Privacy Policy
Privacy Policy
Last updated: October 2025
This notice is issued in accordance with Regulation (EU) 2016/679 ("GDPR") and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. It applies to navigation of the site robyone.it and to the use of contact/booking services (including any online deposits). For cookies, see the Cookie Policy.
1. Data Controller
Robyone di Abram Germano
Legal and operational address: Via Sospello 123/A – 10147 Turin (TO)
VAT number 07636130010 – Registration Chamber of Commerce Turin no. TO-907966
Tel./Fax: 011 7770362
For contacts and requests, use the form available on the page: www.robyone.it/contatti
The Data Controller independently determines the purposes and methods of processing, as well as the technical and organizational measures to ensure confidentiality, integrity and availability of data.
2. Types of Data Processed
- Identification and contact data (name, surname, telephone);
- Data relating to requests/bookings (request text, date/time, service requested);
- Payment data limited to any deposits (e.g. transaction result via third-party provider).
No special data as referred to in art. 9 GDPR (e.g. health, political opinions, biometric data) are collected.
3. Purposes and Legal Bases
- Management of requests and bookings (contact, quote, appointment).
Legal basis: performance of pre-contractual or contractual measures (art. 6, par. 1, lett. b GDPR). - Management of deposits or payments connected to booked services and related obligations.
Legal basis: contract and legal obligation (art. 6, par. 1, lett. b and c GDPR). - Sending informative/promotional communications about Robyone services (newsletter, offers), only with prior consent box checked.
Legal basis: consent (art. 6, par. 1, lett. a GDPR). - Protection of rights, prevention of fraud/abuse and service improvement.
Legal basis: legitimate interest of the Data Controller (art. 6, par. 1, lett. f GDPR). - Legal, tax and accounting compliance related to services rendered.
Legal basis: legal obligation (art. 6, par. 1, lett. c GDPR).
4. Processing Methods and Security
Data is processed using electronic and/or paper tools in compliance with the principles of lawfulness, fairness, transparency, minimization, accuracy and storage limitation. Appropriate technical and organizational measures are adopted to prevent unauthorized access, loss, disclosure or destruction of data.
5. Nature of Data Provision
Providing data marked as mandatory in the forms is necessary to process requests or bookings; failure to provide such data prevents the delivery of the requested service. Provision for marketing purposes is optional and subject to consent.
6. Recipients and Categories of Subjects
Data may be communicated exclusively to subjects providing services functional to the stated purposes, including:
- IT service providers/hosting and site maintenance;
- electronic payment providers and credit institutions;
- couriers and transport services (where necessary);
- tax/legal consultants.
These subjects act as Data Processors pursuant to art. 28 GDPR or, where applicable, as autonomous controllers. Data is not published or transferred to third parties for unauthorized commercial purposes.
7. Transfers Outside the EU
As a rule, data is processed in EEA Countries. Should a transfer to third countries become necessary for technical reasons (e.g. cloud providers or analytics tools), it will take place in compliance with arts. 44–49 GDPR, adopting appropriate safeguards (e.g. Adequacy Decisions or Standard Contractual Clauses).
8. Data Retention
- Requests/bookings: for the time necessary for management and up to 24 months for organizational and defensive purposes;
- Accounting/tax data: up to 10 years as required by law;
- Marketing: until revocation of consent or, failing that, for a reasonable maximum period (24 months).
9. Data Subject Rights
The user may exercise the rights provided for in arts. 15–22 GDPR (access, rectification, erasure, restriction, opposition, portability), and may revoke consent at any time without prejudicing the lawfulness of processing based on consent prior to revocation. The right to lodge a complaint with the Guarantor for the Protection of Personal Data is always reserved.
To exercise your rights, you can use the contact form available at: www.robyone.it/contatti
or send written communication to:
Via Sospello 123/A – 10147 Turin (TO) – Tel./Fax: 011 7770362
10. Cookies and Tracking Tools
The site uses technical cookies and, with prior consent, third-party cookies for analysis and additional features. For details on cookie types, legal bases and how to manage/revoke consent, see the Cookie Policy, drafted pursuant to the Guarantor's Measure of June 10, 2021.
11. Changes to This Notice
The Data Controller reserves the right to update this notice to adapt it to regulatory or technical changes. Variations will be published on this page and will become effective upon publication.