Privacy Policy
INFORMATION ON THE PROCESSING OF PERSONAL DATA
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), G.T.F. S.r.l. provides the following information regarding the processing of personal data carried out through the website delfinapalacehotel.it.
1. Data Controller
G.T.F. S.r.l.
Via Santa Margherita 24
06034 Foligno (PG) – Italy
VAT No. / Tax Code: 00477380547
Email: info@delfinapalacehotel.it
Certified Email (PEC): gtf@sicurezzapostale.it
For any request regarding the processing of personal data, users may contact the Data Controller at the email address indicated above.
2. Data Protection Officer (DPO)
For any privacy-related matter and for the exercise of data subject rights, users may contact the Data Controller at: info@delfinapalacehotel.it
3. Categories of Personal Data Processed
The website may process the following categories of personal data:
a) Browsing data
The computer systems and software procedures used to operate the website acquire, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols, including, by way of example:
IP address;
browser and device data;
URI/URL of requested resources;
time of the request;
method used to submit the request to the server;
parameters relating to the operating system and the user’s IT environment;
technical logs and security data.
Such data is not collected in order to be directly associated with identified individuals, but may, by its nature, allow users to be identified through processing and association with data held by third parties.
b) Data voluntarily provided by the user
The optional, explicit and voluntary sending of messages to the email addresses published on the website entails the processing of the sender’s contact details, as well as any personal data included in the communication.
At present, the website does not use internal contact forms: contact is made through an email link (“mailto”) which opens the user’s email client.
c) Booking-related data
The website allows users to initiate an availability/booking request through the Slope system, integrated into the website through a plugin/shortcode, with subsequent redirection to an external platform in order to complete the booking.
In connection with this functionality, data may be processed such as:
selected stay dates;
number of guests or other stay preferences;
any additional data required by the external booking platform.
The actual booking process is then completed on the external provider’s platform, which operates in accordance with its own privacy policy.
d) Data processed through third-party content and services
The website may embed or call third-party content and services, such as:
Google Maps;
YouTube;
Instagram;
Facebook;
Google Fonts;
the Slope booking platform.
Interaction with such services may involve the processing of personal data by the respective providers in accordance with their own privacy policies.
e) Data relating to public reviews
The website may display, for editorial or promotional purposes, excerpts of public reviews taken from the business’s Google profile, including the name or public identifier displayed on the source platform.
Such data is processed within the limits of its public availability and for the purpose of presenting the reputation of the hotel.
4. Purposes of Processing
Personal data is processed for the following purposes:
to enable website browsing and ensure the proper technical functioning of the website;
to respond to information requests voluntarily sent by the user;
to manage pre-contractual requests relating to the hotel’s services;
to allow the user to check availability and access the external booking system;
to protect website security, prevent abuse, unauthorised access and unlawful activities;
to display external content and social or multimedia features requested by the user;
to present the hotel’s services, editorial content, experiences, blog articles and general information about the property;
to enhance the hotel’s reputation, including by referring to public reviews or inviting users to leave reviews on external platforms.
5. Legal Basis for Processing
Depending on the specific case, the processing of personal data is based on the following legal grounds:
performance of pre-contractual measures taken at the data subject’s request
for information requests, contacts relating to stays, events, services or availability;
the Data Controller’s legitimate interest
in the technical operation of the website, system security, prevention of abuse, day-to-day website management and the promotion of the hotel’s reputation through the display of public reviews;
compliance with legal obligations
where processing is necessary to comply with legal, administrative, tax, accounting or regulatory obligations, or requests from public authorities;
the user’s consent, where required
in particular for the installation of non-technical cookies and similar technologies, and for the activation of specific third-party content or services subject to consent through the website’s cookie management system.
6. Nature of Data Provision
The provision of browsing data necessary for website operation is inherent in the use of Internet protocols.
The sending of data by email is optional; however, failure to provide the data necessary to process a request may make it impossible for the Data Controller to respond.
Any provision of data within the booking process is also governed by the external booking system/provider.
7. Methods of Processing
Personal data is processed by electronic, telematic and, where necessary, paper-based means, in accordance with the principles of lawfulness, fairness, transparency, data minimisation, purpose limitation and storage limitation.
The Data Controller adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, disclosure or unlawful use.
8. Recipients of Personal Data
Personal data may be disclosed or made accessible, within the limits of the purposes indicated above, to:
authorised internal personnel of the Data Controller;
consultants, technicians, system administrators, developers and website maintenance providers;
hosting, infrastructure, security, backup and maintenance service providers;
providers of services integrated into or called by the website;
external booking platforms, including Slope, for the management of the requested service;
public authorities, public bodies or third parties where disclosure is required by law or necessary to establish, exercise or defend a legal claim.
Where required, parties processing personal data on behalf of the Data Controller are appointed as Data Processors pursuant to Article 28 GDPR.
9. Hosting and Technical Infrastructure
The website may be hosted on technical infrastructure provided by Register S.p.A., or in any case by technical service providers engaged by the Data Controller or its technical consultants, for hosting, connectivity, application security, maintenance and system support purposes.
The Data Controller reserves the right to update this Privacy Policy should the infrastructure provider or technical architecture change.
10. Transfer of Data Outside the EEA
The use of certain third-party services present on or called by the website, including services provided by Google, Meta or other international providers, may involve the transfer of personal data to countries outside the European Economic Area.
Where such transfers take place, they are carried out in compliance with the conditions laid down by the GDPR, including adequacy decisions, standard contractual clauses or other safeguards provided for by applicable law.
11. Data Retention Period
Personal data is retained for no longer than is necessary to achieve the purposes for which it was collected, and in particular:
browsing data and technical logs: for the period strictly necessary for website operation, security and technical management, unless further retention is required for the investigation of unlawful conduct or for the establishment, exercise or defence of legal claims;
requests sent by email: for the time necessary to manage the request and, subsequently, for the period useful to protect the Data Controller in administrative, contractual or judicial matters;
data processed within the booking process: according to the timeframes and rules of the booking system provider and, where applicable, according to the legal obligations incumbent upon the Data Controller;
data processed for legal compliance purposes: for the retention period required by the applicable legislation;
data processed on the basis of consent: until consent is withdrawn, without affecting the lawfulness of processing carried out before such withdrawal.
12. Cookies and Similar Technologies
The website uses cookies and similar technologies.
For detailed information on categories, purposes, legal basis, retention periods and methods for managing consent, users are invited to consult the Cookie Policy and the preference management tools made available through the cookie banner.
Any prior blocking of third-party content requiring consent is managed through the system adopted on the website.
13. Links to Third-Party Websites and Services
The website may contain links to third-party websites, platforms or services, including social networks, video platforms, maps, review platforms and booking systems.
Such websites and services act as independent data controllers in accordance with their own privacy policies. The Data Controller is not responsible for the processing carried out by third parties on external websites accessible through links.
14. Data Subject Rights
Data subjects may exercise, where applicable, the rights provided for in Articles 15–22 GDPR, including the right to:
obtain confirmation as to whether or not personal data concerning them is being processed;
access their personal data;
request rectification of inaccurate data or completion of incomplete data;
request erasure of personal data;
request restriction of processing;
object to processing, where applicable;
receive their data in a structured, commonly used and machine-readable format, where the right to data portability applies;
withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal;
lodge a complaint with the competent Data Protection Authority.
Requests may be sent to: info@delfinapalacehotel.it
15. Minors
The website is not intended for the direct collection of personal data relating to minors. The Data Controller does not knowingly collect personal data from minors through the website.
16. Changes to this Privacy Policy
The Data Controller reserves the right to update or amend this Privacy Policy, in whole or in part, including as a result of changes in applicable laws, technical developments or organisational changes.
Any changes will be published on this page together with the date of the latest update.