Privacy Policy

Last updated: 19 August 2026

This Privacy Policy describes how Chianti Cooking Experience collects, uses and protects personal data through the website chianticookingexperience.com in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Italian data protection legislation.

1. Data Controller

The Data Controller is:

Paola Negri – Chianti Cooking Experience
VAT No. 07193130486
Borgo Sarchiani 142
50026 San Casciano in Val di Pesa (FI), Italy

Email: info@chianticookingexperience.com

The Data Controller determines the purposes and means of processing personal data collected through this website.

2. Personal Data We Process

Depending on how you use the website, we may process the following categories of personal data.

Data provided directly by you

When you contact us by email or through a contact or information request form, we may process information such as:

  • name and surname;

  • email address;

  • telephone number, where provided;

  • information relating to the service, cooking class, catering service, event or experience you are interested in;

  • preferred dates, location and number of participants, where provided;

  • any other information you voluntarily include in your message.

Please do not provide personal data that is not necessary for handling your request.

Browsing and technical data

When you visit the website, the systems used to operate it may automatically process technical information including:

  • IP address;

  • browser and device information;

  • operating system;

  • date and time of access;

  • requested pages and resources;

  • referring page;

  • technical logs necessary for security, diagnostics and website operation.

Cookies and similar technologies

The website uses technical cookies and, subject to your choices and consent where required, may use analytics or other non-essential technologies.

Detailed information about cookies, services, purposes and your consent preferences is available in the Cookie Policyaccessible from the website and through the “Manage Consent” function.

3. Purposes and Legal Bases of Processing

Responding to requests and providing information

Personal data submitted through contact forms, email or telephone is processed to respond to your enquiries, provide quotations and information, check availability and organise the services you request.

Legal basis: taking steps at your request prior to entering into a contract and, where applicable, performance of a contract pursuant to Article 6(1)(b) GDPR.

Management of bookings and contractual relationships

Where a request results in a booking or service agreement, personal data may be processed for organisational, administrative, accounting and customer service purposes.

Legal basis: performance of a contract under Article 6(1)(b) GDPR and compliance with legal obligations under Article 6(1)(c) GDPR.

Website operation and security

Technical and log data may be processed to maintain the website, prevent abuse, diagnose technical problems, ensure security and protect the website and its users.

Legal basis: the Data Controller’s legitimate interest in maintaining a secure and properly functioning website pursuant to Article 6(1)(f) GDPR.

Website statistics

Subject to consent where required, analytics technologies such as Google Analytics may be used to understand in aggregate how visitors use the website and to improve its content, usability and performance.

Legal basis: consent pursuant to Article 6(1)(a) GDPR where consent is required.

You may withdraw or change your consent at any time by using the Manage Consent function available on the website.

Marketing technologies

Any marketing or profiling technologies that may be activated on the website will only be used after obtaining consent where required by law.

Legal basis: consent pursuant to Article 6(1)(a) GDPR.

Data submitted through the website’s contact forms is not currently used to subscribe users automatically to newsletters or unrelated direct marketing communications.

4. Nature of Providing Personal Data

Providing browsing data that is technically necessary is inherent in the use of the website.

Providing personal data through contact forms or email is voluntary. However, failure to provide information that is necessary to handle a request may make it impossible for us to respond or provide the requested service.

Fields marked as required in a form must be completed in order to submit the request.

5. How Personal Data Is Processed

Personal data is processed using electronic and, where necessary, organisational procedures designed to ensure an appropriate level of security.

We apply reasonable technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure or misuse.

The website is made available through HTTPS encrypted connections.

6. Recipients and Service Providers

Personal data may be accessed, where necessary, by persons authorised by the Data Controller and by external providers involved in operating the website and providing the requested services.

These may include:

  • website hosting and infrastructure providers;

  • email service providers;

  • website development, maintenance and IT support providers;

  • analytics and technology providers, where enabled;

  • accounting, tax, legal or professional advisers where necessary;

  • suppliers or collaborators involved in providing a service requested by the customer, where necessary;

  • public authorities or other entities where disclosure is required by law.

Where required by the GDPR, service providers processing personal data on behalf of the Data Controller are appointed as Data Processors pursuant to Article 28 GDPR.

An updated list of relevant Data Processors may be requested from the Data Controller.

7. Google Analytics and Third-Party Services

The website may use Google Analytics and related Google technologies to obtain website usage statistics.

Where prior consent is required, these technologies are activated only after the visitor has given the relevant consent through the cookie management system.

Information on cookies, retention periods and individual services detected on the website is provided in the Cookie Policy.

The website may also contain links to third-party websites or services such as Facebook, Instagram or Tripadvisor. When you follow an external link, the processing of your personal data is governed by the privacy policies of the relevant third party.

8. Transfers Outside the European Economic Area

Some technology providers may process personal data in countries outside the European Economic Area.

Where such transfers occur, they are carried out using the safeguards required under Chapter V of the GDPR, such as an adequacy decision adopted by the European Commission or appropriate safeguards including Standard Contractual Clauses, where applicable.

Further information about transfers made by individual cookie or technology providers may also be available in the Cookie Policy and in the privacy documentation of the relevant provider.

9. Data Retention

Personal data is retained only for as long as necessary for the purpose for which it was collected.

In particular:

  • enquiries and correspondence that do not lead to a contractual relationship may normally be retained for up to 24 months from the last relevant interaction, unless a longer period is necessary to establish, exercise or defend legal claims;

  • data relating to bookings, invoices, payments and contractual or administrative relationships may be retained for the period required by applicable civil, accounting and tax legislation, generally up to 10 years where required;

  • technical and security logs are retained according to the security and operational requirements of the website and its infrastructure providers and only for as long as necessary for those purposes;

  • analytics and cookie-related data is retained according to the settings and retention periods of the relevant services, as further specified in the Cookie Policy;

  • consent records may be retained for the period necessary to demonstrate compliance with legal obligations.

When personal data is no longer required, it will be deleted or anonymised where appropriate.

10. Your Rights

Under Articles 15 to 22 GDPR, where applicable, you have the right to:

  • obtain confirmation as to whether your personal data is being processed;

  • access your personal data;

  • request rectification of inaccurate or incomplete data;

  • request erasure of your personal data;

  • request restriction of processing;

  • object to processing based on legitimate interests;

  • receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies;

  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

To exercise your rights, contact:

info@chianticookingexperience.com

We may request information necessary to verify the identity of the person making the request.

11. Right to Lodge a Complaint

If you believe that your personal data has been processed in breach of applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority.

For Italy, the supervisory authority is the:

Garante per la protezione dei dati personali

You may also seek protection before the competent courts.

12. Automated Decision-Making

The Data Controller does not carry out solely automated decision-making producing legal effects or similarly significant effects on website users within the meaning of Article 22 GDPR.

13. Changes to This Privacy Policy

This Privacy Policy may be updated to reflect changes to the website, the services used, the way personal data is processed or applicable legislation.

The current version will always be published on this page together with its date of last update.