top of page

Privacy Policy

Information notice on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679

Website: villa-incanto-tropea.com / villa-incanto-tropea.it

Last updated: [insert date]

1. Introduction

This information notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the "GDPR") and Italian Legislative Decree no. 196/2003 (the "Privacy Code"), as amended by Legislative Decree no. 101/2018.

This document describes how the personal data of users who visit the Villa Incanto Tropea website (the "Website") and who interact with the services offered by the accommodation facility are processed.

This notice is provided for this Website only and not for any other websites that may be reached via hyperlinks.

2. Data Controller

The Data Controller is:

  • Controller: [Name and Surname / Company name]

  • Address: [full registered address]

  • Tax Code / VAT number: [insert]

  • E-mail: [insert e-mail address]

  • Telephone: [insert telephone number, if any]

The Controller may be contacted at the details above for any matter relating to the processing of personal data and for the exercise of the data subject's rights.

3. Types of data processed

The Controller may process the following categories of personal data.

3.1 Data provided voluntarily by the user

This is data communicated directly by the user by completing the forms on the Website or by sending communications to the Controller, including, by way of example:

  • identification and contact data (name, surname, e-mail address, telephone number);

  • information relating to availability and booking requests (stay dates, number of guests, any special requirements);

  • the content of messages sent through the contact form or by e-mail;

  • any other data voluntarily provided by the user in communications with the Controller.

3.2 Browsing data

The IT systems and software procedures used to operate the Website acquire, in the course of their normal operation, certain data the transmission of which is implicit in the use of Internet communication protocols (such as IP addresses, browser and device type, operating system, date and time of access, pages visited).

This data is used solely to obtain anonymous statistical information on the use of the Website and to monitor its proper functioning and security.

3.3 Data collected through cookies

The Website uses cookies and other tracking tools. For detailed information, please refer to the Website's Cookie Policy.

Note for the Website operator: adjust section 3 according to the tools actually active on the Website (e.g. newsletter subscription, members' area, online payment system, reviews). Remove any items that do not apply.

4. Purposes and legal basis of the processing

The user's personal data is processed for the following purposes.

Purpose of the processingLegal basis (Art. 6 GDPR)

Responding to requests for information and contact sent through the WebsitePerformance of pre-contractual measures taken at the data subject's request (Art. 6.1.b)

Handling availability and booking requests for the stayPerformance of a contract or of pre-contractual measures (Art. 6.1.b)

Complying with legal, accounting, tax and administrative obligations connected with the accommodation serviceCompliance with a legal obligation (Art. 6.1.c)

Ensuring the security of the Website and preventing abuse or fraudLegitimate interest of the Controller (Art. 6.1.f)

Sending promotional communications and newsletters, where applicableConsent of the data subject (Art. 6.1.a)

Installing non-technical cookies, where applicableConsent of the data subject (Art. 6.1.a)

Providing data for the purposes of responding to requests and handling bookings is optional, but any refusal makes it impossible to act on the user's request. Providing data for promotional purposes is always optional.

5. Methods of processing

Personal data is processed using electronic and IT tools and, where necessary, on paper, with logic strictly related to the stated purposes and in compliance with the principles of lawfulness, fairness, transparency, data minimisation and storage limitation.

The Controller adopts appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in order to protect data against unauthorised access, loss, destruction or disclosure.

6. Recipients of the data

The user's personal data may be disclosed, strictly within the limits necessary for the purposes indicated above, to the following parties:

  • authorised personnel of the Controller, suitably instructed;

  • service providers acting as Data Processors pursuant to Article 28 of the GDPR, including in particular the provider of the Website platform and hosting services (Wix.com Ltd.), and any e-mail, booking management and technical support service providers;

  • consultants, professionals and firms providing accounting, tax, legal or administrative assistance;

  • competent authorities, public bodies and supervisory authorities, where required by legal obligations or by orders of the authorities.

The data is not subject to dissemination and is not transferred to third parties for their own marketing purposes.

7. Transfer of data outside the EU

Some service providers used by the Controller (such as the provider of the Website platform) may process personal data outside the European Economic Area.

In such cases, the Controller ensures that the transfer takes place in accordance with Chapter V of the GDPR, on the basis of an adequacy decision of the European Commission or of appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission.

8. Data retention period

Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected and, in particular:

  • data relating to information requests not followed by a booking is retained for the time needed to handle the request and for a limited period thereafter;

  • data relating to bookings and stays is retained for the duration of the relationship and, subsequently, for the period required by civil and tax legislation (generally 10 years);

  • data processed on the basis of consent is retained until such consent is withdrawn;

  • browsing data and data collected through cookies is retained as indicated in the Cookie Policy.

At the end of the periods indicated, the data is deleted or irreversibly anonymised.

9. Rights of the data subject

As a data subject, the user may exercise at any time the rights set out in Articles 15-22 of the GDPR and, in particular:

  • right of access: to obtain confirmation as to whether processing is taking place and to receive a copy of their data;

  • right to rectification: to obtain the correction of inaccurate data or the completion of incomplete data;

  • right to erasure ("right to be forgotten");

  • right to restriction of processing;

  • right to data portability;

  • right to object to processing based on legitimate interest;

  • right to withdraw consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal.

Requests relating to the exercise of these rights may be sent to the Controller at the contact details provided in section 2. The Controller will respond within the time limits set out in the applicable legislation.

10. Right to lodge a complaint

Data subjects who believe that the processing of their personal data infringes the applicable legislation have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures indicated on its website www.garanteprivacy.it, without prejudice to any other administrative or judicial remedy.

11. Cookies

The Website uses cookies and other tracking tools. For detailed information on the types of cookies used and how to manage preferences, please refer to the Website's Cookie Policy.

12. Changes to this notice

The Controller reserves the right to amend and update this notice at any time, including as a result of changes in legislation or in its organisation. Any changes will be published on this page together with the date of the last update. Users are therefore invited to consult this document periodically.

For any questions regarding the processing of personal data, you may contact the Data Controller at the contact details provided in section 2

bottom of page