights of data subjects
Under the GDPR you may exercise the following rights at any time:
- Access to personal data
- Rectification or erasure (right to be forgotten)
- Restriction of processing
- Objection to processing
- Data portability
- Withdrawal of consent, where processing is based on consent
To exercise your rights write to: [email protected]
8. Data security
We adopt technical and organisational measures in line with industry best practices to protect information from loss, misuse or unauthorised access.
9. Changes to this policy
We may update this policy to reflect regulatory or operational changes. Changes will be published on this page together with the new revision date.
We invite you to periodically consult the policy to stay informed about our practices.
10. Contact
For questions or requests relating to this policy you can contact us at:
Email: [email protected]
Address: Largo Umberto I, n 13, Crotone (Italy)
11. Supervisory authority
If you believe that the processing of your data violates the GDPR you have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the supervisory authority of your country.
12. Applicable law
For any dispute relating to this policy the Court of Crotone (Italy) has jurisdiction.