Information presented on this website is promotional in nature

About the GDPR

The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. Espresso Bar Italia is committed to compliance with GDPR requirements in all our data processing activities.

Data Controller

For the purposes of GDPR, the data controller is:

Espresso Bar Italia
Via della Croce 47
00187 Rome, Italy
Email: [email protected]

Your Rights Under GDPR

As a data subject, you have the following rights:

Right of Access (Article 15)

You have the right to obtain confirmation as to whether your personal data is being processed and, where that is the case, access to the personal data along with certain supplementary information.

Right to Rectification (Article 16)

You have the right to have inaccurate personal data rectified and incomplete personal data completed.

Right to Erasure (Article 17)

Also known as the "right to be forgotten," you have the right to have your personal data erased in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restriction of Processing (Article 18)

You have the right to restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object (Article 21)

You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.

Rights Related to Automated Decision Making (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

Lawful Bases for Processing

We process personal data based on the following lawful bases as defined in Article 6 of GDPR:

  • Consent (Article 6(1)(a)): You have given consent to the processing for one or more specific purposes.
  • Contract (Article 6(1)(b)): Processing is necessary for the performance of a contract or to take steps prior to entering into a contract.
  • Legal Obligation (Article 6(1)(c)): Processing is necessary for compliance with a legal obligation.
  • Legitimate Interest (Article 6(1)(f)): Processing is necessary for the purposes of our legitimate interests, except where overridden by your interests or fundamental rights.

Data Protection Measures

In accordance with Article 32 of GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular testing and evaluation of security measures
  • Access controls limiting who can view personal data
  • Staff training on data protection obligations

Data Breach Notification

In accordance with Articles 33 and 34 of GDPR, we have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.

International Data Transfers

When we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place as required by Chapter V of GDPR, including standard contractual clauses approved by the European Commission.

How to Exercise Your Rights

To exercise any of your rights under GDPR, please contact us:

Email: [email protected]
Address: Via della Croce 47, 00187 Rome, Italy

We will respond to your request within one month. In complex cases, this period may be extended by a further two months, in which case we will inform you accordingly.

Right to Lodge a Complaint

If you believe that our processing of your personal data infringes GDPR, you have the right to lodge a complaint with a supervisory authority. In Italy, this is the Garante per la protezione dei dati personali (Italian Data Protection Authority).

Updates to This Information

We may update this GDPR information from time to time. Any significant changes will be communicated through our website.