Privacy Policy

(version dated 23 July 2025)

This privacy policy aims to provide all the information regarding the processing of personal data carried out by We Chef when the user browses the website (as better specified below).

  1. INTRODUCTIONWHO ARE WE?

We Chef S.r.l.s, with registered offices in Roma, via Appia Nuova 226 – 00183, Tax Code/VAT No.
17941881009 (hereinafter the “Controller”), owner of the website www.wechefagency.com
(hereinafter the “Website”), as the controller of personal data of the users who browse on the
Website (hereinafter the “Users”) provides the following privacy policy according to Article 13 of EU Regulation 2016/679 dated 27 April 2016 (hereinafter, “Regulation” or “Applicable Law”).

  1. HOW TO CONTACT US?

The Controller takes the utmost account of its Users’ right to privacy and protection of personal data. Users may contact the Controller at any time, using the following methods:
– Sending a registered letter with return receipt to the following address: Roma, Via Appia
Nuova 226 – 00183;
– Sending an e-mail to the address info@wechefagency.com.
The Controller did not appoint a Data Protection Officer (DPO), because the Controller is not subject to the mandatory obligation to appoint it pursuant to art. 37 of the Regulation.

  1. WHAT DO WE DO? PROCESSING PURPOSES

By navigating the Website, the User can be kept up to date on the services offered by the Controller, book experiences (single-day experiences, multi-day experiences, Cooking Classes, etc.) (hereinafter, “Experiences”) and send job applications.
In connection with the activities that may be carried out through the Website, the Controller collects personal data relating to the Users.
This Website and any services offered through the Website are reserved for individuals who are 18 years and over. Therefore, the Controller does not collect personal data relating to individuals under 18 years of age. Upon request of the Users, the Controller will promptly delete all personal data that has been involuntarily collected and related to subjects under the age of 18.

The personal data of the Users will be processed lawfully by the Controller for the following processing purposes:

  1. surfing the Website to allow surfing of the Website by the User. The User’s data collected by
    the Controller to this end include all personal data whose transmission is implicit in the use of
    Internet communication protocols, that the computer systems and software procedures used to
    operate the Website acquire during their normal functioning (the IP addresses or domain names
    of the computers used by the Users, the addresses in URI notation – Uniform Resource Identifier of the requested resources, the time of the request, the method used in submitting the request to the server, the file size obtained in response, the numerical code indicating the status of the
    response given by the server – good order, error, etc. – and other parameters relating to the
    operating system and the User’s IT environment).
  1. booking and management of the Experiences to allow the User to book the Experiences
    made available to them, as well as to enable the Controller to manage such Experiences. The
    User data collected by the Controller for this purpose includes first name, last name, contact
    details (email address and phone number), address (only if the User chooses to participate in a
    Cooking Class), any intolerances and/or allergies of those who will take part in the Experience,
    any other information necessary for the Controller to organize and manage the Experiences, as
    well as any other data voluntarily communicated by the User in their request and/or in
    subsequent communications. With specific regard to the indication of any intolerances
    and/or allergies, the Controller clarifies that it will not, in any way, be able to identify
    the individuals concerned.
  1. application for a position through the “Work with Us – Chef Area” section to allow the
    User to submit their application and to enable the Controller to assess the professional profile
    and, where appropriate, initiate the selection process aimed at establishing a collaboration. The
    data collected by the Controller for this purpose includes the User’s name, email address, the
    additional information provided in the curriculum vitae (such as, for example, place and date of
    birth, residence, citizenship, phone numbers, educational background, professional experience,
    personal interests, and image), as well as any other data voluntarily provided by the User.
  2. processing the User’s request, to process their request, including through the conversation
    started by clicking “Chat with us”. The User’s data collected by the Controller for this purpose
    include the email address, first name, last name, and all other User data that may be voluntarily
    communicated by the User through the e-mail, WhatsApp or the open fields on the Website.
  3. legal obligations, or to fulfil obligations provided by the law, an authority, a regulation or
    legislation and for the investigation of liability in case of alleged cybercrimes against the
    Website.

Without prejudice to the provisions set forth elsewhere in this privacy policy, under no circumstances will the Controller make Users’ personal data accessible to other Users and/or third parties.
The provision of personal data for the processing purposes indicated above is optional but necessary, since failure to provide such data will make it impossible for the User to access the Website and to use the services.
The data whose provision is mandatory for the purposes mentioned above are marked with an asterisk in the relevant collection forms.

  1. LEGAL BASIS WHY WE CAN PROCESS THE DATA?

Surfing the Website (as described in paragraph 3, letter a) above): the legal basis is Article 6, paragraph 1, letter b) of the Regulation, since the processing is necessary for the performance of a contract to which the User is party or in order to take steps at the request of the User prior to entering into a contract.

Booking and management of the Experiences (as described in paragraph 3, letter b) above): the
legal basis is Article 6, paragraph 1, letter b) of the Regulation, since the processing is necessary for the performance of a contract to which the User is party or in order to take steps at the request of the User prior to entering into a contract.

Application for a position through the “Work with Us – Chef Area” section (as described in
paragraph 3, letter c) above): the legal basis is Article 6, paragraph 1, letter b) of the Regulation, since the processing is necessary for the performance of a contract to which the User is party or in order to take steps at the request of the User prior to entering into a contract.

Processing the User’s request (as described in paragraph 3, letter d) above): the legal basis is Article 6, paragraph 1, letter b) of the Regulation, since the processing is necessary for the performance of a contract to which the User is party or in order to take steps at the request of the User prior to entering into a contract.

Legal obligations (as described in paragraph 3, letter e) above): the legal basis is Article 6, paragraph 1, letter c) of the Regulation, since the processing is necessary for compliance with a legal obligation to which the controller is subject.

  1. PROCESSING METHODS AND DATA RETENTION PERIODHOW WE WILL PROCESS THE DATA AND FOR HOW LONG WE WILL KEEP IT?

The Controller will process the personal data of Users using manual and IT tools, with logic strictly related to the purposes themselves and, in any case, in order to guarantee the security and
confidentiality of the data.

The personal data of the Users will be retained for the time strictly necessary to carry out the main purposes explained in paragraph 3 above or, in any case, as necessary for the protection in civil law of the interests of both the Users and the Controller or in any case as necessary for the protection of the interests of the Controller and the User in civil proceedings, and for compliance with applicable legal obligations.

  1. TRANSMISSION AND DISSEMINATION OF DATAWHO WILL HAVE ACCESS TO THE DATA AND FROM WHERE?

The User’s personal data may be transferred outside the European Union and, in this case, the
Controller will ensure that the transfer is carried out in accordance with the Applicable Law and, in
particular, in accordance with Articles 45 (Transfer on the basis of an adequacy decision) and 46
(Transfer subject to appropriate safeguards) of the Regulation.

The employees and/or collaborators of the Controller who are in charge of carrying out Website
maintenance may become aware of the personal data of the Users. These subjects, who have been instructed by the Controller according to article 29 of the Regulation, will process the User’s data exclusively for the purposes indicated in this policy and in compliance with the provisions of the Applicable Law.

The personal data of the Users may also be disclosed to third parties who may process personal data on behalf of the Controller as “Data Processors” according to article 28 of the Regulation, such as, for example, IT and logistic service providers functional to the operation of the Website, outsourcing or cloud computing service providers, professionals and consultants.

Users have the right to obtain a list of any data processors appointed by the Controller, making a
request to the Controller in the manner indicated in paragraph 7 below.

  1. RIGHTS OF THE DATA SUBJECTS HOW TO PROTECT YOUR RIGHTS?

Users may exercise their rights granted by the Applicable Law by contacting the Controller as follows:
● Sending a registered letter with return receipt to the following address: Roma, Via Appia Nuova
226 – 00183;
● Sending an e-mail to the following address info@wechefagency.com.

The Controller did not appoint a Data Protection Officer (DPO), because the Controller is not subject to the mandatory obligation to appoint it pursuant to art. 37 of the Regulation.

Pursuant to the Applicable Law, Users have:

  • the right of access to the personal data;
  • (where applicable) the right to data portability (the right to receive all personal data
    concerning them in a structured, commonly used and machine-readable format), the right to
    restriction of processing of personal data, the right to rectification and the right to
    erasure (“right to be forgotten”);
  • the right to object:
    1. i. in whole or in part, for legitimate reasons to the processing of personal data
      concerning them, even if relevant to the purpose of collection;

    2. ii. in whole or in part, to the processing of personal data concerning them for the
      purpose of sending advertising or direct sales material or for carrying out market
      research or commercial communication;
  • if they consider that the processing of their personal data is in breach of the Regulation, the
    right to lodge a complaint with a Supervisory Authority (in the Member State in which they
    have their habitual residence, in the Member State in which they work or in the Member State
    in which the alleged breach has occurred). The Italian Supervisory Authority is the Garante per
    la protezione dei dati personali, located in Piazza Venezia n. 11, 00187 – Rome (http://www.garanteprivacy.it/).

_____________
The Controller is not responsible for updating all links viewed in this Privacy Policy, therefore,
whenever a link does not work and/or is not updated, the Users acknowledge and accept that they
must always refer to the document and/or section of the websites referred to by this link.