Privacy Policy
This notice explains how Casa Dama S.a.s. processes the personal data of people who visit casadama-torino.it and of anyone who contacts us to book a table or ask a question. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the “Italian Privacy Code”). This English text is a translation provided for convenience; in case of discrepancy the Italian version prevails.
1. Who processes your data
Data controller
Casa Dama S.a.s.
Registered office: Corso Massimo D’Azeglio 76 — 10126 Turin (TO), Italy
Restaurant: Via dei Mille 32 — 10123 Turin (TO), Italy
Italian VAT no. 13283090010
Certified e-mail (PEC): casadamasas@pec.buffetti.it
Phone: +39 011 242 4437
The controller has not appointed a Data Protection Officer, as the conditions set out in Article 37 GDPR do not apply. For any data protection matter you can write to the certified e-mail address above.
2. What data we collect
2.1 Browsing data
The IT systems and software procedures that run this website acquire, during normal operation, certain data whose transmission is inherent in the use of internet communication protocols: IP addresses, browser and operating system type, date and time of the request, pages requested, and response status codes. This data is used solely to deliver the website, to derive anonymous statistical information, and to establish liability in the event of computer crimes against the site.
2.2 Cookies and tracking tools
The site uses technical cookies and, subject to your consent, third-party statistics and marketing cookies, plus external content (the 360° virtual tour of the dining room). Full details — names, purposes, retention and providers — are set out in the Cookie Policy.
2.3 Data you give us yourself
There is no contact form anywhere on this site: we collect no data through forms. You can however reach us using the buttons on the pages, in which case we process the data you provide voluntarily:
- WhatsApp — the button opens a conversation with the restaurant’s number. We receive your phone number, profile name, profile picture if public, and the content of your messages. The messaging service is operated by WhatsApp Ireland Ltd., which acts as an independent controller for the running of the platform.
- Phone — if you call us, we process your number and whatever information is needed to handle the booking or enquiry.
2.4 Third-party services we link to
Some buttons and links lead to external platforms that handle data on their own account, as independent controllers. When you use them, their notice applies, not this one:
- TheFork (TheFork SAS — Tripadvisor Group) for online table booking;
- Tripadvisor (Tripadvisor LLC) for reading and posting reviews;
- Instagram (Meta Platforms Ireland Ltd.) for the restaurant’s social profile;
- Google Maps (Google Ireland Ltd.) for directions.
A plain link transmits no data before you click it: the choice is yours. When you book through TheFork, the booking details (name, contact details, date, number of guests, any notes) are passed to us by the platform and from that moment we process them to provide the service.
3. Why we process data and on what legal basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Delivering the site, keeping it secure and preventing abuse | Controller’s legitimate interest in a working, secure website (Art. 6(1)(f) GDPR) | System logs: up to 12 months |
| Remembering your cookie choices | Legal obligation to document consent and legitimate interest in not re-showing the banner (Arts. 6(1)(c) and 6(1)(f) GDPR) | 6 months from your choice |
| Answering enquiries and handling bookings received by phone or WhatsApp | Pre-contractual measures and performance of the catering contract at your request (Art. 6(1)(b) GDPR) | 24 months from last contact |
| Measuring site usage in aggregate form (Google Analytics 4) | Your freely given, revocable consent (Art. 6(1)(a) GDPR and Art. 122 Italian Privacy Code) | Up to 14 months at Google; consent valid 6 months |
| Measuring advertising campaigns and serving personalised ads (Meta Pixel) | Your freely given, revocable consent (Art. 6(1)(a) GDPR and Art. 122 Italian Privacy Code) | Up to 90 days at Meta; consent valid 6 months |
| Showing the 360° virtual tour of the dining room (CloudPano) | Your freely given, revocable consent (Art. 6(1)(a) GDPR and Art. 122 Italian Privacy Code) | Session duration, save for the provider’s own cookies |
| Meeting tax, accounting and other legal obligations | Legal obligation (Art. 6(1)(c) GDPR) | 10 years, as required by Italian civil and tax law |
| Establishing or defending legal claims | Controller’s legitimate interest (Art. 6(1)(f) GDPR) | For the duration of the dispute and any appeal periods |
Providing data is always optional. Refusing statistics cookies, marketing cookies and external content does not limit your use of the site in any way, with the single exception of the 360° virtual tour, which remains viewable directly on the provider’s own site. Not providing the data needed to handle a booking does, however, make it impossible for us to confirm it.
4. No automated decision-making
We carry out no automated decision-making or profiling producing legal effects concerning you or similarly significantly affecting you, within the meaning of Article 22 GDPR. The marketing tools described in section 3 serve to measure campaign effectiveness and show more relevant ads, and run only if you give consent.
5. Who we share data with
Data is handled by the controller’s authorised staff, who are duly instructed. It may also be processed by the following parties, appointed as processors under Article 28 GDPR or acting as independent controllers for their own platforms:
- the website hosting and maintenance provider;
- Google Ireland Ltd. — Google Analytics 4, Google Tag Manager, Google Maps;
- Meta Platforms Ireland Ltd. — Meta Pixel, Instagram, WhatsApp;
- CloudPano — hosting of the 360° virtual tour;
- TheFork SAS — online booking management;
- accounting, tax and legal advisers, for their respective duties;
- public authorities, where required by law.
Data is never disseminated and is not sold to third parties for their own commercial purposes.
6. Transfers outside the European Union
Some of the providers listed have affiliates in the United States and may transfer data outside the European Economic Area. Such transfers take place on the basis of an adequacy decision of the European Commission (the EU-US Data Privacy Framework, for certified providers) or of the Standard Contractual Clauses approved by the Commission, supplemented by additional security measures. You may request a copy of the safeguards in place by writing to the certified e-mail address in section 1.
7. How we protect data
We apply technical and organisational measures appropriate under Article 32 GDPR: encrypted HTTPS connections across all pages, system access restricted to authorised staff, continuous software updates, regular backups, and selection of providers offering sufficient data protection guarantees.
8. Your rights
At any time you may exercise the following rights against the controller under Articles 15 to 22 GDPR:
- access to your data and to information about the processing (Art. 15);
- rectification of inaccurate or incomplete data (Art. 16);
- erasure of your data, in the cases provided for (Art. 17);
- restriction of processing (Art. 18);
- portability of your data in a structured, machine-readable format (Art. 20);
- objection to processing based on legitimate interest (Art. 21);
- withdrawal of consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3)).
To withdraw or change your cookie consent, use the button below or the “Cookie preferences” link in the footer of every page.
For all other requests, write to casadamasas@pec.buffetti.it or call +39 011 242 4437, stating which right you wish to exercise. We will reply without undue delay and in any case within one month of the request, a period that may be extended by two months in particularly complex cases.
9. Complaint to a supervisory authority
If you believe the processing of your data breaches data protection law, you have the right to lodge a complaint with the Italian Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — garanteprivacy.it) or with the supervisory authority of the Member State where you habitually reside, as well as to seek a judicial remedy.
10. Children
This site is not intended for children under 14 and we do not knowingly collect their data. If you believe a child has provided us with personal data, let us know at the certified e-mail address above and we will delete it.
11. Changes to this notice
We may update this notice to reflect changes in the law or in the services we offer. The version in force is always the one published at this address, with the last-updated date shown at the top of the page. If the changes concern processing based on consent, we will ask for your consent again.