Legal notice
Privacy policy
Last updated: 1 October 2026
This page explains, as required by Regulation (EU) 2016/679 (GDPR, articles 13 and 14) and the Italian Privacy Code, which personal data we collect through the website www.trattorialenuvole.it and the related services (bookings, card guarantee, gift cards, email), why we use it, how long we keep it and what rights you have. We wrote it in plain language: if anything is unclear, write to us. Cookies have their own page: the Cookie Policy.
1. Who the data controller is
Trattoria Le Nuvole di Manservisi Elisabetta, Via Fondo Banchetto 5, 44121 Ferrara (FE), Italia, VAT number 01896090386. Email: info@trattorialenuvole.it. Phone: +39 347 259 1995.
No data protection officer (DPO) has been appointed, because the law does not require one for a business like ours: for any question about your data, write to the address above or call us.
2. Which data we process, why and on what basis
Below, for everything you can do on the site, you find the data needed, the purpose, the legal basis (the GDPR article that allows us to process it) and how long we keep it.
2.1 Browsing the site
When you open a page, the systems that run the site (Vercel for the pages, Hostinger for the images of the news published on data.trattorialenuvole.it) record in technical logs data such as IP address, date and time, page requested, browser and operating system. They are needed to serve the site, protect it from abuse and understand what went wrong in case of errors. We do not use them to identify or profile you.
- Legal basis: legitimate interest (art. 6.1.f) in running the site securely.
- Retention: logs stay with the providers for the technical time their services provide, normally a few days; we do not keep a copy.
- Cookies: see the Cookie Policy. The site only uses technical cookies; the statistics use none.
To know how many people visit the site and which pages they read we use Umami, an anonymous, cookie-free analytics tool installed by Smarti, the agency that built the site, on a server in Finland (Hetzner, European Union). It collects the page visited, the site you came from, browser, operating system, device type, language and, from the IP address, country and approximate city; the IP address is not kept and nothing is stored on your device. Visits cannot be linked to you over time or across other sites. We also count, without any personal data, how many times the buttons to call, write, open WhatsApp or get directions are pressed, and how many bookings and gift cards are sent.
- Legal basis: legitimate interest (art. 6.1.f) in understanding how the site is used and improving it.
- Retention: data on individual visits 12 months; daily totals, without personal data, beyond that.
2.2 Booking a table
To book online we ask for your first and last name, phone number, email address, number of guests, day and time, the language you are browsing in (to write your emails in your language) and, if you wish, free-text notes.
- Purpose and legal basis. Managing the booking (recording it, confirming it, holding your table, telling you if something changes) and the related messages: confirmation, reminder the day before, link to change or cancel, any cancellation. This is the performance of the contract created by the booking (art. 6.1.b). Without name, phone and email we cannot book online: you can always call us.
- Notes and allergies. In the notes you can write requests such as a high chair or an occasion to celebrate. If you write food allergies or intolerances, this is health data (art. 9 GDPR): we use it solely to prepare your table and dishes safely, only dining room and kitchen staff read it, and we process it on the basis of your explicit consent (art. 9.2.a, together with art. 6.1.b for the booking), which you give by ticking the dedicated box before sending the booking. You can withdraw it at any time by writing to us: we will delete the notes and may not be able to take into account the need you told us online, but you can tell us in person when you arrive. Withdrawal does not affect what was done before. Notes are in any case deleted 30 days after the booking date.
- Booking status and history. We record what happened to the booking: confirmed, arrived, table left, cancelled, no-show. In our management panel this information, grouped by phone number, forms a simple customer history: how many times you came, the last visit, any bookings not honoured. We use it to organise the dining room better, to manage bookings with a card guarantee and to answer disputes about the penalty. Legal basis: legitimate interest (art. 6.1.f) in running the restaurant and preventing no-shows. We make no automated decisions based on this history. A phone number may be used by several people: the history is linked to the number, it does not certify the identity of whoever booked, and you can ask for it to be corrected or deleted.
- Retention. We keep booking data (name, contacts, status, history) for 24 months from the booking date, then delete or anonymise it. Notes are deleted after 30 days. Data about any penalty charge stays in the accounts for 10 years (legal obligation, art. 6.1.c).
2.3 The card guarantee
For some services (you see it written before booking) we ask for a payment card as a guarantee. You enter the card details in a form provided by Stripe: they go directly to Stripe and never pass through our servers. From Stripe we only receive identification codes (customer, payment method, authorisation) that allow us, if you do not show up and have not cancelled at least 2 hours before, to charge the penalty stated at booking time (30 euros per person). The charge is started by staff after marking the booking as a no-show: it is not automatic.
- Legal basis: performance of the contract (art. 6.1.b) for the guarantee and any penalty; legal obligations (art. 6.1.c) for accounting.
- Stripe (Stripe Payments Europe Ltd, Ireland, with Stripe Inc. in the United States) processes payment data as an independent controller, including for fraud prevention and its obligations as a payment institution: Stripe privacy policy.
- Retention: Stripe codes stay linked to the booking and are deleted with it (24 months); data about any charge stays in the accounts for 10 years.
2.4 Gift cards
To buy a gift card we ask for your name, email and phone, the amount, whether the card is for you or for someone else (in that case the recipient's name, a dedication if you wish and, if you choose direct delivery, their email and the delivery date) and, only if you want an invoice, the billing details (tax code or VAT number, address, SDI code or certified email).
- Purpose and legal basis. Issuing the gift card, collecting payment, delivering it by email as a PDF or at the counter, recording its use in the restaurant and helping you if something goes wrong: performance of the contract (art. 6.1.b). Issuing the invoice and keeping accounting documents: legal obligation (art. 6.1.c).
- Payment. It takes place on Stripe's payment page (Stripe Checkout), to which you are redirected: card details are processed only by Stripe, as an independent controller (Stripe privacy policy). Stripe tells us the outcome of the payment and the transaction reference.
- Recipient's data. If you give the card to someone, you provide their name, the dedication and possibly their email: you may do so only if you are allowed to. In the first email the recipient receives a note saying where their data comes from and where to find this policy (art. 14 GDPR). In the dedication we ask you not to write personal information that is not needed.
- Retention. We keep gift card data (purchaser, recipient, dedication, movements) for up to 24 months after the card expires or is used up, to handle any disputes; invoices and billing details are kept for 10 years (art. 2220 of the Italian Civil Code and tax rules).
2.5 The invitation to leave a review
The day after your visit, if you gave us your email and actually had lunch or dinner with us, we send you a single thank-you email inviting you to leave a review on Google. It is not a newsletter: no others follow, we profile nobody and we pass the address to nobody.
- Legal basis. Legitimate interest (art. 6.1.f) in knowing the opinion of those who visited us and in becoming known, in compliance with art. 130 paragraph 4 of the Italian Privacy Code, which allows writing to one's own customers at the address left for the service provided they can object immediately and every time.
- How to say no. When booking, by ticking the box "do not send me the invitation"; or by replying to the email itself with one line; or by writing to info@trattorialenuvole.it. On request we exclude your phone number from all future invitations: in that case we keep the number in an exclusion list (only the number, nothing else) for as long as we keep sending invitations, because it is the only way to respect your choice.
- The link in the email leads to our Google listing: from there on, Google's privacy policy applies.
2.6 When you write or call us
If you write to info@trattorialenuvole.it, call us or message us on WhatsApp from the link on the site, we use the data you give us (name, contacts, content of the message) only to reply and handle the request. Legal basis: pre-contractual measures or contract (art. 6.1.b), or legitimate interest in replying to those who write to us (art. 6.1.f). Retention: up to 24 months from the last contact, unless the request becomes a booking or a purchase. WhatsApp is a service of WhatsApp Ireland Ltd (Meta group): if you use it, messages pass through its systems under its privacy policy, with possible transfers outside the European Union.
2.7 The Google map and social links
The Contact page contains a Google Maps map that loads only if you accept functionality cookies in the banner or press "Show the map": at that moment Google receives your IP address, may set its cookies and processes the data as an independent controller, including in the United States (Google privacy policy). Legal basis: consent (art. 6.1.a), which you can withdraw at any time from "Cookie preferences" at the bottom of the pages. The links to Instagram, Facebook, WhatsApp and Google Maps are plain links: no data passes to those services until you press them; once on their sites, their policies apply.
2.8 Staff area
The panel we use to manage bookings and gift cards is accessible only to staff, with personal credentials. Staff data (name, work email, role, logins) is processed to manage the employment relationship and for the security of the system.
3. Providing your data
The data marked as required in the forms is needed to do what you ask: without it we cannot complete the booking or the purchase online, but you can always call us or drop by the restaurant. Notes, dedication, billing details and the allergy consent are optional.
4. How long we keep your data
| Data | How long | Why |
|---|---|---|
| Booking: name, contacts, status, history by phone number | 24 months from the booking date | Running the dining room, preventing no-shows, penalty disputes |
| Booking notes, including any allergies | 30 days from the booking date | Only needed for that visit |
| Stripe codes for the card guarantee | Deleted together with the booking | Only needed for any penalty |
| Penalty charges and accounting documents | 10 years | Tax and accounting obligations |
| Gift card: purchaser, recipient, dedication, movements | 24 months after the card expires or is used up | Support and disputes |
| Invoices and billing details | 10 years | Legal obligations |
| List of numbers excluded from review invitations | As long as we send invitations | Respecting your objection |
| Emails and messages you send us | 24 months from the last contact | Replying and finding the conversation again |
| Technical site logs | A few days, with the providers | Security and operation |
| Anonymous visit statistics (without IP address) | 12 months | Understanding how the site is used |
| Choices made in the cookie banner | 6 months | See the Cookie Policy |
Database backups are kept by the provider for a limited period, at most 30 days, and then overwritten. Once the periods have passed, data is deleted or anonymised, unless needed to establish or defend a right in an ongoing dispute.
5. Who can see your data
Your data is processed by the people who work in the restaurant, authorised and trained, and by some providers that give us technical services and act as processors (art. 28 GDPR) under a contract, or as independent controllers where indicated:
- Vercel Inc. (United States): hosting of the site and its functions, run in the Frankfurt region. Policy.
- Neon Inc. (United States): database of bookings and gift cards, hosted in Frankfurt. Policy.
- Stripe Payments Europe Ltd (Ireland) and Stripe Inc. (United States): payments and card guarantees, independent controller. Policy.
- Aruba S.p.A. (Italy): mailboxes and email sending. Policy.
- Hostinger International Ltd (Cyprus): hosting of the WordPress site for the news and images on data.trattorialenuvole.it. Policy.
- Cloudflare Inc. (United States): DNS management for the domain and, when active, routing of traffic to the site. Policy.
- Smarti (Italy): the agency that built and maintains the site; anonymous visit statistics with the Umami software, on a server of Hetzner Online GmbH (Germany) located in Helsinki, Finland.
- Google Ireland Ltd and Google LLC: Google Maps map, only with your consent, independent controller. Policy.
- Our accountant and advisers for tax and accounting duties; the bank for payments received.
Data may be disclosed to public authorities when the law requires it. We do not sell it and do not publish it.
6. Transfers outside the European Union
Pages and database are hosted in Frankfurt, but some providers (Vercel, Neon, Stripe, Cloudflare, Google and, if you use it, WhatsApp) are based in the United States or may access data from there, for example for technical support. These transfers take place with the safeguards of articles 44-49 GDPR: certification under the EU-US Data Privacy Framework for the companies that adhere to it and, in any case, the standard contractual clauses approved by the European Commission. You can ask us for a copy of the safeguards by writing to info@trattorialenuvole.it.
7. How we protect your data
The site and communications with providers are encrypted (HTTPS). The management panel requires personal credentials. Card data never passes through our systems. Access to notes with any allergies is limited to dining room and kitchen staff, who are instructed not to copy them elsewhere.
8. Your rights
You can ask us at any time: to know which data we hold about you and receive a copy (access); to correct it; to delete it; to restrict its use; to receive it in a machine-readable format to take it elsewhere (portability); to object to processing based on legitimate interest, including the review invitation; to withdraw the consents given (allergies, map), without affecting what was done before.
Just write to info@trattorialenuvole.it or call +39 347 259 1995: we reply within one month. If you believe your data is being processed unfairly, you can contact the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it), including with a complaint, or the courts.
9. Minors
The site and its services are aimed at adults. Information about children that a parent enters in a booking (for example a high chair) is processed only for that visit.
10. Automated decisions
We make no decisions based solely on automated processing that produce effects on you. The no-show penalty is decided and started by staff, and you can always dispute it by writing to us.
11. Changes
If we change something important we update this page and the date at the top. For cookies, the banner is shown again. This is the version of 1 October 2026.