Last updated: August 2026
Our Commitment to GDPR
Il Barbiere di Roma is committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679. This page explains how we comply with GDPR requirements and outlines your rights as a data subject.
Data Controller
Il Barbiere di Roma acts as the data controller for personal information collected through this website. Our contact details are:
Address: Via del Corso, 127, 00186 Roma, Italia
Email: [email protected]
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so. The legal bases we rely on include:
- Consent: When you explicitly agree to the processing, such as when submitting a contact form or accepting cookies.
- Contract: When processing is necessary to fulfill an appointment booking or service request.
- Legitimate Interest: When processing is necessary for our legitimate business interests, provided these do not override your rights.
- Legal Obligation: When we are required to process data to comply with the law.
Your Rights Under GDPR
As a data subject, you have the following rights:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
Right to Rectification
If any personal data we hold is inaccurate or incomplete, you have the right to request its correction.
Right to Erasure
You may request that we delete your personal data when it is no longer necessary for the purpose it was collected, or if you withdraw your consent.
Right to Restriction
You can request that we limit the processing of your personal data in certain circumstances, such as when you contest its accuracy.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object
You may object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you.
Data Protection Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular testing and evaluation of security measures
- Staff training on data protection
- Access controls limiting who can view personal data
Data Breach Procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If the breach is likely to result in a high risk to you, we will also notify you directly.
International Data Transfers
We do not transfer personal data outside the European Economic Area. If this changes, we will ensure appropriate safeguards are in place and update this notice accordingly.
Exercising Your Rights
To exercise any of your rights, please contact us using the details provided above. We may ask you to verify your identity before processing your request. We will respond to all legitimate requests within one month.
Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or your local supervisory authority.