Romano Braconi NCC
Back to Home

Privacy Policy

Pursuant to EU Regulation 2016/679 (GDPR)

Last updated: 10 June 2026

This English text is a courtesy translation. In the event of any discrepancy, the Italian version prevails.

1. Privacy Policy

Pursuant to Regulation (EU) 2016/679 (the “Regulation”), this page describes how the personal data of Users who consult the website accessible online at the following address is processed: romanoncc.it This notice does not concern other sites, pages or online services reachable through hyperlinks that may be published on the site.

1.1. DATA CONTROLLER

As a result of consulting the sites listed above, data relating to identified or identifiable natural persons may be processed. The data controller is Romano Braconi, Via Alessandro Pieri 13, 00146 - Roma (RM), Tax code: BRCRMN61T08H501J — VAT no.: IT14664581007. Email: romanoncc@gmail.com — Phone: +39 331 866 5445

1.2 CATEGORIES OF PERSONAL DATA PROCESSED

Navigation data: The computer systems and software procedures used to operate this site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes the IP addresses or domain names of the computers and terminals used by users, the URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server (success, error, etc.) and other parameters relating to the user’s operating system and computer environment. Such data, necessary for the use of web services, are also processed in order to:

  • check the correct operation of the services offered.
  • ensure the security of the site and prevent abuse and unauthorised access (e.g. rate limiting).
  • Use of the data provided when sending an information request in order to respond to the requests made and/or provide the requested service. Should the processing of the data be refused, the data controller will not be able to fulfil the request in question.

Data provided by the User when filling in the form to request/book the Service:

  • Personal and identifying data: first name and surname;
  • Contact data (telephone number, e-mail, etc.)
  • departure and destination addresses of the ride
  • ride details: date, time, number of passengers and any accessory information (flight number, ship name, notes)
  • Technical cookies (see Cookie Policy)

More specifically:

  • Data collected automatically. The computer systems and applications dedicated to the operation of this website detect, during their normal operation, certain data potentially associated with identifiable users (whose transmission is implicit in the use of Internet communication protocols). These data are processed for the time strictly necessary, for the sole purpose of monitoring their correct operation and ensuring their security. The provision of such data is mandatory as it is directly linked to the web browsing experience.
  • Data voluntarily provided by the user. The voluntary and explicit sending of e-mail messages to the addresses indicated in the various access channels of this site does not require consent. On the contrary, specific summary notices will be reported or displayed on the pages of the site set up for services on request (forms). Contact forms involve the acquisition of the sender/user’s address and data necessary to respond to the requests made and/or to provide the requested service; the user must therefore explicitly consent to the collection and processing of the data reported in these forms in order to send the request and allow us to respond.
  • Cookies. This site uses exclusively technical cookies, strictly necessary for its operation. To learn more, visit the dedicated cookie section.

Data for the fulfilment of legal obligations:

  • The so-called service sheet (“foglio di servizio”). Italian law requires NCC drivers to keep a “service sheet” regulated by Law no. 21/1992 and subsequent amendments, under which there is an obligation to record on that sheet the customer’s data, the itinerary and the times.

Special data (formerly sensitive data):

  • Should the service be requested by users with particular needs (e.g. transport of persons with disabilities requiring the communication of health-related data), the processing of such data is permitted only with the explicit consent of the data subject and limited to what is strictly necessary for the provision of the service. Users are invited not to enter health-related data or data belonging to other special categories where not indispensable.

1.3. PURPOSES OF PROCESSING AND LEGAL BASIS

Personal data, as well as any subsequent changes, communicated to Romano Braconi are collected and processed for the following and exclusive purposes:

  • performance of pre-contractual measures and of the contract (Art. 6(1)(b) GDPR). To manage quote requests, bookings and to provide the requested transport service.
  • Compliance with a legal obligation (Art. 6(1)(c) GDPR). For the completion of the service sheet, as required by Law no. 21/1992.
  • Consent of the data subject (Art. 6(1)(a) GDPR). For the processing of the data provided through the form for the purpose of managing the booking. Consent must be specific, freely given and informed. It cannot be presumed or obtained through pre-ticked boxes.
  • Legitimate interest of the controller (Art. 6(1)(f) GDPR). For example, for security purposes, fraud prevention or to defend a right in court.

1.4 - METHODS OF PROCESSING

Personal data will be processed by the Controller and by any duly appointed processors in order to correctly fulfil the processing purposes indicated in the previous points. The data will be collected by means of electronic tools, paper archives or other suitable media, and subjected to security measures designed to ensure the confidentiality of personal data and to prevent improper access by unauthorised parties (Art. 5(1)(f) GDPR).

Access to processing. The data will be made accessible, for the purposes described above, to:

  • Authorised staff of the Controller such as employees/collaborators in their capacity as persons authorised to process data, following a suitable appointment;
  • Third parties carrying out outsourced activities on behalf of the controller (by way of example: banking institutions for the financial handling of customers and suppliers);
  • Public authorities and law enforcement, for the fulfilment of legal obligations (e.g. checks on the service sheet);
  • Companies or Entities providing specific instrumental or support services.

The transmitted data will not in any way be subject to communication to third parties or dissemination (e.g. social networks, websites, etc.).

In any case, the data will not be communicated to unauthorised third parties or disseminated in any way.

To this end, processing is carried out using security measures suitable to prevent unauthorised access to the data by third parties and to ensure its confidentiality. Without the need for express consent, the Controller may communicate the data for the purposes indicated above to the following parties:

  • Supervisory bodies, judicial authorities, control bodies;
  • Other parties whose right to access your personal data is recognised by provisions of law or of secondary or EU regulations.

Said parties will process the data in their capacity as autonomous data controllers.

Data processors (sub-processors, Art. 28 GDPR). For the operation of the site and the service, the Controller makes use of the following providers, which process data on its behalf on the basis of agreements compliant with Art. 28 GDPR:

  • Supabase Inc. — database and management of bookings/messages;
  • Vercel Inc. — hosting and distribution of the site; aggregated and anonymous traffic analytics (Vercel Web Analytics), without cookies or persistent identifiers;
  • Resend Inc. — sending of notification and confirmation emails;
  • Upstash, Inc. — request limiting (rate limiting) and abuse prevention: temporarily stores the IP address (or an equivalent technical identifier) for the sole purpose of counting requests coming from the same device;
  • Google LLC — automatic address completion (Places API): the addresses typed into the form are transmitted to Google for the sole purpose of providing suggestions. Google privacy policy: https://policies.google.com/privacy

Non-EU data transfers. The above providers may process data in the United States of America. Transfers take place on the basis of the Standard Contractual Clauses (SCC) approved by the European Commission and/or the EU-US Data Privacy Framework, in compliance with the GDPR.

Security measures. The Controller adopts in particular: encryption of data in transit (mandatory HTTPS); restricted and protected database access; management of credentials through encrypted environment variables; request limitation (rate limiting) to prevent abuse; absence of personal data in application logs.

1.5 DATA RETENTION PERIOD

The collected data will be kept for a period not exceeding that required to achieve the purposes for which they were collected (“storage limitation principle”, Art. 5 GDPR), or according to the deadlines set by law. The obsolescence of the stored data in relation to the purposes for which they were collected is checked periodically. In any case, the Controller will process personal data for the time necessary to fulfil the purposes set out above and in any event for no longer than 10 years from the termination of the contract, as well as for the retention of the service sheet. After this period, the data will be destroyed or rendered anonymous.

1.6 RIGHTS OF THE DATA SUBJECT

The data subject always has the right to request from the Controller access to, rectification or erasure of their data, the restriction of processing, the objection to processing, as well as to request the portability of their data, or to withdraw consent to processing, asserting these and the other rights provided by the GDPR through simple communication to the Controller. The request may be made by e-mail or registered letter with the subject: “Request by the data subject”, specifying in the request the right that the data subject wishes to exercise (erasure, rectification, portability, right to be forgotten), together with a valid e-mail/certified-email address to which the response should be sent. The data controller, or a person appointed by them, will fulfil the request within 30 days of the date of receipt. Should the response be complex, the time may be extended by a further 30 days, with prior timely communication to the data subject. Should they consider it appropriate to assert their rights, the data subject has the right to lodge a complaint also with the competent supervisory authority.

According to the provisions of the GDPR, the data subject has the following rights vis-à-vis the Data Controller:

  • to obtain confirmation as to whether or not personal data concerning them is being processed and, in such case, to obtain access to the personal data (Right of access, Art. 15);
  • to obtain the rectification of inaccurate personal data concerning them without undue delay (Right to rectification, Art. 16);
  • to obtain the erasure of personal data concerning them without undue delay, and the data controller has the obligation to erase personal data without undue delay where certain conditions apply (Right to be forgotten, Art. 17);
  • to obtain the restriction of processing in certain cases (Right to restriction of processing, Art. 18);
  • to receive in a structured, commonly used and machine-readable format the personal data concerning them which they have provided, and to have the right to transmit such data to another controller without hindrance from the controller to which they were provided, in certain cases (Right to data portability, Art. 20);
  • to object at any time, for reasons connected with their particular situation, to the processing of personal data concerning them (Right to object, Art. 21);
  • to receive without undue delay communication of a personal data breach suffered by the Data Controller (Art. 34);
  • to withdraw the consent given at any time (Conditions for consent, Art. 7).

Where applicable, the data subject also has the rights set out in Arts. 16-21 GDPR (Right to rectification, right to be forgotten, right to restriction of processing, right to data portability, right to object), as well as the right to lodge a complaint with the Supervisory Authority.

The Controller reserves the right to update this Privacy Policy in the future, giving notice of substantial changes to this Privacy Policy by sending a communication to the e-mail address provided or by publishing a notice on the website.

2. Cookie Policy

2.1 WHAT COOKIES ARE

Cookies are short fragments of text (letters and/or numbers) that allow the web server to store on the client (the browser, e.g. Internet Explorer, Chrome, Firefox, Opera…) information to be reused during the same visit to the site (session cookies) or later, even days later (persistent cookies). Cookies are stored, according to the user’s preferences, by the individual browser on the specific device used (computer, tablet, smartphone). Some of the functions of cookies may be delegated to other technologies. The term ‘cookies’ is intended to refer to cookies and all similar technologies. A cookie cannot retrieve any other data from the user’s hard disk, nor transmit computer viruses or acquire e-mail addresses. Each cookie is unique to the user’s web browser. With these tools, however, information relating to the user may be collected, some of which may fall within the definition of “personal data” and, therefore, in application of the Privacy Code, their collection and use must be regulated, allowing the user to consent to or refuse their processing. Cookies can be distinguished into first-party cookies and third-party cookies.

First-party cookies

Cookies are defined as first-party when they are installed directly by the operator (publisher) of the site being visited, and whose address appears in the URL window. The use of such cookies allows the site to function efficiently and to track the behavioural patterns of visitors.

Third-party cookies

Third-party cookies are instead those installed on the terminal by a party other than the operator (publisher) of the site that the user is visiting. If a user visits a site and a different company sends information by exploiting that site, third-party cookies are present.

2.2 TYPES OF COOKIE

There are different types of cookies. Some are necessary to be able to browse the Site, others have different purposes such as ensuring internal security, administering the system, carrying out statistical analyses, understanding which sections of the Site are of most interest to users or offering a personalised visit to the Site. Disabling cookies could limit the ability to use the Site and prevent full benefit from the features and services on the Site.

  • Essential technical cookies. This type of cookie is the one that allows the correct operation of certain sections of the Site. They include, for example, cookies that allow access to protected areas of the Site, and without these cookies certain necessary services, such as filling in a form, could not be used. Technical cookies are used solely for the purpose of carrying out the transmission of a communication over an electronic communications network, or to the extent strictly necessary for the provider of an information society service explicitly requested by the subscriber or user to provide that service. They do not collect information for marketing purposes, are installed directly by the owner or operator of the site and are not used for any further purpose. They can be divided into: Persistent cookies: so called because once the browser is closed they are not destroyed but remain until a pre-set expiry date; Session cookies: so called because they are destroyed each time the browser is closed.

This site uses exclusively technical cookies. No profiling cookies, analytics cookies, statistics tools (e.g. Google Analytics), social plugins or third-party cookies are used. Maps and address suggestions are processed server-side and do not involve the installation of cookies on the user’s device. The technical cookies actually used are:

  • NEXT_LOCALE (technical, persistent) — stores the chosen language (IT/EN);
  • Session cookie (technical, session) — authentication of the administrative area, reserved for the Controller.

As these are only technical cookies, pursuant to the Guidelines of the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) of 10 June 2021, no consent banner is required.

2.3. HOW TO CHANGE COOKIE SETTINGS

Most browsers automatically accept cookies, but they can be enabled and disabled through your browser. The user can in fact change the settings to disable this function and block all types of cookies, or accept only some of them. The “Options” or “Preferences” section in the browser menu allows you to avoid receiving cookies and other user-tracking technologies, or to be notified by the browser of the activation of these technologies. Alternatively, you can also consult the “Help” section of the toolbar found in most browsers. You can also select the browser used from the list below and follow the instructions:

  • Chrome: https://support.google.com/chrome/answer/95647
  • Safari: https://support.apple.com/it-it/HT201265
  • Firefox: https://support.mozilla.org/it/kb/Attivare%20e%20disattivare%20i%20cookie
  • Opera: http://www.opera.com/help/tutorials/security/

From a mobile device:

  • Android: https://support.google.com/chrome/answer/95647?hl=it
  • Safari: https://support.apple.com/it-it/HT201265
WhatsApp