Pursuant to Articles 13 and, where applicable, 14 of Regulation (EU) 2016/679 ("GDPR").
Last updated: 22/09/2026
This Notice explains how personal data are processed when users use RISTO PILOT to make reservations, place orders, submit requests, access digital services or interact with restaurants and other businesses participating in the Platform.
When you use this website or a RISTO PILOT subdomain associated with the venue, you are using a technology service provided by Webofficine S.r.l.s. through the RISTO PILOT platform. When you choose to book, order or request a service from a specific restaurant, RISTO PILOT discloses to the selected restaurant the data necessary to manage your request.
RISTO PILOT and the restaurant may therefore process some of the same personal data for different purposes and under different privacy roles, as explained below.
For processing activities carried out directly within the RISTO PILOT services, the Data Controller is:
Webofficine S.r.l.s.
Registered office: Viale Guglielmo Marconi 50/15, 59100 Prato (PO), Italy
VAT No.: 02613570973
REA: PO-621021
Platform: RISTO PILOT
E-mail: [email protected]
Certified e-mail (PEC): [email protected]
When you use RISTO PILOT to request a service from this business, the necessary data are disclosed to:
Once received, the restaurant processes those data as an independent Data Controller for its own purposes, such as managing the reservation or order, table and service management, waiting lists, communications relating to the request, customer relationship management and compliance with legal obligations. Any use by the restaurant for additional purposes, such as marketing or profiling, requires its own appropriate legal basis and, where necessary, specific consent.
RISTO PILOT does not always act merely as the restaurant's technical provider. For the services described in this Notice, RISTO PILOT has a direct relationship with the User and may process personal data as an independent Data Controller.
When Webofficine processes data exclusively on behalf of the restaurant and according to the restaurant's instructions, it instead acts as a Data Processor pursuant to Article 28 GDPR. The fact that RISTO PILOT and the restaurant may process some of the same data does not automatically create joint controllership.
Depending on the services used, the following categories of personal data may be processed:
Full payment-card data may be handled directly by specialised payment providers and may not be accessible to RISTO PILOT.
In connection with certain requests, the User may provide information concerning, for example, allergies, intolerances or dietary needs related to health. Such information falls within the special categories of personal data under Article 9 GDPR. RISTO PILOT asks Users to provide only information that is strictly necessary.
Where required by law, such data are processed on the basis of the User's explicit consent pursuant to Article 9(2)(a) GDPR. They may be disclosed to the restaurant where necessary to manage the requested service and are not used by RISTO PILOT for marketing, commercial profiling or commercial network segmentation.
Personal data are normally provided directly by the User. They may also be obtained through authentication procedures, communications from the User, another person legitimately making a reservation also on behalf of the User, the restaurant for updating the status of a service, external providers used to deliver the service, or automatically during use of the Platform in relation to technical data.
Only with the User's specific optional consent, RISTO PILOT may use contact details to send offers, promotions, initiatives, news and communications relating to RISTO PILOT and restaurants or businesses participating in the network, by e-mail, SMS, WhatsApp or other messaging services, telephone or other channels identified when consent is collected. Legal basis: Article 6(1)(a) GDPR, together with the applicable rules on electronic communications. Consent may be withdrawn at any time and refusing consent does not prevent use of the core services.
Only with specific and separate consent, RISTO PILOT may analyse information about use of the Platform, such as geographic area, booking frequency, restaurants used, types of services and preferences inferred from interactions, in order to personalise commercial communications and proposals. Legal basis: Article 6(1)(a) GDPR. Health data and other special categories of personal data are not used for commercial profiling.
The restaurant may also use RISTO PILOT for its own marketing, newsletters, promotions, campaigns, loyalty programmes, segmentation or profiling. Where such processing is determined by the restaurant, the restaurant acts as an independent Data Controller and Webofficine may merely provide the technical tools as Data Processor.
Any consent requested by the restaurant is separate from consent given to RISTO PILOT. Consent to RISTO PILOT marketing does not constitute consent to restaurant marketing, and vice versa.
Providing the data necessary to identify the User where required, make reservations or orders, request services, transmit the request to the restaurant and manage related communications is necessary to provide the requested service. Failure to provide essential data may make it impossible to complete the operation.
Providing data for marketing or profiling, whether by RISTO PILOT or by the restaurant, is optional.
Personal data may be disclosed or made accessible, where necessary, to:
Where a provider processes data on behalf of Webofficine, it is appointed as Data Processor pursuant to Article 28 GDPR where the relevant requirements are met. Personal data are not indiscriminately disclosed to the public.
Some technology providers may involve processing in countries outside the European Economic Area. Where this occurs, transfers are carried out in accordance with Articles 44 et seq. GDPR using adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules or other mechanisms allowed by law and, where necessary, appropriate supplementary measures.
Certain data may be retained for longer where necessary to comply with legal obligations or to establish, exercise or defend legal claims. Retention periods applied by the restaurant to its own processing are determined by the restaurant.
Unless otherwise specifically stated, RISTO PILOT does not make decisions based solely on automated processing that produce legal effects concerning the User or similarly significantly affect the User within the meaning of Article 22 GDPR.
RISTO PILOT websites and subdomains may use cookies and similar technologies. Strictly necessary cookies may be used for operation, security and delivery of services. Any non-essential cookies or tools are used in accordance with applicable law and, where required, with the User's prior consent. Further information is available in the Cookie Policy made available through the Platform.
Where provided for by the GDPR, the User may exercise the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), objection (Article 21), withdrawal of consent and rights relating to automated decisions (Article 22). Where personal data are processed for direct marketing, the User may object at any time without having to provide reasons.
For processing carried out by Webofficine as independent Data Controller, the User may contact:
Webofficine S.r.l.s.
E-mail: [email protected]
Certified e-mail (PEC): [email protected]
Registered office: Viale Guglielmo Marconi 50/15, 59100 Prato (PO), Italy
For processing carried out by the restaurant as independent Data Controller, the User may contact:
La Nassa
Privacy contact: [email protected]
Where a request is sent to the wrong party and clearly concerns processing for which the other party is responsible, it may be forwarded to the appropriate party where appropriate.
The User has the right to lodge a complaint with the competent supervisory authority if they consider that the processing of their personal data infringes applicable data-protection law. In Italy, the competent authority is the Garante per la protezione dei dati personali. The User's right to seek judicial remedies remains unaffected.
RISTO PILOT may update this Notice to reflect service developments, new features, organisational changes or changes in applicable law.
In the event of material changes, appropriate measures will be taken to inform Users. The current version will be made available through the Platform.
Version: 22/09/2026
Last updated: 22/09/2026