Privacy Policy
Last updated: 5 June 2026
This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and of the Italian Privacy Code (Legislative Decree 196/2003) as amended by Legislative Decree 101/2018.
1. Data Controller
The Data Controller of the personal data collected through this website is MAGICLA S.R.L.S., with registered office at Via Nuova Poggioreale 60/L, Centro Polifunzionale Torre 8, 80143 Napoli (NA), Italy and operating office at Via Vincenzo D’Annibale 1, 80129 Napoli (NA), Italy, Tax Code / VAT No. 09637271215, registered with the Companies Register of Naples under REA No. NA 1046662. For any request concerning the processing of personal data, the Data Controller may be contacted at info@vincarne.it (certified email — PEC: magiclasrls@pec.it).
2. Data Protection Officer (DPO)
Having regard to the size of the company, the nature of the processing and the absence of the conditions set out in Article 37 GDPR, the Data Controller has not appointed a Data Protection Officer (DPO). For any privacy-related matter, the Data Controller may be contacted directly at info@vincarne.it.
3. Categories of data processed
- Browsing data: IP address (hashed with SHA-256), user-agent, pages visited, timestamp. Collected in aggregate form only where analytics-cookie consent has been given.
- Data provided voluntarily through the early access form: first name, last name, email address, telephone number and marketing preferences.
- Cookie consent records: pseudonymous session_id, SHA-256 hash of the IP address, preferences expressed, action taken and timestamp (see Cookie Policy).
- VinCarne Club loyalty programme data: name, email, points history, tier, coupons generated and redeemed, referral code, count of completed invitations.
- Device fingerprint hash: for the purposes of abuse prevention and anti-farming within the loyalty programme.
- Health-related data: information on food allergies and intolerances provided voluntarily by the data subject when making a reservation, pursuant to Article 9(1) GDPR. Processed exclusively to ensure the customer’s food safety during service. Access restricted to kitchen and dining-room staff; not used for marketing or profiling purposes.
4. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Managing early access registration and contact with the data subject | Explicit consent (Article 6(1)(a) GDPR) | Until withdrawal of consent by the data subject |
| Sending informational and marketing communications relating to the VinCarne by Dixie project | Explicit consent (Article 6(1)(a) GDPR) | Until withdrawal of consent |
| Aggregate browsing statistics | Consent (Article 6(1)(a) GDPR) | 24 months |
| Website security and abuse prevention | Legitimate interest of the Data Controller (Article 6(1)(f) GDPR) | 12 months (technical logs) |
| Retention of proof of cookie consent | Legal obligation (Article 6(1)(c) GDPR) in conjunction with Article 5(2) GDPR (accountability) | 24 months |
| Managing the VinCarne Club loyalty programme (points accrual, tiers, coupons, leaderboard) | Performance of a contract — acceptance of the programme Terms (Article 6(1)(b) GDPR) | Duration of enrolment in the programme + 24 months |
| Referral system (code generation, count of completed invitations). Note: the data of the invited party (referee) is processed exclusively after their voluntary registration on the website; no email or communication is sent automatically to the referee by the system. When a user registers via a referral link, the system records the association with the Member who shared the link: such data is collected at the time of the data subject’s voluntary registration (Article 13 GDPR) and not through communication from third parties, and therefore does not constitute processing within the meaning of Article 14 GDPR. | Performance of a contract (Article 6(1)(b) GDPR) | Duration of enrolment in the programme + 24 months |
| Managing food allergies and intolerances for the purposes of customer safety | Explicit consent under Article 9(2)(a) GDPR + performance of a contract under Article 6(1)(b) GDPR | Up to 24 months from the date of the reservation, then anonymisation |
| Communications regarding services similar to those covered by the reservation (events, tastings, menu news, restaurant anniversaries, cellar news) sent to the customer who has made a reservation | Soft opt-in — Article 130(4) of the Italian Privacy Code (Legislative Decree 196/2003) | Until objection by the data subject |
5. Data Processor (Article 28 GDPR)
InTasca Srls, as the provider of the technical and digital services of the website, is appointed as Data Processor pursuant to Article 28 of Regulation (EU) 2016/679, processing the data on behalf of the Data Controller exclusively for the purposes connected with the management and maintenance of the website.
- Registered office: Via Nuova Poggioreale, Torre 7 snc — 80143 Napoli (NA)
- PEC: intascasrls@pec.it
- Tax Code / VAT No.: 11039821217
- REA: NA — 1150116
The relationship is formalised by a dedicated Data Processing Agreement pursuant to Article 28 GDPR.
6. Further data recipients
Personal data may be disclosed to the following further parties, likewise appointed as Data Processors under Article 28 GDPR:
- Hetzner Online GmbH — VPS hosting provider (Germany, EU)
- Cloudflare Inc. — CDN, WAF and DNS services (United States, under Standard Contractual Clauses)
- Resend Inc.— provider of the delivery service for transactional emails (registration confirmations, reservation confirmations, magic login links) and for marketing emails sent subject to the data subject’s consent (United States, under Standard Contractual Clauses approved by the European Commission)
- Google Ireland Ltd(Mountain View, USA for Google LLC) — LLM provider for the Maitre Digitale via the Gemini API (see section 9.5 for details of the processing). The transfer to the United States takes place on the basis of the Standard Contractual Clauses (SCC) and, where applicable, of the adequacy framework
- Groq Inc.(Mountain View, USA) — fallback LLM provider for the Maitre Digitale (see section 9.5 for details of the processing). The transfer to the United States takes place on the basis of the Standard Contractual Clauses (SCC).
- Advisors, accountants and professionals engaged by the Data Controller, strictly within the limits necessary to fulfil legal obligations
Personal data may also be disclosed to the following parties, which act as independent controllersof the processing, exclusively subject to the data subject’s consent for marketing purposes:
- Meta Platforms Ireland Ltd(Facebook/Instagram Pixel, Instagram content embedded via embed) — data transmitted only subject to marketing consent; embedded content is loaded only upon user interaction
- Meta Platforms Ireland Ltd (Meta Conversions API — CAPI)— server-side transmission of hashed identifying data (SHA-256 email, telephone, first name, last name, city, country), IP address, user-agent, _fbp/_fbc cookies, for campaign measurement and ad optimisation purposes. Meta acts as a joint controller of the processing (Article 26 GDPR). Transfer to the USA under Standard Contractual Clauses
- Google Ireland Ltd(Google Ads) — data transmitted only subject to marketing consent
- TikTok Technology Ltd(TikTok Pixel) — data transmitted only subject to marketing consent
7. Transfers outside the EU
Some of the providers indicated above — in particular Cloudflare Inc. and Resend Inc. — are based in the United States of America. The transactional and marketing emails sent to members are delivered via the API of Resend Inc., which acts as Data Processor under Article 28 GDPR. The transfer of data to such countries takes place on the basis of the Standard Contractual Clauses approved by the European Commission by Decision (EU) 2021/914 and, where applicable, on the basis of the providers’ adherence to the EU-US Data Privacy Framework. The data subject may request a copy of the safeguards adopted from the Data Controller by writing to info@vincarne.it.
TikTok Technology Ltd(TikTok Pixel) may transfer data to the United States and, potentially, to the People’s Republic of China through the parent company ByteDance Ltd. Such transfers take place on the basis of the Standard Contractual Clauses (SCC) approved by the European Commission and of the supplementary measures adopted by TikTok, including encryption in transit and at rest and Transfer Impact Assessments. The processing is subject to the prior consent of the data subject for marketing purposes.
8. Rights of the data subject
Pursuant to Articles 15-22 GDPR, the data subject has at any time the right to: (i) access their personal data and obtain a copy thereof; (ii) request its rectification or integration; (iii) obtain its erasure (right to be forgotten); (iv) request restriction of processing; (v) object to processing on legitimate grounds; (vi) receive their data in a structured, commonly used format (data portability); (vii) withdraw at any time the consent previously given, without affecting the lawfulness of the processing carried out up to that point; (viii) lodge a complaint with the Italian Data Protection Authority (Garante) (www.gpdp.it) where they consider that the processing infringes the GDPR. To exercise such rights, it is sufficient to send a request to info@vincarne.it; the Data Controller will respond without undue delay and in any event within 30 days.
Right to object to direct marketing (Article 21(2) GDPR). At any time, and without the need to provide reasons, the data subject may object to the processing of their data for direct marketing purposes. In such case the data will no longer be processed for such purposes. The objection may be exercised through the unsubscribe link included in every communication, or by writing to info@vincarne.it.
Communications regarding similar services (Article 130(4) of Legislative Decree 196/2003). When the data subject makes a reservation at the restaurant, the email address provided on that occasion may be used by the Data Controller to send communications relating to services similar to the one booked (in particular: events, tastings, menu news, restaurant anniversaries, cellar news). Such processing is based on the derogation set out in Article 130(4) of the Italian Privacy Code and does not require further consent, without prejudice to the data subject’s right to object at any time, easily and free of charge, through the unsubscribe link included in every communication, or by writing to info@vincarne.it. The objection does not affect the Data Controller’s ability to send exclusively transactional communications (reservation confirmation, service changes, receipts, technical communications). The data subject is informed of such processing already at the time of collection of the data on the reservation page, pursuant to Article 13 GDPR.
9. Maitre Digitale — AI data processing
9.1 Description of the service and nature of the processing
The vincarne.it website provides a digital assistant named “Maitre Digitale” (or “The maitre of VinCarne”), accessible via the chat widget placed on the pages of the website and via the dedicated page /maitre. The service allows users to receive personalised suggestions on the composition of dinner, on the choice of cuts of meat, on wine pairings and on the courses available on the menu.
Pursuant to Article 50 of Regulation (EU) 2024/1689 (“AI Act”), the Data Controller expressly informs that the Maitre Digitale is an artificial intelligence-based system. The responses are generated automatically and do not come from a human operator. The user who uses the chat service interacts with a generative AI system.
9.2 Personal data processed
- Message text: the content of the messages sent by the user during the conversation.
- Conversation history: the most recent message-exchange sessions necessary to maintain the context of the session (maximum 10 messages held in memory per session).
- Session identifier: a randomly generated unique code (UUID) to correlate the messages within the same chat session. The session has a maximum duration of 24 hours, after which it is automatically deleted from the system by a scheduled job.
- Device fingerprint hash: a pseudonymised value derived from technical characteristics of the user’s device (not directly attributable to the identity of the individual), used exclusively for moderation and abuse-prevention purposes (table
device_bans, maximum retention 1 hour in the event of a temporary suspension). - Technical data of the conversation log: AI provider used (e.g. Groq), number of tokens processed, response latency. Such data is stored in the table
sommelier_conversationsfor the purpose of monitoring the quality of the service.
9.3 Purposes of the processing
The data indicated above is processed exclusively for the following purposes:
- Provision of the service assisting with the composition of dinner, the selection of wines and guidance on the menu.
- Maintaining the consistency of the context during the chat session.
- Prevention of abuse and content moderation (e.g. messages with inappropriate language or out-of-scope requests), through a system of progressive escalation.
- Technical monitoring of the quality of the AI service (latency, provider availability, number of tokens).
The conversation data is not used for marketing purposes, commercial profiling, creation of advertising audiences, nor to train or fine-tune AI models owned by the Data Controller.
9.4 Legal basis
The legal basis for the processing is Article 6(1)(b) GDPR (“performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract”): the user who starts the chat voluntarily requests the provision of the digital assistance service, and the processing of the data is necessary to provide such service.
The processing of the device fingerprint hash for security and abuse-prevention purposes is based on Article 6(1)(f) GDPR (legitimate interest of the Data Controller), consistently with the provisions of Recital 49 GDPR.
9.5 Sub-processors: Google (Gemini API) and Groq Inc.
The text of the messages sent by the user is transmitted, for the purpose of generating the AI response, to the AI inference providers appointed as sub-processors by InTasca S.r.l.s. pursuant to Article 28 GDPR. The primary provider is Google (Gemini API), with the model Gemini 2.5 Flash; in the event of unavailability the system resorts, as a fallback, to Groq Inc., based in the United States of America, which runs the open source model Llama 3.1 8B Instant (developed by Meta AI) on its own infrastructure.
The providers declare that they process the data on behalf of the customer exclusively for the provision of the API service and not to train their own models. The transfer to the United States takes place on the basis of the Standard Contractual Clauses (SCC) approved by the European Commission by Decision (EU) 2021/914 and, where applicable, of the adequacy framework. The data subject may request a copy of the safeguards adopted by writing to info@vincarne.it.
Should no AI provider be available, the system does not generate responses and displays to the user a message indicating that the service is temporarily unavailable, without transmitting the text to external providers.
9.6 Data retention
| Data | Table | Retention |
|---|---|---|
| Chat session and in-session messages | sommelier_sessions | 24 hours — automatic deletion via scheduled job |
| Technical conversation log (provider, tokens, latency) | sommelier_conversations | Retained for service quality monitoring; subject to the Data Controller’s general retention policy (max 24 months) |
| Device fingerprint hash for moderation | device_bans | Maximum 1 hour (temporary suspension), then automatic deletion |
9.7 Automated decision-making — Article 22 GDPR
The Maitre Digitale does not take automated decisions producing legal effects or similarly significantly affecting the data subject within the meaning of Article 22 GDPR. The responses generated by the AI constitute exclusively non-binding gastronomic suggestions. The system does not carry out commercial profiling, does not determine individualised prices, does not produce credit scores or legally relevant assessments.
The only automated decision present concerns the temporary moderation of access to the chat service in the event of repeated abusive behaviour (maximum suspension of 1 hour per device fingerprint). Such measure does not produce legal effects on the data subject and does not concern the principal contractual relationship with the restaurant.
9.8 AI Act risk classification
The Maitre Digitale is classified as a minimal risk AI system pursuant to Regulation (EU) 2024/1689 (AI Act). The system does not fall within the high-risk AI categories set out in Annex III of the Regulation, nor does it use biometric data, nor does it carry out social scoring, nor is it intended for law-enforcement, public-security purposes or decisions concerning employment or education.
9.9 Right not to use the AI service
Use of the Maitre Digitale is entirely optional. A user who does not wish to interact with the AI system may simply not start the chat or close the widget without any consequence for their access to the website or to the VinCarne Club loyalty programme. No penalty is provided for non-use of the service.
A user who has started a session may request the deletion of their session data by writing to info@vincarne.it. In any event, session data is automatically deleted within 24 hours.
10. Automated decision-making (Articles 13.2.f and 22 GDPR) — Loyalty Programme
The gamification system of the VinCarne Club programme assigns points and tiers (Bronze, Silver, Gold) deterministically on the basis of predefined thresholds. There are no automated decision-making processes producing legal effects or significantly affecting the data subject within the meaning of Article 22 GDPR. The assignment of benefits takes place automatically upon reaching the thresholds, without any elements of discretion or randomness. For the automated decision-making processes connected with the Maitre Digitale, please refer to section 9.7 of this notice.
11. Nature of the provision of data
The provision of data is optional. Failure to provide it prevents access to the services that require it (e.g. early access registration, loyalty programme). Use of the Maitre Digitale is always optional; please refer to section 9.9 for further details.
12. Data breach
In the event of a personal data breach, the Data Controller will notify the Italian Data Protection Authority (Garante) within 72 hours (Article 33 GDPR) and, where necessary, communicate it to the data subjects (Article 34 GDPR).
13. Security measures
TLS 1.2+ on all endpoints, SHA-256 hashing for IP and device fingerprint, encrypted daily backups, database access with strong authentication, access to the administrative area protected by two-factor authentication. The Maitre Digitale sessions are encrypted in transit and automatically deleted after 24 hours.
See also our Cookie Policy.