Privacy Policy and Cookie Policy Notice

1. Introduction and context of the processing

The website www.bebilterrazzo.it is the website of the B&B “Il Terrazzo”, an accommodation facility located in Italy, which allows adult users to consult information about the B&B, request availability/bookings via form, email and telephone, and possibly submit reviews/comments to be published on the website. 

The website uses exclusively technical cookies necessary for the operation of the pages and does not use profiling cookies or non-anonymised third-party analytics tools (such as Google Analytics). 

Links or plugins are present that refer to third-party services (Facebook, Instagram, YouTube, WhatsApp); these parties process users’ data as independent Data Controllers, including possibly transferring them to third countries, in compliance with European legislation on transfers of personal data.

The following notice is drawn up pursuant to Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003, as amended, and describes in a concise but complete manner the methods of processing the personal data of users who browse the website or interact with the B&B. 

2. Notice on the processing of personal data

2.1. Data Controller and contact details

The Data Controller is: 

Danilo Farnesi
B&B Il Terrazzo by Danilo Farnesi
Via Arno 37/a, 05018 Orvieto (TR) Umbria
Email: danilof.df@gmail.com

All contact details of the Data Controller must be indicated clearly and be easily accessible, so as to allow data subjects to exercise their rights. 

 Data Protection Officer (DPO)

The B&B has not appointed a Data Protection Officer (DPO), as the legal conditions making this role mandatory do not apply; for any matter relating to the processing of personal data it is possible to contact the Data Controller directly using the contact details indicated above. 

2.2. Types of data processed

 Browsing data

The information systems and software procedures used to operate the website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols (for example IP addresses, domain names of computers used by users, URI/URL of the requested resources, time of the request, method used to submit the request to the server, size of the file obtained, numerical code indicating the status of the response). 

Such data are used in aggregate form or in any case in a form that is not immediately identifying, solely for the purpose of:

  • • enabling browsing;
  • • obtaining anonymous statistical information on the use of the website;
  • • checking the proper operation of the services offered. 

 Data provided voluntarily by the user

The optional, explicit and voluntary sending of messages through:

  • • the contact/booking form available on the website;
  • • the email addresses indicated on the website;
  • • telephone-contact,

involves the acquisition of personal data provided by the user (e.g. name, surname, email and/or telephone contact details, requested period of stay, number of people, any special requests)

 Data relating to bookings and the stay

To manage availability requests and bookings, as well as the performance of the accommodation contract, the Data Controller processes the personal and contact data of guests, as well as any tax data necessary for invoicing or registration under the legislation in force (e.g. data necessary for communications to public security authorities). 

Guest reviews and comments

If the user submits a review or comment about the stay, the Data Controller may process the guest’s identification data (e.g. name or initials, content of the comment) for the purpose of possible publication on the website, in compliance with the principles of fairness, minimisation and transparency. 

 Data collected through technical cookies

The website uses exclusively technical cookies necessary for the proper operation of the pages (for example session cookies, cookies for storing basic browsing preferences); profiling cookies and non-anonymised third-party analytics cookies are not used. 

2.3. Purposes, legal bases and retention periods

Purposes of processing and legal bases

For each purpose, the legal basis and the main retention periods are identified as follows: 

Purpose Legal basis Description Indicative retention period
Management of browsing on the website and technical security Need to enable use of the website; legitimate interest of the Data Controller in security and proper operation (Art. 6, para. 1, letter f GDPR) Processing of browsing data and necessary technical cookies Log and technical data retained for the time strictly necessary for the security and operation of the website, and in any case according to the technical periods of the hosting provider
Management of requests for information and availability Performance of pre-contractual measures taken at the request of the data subject (Art. 6, para. 1, letter b GDPR) Response to requests sent via form, email or telephone For the time necessary to respond to the request and, if no booking is made, for a period not exceeding 12 months, unless the user makes further contact
Management of bookings and the contractual accommodation relationship Performance of a contract to which the data subject is a party (Art. 6, para. 1, letter b GDPR) Acquisition and management of the data necessary for the booking, the stay and the related obligations For the duration of the contractual relationship and, subsequently, for the period provided for by the applicable civil, tax and accounting legislation
Compliance with legal obligations (e.g. guest registration, tax obligations) Compliance with legal obligations to which the Data Controller is subject (Art. 6, para. 1, letter c GDPR) Communications to competent authorities, tax and accounting obligations For the period provided for by the applicable legislation (e.g. document and tax retention obligations)
Publication of reviews/comments on the website Legitimate interest of the Data Controller in promoting its services, in compliance with the rights and freedoms of data subjects (Art. 6, para. 1, letter f GDPR); consent where required Management and publication of guest reviews and comments; possible partial anonymisation of the data For the period during which the review is published on the website; possible further retention in anonymised form
Management of contacts with social networks and third-party services (links/plugins) Legitimate interest of the Data Controller in promoting the visibility of the accommodation and communication with users (Art. 6, para. 1, letter f GDPR); further processing by social networks as independent Data Controllers Simple redirection or integration of buttons/links to Facebook, Instagram, YouTube, WhatsApp For processing carried out by the B&B: limited to the time necessary to manage contacts; for processing carried out by social networks: reference is made to their respective notices

Consent is required only where strictly necessary (e.g. possible publication of reviews with a full name or clearly identifiable photograph, if not justified by legitimate interest and the reasonable expectations of the data subject). 

2.4. Methods of processing and principles applied

Personal data are processed using paper, computer and electronic tools, in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality. 

Appropriate technical and organisational measures are adopted to ensure the security of personal data, in accordance with the accountability principle of the Data Controller. 

2.5 Recipients of data and transfers to third countries

Categories of recipients

Personal data may be disclosed, within the limits of the purposes indicated above, to the following categories of parties: 

  • • providers of IT services and website hosting;
  • • consultants (e.g. tax or accounting consultants) and other professionals who assist the Data Controller in complying with legal obligations;
  • • public bodies and authorities to which disclosure is required by law (e.g. public security authorities, tax administration);
  • • parties providing services connected with the management of bookings (if outsourced).

These parties process the data as independent Data Controllers or as duly appointed Data Processors, as provided for by the GDPR. 

Transfers of data to third countries

The Data Controller, for the management of the website and the related services, mainly uses providers located in the European Union. 

Browsing the website does not involve, as a rule, a transfer of personal data to third countries by the B&B; however, by clicking links or plugins that refer to Facebook, Instagram, YouTube, WhatsApp or other third-party services, the user’s data may be processed by those parties, possibly also outside the European Economic Area. 

In such cases, processing is carried out by the respective providers as independent Data Controllers, on the basis of the conditions and safeguards provided for by Articles 44 and following of the GDPR (e.g. adequacy decisions, standard contractual clauses, other safeguard instruments).

For further information on processing carried out by these platforms and on transfers outside the EU, the user is invited to consult the relevant privacy notices and cookie policies. 

2.6 Rights of data subjects

Data subjects may exercise, at any time, against the Data Controller, the rights provided for by the GDPR, in particular:

  • • the right of access to personal data (Art. 15 GDPR); 
  • • the right to obtain rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR); 
  • • the right to erasure of data (“right to be forgotten”) in the cases provided for (Art. 17 GDPR); 
  • • the right to restriction of processing (Art. 18 GDPR);
  • • the right to data portability, where applicable (Art. 20 GDPR); 
  • • the right to object to processing based on the legitimate interest of the Data Controller (Art. 21 GDPR); 
  • • the right to withdraw at any time any consent given, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7 GDPR). 

Requests may be addressed to the Data Controller using the contact details indicated in point 2.1; the Data Controller must respond without undue delay and in any case, as a rule, within one month of the request, subject to extensions in the permitted cases. 

Right to lodge a complaint with the Supervisory Authority

Data subjects who believe that the processing of personal data concerning them infringes data protection legislation may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it), or with another competent supervisory authority, as provided for by Art. 77 GDPR, or bring proceedings before the appropriate courts. 

4. Data processed during booking

For the management of online bookings, the B&B “Il Terrazzo” uses a booking system (Booking Engine) made available by the Bed-and-Breakfast.it portal. In this context, the personal data entered by the user to make the booking are also processed by Bed-and-Breakfast.it, which acts as an independent Data Controller for the activities carried out through its website and services. For further information on how Bed-and-Breakfast.it processes personal data, reference is made to the relevant Terms of Service, Privacy Notice and Cookie Policy, available on the provider’s website.

Access to the online booking system provided by Bed-and-Breakfast.it and its use are subject to acceptance of the Terms of Service, Privacy Notice and Cookie Policy prepared by that provider, which can be consulted directly on the Bed-and-Breakfast.it website.

5. Updates to this notice

This Privacy Policy and Cookie Policy Notice may be amended over time (for example in the event of regulatory updates or changes to the services offered). You are therefore invited to consult this page periodically. The notice always indicates the date of its latest update. Last updated: 28/07/2026