Privacy Policy

Privacy Policy

Privacy Policy
This page describes how this website is managed with regard to the processing of personal data of users who consult it. This is a notice provided pursuant to Article 13 of EU Regulation 2016/679 – the General Data Protection Regulation (hereinafter the "GDPR") to those who interact with the web services of the "Le Grondici Ristorante & Bar" website, accessible online at https://www.legrondici.it/en/.
This notice applies solely to the website https://www.legrondici.it/en/. Any other websites that may be reached through links on this site are subject to their own privacy notices, independently established by their respective Data Controllers.


DATA CONTROLLER
Pursuant to Article 4(7) of the GDPR, the Data Controller for the processing of your personal data is Remarhotels S.r.l., with registered office at Via Poli 6, 00187 Rome, Italy.


DATA PROCESSORS
In the course of processing your personal data, external parties formally appointed as Data Processors pursuant to Article 28 of EU Regulation 2016/679 may be involved, including web agencies responsible for managing the website and data centres providing hosting services for the site. The complete list of appointed Data Processors may be requested directly from the Data Controller.


PLACE OF DATA PROCESSING
Processing operations connected with the web services of this site take place at the premises of the Data Controller and of the Data Processors, and are handled solely by technical staff assigned to the processing activity.
No data arising from the web service is disclosed or disseminated. Personal data provided by users who submit requests for informational material is used solely to carry out the requested service, and is disclosed to third parties only where strictly necessary for that purpose.


TYPES OF DATA PROCESSED
Browsing data
In the course of their normal operation, the computer systems and software procedures used to run this website acquire certain personal data whose transmission is inherent to the use of internet communication protocols. This information is not collected for the purpose of being linked to identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server's response (successful, error, etc.), and other parameters relating to the user's operating system and computing environment. This data is used solely to derive anonymous statistical information on the use of the site and to monitor its correct functioning, and is deleted immediately after processing. The data may be used to establish liability in the event of hypothetical computer crimes against the site; save for this possibility, web contact data is not currently retained for more than thirty days.
Data provided voluntarily by the user
The optional, explicit and voluntary submission of communications to the e-mail addresses shown on this website, as well as the use of the WhatsApp messaging service linked from the site, results in the subsequent acquisition of the sender's e-mail address or mobile phone number, which is necessary to respond to the request, together with any other personal data included in the message. Specific summary notices will be progressively provided or displayed on the pages of the site dedicated to particular services available on request.


PROCESSING METHODS
Personal data is processed using IT tools for the time necessary to achieve the purposes for which it was collected. Specific security measures are observed to prevent data loss, unlawful or improper use, and unauthorised access.


PURPOSE, LEGAL BASIS AND NATURE OF PROVISION
The processing activities connected with the management of this website relate to:

  • Research and statistical analysis purposes based on anonymous aggregate data, aimed at measuring the functioning of the Site, measuring traffic, and assessing usability and interest in order to make it more functional and efficient. Consent is not required, as this does not constitute processing of personal data;
  • Purposes relating to compliance with laws and regulations. The legal basis is Article 6(1)(c) of the GDPR, i.e. the processing is necessary for compliance with a legal obligation to which the Data Controller is subject. Consent is not required;
  • Purposes necessary to establish, exercise or defend a right in judicial proceedings, whenever the judicial authorities exercise their jurisdictional functions. The legal basis is Article 6(1)(f) of the GDPR, i.e. the processing is necessary for the pursuit of the Data Controller's legitimate interest. Consent is not required;
  • Management of requests for information submitted by users through the contact details provided on the site. The legal basis is Article 6(1)(b) of the GDPR, i.e. the processing is necessary to carry out pre-contractual measures requested by the data subject. Consent is not required.


BOOKING MANAGEMENT
By clicking the "Book a table" button, the user is redirected to the TheFork booking platform. The personal data necessary to complete the booking is collected directly by TheFork, in accordance with the procedures described in its own privacy notice.


TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS
The Data Controller undertakes to limit the circulation and processing of personal data (e.g. storage, filing and retention of data on its own servers) to countries within the European Economic Area, and expressly prohibits transferring such data to non-EU countries that do not guarantee (or in the absence of) an adequate level of protection, or in the absence of the safeguards provided for under Chapter V of EU Regulation 2016/679 (an adequacy decision, Standard Contractual Clauses, or the explicit consent of the data subject).


DATA RETENTION
The Data Controller will process the data subject's personal data for the time strictly necessary to achieve the purposes set out in this notice. Without prejudice to the foregoing, the Data Controller will process the data subject's personal data until the end of the period permitted under applicable law for the protection of its own interests (Article 2947(1) and (3) of the Italian Civil Code).


AUTOMATED PROCESSING
The Company does not carry out any processing based on automated decision-making, including profiling, which produces legal effects concerning the data subject or which significantly affects them.
For any profiling activities carried out through cookies, please refer to the relevant Cookie Policy.


SOCIAL BUTTONS
The Company's website may use, as social plug-ins, certain platforms managed by third parties (for example, Facebook and Instagram). This means that by clicking on specific "buttons" (known as social buttons/widgets), the user is automatically and directly redirected to the provider of the chosen social network, where they may interact with the Company's official profile.
Data subjects are therefore invited to consult and take into consideration the privacy policy of the selected platform, and to visit the section of the site dedicated to the Company's Cookie Policy for a more complete and detailed description of the features of this functionality.


RIGHTS OF DATA SUBJECTS
Users may freely exercise the rights set out in Articles 15 et seq. of the GDPR, namely the right to:

  • Withdraw consent at any time. The User may withdraw consent previously given for the processing of their Personal Data;
  • Object to the processing of their Data. The User may object to the processing of their Data where such processing is based on a legal basis other than consent;
  • Access their Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the Data processed;
  • Verify and request rectification. The User may verify the accuracy of their Data and request that it be updated or corrected;
  • Obtain restriction of processing. Under certain conditions, the User may request that the processing of their Data be restricted. In such cases, the Data Controller will not process the Data for any purpose other than its storage;
  • Obtain erasure or removal of their Personal Data. Under certain conditions, the User may request that the Data Controller erase their Data;
  • Receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another controller. This provision applies where the Data is processed by automated means and the processing is based on the User's consent, on a contract to which the User is a party, or on contractual measures connected thereto;
  • Lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority, as provided for under Article 77 of the Regulation, or take legal action as provided for under Article 79 of the same Regulation.
    Requests should be sent by e-mail to: direzionecommerciale@remarhotels.com


UPDATE AND REVISION
This Privacy Policy was drawn up on 23 July 2026 and may be subject to future revisions.