Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
This notice describes how we process the personal data of users who visit the website www.sottoilimoni.com and of those who request or make a booking for our experiences (Cooking experience, Pizza experience, Lemon tour) through the online booking system, in accordance with Regulation (EU) 2016/679 (“GDPR”), Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, and the guidelines of the Italian Data Protection Authority (Garante per la protezione dei dati personali) on cookies and other tracking tools of 10 June 2021.
1. Data controller
The data controller is Azienda Agricola Sotto i Limoni, with registered office at Località Annunziata, 6 – 84010 Minori (SA) – Italy, VAT no. IT 06160130651, e-mail info@sottoilimoni.com, certified e-mail (PEC) dilietoantonietta@pec.it. The controller can be contacted to exercise the rights provided by the GDPR or for any information relating to the processing of data.
2. Data Protection Officer
The controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Article 37 GDPR are not met. For any matter relating to the protection of personal data, you can write to info@sottoilimoni.com.
3. Categories of data processed
3.1 Browsing and use of the website
The website processes the following categories of data: browsing data collected automatically (IP address, logs, device and browser identifiers); data voluntarily provided through contact forms managed with Forminator; data needed for the technical management and security of the website, also collected through Jetpack, Jetpack Protect and Defender; data processed for anti-spam purposes by Akismet; data that may be processed to send communications through WP Mail SMTP; technical data needed for the automatic translation feature provided by GTranslate; data displayed or retrieved by the Tripadvisor reviews widget.
3.2 Online booking system
When you request a booking, and in the following stages until the end of the experience, we process the following data:
- Booking request data (entered by you in the online form): chosen experience, format (shared or private), additional services, requested date and time slot, number of participants by age group (adults 13+, children 5-12, infants 0-4), any special occasion (honeymoon, anniversary, birthday or other, optional), language, date and time of the request.
- Contact details: first name, last name, e-mail address and telephone number (in international format) of the person making the booking.
- Food allergies and intolerances (optional): the information you give us, for yourself and for your guests, is health data and falls within the special categories of data under Article 9 GDPR.
- Participants’ data: after the final confirmation of the booking we send you by e-mail a personal, confidential link to a page where you can enter, for each participant, first name, last name, date of birth and any allergies or intolerances. The date of birth is used to check that it matches the age group booked and, together with the name, to organise the experience safely and to prepare the personalised certificate of participation, if any.
- Payment data: amount, reason (deposit, balance or full payment), method (cash, card, bank transfer), date and payment code or link. We do not see or store your payment card details: card payments take place on the secure page of the provider SumUp. For bank transfers we process the details of the transaction that appear on our account.
- Communications and documents: the e-mails we send and receive in connection with the booking (request received, alternative dates proposed, provisional and final confirmation, rescheduling, reminder before the experience, cancellation and any refund, thank-you message with the recipes), the confirmation document in PDF with the booking code, any calendar file and the certificate of participation. In case of cancellation we also record the reason given and the refund method.
- Internal log and notes: a record of the operations carried out on the booking (with date, time and name of the operator who performed them) and any service notes.
- Bookings through agencies and intermediaries: if the booking is made by a travel agency or other intermediary, we process the agency’s data (name, offices, VAT number, tax code, recipient code, names and contact details of contact persons and of the agent) and the data of end customers that the agency provides to us. In this case the end customers’ data are not collected from the data subject (Article 14 GDPR): they come from the agency, which is required to inform its own customers.
- Anti-abuse measures: to prevent automated or abusive submissions of the form we use a hidden field, a minimum completion time and an hourly limit on requests per IP address and per e-mail address. The counters are stored in abbreviated form (hash), not in clear, and are deleted automatically after one hour.
The booking system does not use cookies or profiling or tracking tools, does not record payment card data and does not use your data for promotional mailings.
4. Embedded social buttons, content and maps
The website includes link buttons and/or widgets that refer to third-party platforms, including Facebook, Instagram, TikTok, Google Maps and Tripadvisor. Some of these elements, if implemented through embedded plugins or scripts, may automatically transmit the user’s technical data (IP address, user agent, device identifiers) to the third-party provider as soon as the page loads, even without any active interaction by the user.
In particular:
- simple hyperlink buttons to the Facebook, Instagram and TikTok profiles, which merely send the user to the external site without loading scripts or iframes from those platforms, do not normally involve automatic transmission of data and do not require prior consent;
- if the buttons are built with widgets or embedded scripts of the respective platforms, such elements are treated as tracking tools and require the user’s prior consent before loading;
- the integration of Google Maps through an iframe involves the transmission of the IP address and other technical data to Google Ireland Limited as soon as the page loads, and is therefore managed, where technically possible, with deferred loading subject to consent;
- the Tripadvisor reviews widget creates direct connections with the servers of Tripadvisor LLC to load its content, involving the transmission of technical data to the third-party provider according to the same principle.
The e-mails and confirmation documents we send you also contain links to external services (Google Maps and Apple Maps to reach our location; Google Calendar or other calendars to save the event; WhatsApp to contact us). These services are activated only if you click on the link; from that moment your data are processed by the relevant provider, as an independent controller, according to its own privacy notice. If you write to us or we write to you through WhatsApp, your telephone number and the content of the messages are also processed by WhatsApp/Meta under their respective terms.
5. Purposes and legal basis of the processing
5.1 Website
Data relating to browsing and use of the website are processed on the basis of the controller’s legitimate interest, limited to the technical data essential for its operation, through the cache and optimisation services provided by Aruba HiSpeed Cache, Jetpack Boost and Colibri Page Builder. Data entered in contact requests are processed, through Forminator, on the basis of the performance of pre-contractual or contractual measures requested by the user. The anti-spam processing on forms, carried out by Akismet Anti-spam, is based on the controller’s legitimate interest, as is the processing connected with the security of the website and the prevention of cyber attacks, carried out through Defender and Jetpack Protect.
The sending of e-mail communications through WP Mail SMTP takes place on the basis of the performance of requests made by the user, while the automatic translation of content offered by GTranslate is based on the controller’s legitimate interest in making the website available in several languages. The display of third-party reviews through WP Tripadvisor Review Widgets is likewise based on the controller’s legitimate interest, unless it involves non-technical tracking, in which case the user’s consent is required.
Embedded social content (Facebook, Instagram, TikTok) and the Google Maps map are instead processed exclusively on the basis of the data subject’s consent, as are any additional statistical or social features that may be activated on the website: the legal basis is always and only the user’s free, specific, informed and unambiguous consent, since legitimate interest cannot be invoked to justify such processing.
5.2 Bookings
- Managing the booking request and related communications: checking availability, alternative proposals, confirmations, rescheduling, reminders before the experience, cancellations, sending the recipes – data processed: booking request data, contact details, communications and documents; legal basis: performance of pre-contractual measures and of a contract to which you are a party (Article 6(1)(b) GDPR).
- Managing deposits, balances, payments and refunds – data processed: payment data, contact details; legal basis: performance of the contract (Article 6(1)(b)).
- Organising the experience safely: list of participants, checking age groups, certificate of participation – data processed: participants’ data; legal basis: performance of the contract (Article 6(1)(b)) and the controller’s legitimate interest in the safety and proper organisation of the service (Article 6(1)(f)).
- Taking allergies and intolerances into account when preparing the dishes – data processed: health data (allergies and intolerances); legal basis: explicit consent (Article 9(2)(a) GDPR), which you can withdraw at any time.
- Complying with accounting and tax obligations – data processed: booking and payment data, invoicing data; legal basis: legal obligation (Article 6(1)(c)).
- Managing relationships with agencies and intermediaries – data processed: data of the agency and its contact persons, data of end customers; legal basis: performance of the contract (Article 6(1)(b)) and legitimate interest (Article 6(1)(f)).
- Preventing abuse and automated submissions of the form; keeping an internal record of operations; establishing, exercising or defending legal claims, including in court; ensuring continuity of the service through backup copies – data processed: technical anti-abuse data, internal log, booking data; legal basis: the controller’s legitimate interest (Article 6(1)(f)).
Data about allergies are processed only if, in the booking form, you select the relevant option and give your specific consent using the second checkbox. Consent is optional; without it, however, we will not be able to receive or take into account information about allergies and intolerances. Your agreement to the cancellation terms, which is required to submit the booking, concerns acceptance of the contractual conditions and is not a legal basis for the processing of data.
6. Nature of the provision of data
Providing the data necessary for technical browsing is indispensable for accessing the website. Providing the data requested through contact forms is optional, but necessary to receive a reply or to handle the request. For a booking, first name, last name, e-mail, telephone, experience, date and number of participants are mandatory: without them we cannot handle the request. Information about the special occasion, about allergies and the data of individual participants are optional, but without them some aspects of the experience (such as adapting the dishes or the personalised certificate) may not be possible. Providing data for non-technical purposes, such as statistics, social content or embedded maps, is always optional and subject to consent.
7. Recipients and data processors
Data are processed by the controller and by the persons authorised by the controller (family members and collaborators who manage bookings and the running of the experiences), who access the management panel with personal credentials and only the data needed for their task.
Data may be disclosed to providers acting as data processors, including: Automattic Inc. (Jetpack, Jetpack Boost, Jetpack Protect, Akismet); WPMU DEV (Defender, Forminator); WPForms LLC (WP Mail SMTP); GTranslate LLC; iubenda S.r.l.; Aruba S.p.A. (hosting and cache, on whose server the booking system, documents and backup copies are stored); the e-mail service provider through which booking e-mails are sent; accountants and tax and accounting advisers for legal compliance.
The following may also be recipients, as independent controllers: SumUp, for processing card payments; the bank where bank transfers are credited; the agencies and intermediaries that made the booking on your behalf; the competent authorities, in the cases provided for by law.
7-bis. Recipients – social platforms and maps
Technical browsing data may also be disclosed, because of the presence of embedded buttons or widgets, to: Meta Platforms Ireland Limited (Facebook, Instagram); TikTok Technology Limited; Google Ireland Limited (Google Maps); Tripadvisor LLC. Each of these parties acts as an independent controller for the data collected through its own tools, according to its respective privacy notice. The same applies to Apple (Apple Maps, Apple Calendar) and to any calendar services you choose to use, limited to the links you activate.
8. Transfer of data to third countries
Some of the providers listed, in particular Automattic Inc., WPForms LLC, GTranslate LLC, Meta Platforms Ireland Limited, TikTok Technology Limited, Google Ireland Limited and Tripadvisor LLC, are based or also process data in the United States or other non-EU countries. In such cases the transfer takes place on the basis of the standard contractual clauses approved by the European Commission, any applicable adequacy decisions (including the EU-US Data Privacy Framework, where the provider adheres to it) or other appropriate safeguards provided for by Articles 44-49 GDPR. Booking data are stored on servers located in Italy/EU.
9. Retention period
- Browsing data: for the minimum time necessary for technical and security purposes, unless needed to establish criminal offences. Data processed for security purposes are kept for the time necessary to detect and prevent threats.
- Contact form data: for the time necessary to handle the request and, afterwards, for the ordinary limitation period under Italian law, for administrative or defence purposes.
- Booking, contact and payment data: for the duration of the relationship and, afterwards, for 10 years from the date of the experience, to comply with accounting and tax obligations (Article 2220 of the Italian Civil Code) and to exercise or defend legal claims. Requests that were not completed (for example not confirmed, or cancelled before any payment) are deleted within 24 months.
- Allergies and intolerances and data of individual participants (name, date of birth): for the time strictly necessary to organise and deliver the experience and in any case no longer than 12 months after its date, after which they are deleted or anonymised. In any case they are deleted earlier at your request or if you withdraw your consent.
- Internal log of operations: together with the booking to which it refers.
- Anti-abuse counters: one hour.
- Backup copies: every night the system saves a copy of the data, in a folder that is not accessible from the internet, and keeps the latest 30 copies, automatically deleting the oldest ones. Data that we delete from the system may therefore remain in the backup copies for a maximum of about 30 days, after which they disappear permanently.
10. Cookies and other tracking tools
The website uses technical cookies, strictly necessary for its operation (cache, security, consent management), which do not require prior consent. The online booking form does not install any cookies and does not use tracking tools. The loading of social widgets and buttons (Facebook, Instagram, TikTok), of the Google Maps map and of the Tripadvisor widget is configured, through the iubenda consent management tool, so that it takes place only with the user’s specific prior consent for the relevant category of services, avoiding automatic loading before consent is given. If Jetpack activates statistical or third-party cookies that are not strictly necessary, such cookies are installed only with express prior consent, through an opt-in mechanism, with no pre-ticked boxes and no cookie wall. Users can withdraw or change their consent at any time through the cookie preferences panel available on the website.
11. Minors
Our experiences are also open to children and young people. Data of minors (including name, date of birth and any allergies or intolerances) are provided to us exclusively by the person making the booking, who declares to be the parent or legal guardian or otherwise authorised to provide them. We do not collect data directly from minors.
12. No automated decision-making
The controller does not carry out processing based solely on automated decision-making, including profiling, that produces legal effects or similarly significantly affects the data subject, pursuant to Article 22 GDPR. Confirmation e-mails and reminders are generated automatically by the system, but every booking is reviewed and confirmed by a person.
13. Rights of the data subject
The data subject may exercise at any time, against the controller, the rights provided for by Articles 15-22 GDPR: access, rectification, erasure, restriction, objection, data portability, as well as withdrawal of consent given at any time (for example consent to the processing of data about allergies), without affecting the lawfulness of the processing carried out before the withdrawal. Requests can be sent to info@sottoilimoni.com or to the PEC address given in point 1, stating the booking code, if available; we will reply within one month of receipt. The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), based in Piazza Venezia 11, 00187 Rome, Italy.
14. Data security
The controller adopts appropriate technical and organisational measures to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR, including perimeter protection and anti-malware tools (Defender, Jetpack Protect) and spam prevention systems (Akismet). For the booking system in particular: access to the management panel is restricted to authorised users with personal credentials; personal, confidential and non-guessable links are used for submitting participants’ data, which can be used only once unless we reopen them; documents, recipes and backup copies are kept in protected folders that cannot be reached directly from the internet; there are limits on requests and checks against automated submissions; payment card data are never stored.
15. Changes to this notice
The controller reserves the right to amend or update this notice at any time, also because of regulatory changes or changes in the services and plugins used. Changes take effect from the date of publication on the website.
Last updated: 02/10/2026