This is an English translation provided for convenience. In case of any discrepancy, the Italian version prevails.

1. Data controller

The controller of personal data is:

For any privacy-related matter, please write to: info@appwieland.com

2. Data processed and purposes

2.1 Browsing the website

During normal browsing of the website appwieland.com, the IT systems and software procedures acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols:

These data are used solely to obtain anonymous statistical information on the use of the website and to check that it functions correctly. The data may be used to establish liability in the event of computer crimes against the website.
Legal basis: Art. 6(1)(f) GDPR — the Controller's legitimate interest in the security and proper functioning of the website.

2.2 Booking requests and contact

When users contact the property by email (info@appwieland.com) or phone, or through the bookpage.io booking system, the following personal data are collected:

Legal basis: Art. 6(1)(b) GDPR — performance of a contract or pre-contractual measures requested by the data subject.
Purposes: managing the booking, pre- and post-stay communication, accounting and tax obligations.
Retention: 10 years for accounting documents (legal obligation); 24 months for contact data only, where no contract was concluded.

2.3 Communication to the public security authorities (Alloggiati Web)

Under the Italian Consolidated Law on Public Security (TULPS) and the Ministerial Decree of 7 January 2013, the operator is required by law to communicate guests' identification data to the public security authorities within 24 hours of arrival, via the State Police Alloggiati Web portal. The data communicated include: first name, last name, date and place of birth, nationality, number and type of identity document, arrival and departure dates.
Legal basis: Art. 6(1)(c) GDPR — legal obligation.
Retention: according to the terms set by public security legislation.

2.4 Icons (Iconify)

The website uses the open-source Iconify service to display icons. When the page loads, the user's browser downloads the icons from the service's servers (code.iconify.design, api.iconify.design): this connection involves the transmission of the user's IP address. To speed up later visits, the icons are stored in the browser's local storage (localStorage), without any personal data.
Legal basis: Art. 6(1)(f) GDPR — the Controller's legitimate interest in the correct display of the website.

2.5 Map (Google Maps)

The home page contains a Google Maps map (Google LLC, USA) showing the location of the property. When the map loads, the user's browser connects to Google's servers, which receive the IP address and may process further data in accordance with the Google Privacy Policy.
Legal basis: Art. 6(1)(f) GDPR — the Controller's legitimate interest in showing the location of the property.

2.6 Availability search form (CiaoBooking)

The home page contains the availability search form provided by CiaoBooking, loaded from the provider's servers (cdn.ciaobooking.com): this connection involves the transmission of the user's IP address. The dates and number of guests entered are used to show availability; the search continues on the bookpage.io booking system (see section 2.2). The form does not set cookies.
Legal basis: Art. 6(1)(b) GDPR — pre-contractual measures requested by the data subject.

3. Cookies and tracking technologies

The website uses only technical cookies necessary for its operation. No profiling or marketing cookies are used. For detailed information on the cookies used, their purposes and how to disable them, please see the Cookie Policy.

4. Disclosure and dissemination of data

The personal data collected are not disseminated or transferred to third parties, except in the following cases:

5. Transfer of data outside the EU

Google LLC is based in the United States. Data are transferred in accordance with the Standard Contractual Clauses approved by the European Commission. For more details see Google Cloud Privacy.

The bookpage.io booking service may process users' personal data (name, email, dates of stay) for booking management purposes. We recommend consulting the bookpage.io privacy policy for information on server locations and data transfers.

6. Rights of data subjects

Under Articles 15–22 GDPR, users have the right to:

To exercise these rights, write to: info@appwieland.com — reply within 30 days.

7. Security

The website uses the HTTPS (TLS) protocol to protect data transmission. The Controller adopts appropriate technical and organisational measures to protect data against unauthorised access, loss, destruction or disclosure, in accordance with Art. 32 GDPR.

8. Changes to this policy

The Controller reserves the right to amend this policy at any time. Changes will be published on this page with the date of the update. Please check this page periodically.

9. Applicable legislation