Risto Pilot Privacy Policy

PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA

Pursuant to Articles 13 and, where applicable, 14 of Regulation (EU) 2016/679 ("GDPR").
Last updated: 22/09/2026

This Notice explains how personal data are processed when users use RISTO PILOT to make reservations, place orders, submit requests, access digital services or interact with restaurants and other businesses participating in the Platform.

When you use this website or a RISTO PILOT subdomain associated with the venue, you are using a technology service provided by Webofficine S.r.l.s. through the RISTO PILOT platform. When you choose to book, order or request a service from a specific restaurant, RISTO PILOT discloses to the selected restaurant the data necessary to manage your request.

RISTO PILOT and the restaurant may therefore process some of the same personal data for different purposes and under different privacy roles, as explained below.

1. Data Controller for RISTO PILOT

For processing activities carried out directly within the RISTO PILOT services, the Data Controller is:
Webofficine S.r.l.s.
Registered office: Viale Guglielmo Marconi 50/15, 59100 Prato (PO), Italy
VAT No.: 02613570973
REA: PO-621021
Platform: RISTO PILOT
E-mail: [email protected]
Certified e-mail (PEC): [email protected]

2. The restaurant selected by the User

When you use RISTO PILOT to request a service from this business, the necessary data are disclosed to:

Once received, the restaurant processes those data as an independent Data Controller for its own purposes, such as managing the reservation or order, table and service management, waiting lists, communications relating to the request, customer relationship management and compliance with legal obligations. Any use by the restaurant for additional purposes, such as marketing or profiling, requires its own appropriate legal basis and, where necessary, specific consent.

3. Difference between RISTO PILOT and the restaurant

RISTO PILOT does not always act merely as the restaurant's technical provider. For the services described in this Notice, RISTO PILOT has a direct relationship with the User and may process personal data as an independent Data Controller.

  1. RISTO PILOT receives and processes the request within its Platform;
  2. RISTO PILOT discloses to the selected restaurant the data necessary to fulfil the request;
  3. the restaurant subsequently processes those data as an independent Data Controller in managing its relationship with the User.

When Webofficine processes data exclusively on behalf of the restaurant and according to the restaurant's instructions, it instead acts as a Data Processor pursuant to Article 28 GDPR. The fact that RISTO PILOT and the restaurant may process some of the same data does not automatically create joint controllership.

4. Personal data we process

Depending on the services used, the following categories of personal data may be processed:

Full payment-card data may be handled directly by specialised payment providers and may not be accessible to RISTO PILOT.

5. Health data and other special categories of personal data

In connection with certain requests, the User may provide information concerning, for example, allergies, intolerances or dietary needs related to health. Such information falls within the special categories of personal data under Article 9 GDPR. RISTO PILOT asks Users to provide only information that is strictly necessary.

Where required by law, such data are processed on the basis of the User's explicit consent pursuant to Article 9(2)(a) GDPR. They may be disclosed to the restaurant where necessary to manage the requested service and are not used by RISTO PILOT for marketing, commercial profiling or commercial network segmentation.

6. Where the data come from

Personal data are normally provided directly by the User. They may also be obtained through authentication procedures, communications from the User, another person legitimately making a reservation also on behalf of the User, the restaurant for updating the status of a service, external providers used to deliver the service, or automatically during use of the Platform in relation to technical data.

7. Purposes and legal bases of RISTO PILOT processing

  1. Managing requests and RISTO PILOT services: receiving reservations and orders, forwarding them to the selected restaurant, displaying status and enabling changes or cancellations. Legal basis: Article 6(1)(b) GDPR.
  2. Managing the RISTO PILOT account and identity: identification, telephone/e-mail verification, access, profile, history and preferences. Legal basis: Article 6(1)(b) GDPR.
  3. Disclosure to the selected restaurant: transmission of the data necessary to receive and manage the User's request. Legal basis: Article 6(1)(b) GDPR.
  4. Service communications: confirmations, rejections, changes, reminders, authentication, security and messages necessary to provide the service. Legal basis: Article 6(1)(b) GDPR and, for security, Article 6(1)(f) GDPR.
  5. Security, fraud and abuse prevention: protecting accounts and the Platform, detecting anomalies and preventing unlawful use. Legal basis: Article 6(1)(f) GDPR.
  6. Statistics, analytics and improvement: measuring performance, detecting anomalies, improving the Platform and producing benchmarks, preferably using aggregated or anonymised data. Legal basis: Article 6(1)(f) GDPR.
  7. Legal compliance: complying with legal obligations, authority requests and judicial orders. Legal basis: Article 6(1)(c) GDPR.
  8. Establishment, exercise or defence of legal claims: preventing and managing disputes and protecting RISTO PILOT, Users or third parties. Legal basis: Article 6(1)(f) GDPR.

8. RISTO PILOT and network marketing

Only with the User's specific optional consent, RISTO PILOT may use contact details to send offers, promotions, initiatives, news and communications relating to RISTO PILOT and restaurants or businesses participating in the network, by e-mail, SMS, WhatsApp or other messaging services, telephone or other channels identified when consent is collected. Legal basis: Article 6(1)(a) GDPR, together with the applicable rules on electronic communications. Consent may be withdrawn at any time and refusing consent does not prevent use of the core services.

9. RISTO PILOT profiling

Only with specific and separate consent, RISTO PILOT may analyse information about use of the Platform, such as geographic area, booking frequency, restaurants used, types of services and preferences inferred from interactions, in order to personalise commercial communications and proposals. Legal basis: Article 6(1)(a) GDPR. Health data and other special categories of personal data are not used for commercial profiling.

10. Restaurant marketing and profiling

The restaurant may also use RISTO PILOT for its own marketing, newsletters, promotions, campaigns, loyalty programmes, segmentation or profiling. Where such processing is determined by the restaurant, the restaurant acts as an independent Data Controller and Webofficine may merely provide the technical tools as Data Processor.

Any consent requested by the restaurant is separate from consent given to RISTO PILOT. Consent to RISTO PILOT marketing does not constitute consent to restaurant marketing, and vice versa.

11. Whether providing data is mandatory

Providing the data necessary to identify the User where required, make reservations or orders, request services, transmit the request to the restaurant and manage related communications is necessary to provide the requested service. Failure to provide essential data may make it impossible to complete the operation.

Providing data for marketing or profiling, whether by RISTO PILOT or by the restaurant, is optional.

12. Recipients of personal data

Personal data may be disclosed or made accessible, where necessary, to:

Where a provider processes data on behalf of Webofficine, it is appointed as Data Processor pursuant to Article 28 GDPR where the relevant requirements are met. Personal data are not indiscriminately disclosed to the public.

13. Transfers outside the European Economic Area

Some technology providers may involve processing in countries outside the European Economic Area. Where this occurs, transfers are carried out in accordance with Articles 44 et seq. GDPR using adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules or other mechanisms allowed by law and, where necessary, appropriate supplementary measures.

14. Retention periods

Certain data may be retained for longer where necessary to comply with legal obligations or to establish, exercise or defend legal claims. Retention periods applied by the restaurant to its own processing are determined by the restaurant.

15. Automated decision-making

Unless otherwise specifically stated, RISTO PILOT does not make decisions based solely on automated processing that produce legal effects concerning the User or similarly significantly affect the User within the meaning of Article 22 GDPR.

16. Cookies and similar technologies

RISTO PILOT websites and subdomains may use cookies and similar technologies. Strictly necessary cookies may be used for operation, security and delivery of services. Any non-essential cookies or tools are used in accordance with applicable law and, where required, with the User's prior consent. Further information is available in the Cookie Policy made available through the Platform.

17. User rights

Where provided for by the GDPR, the User may exercise the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), objection (Article 21), withdrawal of consent and rights relating to automated decisions (Article 22). Where personal data are processed for direct marketing, the User may object at any time without having to provide reasons.

18. How to exercise rights against RISTO PILOT

For processing carried out by Webofficine as independent Data Controller, the User may contact:
Webofficine S.r.l.s.
E-mail: [email protected]
Certified e-mail (PEC): [email protected]
Registered office: Viale Guglielmo Marconi 50/15, 59100 Prato (PO), Italy

19. How to exercise rights against the restaurant

For processing carried out by the restaurant as independent Data Controller, the User may contact:
La Nassa
Privacy contact: [email protected]

Where a request is sent to the wrong party and clearly concerns processing for which the other party is responsible, it may be forwarded to the appropriate party where appropriate.

20. Complaint to a supervisory authority

The User has the right to lodge a complaint with the competent supervisory authority if they consider that the processing of their personal data infringes applicable data-protection law. In Italy, the competent authority is the Garante per la protezione dei dati personali. The User's right to seek judicial remedies remains unaffected.

21. Changes to this Privacy Policy

RISTO PILOT may update this Notice to reflect service developments, new features, organisational changes or changes in applicable law. In the event of material changes, appropriate measures will be taken to inform Users. The current version will be made available through the Platform.

Version: 22/09/2026
Last updated: 22/09/2026