Privacy Policy
Information on the processing of personal data pursuant to EU Regulation 2016/679 (GDPR) and applicable Italian law.
1. Data Controller
The Data Controller for the processing of personal data is:
Maria Luisa Staino
Via Vecchia Pesciatina 106, 55012 Capannori (LU), Italy
Contact details:
Email: luccaapartmentsinvilla@gmail.com
Telephone: +39 0583 935355 — Organisational contact (Hotel Hambros Il Parco, Gest. Garis S.r.l.), used exclusively for key delivery coordination. The Hotel is not a party to the rental contract nor a Data Controller.
2. Types of data collected
Through this website we collect the following categories of personal data, in compliance with the principle of minimisation (Art. 5 GDPR):
- Browsing data: IP address, browser type, operating system, time of visit, pages visited and other technical data automatically collected by computer systems during browsing. Such data are used exclusively to obtain anonymous statistical information on site usage and to check its correct functioning.
- Data provided voluntarily: name, email address, telephone number and any other personal data entered by the user via the mailto and tel links on the site. The optional and explicit sending of communications to these addresses entails the subsequent acquisition of the data provided.
- Data collected via cookies: as described in the Cookie section.
- Payment data: in the event of card payment via the Stripe link, card data are collected and processed directly by Stripe; the landlord receives only confirmation of payment and the transaction identifying data (see Section 9).
- Data collected at check-in: personal and identity-document data of guests, collected during the stay for legal obligations (see Section 10).
3. Cookies
This site uses exclusively the following types of cookies:
- Technical cookies: necessary for the functioning of the site and navigation management. They do not require consent (Art. 122 of Italian Legislative Decree 196/2003). They include the preference cookie that stores the user's cookie consent choices (
cookie-consent-vb). - Google Fonts: the site uses Google Fonts for displaying typographic characters (Marcellus, Albert Sans, Spline Sans Mono). Loading fonts from Google occurs only with the user's consent via the cookie banner. If the user rejects, the site uses the default system fonts. For more information, please consult Google's privacy policy: https://policies.google.com/privacy.
We do not use profiling cookies, third-party cookies for advertising or marketing purposes, nor analytical tracking tools that involve the transfer of personal data to third parties.
4. Purpose and legal basis of processing
Personal data are processed for the following purposes:
- Browsing management: ensuring the correct technical functioning of the site. Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
- Font loading: improving the visual experience of the site. Legal basis: consent of the data subject (Art. 6(1)(a) GDPR), collected via the cookie banner.
- Responding to contact requests: managing communications received via email or telephone regarding availability, rates and bookings. Legal basis: performance of pre-contractual measures at the request of the data subject (Art. 6(1)(b) GDPR).
- Payment management: processing payment for the stay via the provider Stripe. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
- Public-security and tax obligations: communication of guest data to the Authorities and retention of accounting documentation. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
5. Processing methods and security
The processing of personal data is carried out using IT and telematic tools, with methods strictly related to the purposes indicated above and, in any case, so as to guarantee the security and confidentiality of the data, in full compliance with the security measures provided for by Art. 32 of the GDPR.
The site is hosted on static infrastructure and does not include databases, contact forms or backend systems that process personal data server-side. Communications via email and telephone are managed directly by the Controller through the usual email and telephone channels. Electronic payments are managed on a secure external platform (Stripe), as described in Section 9.
6. Communication and dissemination of data
The personal data collected are not in any case subject to public dissemination. They may be communicated to:
- Technical service providers strictly necessary for the operation of the site (e.g. hosting service), who act as Data Processors pursuant to Art. 28 GDPR.
- Google LLC (only in the event of consent to Google Fonts loading), limited to the technical browsing data connected to the font file request. Google servers may be located outside the European Economic Area; in this case, the transfer takes place on the basis of the Standard Contractual Clauses adopted by the European Commission.
- Stripe Payments Europe Ltd. and Stripe group companies, as providers of the payment-processing service, limited to the data necessary to complete the transaction. Stripe may transfer data outside the European Economic Area on the basis of the European Commission's Standard Contractual Clauses.
- Competent authorities, only in cases provided for by law.
7. Data retention
Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected:
- Browsing data: are not permanently retained and are deleted at the end of the browsing session. Any anonymised server logs may be retained for security purposes for a maximum period of 30 days.
- Data provided for contact requests: retained for the time necessary to respond to the request and, in any case, no later than 24 months from the last communication.
- Cookie preferences: stored in the user's browser via localStorage for a period of 12 months, unless manually deleted by the user.
- Contractual, payment and tax data: data relating to bookings, payments and accounting documents are retained for the period required by civil and tax law, equal to 10 years (Art. 2220 of the Italian Civil Code).
- Data communicated to Public Security Authorities: retained and transmitted in accordance with the terms and methods provided for by law (see Section 10).
8. Rights of the data subject
Pursuant to Articles 15-22 of the GDPR, the data subject has the right to:
- Access (Art. 15): obtain confirmation of the existence of processing and access their personal data.
- Rectification (Art. 16): obtain the correction of inaccurate data or the completion of incomplete data.
- Erasure (Art. 17): obtain the erasure of their personal data («right to be forgotten»).
- Restriction (Art. 18): obtain the restriction of processing.
- Portability (Art. 20): receive their data in a structured format and transmit them to another controller.
- Objection (Art. 21): object to the processing of their personal data.
- Withdrawal of consent (Art. 7): withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise their rights, the data subject may contact the Controller at the contact details indicated in Section 1. The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
9. Payment data (Stripe)
Card payments are managed through the Stripe platform (Stripe Payments Europe Ltd.). When the user makes a payment via the secure link provided by the landlord, card data are entered and processed directly on Stripe's systems: the landlord does not collect or store the full card number, receiving only the transaction outcome and the identifying data needed for the administrative and accounting management of the stay.
Stripe acts as an independent controller/processor for payment processing and fraud prevention purposes. Data may be transferred outside the European Economic Area on the basis of the European Commission's Standard Contractual Clauses. For more information, please refer to Stripe's privacy policy: https://stripe.com/privacy.
10. Data collected at check-in and communication to Public Security Authorities
At check-in, the landlord is required by law to record the personal and identity-document data of all accommodated guests and to communicate them to the competent Police Headquarters (Questura) through the "Alloggiati Web" portal, pursuant to Art. 109 of the Italian Consolidated Public Security Act (T.U.L.P.S., Royal Decree no. 773 of 18 June 1931) and the related implementing legislation.
Purpose: compliance with a legal public-security obligation. Legal basis: Art. 6(1)(c) GDPR (legal obligation). Provision of such data is mandatory: refusal makes it impossible to proceed with the stay.
Recipients: Public Security Authorities (Questura). Retention: for the period provided for by law. Data collected for this purpose are not used for further purposes nor disseminated.
11. Amendments to this policy
The Controller reserves the right to amend this policy at any time, notifying users on this page. Please consult this page regularly, taking as reference the last-updated date shown below.
Last updated: 26 June 2026
12. Regional identifiers (CIN)
Pursuant to regional and national regulations, the accommodation facilities are identified by the following National Identification Codes (CIN):
- Il Giardino di Villa Banchieri: 046007LTN0869
- Residenza Villa Banchieri: 046007LTN0864