Privacy Notice
Last updated: 16/12/2025
Introduction
- This section contains information on the data processing methods of the data controller Carlo Rango, with reference to the processing of users of giardinodilei.it.
- This notice also applies for the purposes of Article 13 of EU Regulation No. 2016/679 for users who submit a request via the form Booking Request on the website giardinodilei.it, relating to the short-term tourist apartment "Il Giardino di Lei" and for users browsing the website.
- The notice may be modified due to the introduction of new regulations, so users are invited to periodically consult this page.
- If the user is under 14 years old, pursuant to Article 8 paragraph 1 EU Regulation 2016/679 and Article 2-quinquies of Legislative Decree 196/2003, as amended by Legislative Decree 181/2018, they must legitimize their consent through the authorization of parents or guardians.
1. Data Controller
Regarding this website giardinodilei.it, the data controller is Carlo Rango
Email: info@giardinodilei.it
Address: Via Oriana Fallaci n. 14, 35036 Montegrotto Terme
The Controller manages the processing of personal data collected through the availability request form and technical data of users browsing the website.
2. Types of Data Processed
- Personal data entered in the form: name, surname, email, phone number, message text, any arrival/departure dates, number of guests or notes.
- Some technical data is automatically collected during navigation by external providers such as Cloudflare, Vercel and Google Maps. This data is used for security (DDoS protection), hosting, performance, and map display.
Technical logs automatically collected by hosting and security services (Cloudflare, Vercel) are retained for a variable period depending on their policies.
Displaying the map via Google Maps requires the user's consent, who may choose whether to load it by clicking the corresponding button.
3. Purpose of Processing and Legal Basis
a) Responding to the user's request and providing availability information
Legal basis: Art. 6.1.b GDPR - pre-contractual measures requested by the data subject.
b) Legal and administrative obligations related to any accommodation facility / tourist rental
Legal basis: Art. 6.1.c GDPR - legal obligation.
c) Technical management and site security
Technical data of users is processed to ensure security, proper functioning and performance of the website.
Legal basis: Art. 6.1.f GDPR - legitimate interest of the controller.
4. Processing Methods
Processing is carried out through electronic and telematic tools, with adequate security measures to protect personal data.
Data sent via the form is transmitted by email to the Controller through Mailgun (Sinch). Mailgun processes the data solely to send emails on behalf of the Controller and in accordance with the GDPR.
Mailgun retains technical email logs (metadata) for a limited period necessary for service functioning, according to its Privacy Policy.
A Data Processing Agreement (DPA) has been signed between the Controller and Mailgun/Sinch.
5. Data Recipients
- Mailgun Technologies, Inc. - email delivery, extra-EU transfers via SCC.
- Cloudflare, Inc. - CDN, security, technical data collection.
- Vercel, Inc. - hosting/serverless, technical log collection.
- Google LLC - via Google Maps embed.
- Competent authorities in case of legal obligations.
6. Extra-EU Data Transfers
Mailgun, Cloudflare, Vercel and Google may transfer data outside the EU, governed through Standard Contractual Clauses or according to their own policies. Policy links:
7. Data Retention
- Form data: stored in the Controller’s email inbox until a potential deletion request, except for data required to comply with legal obligations related to bookings.
- Technical browsing data: stored only for the time strictly necessary to ensure website security and functionality.
8. Data Subject Rights
The user may exercise at any time the rights provided by Articles 15-22 of the GDPR: access, rectification, erasure, restriction of processing, objection, portability.
Note: rights are limited for data necessary to comply with legal obligations related to bookings.
To exercise these rights: info@giardinodilei.it
9. Nature of Data Provision
Providing data in the form is necessary to be contacted and receive information. Technical data collected automatically is required for website operation and security. No processing is carried out for marketing purposes.
10. Automated Decision-Making
No automated decision-making or profiling is carried out.
11. Contacts
Email: info@giardinodilei.it
Phone: +39 340 361 5717
12. Updates
This notice may be modified at any time. Updated versions will be published on this page.