Privacy Policy

WeCanRace S.r.l.

Ultimo aggiornamento: September 8, 2025

This privacy policy is provided pursuant to Art. 13 of EU Regulation 2016/679 (hereinafter GDPR) by We Can Race S.r.l., with registered office at via Ospedale Vecchio n.3 c/o NEST SRL STP – 33170 – Pordenone (PN), VAT number 00951680941, in its capacity as Data Controller.

1. Data Controller

The Data Controller is We Can Race S.r.l., with registered office at via Ospedale Vecchio n.3 c/o NEST SRL STP – 33170 – Pordenone (PN), VAT number 00951680941. To contact the Controller, the following contact details can be used: email: [email protected], pec: [email protected], phone: +39 0434.175.4520.

2. Purposes of Processing

Personal data provided by users are processed for the following purposes:

a) Booking Management

Data is processed to manage bookings for track driving experiences, including payments and communication with customers.

b) Contract Performance

Processing necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

c) Legal Compliance

Processing necessary for compliance with a legal obligation to which the controller is subject, including tax and accounting obligations.

d) Direct Marketing

Sending commercial and promotional communications regarding offered services, only with prior consent of the data subject.

e) Profiling

Analysis of preferences and consumption habits to improve the commercial offer, only with prior consent of the data subject.

f) Safety

Ensuring user safety during driving experiences and complying with legally required safety obligations.

3. Legal Basis for Processing

The processing of personal data is based on the following legal bases: performance of a contract (Art. 6, para. 1, lett. b GDPR), compliance with legal obligations (Art. 6, para. 1, lett. c GDPR), consent of the data subject (Art. 6, para. 1, lett. a GDPR), legitimate interest of the controller (Art. 6, para. 1, lett. f GDPR).

4. Categories of Data Processed

The following categories of personal data are processed: personal details (name, surname, date of birth), contact data (email address, phone number, address), payment data (credit card information through secure processors), driving preference data, website navigation data.

5. Processing Methods

The processing of personal data is carried out using computer and/or telematic tools, with organizational and logical methods strictly related to the stated purposes. Data is processed in compliance with the security measures provided for by the GDPR.

6. Communication of Data to Third Parties

Personal data may be communicated to third parties in the following cases: payment service providers (Stripe, PayPal, Scalapay), IT service providers, consultants and professionals, competent authorities when required by law, business partners only with prior consent of the data subject.

7. Transfer of Data to Third Countries

Some data may be transferred to third countries (e.g., United States) for the use of cloud and payment services. All transfers take place in compliance with the guarantees provided for by the GDPR.

8. Retention Period

Data is retained only for the time strictly necessary to achieve the purposes for which it was collected: contract data: 10 years from the end of the relationship, marketing data: until consent is withdrawn, navigation data: 24 months.

9. Automated Decision-Making Processes

No automated decision-making processes or profiling activities that produce significant legal effects are implemented.

10. Data Subject Rights

The data subject has the right to: access their personal data, rectify inaccurate data, erase data (right to be forgotten), restrict processing, object to processing, data portability, withdraw consent at any time.

11. How to Exercise Rights

To exercise their rights, the data subject can contact the Controller using the contact details indicated in point 1. The Controller will provide a response without undue delay and in any case within one month of the request.

12. Right to Complain

The data subject has the right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it) if they believe that the processing of their personal data violates the GDPR.

13. Changes to this Privacy Policy

This privacy policy may be modified periodically. Changes will be published on this page with indication of the last update date.

14. Contact

For any questions regarding the processing of personal data, the Controller can be contacted at the contact details indicated in point 1.

Contatti

Email: [email protected]

PEC: [email protected]

Telefono: +39 0434.175.4520

ISCRIVITI ALLA NEWSLETTER

Ricevi le ultime notizie e offerte esclusive