Privacy Policy — Galatina Suites
Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
Last updated: September 21, 2026
This information describes the methods with which the personal data of users who consult the site are processed. www.galatinasuites.it, send a request for information or availability or establish a relationship with Palazzo Scalfo.
1. Data controller
The Data Controller is:
DG Srl
Registered office: [INSERIRE INDIRIZZO COMPLETO]
VAT / Tax code: [INSERIRE DATI]
E-mail: [INSERIRE E-MAIL PRIVACY O E-MAIL DEL TITOLARE]
PEC: [INSERIRE PEC, SE PRESENTE]
The Data Controller determines the purposes and methods of processing personal data collected through the website and in the context of the services offered by Palazzo Scalfo.
2. Scope of application
This Privacy Policy applies to data processed through the website, contact and accommodation request forms, electronic correspondence, and subsequent communications with guests.
It does not regulate the processing performed independently by external websites, platforms, or services accessible via links on Galatina Suites pages. Before using these services, users are encouraged to consult their respective policies.
3. Categories of data processed
3.1 Browsing data
While browsing the site, computer systems and software procedures may automatically acquire technical information necessary for the operation and security of the service, including:
- IP address;
- date and time of the request;
- requested page and originating address;
- browser type, operating system and device;
- server response code;
- other technical parameters relating to the user’s connection and IT environment.
This data is generally processed in a non-directly identifiable form and is not used to reconstruct the user’s individual behavior, except as necessary for site security, the detection of malfunctions, or the protection of the Data Controller’s rights.
3.2 Data provided via the stay request form
When the user fills out the form, the following may be collected:
- name and surname;
- e-mail address;
- phone number or WhatsApp contact;
- desired arrival and departure dates;
- number of adult guests;
- favorite suite;
- any notes voluntarily inserted in the message.
Submitting the form allows the Owner to check availability and respond to your request, but does not automatically confirm your booking.
3.3 Booking and stay data
If the request continues with a booking, the Data Controller may process additional data necessary to manage the relationship, including:
- guest identification and contact details;
- information on the booking, stay and requested services;
- data required for billing and payments;
- information required by administrative, tax, accounting and public safety regulations;
- correspondence exchanged before, during and after the stay.
Any card or payment instrument data must be processed directly by the payment service provider. Palazzo Scalfo is not required to store complete card details in its systems, unless specifically compliant with applicable regulations and security standards.
3.4 Data communicated via email, telephone or WhatsApp
When the user contacts Palazzo Scalfo via email, telephone or messaging services, the data necessary to manage the communication and respond to the request are processed.
If the user chooses to use WhatsApp, the relevant processing is also carried out by the service provider according to its terms and conditions. The user can always use email or the website form as alternative channels.
3.5 Special categories of data
The website form is not intended to collect data relating to health, ethnic origin, religious beliefs, or other special categories of personal data as indicated in Article 9 of Regulation (EU) 2016/679.
Users are asked not to enter such information in the blank field. If it is necessary to communicate needs related to accessibility, health, or other sensitive circumstances, the Data Controller will indicate an appropriate channel and, when requested, obtain explicit and separate consent.
4. Purposes and legal bases of the processing
| Purpose | Processed data | Legal basis |
|---|---|---|
| Allow consultation and correct functioning of the site | Browsing data | Legitimate interest of the Data Controller to ensure functionality, security, and continuity of the service, pursuant to art. 6, paragraph 1, letter f) GDPR |
| Prevent abuse, attacks and malfunctions | Browsing data and technical logs | Legitimate interest of the Data Controller in the security of the site and the protection of its systems, pursuant to art. 6, paragraph 1, letter f) GDPR |
| Respond to requests for information or availability | Personal details, contact details and information about the requested stay | Execution of pre-contractual measures taken at the request of the data subject, pursuant to art. 6, paragraph 1, letter b) GDPR |
| Manage bookings, stays, assistance and requested services | Identification, contact, booking and stay data | Performance of a contract, pursuant to art. 6, par. 1, letter b) GDPR |
| Comply with administrative, fiscal, accounting and public safety obligations | Identification, contractual and tax data | Fulfillment of legal obligations, pursuant to art. 6, par. 1, letter c) GDPR |
| To ascertain, exercise or defend a right | Data relevant to the relationship and the dispute | Legitimate interest of the Data Controller in protecting its rights, pursuant to art. 6, paragraph 1, letter f) GDPR |
| Use cookies or unnecessary tracking tools, if enabled | Browsing data and online identifiers | Consent of the interested party, pursuant to art. 6, paragraph 1, letter a) GDPR and art. 122 of the Privacy Code |
| Process special categories of data that may be communicated for specific needs | Information strictly necessary for the request | Explicit consent of the data subject, where applicable, pursuant to art. 9, paragraph 2, letter a) GDPR |
The Data Controller does not use the data collected through the form for promotional purposes or to send newsletters, except for the future activation of a specific service and the acquisition of a free and separate consent.
5. Nature of the data provision
Providing the data marked as mandatory in the form is necessary to allow the Data Controller to respond to your request. Failure to provide this data will prevent the form from being sent or your request from being processed.
Optional data may be omitted without consequences. The user must provide only information that is relevant and necessary for the requested service.
For the processing necessary to respond to a request or to make a reservation, consent is not required as a legal basis: it is sufficient that the user receives and can consult this information.
6. Processing methods and security measures
The data is processed using electronic and, where necessary, paper-based tools, according to the principles of lawfulness, fairness, transparency, minimization, accuracy, and storage limitation.
The Data Controller adopts appropriate technical and organizational measures to protect data from unauthorized access, loss, destruction, modification, or improper disclosure. Access is limited to those who need the information to perform their duties.
However, no system can guarantee absolute security. Users are advised not to submit excessive or unnecessary information through standard forms or messages.
7. Data recipients
Personal data may be processed by personnel and collaborators authorized by the Data Controller and, within the limits of their respective functions, communicated to:
- hosting, email and IT infrastructure providers;
- persons responsible for the development, maintenance and security of the site;
- suppliers of reservation systems, channel managers or hotel management systems, if activated;
- payment service providers, if used;
- administrative, tax, accounting and legal consultants;
- suppliers necessary for the provision of the services requested by the guest;
- public authorities, police forces and other entities to whom communication is required by law.
Suppliers who process personal data on behalf of the Data Controller are designated as data processors pursuant to Article 28 of the GDPR, when the conditions are met.
The data is not disclosed or sold to third parties.
8. Transfers to third countries
Some technology providers may process data outside the European Economic Area. In such cases, the transfer is based on an adequacy decision by the European Commission or through the safeguards set forth in Articles 44 et seq. of the GDPR, including, where applicable, standard contractual clauses.
As of the last update, the site loads fonts via Google Fonts. This connection may involve the transmission of technical data, including the IP address, to Google. To reduce this external communication, the Data Controller may host the fonts locally on its own server.
Any voluntary use of WhatsApp or future booking, payment, mapping, analytics, or embedded content services may entail additional processing and transfers governed by the respective providers’ policies. This policy must be updated before their activation.
9. Retention periods
| Data category | Retention period |
|---|---|
| Technical navigation and security logs | Up to 30 days, unless necessary to ascertain accidents, abuses or illicit activities |
| Information or availability requests that do not lead to a reservation | Up to 12 months after the closure of the request or the last significant communication |
| Data relating to reservations and stays | For the duration necessary to execute the relationship and, subsequently, for the terms established by the applicable legislation and prescription |
| Administrative, fiscal and accounting documents | Normally 10 years, unless otherwise provided by law or the need for legal protection |
| Data processed for the exercise or defense of a right | For the time necessary to manage the dispute and for the subsequent limitation periods |
| Consent-based data | Until consent is revoked or the purpose is achieved, without prejudice to the retention of proof of consent for the period necessary to demonstrate the conformity of the processing |
After the applicable period, the data is deleted, anonymized, or retained only when required by law.
10. Minors
Palazzo Scalfo is a facility reserved for guests of legal age. The services and forms on the site are not intended for persons under the age of 18, and the Data Controller does not intend to knowingly collect their data through the site.
If the Data Controller becomes aware of the unintentional collection of data relating to a minor, it will take reasonable measures to delete them, unless there is a legal obligation to retain them.
11. Automated decision-making processes
The Data Controller does not adopt decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject. Availability and any reservations are confirmed through the facility’s organizational procedures and not simply by submitting the form.
12. Rights of the interested party
In the cases provided for by Articles 15–22 GDPR, the interested party may request:
- access to your personal data;
- the rectification of inaccurate data or the integration of incomplete data;
- data deletion;
- the limitation of processing;
- data portability;
- opposition to processing based on legitimate interest;
- the withdrawal of consent, without prejudice to the lawfulness of the processing carried out before the withdrawal;
- not to be subject to a decision based solely on automated processing, in the cases provided for by law.
Requests can be sent to [INSERIRE E-MAIL PRIVACY]. The Data Controller may request information strictly necessary to verify the applicant’s identity.
The interested party also has the right to lodge a complaint with the Guarantor for the protection of personal data, according to the methods indicated on the site www.garanteprivacy.it, or to contact the competent supervisory authority of the country in which you reside or work.
13. Data Protection Officer
Data Protection Officer, if appointed: [INSERIRE NOMINATIVO O RECAPITO DI CONTATTO].
If a Data Protection Officer has not been appointed, this section can be deleted and requests can be addressed directly to the Data Controller.
14. Cookies and tracking tools
For information on cookies, external services and how to manage preferences, you can consult the Cookie Policy of the site, accessible via the footer of each page.
15. Changes to the Privacy Policy
The Data Controller may update this policy following regulatory, organizational, or technical changes, or the introduction of new services. The updated version will be published on this page, indicating the date of the last update.

