Privacy notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
1. Scope of this notice
This notice explains how the Controller processes the personal data of users of www.primopianofiumicino.com, as well as data received through the contact details and tools accessible from the website. It covers contacts for information, restaurant and swimming-pool bookings, events and commercial enquiries initiated through the tools published on the website.
Separate notices may be provided for processing carried out at the physical premises or within an existing contractual relationship. External platforms reached through links from the website also apply their own notices where they act as independent controllers.
2. Data controller
Yacht Club Tevere S.r.l., with registered office at Via Costalunga 21/31, 00054 Fiumicino (Rome), Italy, Italian Tax Code 03523700585, VAT no. 01206651000, REA RM-438794 (the “Controller”).
• E-mail for privacy requests: amministrazione@portoromano.com
• Certified e-mail (PEC): yctsrl@pec.portoromano.com
• Address: Via Costalunga 21/31, 00054 Fiumicino (Rome), Italy
No contact details for a Data Protection Officer (DPO) are currently published. If a DPO is appointed, the relevant contact details will be added to this notice.
3. Categories of personal data
• browsing and security data: IP address, device and browser identifiers and characteristics, date and time of the request, requested page, referrer, response status, technical logs and cookie-consent records;
• identity and contact data: first and last name, email address, telephone number and, where relevant, address and billing details;
• request and service data: message content, preferences, dates, number of guests or participants and other information needed to handle the request;
• contractual, administrative and payment data received after the relationship begins or from booking platforms, only insofar as necessary for the service;
• any additional data voluntarily supplied by email, telephone, forms or messaging services.
Users should not send special-category data under Article 9 GDPR, criminal-conviction data, full identity documents or unauthorised third-party data through general forms unless strictly necessary and specifically requested by the Controller.
4. How data are collected and services are provided
• the website publishes a telephone number, email address abd WhatsApp link for direct contact;
• table bookings, swimming-pool access and menus or lists continue on the external Plateform platform;
• directions continue on Google Maps and social-media links open the relevant platforms;
• event enquiries may be sent through the contact details or tools available on the website.
At the date of this notice, no standalone table-booking form appears to be hosted directly on the PRIMOPIANO domain. If new forms or services are introduced, this notice and the Cookie Policy must be updated.
5. Purposes, legal bases and retention
| Purpose | Data | Legal basis | Retention |
| Website operation, security and abuse prevention | Technical data, IP, logs and cookie preferences | Legitimate interests in security and propert operation; legal obligations | Normally up to 12 months; longer for incidents or unlawful activity |
| Information, event and commercial enquiries | Name, contact details, message and relevant data | Steps requested before entering a contract; legitimate interests in managing communications | 12 months after closure; 24 months for complex commercial negotiations |
| Table and swimming-pool bookkings after transfer to Plateform | Identity, contact, date, guest-number and relevant preference data | Pre-contractual steps and performance of a contract; legal obligations | For the service; administrative and tax records for up to 10 years |
| E-mail, telephone or WhatsApp communications | Contact details and message content | Pre-contractual steps, contract or legitimate interests, depending on content | 12 months if no relationship begins; otherwise relevant contractual period |
| Compliance and protection of rights | Contractual, administrative, tax and communication data | Legal obligations; legitimate interests; establishment, exercise or defence of legal claims | 10 years or statutory term; disputes until finally resolved |
These are ordinary retention criteria. Data may be kept longer to comply with the law, manage disputes, prevent abuse or protect rights; after expiry they are erased or anonymised, subject to technical backup cycles.
6. Whether the provision of data is mandatory
Providing personal data is voluntary; however, fields marked as mandatory and any data necessary for the requested service are required to answer an enquiry, prepare a quotation, make or manage a booking, or comply with contractual and legal duties. Failure to provide them may prevent the service from being supplied.
7. Processing methods and automated decision-making
Data are processed using electronic and, where necessary, paper-based means in accordance with the principles of lawfulness, fairness, transparency, minimisation, accuracy and storage limitation. The Controller does not use the website to make decisions based solely on automated processing that produce legal or similarly significant effects. Any aggregated statistics or website measurement tools are governed by the Cookie Policy.
8. Authorised persons and recipients
Data may be processed by the Controller’s employees and collaborators who are authorised and instructed according to their duties. Where necessary, data may also be disclosed to:
•hosting, maintenance, security, email, CRM, management-software and IT-support providers;
• booking and service-management providers, particularly Plateform, and Blastness for website and cookie infrastructure, according to the roles defined in the relevant agreements
• administrative, tax, legal and insurance advisers and other professionals bound by confidentiality;
• technical and organisational suppliers involved in delivering the requested service;
• public authorities, law-enforcement bodies or other parties where disclosure is required by law or necessary to protect a right.
Depending on their activities and the applicable agreements, suppliers act as processors under Article 28 GDPR or as independent controllers. An up-to-date list of processors may be requested from the Controller.
9. External platforms and data obtained from third parties
When users continue to an external platform, its provider may collect data directly and process them under its own privacy notice. The Controller may subsequently receive the information needed to manage the enquiry or booking. In that case, the source is the platform selected by the user and the data received may include identity details, contact details and information about the booked service.
10. Transfers outside the European Economic Area
The use of social-media, mapping, messaging or other international services may involve transfers outside the European Economic Area. Where the Controller carries out such a transfer, it relies on an adequacy decision, European Commission standard contractual clauses, any necessary supplementary measures or another safeguard under Articles 44 et seq. GDPR. Processing performed independently by external platforms is governed by their respective notices.
11. Cookies and similar technologies
The website uses cookies and similar technologies. Current information on the tools actually in use, their providers, purposes and duration, and on how to grant, refuse or withdraw consent is available in the Cookie Policy linked in the footer and in the preference panel managed through the Blastness infrastructure. Strictly necessary cookies may be used without consent. Non-essential technologies—including analytics not treated as strictly necessary, profiling or advertising tools—must be activated only after a valid user choice where required. Refusing or withdrawing consent does not affect essential website functions.
12. Social-media, mapping and messaging links
The website may contain links to Google Maps, Instagram, Facebook, LinkedIn and WhatsApp. A simple link does not necessarily install technologies from those platforms, but clicking it opens an external service that processes data under its own terms. If third-party content is embedded directly, loading must be subject to consent where required.
13. Security
The Controller implements technical and organisational measures appropriate to the risks in order to prevent loss, destruction, alteration, unauthorised disclosure or access. No system is entirely risk-free; users should therefore avoid sending excessive or particularly sensitive information through ordinary forms, email or messaging services.
14. Data-subject rights
Where applicable under Articles 15–22 GDPR, data subjects may request access, rectification, erasure, restriction and portability, and may object to processing based on legitimate interests. Where processing is based on consent, consent may be withdrawn at any time without affecting processing carried out beforehand. Requests may be sent to amministrazione@portoromano.com or to yctsrl@pec.portoromano.com. The Controller may request only the information needed to verify the applicant’s identity and normally responds within one month, subject to the extensions allowed by Article 12 GDPR.
15. Complaints and legal remedies
Data subjects may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali,www.garanteprivacy.it) under Article 77 GDPR and may seek a judicial remedy before the competent courts.
16. Children's data
The online services are not directed specifically at children. Enquiries and bookings containing children’s data must be made by a person with parental responsibility or another authorised person and must include only information necessary for the service.
17. Updates
This notice may be updated following legal, organisational or technological changes. The version published on the website states the date of its latest update. Users will be appropriately informed of material changes
18. Operational contact details
• Telephone and WhatsApp: +39 346 666 7626
• E-mail: primopiano@portoromano.com
• Operational address: Via Costalunga 31, 00054 Fiumicino (Rome), Italy
Privacy rights must be exercised using the Controller’s contact details in section 2.