1. Data Controller
The Data Controller for personal data, pursuant to art. 4(7) of EU Regulation 2016/679 (GDPR), is:
- Sonia Caselli, Italian Tax Code (Codice Fiscale) CSLSNO84S53H501Q, host of "La Dolce Casa di Sonia", Via Bricco Dolce 15, 10020 San Sebastiano da Po (TO), Italy.
- Joint Controller under art. 26 GDPR: Lior Kaplan (spouse and co-owner), operational contact for data subject requests.
- CIN: IT001253C2SJX6FAED · CIR: 00125300001.
- Contact for exercising rights: liorkaplan1@gmail.com · WhatsApp +39 327 793 8551.
2. Data Collected
We collect the following personal data:
- Booking data (provided by the Guest via the booking form): first name, last name, email, phone, stay dates, number of guests, optional message.
- Contact data (provided via WhatsApp or email): content of the communications.
- ID data (collected at check-in, legal obligation): identity document for each Guest, for transmission to the Italian Police Alloggiati Web Portal (TULPS art. 109).
- Payment data: when paying via PayPal, the Guest interacts directly with PayPal; the Controller does not store or process card numbers. For bank transfer, only the sender's name and IBAN are received via bank statement.
- Browsing data: technical cookies (always) and, with explicit consent, analytics cookies (Google Ads/Analytics) and marketing cookies (Meta Pixel).
3. Purpose of Processing and Legal Basis
- Booking management and stay communications: legal basis = contract performance (art. 6.1.b GDPR).
- Transmission to Italian Police (Alloggiati Web): legal basis = legal obligation (art. 6.1.c GDPR · TULPS art. 109).
- Tax record-keeping: legal basis = legal obligation (art. 6.1.c GDPR · Italian tax law).
- Analytics and marketing cookies: legal basis = explicit consent (art. 6.1.a GDPR · art. 130 D.Lgs. 196/2003 as amended).
- Defense of legal rights: legal basis = legitimate interest (art. 6.1.f GDPR).
4. Data Retention
- Booking and contact data: 10 years from the stay date, for tax and ordinary contractual prescription.
- ID data (identity documents): transmitted to the Alloggiati Web Portal; we do not keep local copies beyond the 5 years required by Italian public-security law.
- Analytics cookies (Google): retention set to 14 months.
- Meta Pixel: maximum retention 13 months (Meta default).
- Formspree submissions: stored on their system per Formspree Inc. terms.
5. Recipients (Processors and Joint Controllers)
Your personal data may be communicated to the following parties, each within their competence:
- Italian Police — Alloggiati Web Portal: Guest ID data (legal obligation, TULPS art. 109).
- Formspree Inc. (Brookline, MA, USA) — site form management (Processor; non-EU transfer covered by Standard Contractual Clauses 2021/914).
- Cloudflare, Inc. (San Francisco, CA, USA) — hosting infrastructure (CDN/Pages) and DNS (Processor; SCCs 2021/914 + EU-USA Data Privacy Framework).
- PayPal (Europe) S.à.r.l. et Cie, S.C.A. (Luxembourg) — payment intermediary, if the Guest selects PayPal (Independent Controller).
- Crédit Agricole Italia S.p.A. — Host's bank, in case of bank transfer (Independent Controller).
- Google Ireland Ltd (Dublin) and Google LLC (USA) — Google Ads and (in future) Google Analytics 4, only with consent (Processors; SCCs 2021/914 + EU-USA Data Privacy Framework).
- Meta Platforms Ireland Ltd (Dublin) and Meta Platforms, Inc. (USA) — Meta Pixel, only with consent if activated (Processors; SCCs 2021/914 + EU-USA Data Privacy Framework).
- Italian tax and judicial authorities, only as required by law.
6. Non-EU data transfers
Some Processors listed above (Formspree, Cloudflare, Google, Meta) may process data on servers in the United States. The transfer takes place on the basis of:
- European Commission adequacy decision for entities certified under the EU-USA Data Privacy Framework (Decision EU 2023/1795), and/or
- Standard Contractual Clauses (SCCs) approved by the EU Commission (Decision 2021/914).
The data subject can request a copy of the safeguards by writing to liorkaplan1@gmail.com.
7. Data Subject Rights (arts. 15-22 GDPR)
The data subject has the right to: access their data, rectification, erasure (right to be forgotten), restriction of processing, portability, objection, withdrawal of consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal), and to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it).
To exercise rights: liorkaplan1@gmail.com. The Controller will respond within 30 days.
8. Cookies
This site uses:
- Technical cookies: necessary for site operation (storing cookie preferences, booking form management). No consent required (art. 122 D.Lgs. 196/2003).
- Analytics cookies (Google Ads / Analytics): for measuring ad campaign effectiveness and traffic analysis. Explicit consent required.
- Marketing cookies (Meta Pixel): for any future Meta campaign optimization. Explicit consent required.
Preferences can be changed at any time by clearing the cookie-consent value from browser local storage, or via browser cookie settings.
9. Data security
The site uses HTTPS (TLS) on all pages. Booking data is transmitted encrypted to Formspree Inc. and then delivered by email to the Controller. The Controller's email account is protected with two-factor authentication.
10. Contact
For any privacy question, contact us:
Email: liorkaplan1@gmail.com
WhatsApp: +39 327 793 8551
Postal: Via Bricco Dolce 15, 10020 San Sebastiano da Po (TO), Italy.
This notice may be updated due to regulatory changes or processing changes. The "Last updated" date is always shown at the top.