INFORMATION NOTICE PURSUANT TO ART. 13 GDPR
Privacy Policy
Transparency above all. Here is what we collect, why, for how long, and how you can stay in control.
Data controller
The data controller is Villa Panoramica, operating in Artogne (BS), Valle Camonica, Italy. National Identification Code (CIN) of the property: IT017007C286FIEKSF.
For any request regarding your personal data, please contact us:
- E-mail: villapanoramica1.1a@gmail.com
- WhatsApp: +39 377 098 1837
- Postal address: Artogne (BS), Italy
The legal name, VAT number and tax code of the controller will be integrated upon final publication of the site.
A Data Protection Officer (DPO) has not been appointed: processing is carried out on a small scale and does not meet the requirements of art. 37 GDPR.
Categories of personal data
Depending on how you interact with the site and with the property, we may process the following categories of personal data:
- Identification and contact data: first and last name, e-mail address, phone number.
- Booking data: stay dates, number and type of guests, special requests.
- ID document data of guests staying at the villa (first and last name, date and place of birth, citizenship, document type and number), processed exclusively to comply with the obligation to communicate guest data to the Italian State Police via the "Alloggiati Web" portal (art. 109 TULPS).
- Payment data: processed directly by Lodgify Ltd. and the payment provider; the Villa Panoramica website does not store nor display credit-card data.
- Communication data: the content of messages sent via the contact form, WhatsApp or e-mail.
- Navigation data: IP address (anonymised when technically possible), browser type, operating system, pages visited. For details on cookies and tracking tools see the Cookie Policy.
Purposes and legal basis
We process your personal data, separately, for the following purposes:
a) Replying to information requests
To answer your enquiries via contact form, e-mail or WhatsApp. Legal basis: art. 6.1.b GDPR (pre-contractual measures taken at your request).
b) Booking and stay management
To organise and manage your stay at the villa, including operational communications (check-in, check-out, house rules). Legal basis: art. 6.1.b GDPR (performance of the short-term rental contract).
c) Legal obligations — Public Security
To communicate guest details to the Italian State Police via the Alloggiati Web portal within 24 hours of arrival, pursuant to art. 109 TULPS (R.D. June 18, 1931, no. 773). Legal basis: art. 6.1.c GDPR (legal obligation binding the controller).
d) Legal obligations — City tourism tax
To communicate guest counts and pay the tourism tax to the Municipality of Artogne, in accordance with local regulations. Legal basis: art. 6.1.c GDPR.
e) Tax and accounting obligations
For invoicing, accounting and any further fiscal duty. Legal basis: art. 6.1.c GDPR.
f) Newsletter / promotional communications (optional)
Only if you give explicit, separate and revocable consent, we may send you periodic news from the villa. Legal basis: art. 6.1.a GDPR (specific consent). At the time of this notice the villa does not run a newsletter; we will update this section if this should change.
Retention periods
We keep personal data only for as long as strictly necessary to achieve the purposes for which they were collected, in line with legal terms:
- Booking and invoicing data: 10 years from the date of last operation, pursuant to art. 2220 of the Italian Civil Code and tax obligations.
- Data sent to Alloggiati Web: transmitted to the competent Police Headquarters; copies of receipts are kept for at least 5 years for evidentiary purposes.
- Contact-form messages with no booking: maximum 24 months from receipt.
- Marketing data (if activated in the future): until consent is withdrawn, or in any case for 24 months from the last interaction.
- System logs and navigation data: maximum 12 months, except where needed to investigate offences.
Recipients and processors
To pursue the purposes above your data may be shared with the following parties, acting as data processors (art. 28 GDPR) or as autonomous controllers:
- Lodgify Ltd. (United Kingdom) — booking and payment management. Privacy notice: lodgify.com/privacy; data-processing addendum: lodgify.com/dpa.
- Resend Inc. (United States) — transactional e-mail delivery for the contact form. Privacy notice: resend.com/legal/privacy-policy; addendum: resend.com/legal/dpa. Resend is certified under the EU-U.S. Data Privacy Framework.
- Vercel Inc. (United States) — site hosting and delivery. Privacy notice: vercel.com/legal/privacy-policy. Vercel is certified under the EU-U.S. Data Privacy Framework.
- Italian State Police — Brescia Headquarters: to comply with the guest-registration obligation under art. 109 TULPS via alloggiatiweb.poliziadistato.it.
- Municipality of Artogne (BS): for tourism-tax collection and local statistical obligations.
- Tax and accounting consultants appointed by the controller for fiscal compliance.
- Judicial and public-security authorities when legally required.
Data is not disseminated nor sold to third parties for autonomous commercial purposes.
Transfers outside the EU/EEA
Some processors (Lodgify, Resend, Vercel) are based outside the European Economic Area. Transfers occur only on the basis of adequate safeguards under Chapter V GDPR:
- Lodgify Ltd. (United Kingdom): transfer covered by the European Commission's adequacy decision of 28 June 2021 for the United Kingdom.
- Resend Inc. and Vercel Inc. (United States): transfer based on the EU-U.S. Data Privacy Framework adequacy decision (Decision UE 2023/1795) and, as a further safeguard, on Standard Contractual Clauses pursuant to art. 46 GDPR.
You can request a copy of the safeguards in place by writing to villapanoramica1.1a@gmail.com.
Your rights
As a data subject you can exercise the following rights:
- Access to your personal data (art. 15 GDPR).
- Rectification of inaccurate data or completion of incomplete data (art. 16 GDPR).
- Erasure ("right to be forgotten") in the cases provided (art. 17 GDPR).
- Restriction of processing (art. 18 GDPR).
- Data portability to another controller (art. 20 GDPR), for processing based on consent or contract.
- Objection to processing (art. 21 GDPR), particularly for marketing purposes.
- Withdrawal of consent, at any time and without affecting the lawfulness of processing already carried out (art. 7.3 GDPR).
To exercise your rights you can write to villapanoramica1.1a@gmail.com. We will reply within 30 days from receipt of the request.
You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it), or with the supervisory authority of the EU member state in which you reside or habitually work, should you believe the processing of your data infringes the GDPR.
Automated decisions and profiling
The controller does not carry out automated decision-making, including profiling, pursuant to art. 22 GDPR. Commercial choices (availability, rates, booking acceptance) are made by people.
Data security
Personal data are processed with appropriate technical and organisational measures pursuant to art. 32 GDPR: encrypted connections (HTTPS/TLS), credential and two-factor authentication on management services, file storage on redundant cloud infrastructure. Unstructured backups are kept only for the time strictly necessary.
Changes to this notice
The controller reserves the right to update this notice at any time to reflect regulatory, organisational or technological changes. The current version is always the one published on this page, with the date of last update displayed at the top.

