Privacy Policy — Galatina Suites

Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679

Last updated: September 21, 2026

This information describes the methods with which the personal data of users who consult the site are processed. www.galatinasuites.it, send a request for information or availability or establish a relationship with Palazzo Scalfo.

1. Data controller

The Data Controller is:

DG Srl
Registered office: [INSERIRE INDIRIZZO COMPLETO]
VAT / Tax code: [INSERIRE DATI]
E-mail: [INSERIRE E-MAIL PRIVACY O E-MAIL DEL TITOLARE]
PEC: [INSERIRE PEC, SE PRESENTE]

The Data Controller determines the purposes and methods of processing personal data collected through the website and in the context of the services offered by Palazzo Scalfo.

2. Scope of application

This Privacy Policy applies to data processed through the website, contact and accommodation request forms, electronic correspondence, and subsequent communications with guests.

It does not regulate the processing performed independently by external websites, platforms, or services accessible via links on Galatina Suites pages. Before using these services, users are encouraged to consult their respective policies.

3. Categories of data processed

3.1 Browsing data

While browsing the site, computer systems and software procedures may automatically acquire technical information necessary for the operation and security of the service, including:

  • IP address;
  • date and time of the request;
  • requested page and originating address;
  • browser type, operating system and device;
  • server response code;
  • other technical parameters relating to the user’s connection and IT environment.

This data is generally processed in a non-directly identifiable form and is not used to reconstruct the user’s individual behavior, except as necessary for site security, the detection of malfunctions, or the protection of the Data Controller’s rights.

3.2 Data provided via the stay request form

When the user fills out the form, the following may be collected:

  • name and surname;
  • e-mail address;
  • phone number or WhatsApp contact;
  • desired arrival and departure dates;
  • number of adult guests;
  • favorite suite;
  • any notes voluntarily inserted in the message.

Submitting the form allows the Owner to check availability and respond to your request, but does not automatically confirm your booking.

3.3 Booking and stay data

If the request continues with a booking, the Data Controller may process additional data necessary to manage the relationship, including:

  • guest identification and contact details;
  • information on the booking, stay and requested services;
  • data required for billing and payments;
  • information required by administrative, tax, accounting and public safety regulations;
  • correspondence exchanged before, during and after the stay.

Any card or payment instrument data must be processed directly by the payment service provider. Palazzo Scalfo is not required to store complete card details in its systems, unless specifically compliant with applicable regulations and security standards.

3.4 Data communicated via email, telephone or WhatsApp

When the user contacts Palazzo Scalfo via email, telephone or messaging services, the data necessary to manage the communication and respond to the request are processed.

If the user chooses to use WhatsApp, the relevant processing is also carried out by the service provider according to its terms and conditions. The user can always use email or the website form as alternative channels.

3.5 Special categories of data

The website form is not intended to collect data relating to health, ethnic origin, religious beliefs, or other special categories of personal data as indicated in Article 9 of Regulation (EU) 2016/679.

Users are asked not to enter such information in the blank field. If it is necessary to communicate needs related to accessibility, health, or other sensitive circumstances, the Data Controller will indicate an appropriate channel and, when requested, obtain explicit and separate consent.

4. Purposes and legal bases of the processing

PurposeProcessed dataLegal basis
Allow consultation and correct functioning of the siteBrowsing dataLegitimate interest of the Data Controller to ensure functionality, security, and continuity of the service, pursuant to art. 6, paragraph 1, letter f) GDPR
Prevent abuse, attacks and malfunctionsBrowsing data and technical logsLegitimate interest of the Data Controller in the security of the site and the protection of its systems, pursuant to art. 6, paragraph 1, letter f) GDPR
Respond to requests for information or availabilityPersonal details, contact details and information about the requested stayExecution of pre-contractual measures taken at the request of the data subject, pursuant to art. 6, paragraph 1, letter b) GDPR
Manage bookings, stays, assistance and requested servicesIdentification, contact, booking and stay dataPerformance of a contract, pursuant to art. 6, par. 1, letter b) GDPR
Comply with administrative, fiscal, accounting and public safety obligationsIdentification, contractual and tax dataFulfillment of legal obligations, pursuant to art. 6, par. 1, letter c) GDPR
To ascertain, exercise or defend a rightData relevant to the relationship and the disputeLegitimate interest of the Data Controller in protecting its rights, pursuant to art. 6, paragraph 1, letter f) GDPR
Use cookies or unnecessary tracking tools, if enabledBrowsing data and online identifiersConsent of the interested party, pursuant to art. 6, paragraph 1, letter a) GDPR and art. 122 of the Privacy Code
Process special categories of data that may be communicated for specific needsInformation strictly necessary for the requestExplicit consent of the data subject, where applicable, pursuant to art. 9, paragraph 2, letter a) GDPR

The Data Controller does not use the data collected through the form for promotional purposes or to send newsletters, except for the future activation of a specific service and the acquisition of a free and separate consent.

5. Nature of the data provision

Providing the data marked as mandatory in the form is necessary to allow the Data Controller to respond to your request. Failure to provide this data will prevent the form from being sent or your request from being processed.

Optional data may be omitted without consequences. The user must provide only information that is relevant and necessary for the requested service.

For the processing necessary to respond to a request or to make a reservation, consent is not required as a legal basis: it is sufficient that the user receives and can consult this information.

6. Processing methods and security measures

The data is processed using electronic and, where necessary, paper-based tools, according to the principles of lawfulness, fairness, transparency, minimization, accuracy, and storage limitation.

The Data Controller adopts appropriate technical and organizational measures to protect data from unauthorized access, loss, destruction, modification, or improper disclosure. Access is limited to those who need the information to perform their duties.

However, no system can guarantee absolute security. Users are advised not to submit excessive or unnecessary information through standard forms or messages.

7. Data recipients

Personal data may be processed by personnel and collaborators authorized by the Data Controller and, within the limits of their respective functions, communicated to:

  • hosting, email and IT infrastructure providers;
  • persons responsible for the development, maintenance and security of the site;
  • suppliers of reservation systems, channel managers or hotel management systems, if activated;
  • payment service providers, if used;
  • administrative, tax, accounting and legal consultants;
  • suppliers necessary for the provision of the services requested by the guest;
  • public authorities, police forces and other entities to whom communication is required by law.

Suppliers who process personal data on behalf of the Data Controller are designated as data processors pursuant to Article 28 of the GDPR, when the conditions are met.

The data is not disclosed or sold to third parties.

8. Transfers to third countries

Some technology providers may process data outside the European Economic Area. In such cases, the transfer is based on an adequacy decision by the European Commission or through the safeguards set forth in Articles 44 et seq. of the GDPR, including, where applicable, standard contractual clauses.

As of the last update, the site loads fonts via Google Fonts. This connection may involve the transmission of technical data, including the IP address, to Google. To reduce this external communication, the Data Controller may host the fonts locally on its own server.

Any voluntary use of WhatsApp or future booking, payment, mapping, analytics, or embedded content services may entail additional processing and transfers governed by the respective providers’ policies. This policy must be updated before their activation.

9. Retention periods

Data categoryRetention period
Technical navigation and security logsUp to 30 days, unless necessary to ascertain accidents, abuses or illicit activities
Information or availability requests that do not lead to a reservationUp to 12 months after the closure of the request or the last significant communication
Data relating to reservations and staysFor the duration necessary to execute the relationship and, subsequently, for the terms established by the applicable legislation and prescription
Administrative, fiscal and accounting documentsNormally 10 years, unless otherwise provided by law or the need for legal protection
Data processed for the exercise or defense of a rightFor the time necessary to manage the dispute and for the subsequent limitation periods
Consent-based dataUntil consent is revoked or the purpose is achieved, without prejudice to the retention of proof of consent for the period necessary to demonstrate the conformity of the processing

After the applicable period, the data is deleted, anonymized, or retained only when required by law.

10. Minors

Palazzo Scalfo is a facility reserved for guests of legal age. The services and forms on the site are not intended for persons under the age of 18, and the Data Controller does not intend to knowingly collect their data through the site.

If the Data Controller becomes aware of the unintentional collection of data relating to a minor, it will take reasonable measures to delete them, unless there is a legal obligation to retain them.

11. Automated decision-making processes

The Data Controller does not adopt decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject. Availability and any reservations are confirmed through the facility’s organizational procedures and not simply by submitting the form.

12. Rights of the interested party

In the cases provided for by Articles 15–22 GDPR, the interested party may request:

  • access to your personal data;
  • the rectification of inaccurate data or the integration of incomplete data;
  • data deletion;
  • the limitation of processing;
  • data portability;
  • opposition to processing based on legitimate interest;
  • the withdrawal of consent, without prejudice to the lawfulness of the processing carried out before the withdrawal;
  • not to be subject to a decision based solely on automated processing, in the cases provided for by law.

Requests can be sent to [INSERIRE E-MAIL PRIVACY]. The Data Controller may request information strictly necessary to verify the applicant’s identity.

The interested party also has the right to lodge a complaint with the Guarantor for the protection of personal data, according to the methods indicated on the site www.garanteprivacy.it, or to contact the competent supervisory authority of the country in which you reside or work.

13. Data Protection Officer

Data Protection Officer, if appointed: [INSERIRE NOMINATIVO O RECAPITO DI CONTATTO].

If a Data Protection Officer has not been appointed, this section can be deleted and requests can be addressed directly to the Data Controller.

14. Cookies and tracking tools

For information on cookies, external services and how to manage preferences, you can consult the Cookie Policy of the site, accessible via the footer of each page.

15. Changes to the Privacy Policy

The Data Controller may update this policy following regulatory, organizational, or technical changes, or the introduction of new services. The updated version will be published on this page, indicating the date of the last update.