Privacy Policy
WeCanRace S.r.l.
Ultimo aggiornamento: September 8, 2025
This privacy policy is provided pursuant to Art. 13 of EU Regulation 2016/679 (hereinafter GDPR) by We Can Race S.r.l., with registered office at via Ospedale Vecchio n.3 c/o NEST SRL STP – 33170 – Pordenone (PN), VAT number 00951680941, in its capacity as Data Controller.
1. Data Controller
The Data Controller is We Can Race S.r.l., with registered office at via Ospedale Vecchio n.3 c/o NEST SRL STP – 33170 – Pordenone (PN), VAT number 00951680941. To contact the Controller, the following contact details can be used: email: [email protected], pec: [email protected], phone: +39 0434.175.4520.
2. Purposes of Processing
Personal data provided by users are processed for the following purposes:
a) Booking Management
Data is processed to manage bookings for track driving experiences, including payments and communication with customers.
b) Contract Performance
Processing necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
c) Legal Compliance
Processing necessary for compliance with a legal obligation to which the controller is subject, including tax and accounting obligations.
d) Direct Marketing
Sending commercial and promotional communications regarding offered services, only with prior consent of the data subject.
e) Profiling
Analysis of preferences and consumption habits to improve the commercial offer, only with prior consent of the data subject.
f) Safety
Ensuring user safety during driving experiences and complying with legally required safety obligations.
3. Legal Basis for Processing
The processing of personal data is based on the following legal bases: performance of a contract (Art. 6, para. 1, lett. b GDPR), compliance with legal obligations (Art. 6, para. 1, lett. c GDPR), consent of the data subject (Art. 6, para. 1, lett. a GDPR), legitimate interest of the controller (Art. 6, para. 1, lett. f GDPR).
4. Categories of Data Processed
The following categories of personal data are processed: personal details (name, surname, date of birth), contact data (email address, phone number, address), payment data (credit card information through secure processors), driving preference data, website navigation data.
5. Processing Methods
The processing of personal data is carried out using computer and/or telematic tools, with organizational and logical methods strictly related to the stated purposes. Data is processed in compliance with the security measures provided for by the GDPR.
6. Communication of Data to Third Parties
Personal data may be communicated to third parties in the following cases: payment service providers (Stripe, PayPal, Scalapay), IT service providers, consultants and professionals, competent authorities when required by law, business partners only with prior consent of the data subject.
7. Transfer of Data to Third Countries
Some data may be transferred to third countries (e.g., United States) for the use of cloud and payment services. All transfers take place in compliance with the guarantees provided for by the GDPR.
8. Retention Period
Data is retained only for the time strictly necessary to achieve the purposes for which it was collected: contract data: 10 years from the end of the relationship, marketing data: until consent is withdrawn, navigation data: 24 months.
9. Automated Decision-Making Processes
No automated decision-making processes or profiling activities that produce significant legal effects are implemented.
10. Data Subject Rights
The data subject has the right to: access their personal data, rectify inaccurate data, erase data (right to be forgotten), restrict processing, object to processing, data portability, withdraw consent at any time.
11. How to Exercise Rights
To exercise their rights, the data subject can contact the Controller using the contact details indicated in point 1. The Controller will provide a response without undue delay and in any case within one month of the request.
12. Right to Complain
The data subject has the right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it) if they believe that the processing of their personal data violates the GDPR.
13. Changes to this Privacy Policy
This privacy policy may be modified periodically. Changes will be published on this page with indication of the last update date.
14. Contact
For any questions regarding the processing of personal data, the Controller can be contacted at the contact details indicated in point 1.