Skip to main content

Privacy Policy

Personal Data Processing Notice

Pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”), this notice describes how the personal data of users who visit the website of DOMUS SANTA CROCE S.S. AGRICOLA and use the services available through the website are processed.

1. Data Controller

The Data Controller is:

DOMUS SANTA CROCE S.S. AGRICOLA
S.S. Agricola Domus Santa Croce di Fioriti T. e Spigarelli A.
Località Santa Croce
06023 Gualdo Tadino (PG) – Italy
VAT No. and Tax Code: 02946450547
Certified e-mail (PEC): [email protected]

For any request concerning the processing of personal data, the Data Controller may be contacted at the address indicated above.

2. Personal Data Processed

During normal browsing of the website, technical data necessary for the operation of web services may be processed.

The website also provides a form for requesting information regarding stays and bookings.

Through this form, the following information may be collected:

  • first and last name;
  • e-mail address;
  • arrival and departure dates;
  • number of adults and children;
  • number of pets;
  • any description of pets;
  • requested apartment or apartments;
  • requested service;
  • any additional services;
  • any information voluntarily entered by the user in the message field;
  • how the user learned about the property.

Users are invited not to enter irrelevant personal information in the message field and, in particular, data belonging to the special categories referred to in Article 9 of the GDPR.

3. Purposes of Processing

Personal data provided by the user are processed for the following purposes:

a) Gestione delle richieste di soggiorno

To receive, assess and manage requests concerning apartment availability, stay dates and requested services, and to provide a response to the user.

b) Communication with the user

To contact the user in relation to the submitted request and provide the information necessary to process it.

c) Management of the contractual relationship

Where a booking or contractual relationship results from the request, the data may be used to manage the relationship and fulfil the obligations arising from it.

d) Compliance with legal obligations

To comply with obligations imposed by applicable legislation.

4. Legal Basis for Processing

Personal data are processed on the basis of the following legal grounds set out in Article 6 of the GDPR:

  • taking steps at the request of the data subject prior to entering into a contract, for the management of stay requests;
  • performance of a contract, where a contractual relationship is established;
  • compliance with a legal obligation to which the Data Controller is subject;
  • the legitimate interest of the Data Controller, where applicable, for the management and protection of its rights.

The provision of data marked as mandatory in the form is necessary to process the request. Failure to provide such data may prevent the Data Controller from providing the requested service or response.

5. Processing Methods

Personal data are processed using electronic and telematic means and, where necessary, paper-based means, in accordance with the principles of fairness, lawfulness, transparency and protection of confidentiality.

The Data Controller adopts appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

Personal data are not made publicly available.

6. Recipients of Personal Data

Personal data may be processed by the Data Controller and by persons authorised to process personal data within the scope of their respective duties.

Personal data may also be processed by technical service providers necessary for the operation of the website, hosting services and electronic communications.

Where applicable, such providers act as data processors pursuant to Article 28 of the GDPR.

Personal data may also be disclosed to public or private entities where this is necessary to comply with legal obligations or to protect the rights of the Data Controller.

Personal data are not transferred to third parties for their own independent commercial purposes.

7. Data Retention

Personal data are retained for the period necessary to fulfil the purposes for which they were collected.

In the case of a stay request, data are retained for the time necessary to manage the request and the related communications.

Where the request results in a contractual relationship, data are retained for the period necessary to manage the relationship and for any additional periods required by applicable legislation, including for administrative, accounting and tax purposes.

Once the applicable retention periods have expired, data are deleted or anonymised, unless further retention is necessary to comply with legal obligations or for the establishment, exercise or defence of a legal claim.

8. Cookies and Third-Party Content

The website uses cookies and similar technologies that are necessary for its operation and, where required by applicable legislation and subject to the user’s consent, content and services provided by third parties.

The website uses the YOOtheme Consent Manager to manage preferences relating to services that require consent.

The website incorporates video content provided by YouTube, a service operated by Google.

The website also uses mapping content provided by OpenStreetMap.

Before the user provides consent, such external content is blocked and a consent request is displayed. The content is loaded only after the user has given consent.

The use of such services may involve the processing of technical and usage data by the relevant providers in accordance with their respective privacy policies.

Preferences relating to services requiring consent may be managed through the tools provided on the website.

9. Transfers of Personal Data to Third Countries

Some technology service providers used by the website may process personal data outside the European Economic Area.

Where processing involves the transfer of personal data to a third country, the Data Controller adopts the safeguards provided for by Articles 44 et seq. of the GDPR, where applicable.

For services provided by third parties, their respective privacy policies may also apply.

10. Data Subject Rights

The data subject may exercise, where provided for by applicable legislation, the rights recognised under Articles 15 et seq. of the GDPR and, in particular, may request:

  • access to their personal data;
  • rectification of inaccurate data;
  • completion of incomplete data;
  • erasure of data where provided for by law;
  • restriction of processing where provided for by law;
  • data portability where applicable;
  • objection to processing where applicable.

The data subject also has the right to lodge a complaint with the competent supervisory authority, in particular the Italian Data Protection Authority (Garante per la protezione dei dati personali).

11. Exercising Data Subject Rights

To exercise their rights or request information concerning the processing of personal data, users may contact the Data Controller:

DOMUS SANTA CROCE S.S. AGRICOLA
Certified e-mail (PEC): [email protected]

Requests may be submitted without any particular formalities.

The Data Controller will respond within the time limits provided for by applicable legislation.

12. Updates to this Privacy Policy

This Privacy Policy may be amended or updated as a result of changes to the website, the services used or applicable legislation.

Last updated: 29 August 2026

Logo Agriturismo Santa Croce Domus Laetitiae
Domus Santa Croce, località Santa Croce, 06023 Gualdo Tadino (PG), ITALY
VAT ID: 02946450547
CIN (National Identification Code): IT054023B501014451