Skip to content
Fantastic GardenBook
Language:

Privacy policy

Last updated: 8 September 2026Information provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and of Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

1. Data controller

Fortune Group srl
VAT and tax code 07092130488
Viale XX Settembre 200, 50019 Sesto Fiorentino (FI), Italy
Email: eventi@fantastic-garden.com — Tel. +39 055 398 5200

The controller is not required to appoint a Data Protection Officer under Article 37 GDPR: it is not a public authority, it does not process special categories of data (Article 9 GDPR) on a large scale, and it does not carry out regular and systematic monitoring of data subjects on a large scale.

2. What data we collect

  • Table requests at the restaurant — name, phone, email, date and time, number of people and anything else written in the form. These are the fields of the form on the Restaurant page.
  • Requests for events and weddings — whatever you choose to tell us by email or phone: the date, the number of guests, the kind of event.
  • Browsing data — IP address, browser and device type, pages visited and time, recorded automatically by the systems hosting the site.

2.1 Data that does NOT pass through this site

Two important bookings happen elsewhere, and that data does not travel through our systems:

  • Rooms — the booking is completed on Simple Booking, the hotel booking engine embedded in the Hotel page. Data entered there is processed under that provider's own privacy notice, and passed to the controller in order to manage the stay.
  • Pool — booking happens on app.fantastic-garden.com, a separate application with its own database, run by the same controller and with its own privacy notice.
  • All You Can Steak — the restaurant has a site of its own, allyoucansteak.com, with its own privacy notice.

3. Purposes and legal bases

This site does not send newsletters and carries out no marketing based on the data collected here. Should that change, it will be subject to specific, freely given and withdrawable consent.

  • Handling requests and bookings — replying, confirming, changing or cancelling. Legal basis: performance of a contract or pre-contractual measures, Article 6(1)(b) GDPR.
  • Service communications — reminders and changes concerning a booking in progress, by email, phone or WhatsApp. Legal basis: legitimate interest, Article 6(1)(f) GDPR. These messages are strictly functional to the service requested and are not promotional; you may object at any time (Article 21 GDPR).
  • Legal obligations — tax and accounting duties and, for stays, reporting guests to the public security authorities. Legal basis: legal obligation, Article 6(1)(c) GDPR.
  • Security and operation of the site — server access logs. Legal basis: legitimate interest, Article 6(1)(f) GDPR.
  • Traffic measurement — aggregate statistics on pages visited, where visitors come from and what they do (calls, opening the booking systems), through Google Analytics 4. Legal basis: consent, Article 6(1)(a) GDPR. The tool is not loaded until consent is given, and the choice can be withdrawn at any time through "Cookie preferences" in the footer.

4. Who we share data with

Data may be processed, on behalf of the controller and on its documented instructions, by the following categories of provider (processors under Article 28 GDPR):

  • Hosting and technical maintenance providers for the site and the applications connected to it.
  • Simple Booking — the room booking engine.
  • Google Ireland Limited — the map on the Contact page and traffic measurement with Google Analytics 4, both subject to consent. Notice: policies.google.com/privacy
  • Meta Platforms Ireland Limited — only if you choose to write to us on WhatsApp: in that case your phone number and the content of the message are processed by Meta. Notice: facebook.com/privacy/policy
  • Professional advisers — accountants and legal advisers, within the limits of legal obligations.

4.1 Transfers outside the European Economic Area

The controller does not transfer personal data to third countries on its own initiative. The providers listed above operate through European establishments. Should a transfer become necessary, it will take place only under an adequacy decision or with appropriate safeguards under Articles 44 to 49 GDPR.

5. How long we keep data

  • Table and quote requests — 24 months from the last contact, unless the law requires otherwise.
  • Tax and accounting records — 10 years, as required by Italian law.
  • Server access logs — no longer than 12 months.

6. Your rights

Under Articles 15 to 22 GDPR you may at any time:

  • Access (Art. 15) — find out what data we hold and obtain a copy.
  • Rectification (Art. 16) — correct inaccurate or incomplete data.
  • Erasure (Art. 17) — ask for your data to be deleted.
  • Restriction (Art. 18) — ask for processing to be suspended.
  • Portability (Art. 20) — receive your data in a machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interest.

6.1 How to exercise them

Write to eventi@fantastic-garden.com or to Fortune Group srl, Viale XX Settembre 200, 50019 Sesto Fiorentino (FI), Italy. The controller replies within one month.

If you believe that the processing of your data breaches the law, you may lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of the country where you live.

7. Cookies

The cookies and third-party services embedded in these pages are described in the Cookie policy, which is available in Italian only.

8. Changes

This notice may be updated. The version in force is always the one published on this page, with the date of the last update at the top.

Book