Privacy Policy
Last updated: July 2026
This page tells you, plainly, what happens to your data when you visit the site, book a table or write to us. The short version: we collect little, we protect it well, and we sell it to no one. The rest — who we are, what we collect, for how long, and with what rights — is below, at your own pace. This is, in every respect, our notice under Articles 13 and 14 of Regulation (EU) 2016/679, the GDPR: NOS Ristorante is the restaurant division of Palazzo Scotto S.r.l., and this website is its channel for information and bookings.
Who answers for your data
The data controller — the one who decides how and why your data is used (Art. 4(7) GDPR) — is the family company behind NOS:
- Controller
- Palazzo Scotto S.r.l.
- Registered office
- Via Trieste e Trento 30, 70011 Alberobello (BA), Italy
- VAT / Tax code
- 07751560728
- REA
- BA-579682
- Share capital
- EUR 100,000.00 fully paid up
- Certified email (PEC)
- palazzoscotto@pec.it
- Privacy contact
- nosristorante@palazzoscotto.com
We have no Data Protection Officer (DPO): for a business like ours, Article 37 GDPR does not require one. Your point of reference for anything concerning your data is Valerio Scotto, the director — you can reach him at nosristorante@palazzoscotto.com.
What we collect, and why
Only what we need to reply to you and to keep the site running. Here it is, item by item, with the legal basis the GDPR asks us to state (Art. 6(1); for cookies, Art. 5(3) of the ePrivacy Directive):
| Data | Legal basis | What it's for |
|---|---|---|
| First and last name | Pre-contractual measures — Art. 6(1)(b) | Knowing who you are when you ask for a table, an event or information |
| Email address | Pre-contractual measures — Art. 6(1)(b) | Replying to you and keeping you posted on your request |
| Phone number (optional) | Pre-contractual measures — Art. 6(1)(b) | Reaching you quickly if something needs confirming or changing |
| Message, indicative date, occasion | Pre-contractual measures — Art. 6(1)(b) | Understanding your request and getting ready to welcome you |
| IP address, user agent, referrer | Legitimate interest — Art. 6(1)(f) | Keeping the site safe: anti-bot check (Cloudflare Turnstile) on forms, anti-abuse rate limit with a hashed IP, technical service logs |
| Technical and session cookies | Technical necessity — Art. 5(3) Dir. 2002/58/EC | Making the essentials work: language, session, security |
| Analytics and marketing cookies | Consent — Art. 6(1)(a) | Aggregate statistics and campaign measurement — only if activated, and only with your yes |
| Email address (newsletter subscription) | Consent — Art. 6(1)(a) | Writing to you with news from NOS — only if you subscribe, and only for as long as you wish |
One exception deserves its own chapter: the optional allergies-and-intolerances field on the private booking page for small groups, which we process solely with your explicit consent (Art. 9(2)(a) GDPR) — more on that just below. Beyond it, this site does not collect special categories of data (Art. 9 GDPR) or data relating to criminal convictions and offences (Art. 10 GDPR). We kindly ask you not to enter sensitive data in the free-text fields of the forms.
When you write to us through a form
When you send a request from the site — for small groups or for NOS Open Air — the data you type (name, email, phone if you leave it, message) takes two paths, both ours. First: it reaches the NOS team by email through Resend, our transactional email provider, so we can reply to you. Second: it is stored encrypted in a Supabase database — AES-256-GCM encryption, unreadable without the key. The legal basis is your request itself (pre-contractual measures, Art. 6(1)(b)) and, for storage, our legitimate interest in following it up (Art. 6(1)(f)). Before sending, we ask you to tick an informed-consent box — never pre-ticked — and form data never turns into marketing without a further yes from you.
Allergies and intolerances: a delicate chapter
The private booking page for small groups — the one we send you after replying to your request — has an optional field for the allergies and intolerances of the group's guests; the public "Small Groups" form does not ask for them. If you fill it in, that information may say something about health: under the GDPR it is "special category" data (Art. 9(1)) and enjoys enhanced protection. We process it solely on the basis of your explicit consent (Art. 9(2)(a)): filling in the field and ticking the dedicated box is the act by which you give it. It serves one purpose only: letting the kitchen prepare a safe menu for your group and following up on your request. Never marketing, never anything else. The allergen categories you select, and any free text, reach the team by email so the kitchen can get organised, and rest encrypted in the database (AES-256-GCM), visible only to those handling your request; we delete them within 30 days of the service date. Providing them is entirely optional: you can leave the field blank and tell us later, by phone or email, without your request suffering for it. And you can withdraw your consent whenever you wish (Art. 7(3) GDPR) by writing to nosristorante@palazzoscotto.com: withdrawal does not affect the lawfulness of what was done before.
The newsletter
At the bottom of the site you can leave us your email to receive news from NOS. It is a processing activity of its own, distinct from the enquiry forms: the legal basis is your consent (Art. 6(1)(a) GDPR), which you give freely by subscribing, and the purpose is one — writing to you. The email is stored encrypted (AES-256-GCM) and is not passed to third parties for their own marketing. You can withdraw your consent at any time (Art. 7(3)), through the unsubscribe link in every message or by writing to nosristorante@palazzoscotto.com: we keep it while you stay subscribed and delete it when you leave. Withdrawal does not affect what was sent before.
When you book a table
Bookings and some site features run through Plateform, the booking platform we rely on, which processes the necessary data under its own privacy notice, as a processor or independent controller. Its widget may appear on a site page inside an iframe and set its own technical cookies — the ones it needs to work. Some pages also offer a booking form built into the site: what you type is sent securely to Plateform to create the reservation, with Cloudflare Turnstile's anti-bot protection keeping automated submissions and abuse at bay.
Who lends us a hand
A few technical providers process data on our behalf, each appointed as a processor where required (Arts. 13(1)(e) and 28 GDPR). The "Status" column tells it as it is: some tools work all the time, others — analytics and marketing — stay idle until you say yes through the banner.
| Provider | What it does for us | Location | Transfer safeguard | Status |
|---|---|---|---|---|
| Plateform | The booking engine: receives, handles and confirms bookings | EU | Processing within the EEA | Active |
| Supabase | The database: keeps form data, encrypted | EU | Processing within the EEA | Active |
| Resend | Transactional email: delivers form enquiries to the team | USA | SCC (EU Dec. 2021/914) + EU-US DPF where certified | Active |
| Cloudflare | Network and security (CDN, tunnel), Turnstile anti-bot on forms, and a server-side conversion-measurement Worker (with hashed identifiers) | USA / global network | SCC (EU Dec. 2021/914) | Active for network, security and anti-bot; the conversion Worker runs only when marketing is active and with consent |
| Google LLC | Places API for live hours and reviews (active); Analytics 4, Google Ads and Tag Manager (configured) | USA | SCC (EU Dec. 2021/914) + EU-US DPF | Places API active; Analytics and Ads active upon consent |
| Meta Platforms Inc. | Meta Pixel and Conversions API for campaign measurement | USA | SCC (EU Dec. 2021/914) + EU-US DPF | Active upon consent |
| TripAdvisor LLC | The official reviews widget on the home page: loads the public rating and reviews from their service | USA | SCC (EU Dec. 2021/914) + EU-US DPF where participating | Active |
| Mr PRENO / Titanka S.p.A. | The room-request form on the "Beyond the Table" page: stay requests for Palazzo Scotto are received and handled through Mr PRENO (a Titanka product) | EU | Processing within the EEA | Active (only for room requests sent from that form) |
| Bedzzle | Palazzo Scotto's booking engine: the "Book now" box on the "Beyond the Table" page uses its official search widget to show you room prices and availability | EU | Processing within the EEA | Active (it loads only when you use that search form) |
One more word on the "Ask availability" form on the "Beyond the Table" page: it is the one you use to ask for a room at Palazzo Scotto. When you send it, the data you enter (dates, number of guests, your contact details) is collected and processed through Mr PRENO, the booking system provided by Titanka and used by Palazzo Scotto, for the sole purpose of getting back to you about availability. The consent and the specific notice for that form live inside the form itself, under the Mr PRENO / Titanka privacy notice. Right next to it sits the "Book now" box: it uses the official widget of Bedzzle, Palazzo Scotto's booking engine, which does not load until you start using it. The dates and number of guests you enter go to Bedzzle to show you prices and availability; any booking then continues on Bedzzle's systems, under its own notice.
How long we keep it
Nothing stays forever. Every piece of data has its expiry date, as the storage-limitation principle requires (Art. 5(1)(e) GDPR):
| Category | How long we keep it |
|---|---|
| Requests from the site forms (small groups / Open Air) | 24 months from submission, unless a different legal obligation applies |
| Group allergies and intolerances (private booking page) | Deleted within 30 days of the service date |
| Technical and security logs | 12 months, longer only for abuse or security investigations |
| Booking data handled by Plateform | As per Plateform's notice and timeframes |
| Accounting and tax data | 10 years (Art. 2220 Italian Civil Code; D.P.R. 600/1973 and 633/1972) |
| Your cookie choice | Up to 12 months, then we ask you again |
| Newsletter email | While you stay subscribed; deleted upon unsubscription |
Once that time has passed, the data is deleted or irreversibly anonymised.
If data travels outside Europe
Some providers — Resend, Google LLC, Meta Platforms Inc. and Cloudflare in particular — may process data on servers in the United States or elsewhere outside the European Economic Area. When that happens, it does not happen lightly (Arts. 44 et seq. GDPR): with each of them we rely on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914 of 4 June 2021), together with supplementary technical (encryption), organisational (restricted access) and contractual measures, in line with EDPB Recommendations 01/2020; and where the provider is certified under the EU-US Data Privacy Framework, the Commission's adequacy decision of 10 July 2023 applies as well. Transfers tied to analytics or marketing, moreover, happen only if you have said yes through the cookie banner.
How we protect it
With technical and organisational measures appropriate to the risk, as Article 32 GDPR asks — and with a little extra care of our own. The identifying form data and any allergy-and-intolerance information are encrypted at rest with AES-256-GCM: without the key, kept separate from the data and under restricted access, they stay unreadable. Everything travelling between your browser and our servers goes over HTTPS/TLS. The keys that can read the database never touch the browser and stay server-side, following the least-privilege principle; we keep access logs and procedures for handling any incidents. And when marketing is active and you have given consent, the email and phone used to measure conversions leave only in hashed form (SHA-256): the platforms receive a fingerprint, never the data in the clear. The same goes for the IP in the forms' anti-abuse limit.
Your rights — all of them
The GDPR (Arts. 15–22) grants you a set of rights over your data. They are yours, and you can exercise them against us at any time:
- Know what data we hold about you and receive a copy (access, Art. 15);
- Have inaccuracies corrected and gaps completed (rectification, Art. 16);
- Ask us to delete it, in the cases provided for — the "right to be forgotten" (erasure, Art. 17);
- Ask us to pause its use, in the cases provided for (restriction, Art. 18);
- Receive it in a structured, machine-readable format and take it elsewhere (portability, Art. 20);
- Object to processing based on our legitimate interest (objection, Art. 21);
- Take back a consent already given, whenever you wish and without touching what came before (withdrawal, Art. 7);
- Not be subject to decisions based solely on automated processing (Art. 22).
To exercise them, just write to us: nosristorante@palazzoscotto.com, by certified email (PEC) to palazzoscotto@pec.it, or by post to the registered office (Via Trieste e Trento 30, 70011 Alberobello). To protect your data, we may first ask you to confirm your identity. We reply without undue delay, and in any case within one month; for particularly complex or numerous requests the period may stretch by two months, but we will tell you within the first. It is all free of charge, except for manifestly unfounded or excessive requests. For cookies and the newsletter you can do it yourself, faster: the banner and the unsubscribe link are there for exactly that.
If something doesn't sit right
Talk to us first, if you like — nosristorante@palazzoscotto.com — and we will look for an amicable solution. Your right to turn to the supervisory authority remains intact either way: for Italy it is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — tel. (+39) 06.696771, email protocollo@gpdp.it, PEC protocollo@pec.gpdp.it, www.garanteprivacy.it.
And cookies?
The site uses technical cookies to work, always. The analytics and marketing tools are in place, but they write nothing until you say yes through the banner. Every detail, name by name, is in the Cookie Policy.
If this page changes
It can happen: laws get updated, tools change. When it does, we update this page and the date you see at the top. Worth a glance back, every now and then.


