1. Who processes your data
The data controller is La Perla Nera Srls, VAT no. 04869740409, registered at Viale Regina Elena 209, 47924 Rimini (RN), Italia.
For anything concerning your data write to info@perlanerarimini.it or call +39 0541 1411431.
We have not appointed a Data Protection Officer: our activity does not fall within the cases that make it mandatory under Art. 37 GDPR.
2. What we collect
This site collects only what you type into a form, plus the technical data required to deliver the pages to you. We do not profile visitors and we neither buy nor sell contact lists.
2.1 Booking form
Name, phone, email, date and approximate time, number of guests, table type, chosen package and any free-text notes. The notes field is open: please do not enter health information, opinions, beliefs or anything else Art. 9 GDPR classifies as a special category of data.
2.2 Job application form
Name, age, nationality, phone, email, the role you are applying for, experience, message and an optional photograph. The photograph is optional: your application is valid without it. If you send one, it is used solely for the selection, read only by management and never disclosed to third parties. If the outcome is negative we delete it together with the rest of the application.
2.3 Contact form
Name, contact details and the text of your message.
2.4 Technical browsing data
For security and diagnostics our hosting provider logs IP address, date and time of the request, the page requested, browser type and operating system. Every server necessarily receives these in order to reply: we do not use them to identify you, nor do we cross-reference them with forms.
2.5 Storage on your device
The site sets no cookies of its own. It uses three local browser stores, all technical, described in detail in the cookie policy.
3. Why we process it, and for how long
| Purpose | Legal basis | Retention |
|---|---|---|
| Handling a booking request and getting back to you | Art. 6(1)(b) GDPR — pre-contractual steps you asked for | 12 months from the requested date |
| Assessing a job application | Art. 6(1)(b) GDPR; for the photograph, Art. 6(1)(a) — your consent, given by sending it | 12 months from receipt. The photograph is deleted immediately if the outcome is negative |
| Answering a request for information | Art. 6(1)(b) and 6(1)(f) GDPR | 12 months from the last contact |
| Site security, diagnostics, abuse prevention | Art. 6(1)(f) GDPR — our legitimate interest in keeping the service intact and available | As per the hosting provider's logs, typically 30 days |
| Recording your cookie choice | Art. 6(1)(c) GDPR — we must be able to demonstrate consent, Art. 7(1) | 6 months, then you are asked again |
| Statistical measurement and marketing tools | Art. 6(1)(a) GDPR — only with your consent, revocable | No such tool is currently active |
Once these periods expire the data is deleted, unless a legal obligation — tax law or defence of a legal claim, for example — requires us to keep it longer.
4. Do you have to give it to us?
No. No field is required by law: writing to us is your choice. The fields marked with an asterisk are however needed to give you a useful answer — without a contact detail we cannot confirm a table. Leaving them blank simply means the request cannot be processed; there is no other consequence.
5. Who else sees your data
Your data is handled by authorised management staff. It is not disclosed publicly and is not sold to third parties for commercial purposes.
When you submit a form, the data takes two routes at once: it arrives as an email in management's mailbox and it is recorded in an electronic archive we use so that no request is lost and so we can tell what stage each one has reached. The archive is hosted on Neon Inc. infrastructure within the European Union and is reachable only by management, through a password-protected area over an encrypted connection.
Deletion is automatic. Every night a routine removes the requests that have passed the periods set out above: it does not depend on anyone remembering. The photograph attached to an application is moreover deleted immediately, without waiting for that deadline, the moment the selection closes with a negative outcome.
Some technical suppliers, appointed as processors under Art. 28 GDPR, may process it on our behalf:
| Supplier | Role | Where |
|---|---|---|
| Vercel Inc. | Hosting and delivery of the site | Stati Uniti — UE (rete edge) |
| jsDelivr (Cloudflare / Fastly) | Delivery of technical libraries | Rete globale |
| CARTO / OpenStreetMap | Map tiles — loaded only if you ask for them | Unione Europea / Stati Uniti |
| Neon Inc. | Storage of the requests submitted through the forms | Unione Europea (regione francofortese) |
| Resend (Resend, Inc.) | Delivery by email of the forms you submit | Stati Uniti |
If you contact us via WhatsApp, the conversation takes place on the platform of WhatsApp Ireland Ltd. and follows that service's terms: that channel is your choice, and we invite you to read its privacy notice.
6. Does your data leave the European Union?
The site runs on infrastructure that may also sit outside the European Economic Area. Where that happens, the transfer relies on the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) and, for participating US providers, on the Data Privacy Framework recognised by the adequacy decision of 10 July 2023.
We have removed such transfers wherever they were avoidable: typefaces, for instance, are hosted on our own domain rather than pulled from Google Fonts, so merely opening a page does not disclose your IP address to a third party.
7. Your rights
At any time you may ask us to:
- access the data concerning you and receive a copy (Art. 15);
- rectify it if inaccurate or incomplete (Art. 16);
- erase it (Art. 17);
- restrict its processing (Art. 18);
- receive it in a machine-readable format or have it transmitted to another controller (Art. 20);
- object to processing based on legitimate interest (Art. 21).
Where processing rests on consent you may withdraw it at any time, as easily as you gave it; withdrawal does not affect the lawfulness of processing carried out beforehand. For cookies, the button in the cookie policy is enough.
Write to info@perlanerarimini.it: we reply within one month, extendable by two in complex cases (Art. 12(3)). Exercising your rights is free of charge.
If you believe the processing infringes the Regulation you may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — www.gpdp.it), with the authority of your habitual residence, or bring the matter before a court.
8. Automated decisions and profiling
We take no decisions based solely on automated processing and carry out no profiling within the meaning of Art. 22 GDPR. Bookings and applications are assessed by people.
9. Minors
Entry to the venue is restricted to adults and this site is not directed at anyone under 18. We do not knowingly collect their data: if we notice we have received any, we delete it. If you are a parent and believe your child has sent us data, write to us and we will act.
10. Security
The site is served over HTTPS only. We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): access limited to authorised staff, encrypted transmission of forms, retention of only what is necessary. No measure is infallible, but should a breach entail a high risk to your rights we will inform you as Art. 34 requires.
11. Updates
This notice may change, for instance if we introduce new tools. The version in force is always the one published here, with its date and version number at the top of the page. If a change affects consent, the banner will ask you to choose again.