Privacy
Privacy Policy on the Processing of Personal Data
pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
1. Data Controller
The Data Controller is G.A.R.I.S. s.r.l., with registered office at Via Pesciatina, 197 – 55012 Capannori (LU), VAT No.: 01059020469, REA No. LU115722, which manages Hotel Hambros Il Parco.
Controller contact details:
Phone: +39 0583.935355 / +39 0583-924721
Fax: +39 0583-935356
Email: info@hotelhambros.com
2. Types of Data Processed and Source
The Controller processes the following categories of personal data:
- Browsing data: IP addresses, browser type, operating system, pages visited and access times, collected automatically by the site’s computer systems.
- Data voluntarily provided by the user: first name, last name, email address, phone number and other data entered in the contact or booking forms on the site.
- Booking data: information necessary for managing the stay (e.g. personal details, preferences, special requests).
The Controller does not collect data belonging to special categories (formerly “sensitive data”) pursuant to Article 9 GDPR, such as health data, racial or ethnic origin, political opinions, etc. Users are therefore requested not to communicate such data.
3. Purposes and Legal Bases for Processing
Personal data are processed for the following purposes:
- Management of bookings and stays (legal basis: performance of a contract – Art. 6(1)(b) GDPR).
- Fulfilment of legal and regulatory obligations, including communications to Public Security Authorities as required by Italian hotel regulations (legal basis: legal obligation – Art. 6(1)(c) GDPR).
- Responding to contact and information requests submitted through the site’s forms (legal basis: pre-contractual measures – Art. 6(1)(b) GDPR).
- Sending promotional communications and newsletters about the hotel’s services and offers (legal basis: data subject’s consent – Art. 6(1)(a) GDPR). Consent may be withdrawn at any time without prejudice to the lawfulness of processing carried out prior to withdrawal.
- Statistical analysis and improvement of the website, using browsing analysis tools (legal basis: legitimate interest of the Controller – Art. 6(1)(f) GDPR).
4. Methods of Processing
Personal data are processed by means of IT and telematic tools, adopting adequate technical and organisational security measures to prevent loss, unlawful or improper use, and unauthorised access. Data are processed by personnel authorised by the Controller, bound by confidentiality obligations.
5. Recipients and Communication of Data
Personal data may be communicated to the following categories of recipients:
- Technical and IT service providers (e.g. hosting, website management), appointed as Data Processors pursuant to Art. 28 GDPR.
- Banking and payment institutions, for the management of transactions.
- Public Security Authorities and other public bodies, in cases provided for by law.
- Consultants and professionals, to the extent strictly necessary.
Data are not subject to dissemination. They are not transferred to countries outside the European Economic Area (EEA), except where third-party technology services operating in such countries are used, in which case the transfer takes place in compliance with the safeguards provided for by the GDPR (adequacy decisions, standard contractual clauses, etc.).
6. Data Retention Period
Personal data are retained for the time strictly necessary for the purposes for which they were collected, and in any case:
- Booking and stay data are retained for 10 years to fulfil fiscal and accounting obligations.
- Data from guest presence communications to Public Security Authorities are retained in accordance with the terms set out by applicable regulations.
- Data provided for marketing purposes are retained until consent is withdrawn.
- Browsing data are retained for a period not exceeding 12 months.
7. Rights of the Data Subject
As a data subject, pursuant to Articles 15–22 of the GDPR, you have the right to:
- Access (Art. 15): obtain confirmation of processing and a copy of the personal data concerning you.
- Rectification (Art. 16): obtain correction of inaccurate data or completion of incomplete data.
- Erasure (“right to be forgotten”) (Art. 17): obtain the deletion of personal data, in the cases provided for by law.
- Restriction of processing (Art. 18): obtain restriction of processing in certain cases.
- Data portability (Art. 20): receive data in a structured, commonly used and machine-readable format.
- Objection (Art. 21): object to the processing of data at any time, in particular for direct marketing purposes.
- Withdrawal of consent (Art. 7): withdraw consent given at any time, without prejudice to the lawfulness of processing based on consent carried out prior to withdrawal.
To exercise their rights, the data subject may contact the Controller at the details indicated in section 1. The Controller will respond within 30 days of receipt of the request.
8. Right to Lodge a Complaint
The data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali – www.garanteprivacy.it), Piazza Venezia 11 – 00187 Rome, if they believe that the processing of their personal data violates Regulation (EU) 2016/679.
9. Cookies and Tracking Technologies
The site uses technical cookies necessary for the functioning of the site and, subject to the user’s consent, analytical and profiling cookies. For further information on the use of cookies, please refer to our Cookie Policy.
10. Updates to this Policy
This privacy policy may be subject to updates. We recommend consulting this page periodically. The current version was updated in July 2026.