PRIVACY POLICY / INFORMATIVA SULLA PRIVACY

Last updated: September 2026

1. DATA CONTROLLER (TITOLARE DEL TRATTAMENTO)

The entity responsible for the processing of personal data collected through this website is:

Osteria San Giorgio

Piazza Grande 17, 6826 Riva San Vitale

Ticino, Switzerland

Email: hello@sangiorgiosteria.com

Phone: +41 (0)91 788 97 78

2. CATEGORIES OF PERSONAL DATA COLLECTED AND PURPOSES

We process personal data in compliance with the Swiss Federal Act on Data Protection (FADP). Data is processed for the following purposes:

A. Online Reservations

* Data collected: Name, email address, phone number, date and time of reservation, number of guests, and dietary preferences or special notes.

* Purpose: To manage, confirm, and execute table reservations.

* Third-Party Processor: We use a digital reservation platform. Your data is transferred to this provider solely to manage the reservation.

B. Online Ordering (Delivery & Takeaway)

* Data collected: Name, delivery address, billing address, email address, and phone number.

* Purpose: To process, prepare, and deliver your food orders, or manage your takeaway pickup.

C. Online Payments

* Data collected: Payment method details, transaction amounts, and basic validation tokens.

* Purpose: To process payments securely for delivery orders or booking deposits.

* Third-Party Processors: We do not store credit card or banking details on our servers. All transactions are handled securely by PCI-DSS compliant payment gateways (e.g., Stripe, PayPal, TWINT, or Worldline).

D. Newsletter & Marketing Communications

* Data collected: Name and email address.

* Purpose: To send updates, promotions, and seasonal menu news (only with your explicit consent).

* Unsubscribe: You can withdraw consent at any time via the "unsubscribe" link in the emails.

E. Website Analytics & Cookies

* Data collected: IP addresses, browser type, device information, operating system, and user behavior on the site (pages visited, duration).

* Purpose: To optimize website performance, user experience, and analyze traffic.

* Third-Party Tool: We use Google Analytics. Google may store this data on servers located outside of Switzerland (including the United States). The data is anonymized wherever possible (e.g., IP masking).

This privacy notice applies only to data processed by our website; please note that for specific operations (e.g.online bookings) we use third-party sites or applications, either integrated into our platform or via external links to other sites: in all these cases, the data controller is the owner of the respective site/application, who acts as an independent controller, and you should refer to them for the relevant privacy information.

3. INTERNATIONAL DATA TRANSFERS

Some of our service providers (such as Google or specific payment networks) may store or process data outside of Switzerland or the European Economic Area (EEA). If data is transferred to a country without adequate data protection laws, we ensure appropriate safeguards (such as EU Standard Contractual Clauses recognized by the Swiss Federal Data Protection and Information Commissioner - FDPIC) are in place.

4. DATA RETENTION

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, or to comply with statutory legal retention periods (e.g., 10-year retention rule for financial and accounting records under Swiss law).

5. YOUR RIGHTS

Under the FADP, you have the following rights regarding your personal data:

* Right of Access: You can request details of the personal data we hold about you.

* Right to Rectification: You can request corrections to inaccurate personal data.

* Right to Deletion: You can request the erasure of your personal data, subject to legal retention obligations.

* Right to Restrict or Object: You can object to specific data processing operations (such as marketing).

To exercise these rights, please contact us at the email address listed in Section 1.

6. SECURITY

We implement appropriate technical and organizational security measures (such as SSL/TLS encryption for online forms and payment processing) to protect your personal data against unauthorized access, loss, or alteration.