About GDPR
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy. It applies to all organisations that process personal data of individuals in the European Union, regardless of where the organisation is located.
At Caffè Napoli, we are committed to complying with GDPR and protecting your personal data. This page provides additional information about your rights under GDPR and how we fulfil our obligations.
Data Controller
For the purposes of GDPR, the data controller is:
Caffè Napoli
Via San Gregorio Armeno 42
80138 Naples, Italy
Email: [email protected]
Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
Right to Access (Article 15)
You have the right to request a copy of the personal data we hold about you and information about how we process it. We will provide this information free of charge within one month of receiving your request.
Right to Rectification (Article 16)
You have the right to request that we correct any inaccurate personal data we hold about you. You also have the right to have incomplete personal data completed.
Right to Erasure (Article 17)
Also known as the "right to be forgotten," you have the right to request that we delete your personal data in certain circumstances, including:
- When the data is no longer necessary for the purpose it was collected
- When you withdraw consent and there is no other legal basis for processing
- When you object to processing and there are no overriding legitimate grounds
- When the data has been unlawfully processed
Right to Restriction of Processing (Article 18)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when the processing is unlawful but you do not want the data deleted.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You also have the right to request that we transmit this data directly to another controller where technically feasible.
Right to Object (Article 21)
You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or significantly affect you. We do not currently engage in automated decision-making of this nature.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond to your request within one month, though this may be extended by two months for complex requests.
Data Protection Authority
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. In Italy, this is:
Garante per la protezione dei dati personali
Piazza Venezia 11
00187 Rome, Italy
Website: www.garanteprivacy.it
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: When you submit an enquiry form or accept cookies
- Contract: When necessary to fulfil a contract with you or take steps at your request before entering into a contract
- Legitimate Interests: For improving our services, provided this does not override your rights
- Legal Obligation: When required to comply with applicable laws
Data Transfers
We process and store data within the European Economic Area. If any data transfer outside the EEA is necessary, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions by the European Commission.
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
Updates to This Information
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.