This is an English translation provided for convenience. In case of any discrepancy, the Italian version prevails.
1. Data controller
The controller of personal data is:
- Controller: Galazzini Carmelo
- VAT no.: 03024180238
- Registered office: Via Fornare 77, 37010 Torri del Benaco (VR), Italy
- Email: info@appwieland.com
- Phone: +39 329 348 6523
For any privacy-related matter, please write to: info@appwieland.com
2. Data processed and purposes
2.1 Browsing the website
During normal browsing of the website appwieland.com, the IT systems and software procedures acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols:
- IP addresses or domain names of the computers and devices used by visitors
- URI/URL addresses of the requested resources
- time of the request
- method used to submit the request to the server
- size of the file obtained in response
- numeric code indicating the status of the server response (success, error, etc.)
- other parameters relating to the user's operating system and IT environment
These data are used solely to obtain anonymous statistical information on the use of the website and to check that it functions correctly. The data may be used to establish liability in the event of computer crimes against the website.
Legal basis: Art. 6(1)(f) GDPR — the Controller's legitimate interest in the security and proper functioning of the website.
2.2 Booking requests and contact
When users contact the property by email (info@appwieland.com) or phone, or through the bookpage.io booking system, the following personal data are collected:
- first and last name
- email address
- phone number
- dates of stay, number of guests
- any special requests
Legal basis: Art. 6(1)(b) GDPR — performance of a contract or pre-contractual measures requested by the data subject.
Purposes: managing the booking, pre- and post-stay communication, accounting and tax obligations.
Retention: 10 years for accounting documents (legal obligation); 24 months for contact data only, where no contract was concluded.
2.3 Communication to the public security authorities (Alloggiati Web)
Under the Italian Consolidated Law on Public Security (TULPS) and the Ministerial Decree of 7 January 2013, the operator is required by law to communicate guests' identification data to the public security authorities within 24 hours of arrival, via the State Police Alloggiati Web portal. The data communicated include: first name, last name, date and place of birth, nationality, number and type of identity document, arrival and departure dates.
Legal basis: Art. 6(1)(c) GDPR — legal obligation.
Retention: according to the terms set by public security legislation.
2.4 Icons (Iconify)
The website uses the open-source Iconify service to display icons. When the page loads, the user's browser downloads the icons from the service's servers (code.iconify.design, api.iconify.design): this connection involves the transmission of the user's IP address. To speed up later visits, the icons are stored in the browser's local storage (localStorage), without any personal data.
Legal basis: Art. 6(1)(f) GDPR — the Controller's legitimate interest in the correct display of the website.
2.5 Map (Google Maps)
The home page contains a Google Maps map (Google LLC, USA) showing the location of the property. When the map loads, the user's browser connects to Google's servers, which receive the IP address and may process further data in accordance with the Google Privacy Policy.
Legal basis: Art. 6(1)(f) GDPR — the Controller's legitimate interest in showing the location of the property.
2.6 Availability search form (CiaoBooking)
The home page contains the availability search form provided by CiaoBooking, loaded from the provider's servers (cdn.ciaobooking.com): this connection involves the transmission of the user's IP address. The dates and number of guests entered are used to show availability; the search continues on the bookpage.io booking system (see section 2.2). The form does not set cookies.
Legal basis: Art. 6(1)(b) GDPR — pre-contractual measures requested by the data subject.
3. Cookies and tracking technologies
The website uses only technical cookies necessary for its operation. No profiling or marketing cookies are used. For detailed information on the cookies used, their purposes and how to disable them, please see the Cookie Policy.
4. Disclosure and dissemination of data
The personal data collected are not disseminated or transferred to third parties, except in the following cases:
- Technical service providers (Hostinger hosting, bookpage.io booking system) acting as Processors under Art. 28 GDPR
- Providers of services embedded in the website (Google for the map, Iconify for icons, CiaoBooking for the search form), as described in section 2
- Competent authorities where required by law (law enforcement, Italian Revenue Agency, etc.)
- Professionals (accountant, tax adviser) for legal obligations
5. Transfer of data outside the EU
Google LLC is based in the United States. Data are transferred in accordance with the Standard Contractual Clauses approved by the European Commission. For more details see Google Cloud Privacy.
The bookpage.io booking service may process users' personal data (name, email, dates of stay) for booking management purposes. We recommend consulting the bookpage.io privacy policy for information on server locations and data transfers.
6. Rights of data subjects
Under Articles 15–22 GDPR, users have the right to:
- Access (Art. 15) — obtain confirmation as to whether personal data concerning them are being processed and receive a copy of such data
- Rectification (Art. 16) — obtain the correction of inaccurate or incomplete data
- Erasure (Art. 17) — obtain the erasure of data ("right to be forgotten"), subject to legal obligations
- Restriction (Art. 18) — obtain the restriction of processing in certain cases
- Portability (Art. 20) — receive their data in a structured, machine-readable format
- Objection (Art. 21) — object to processing at any time
- Complaint — lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it)
To exercise these rights, write to: info@appwieland.com — reply within 30 days.
7. Security
The website uses the HTTPS (TLS) protocol to protect data transmission. The Controller adopts appropriate technical and organisational measures to protect data against unauthorised access, loss, destruction or disclosure, in accordance with Art. 32 GDPR.
8. Changes to this policy
The Controller reserves the right to amend this policy at any time. Changes will be published on this page with the date of the update. Please check this page periodically.
9. Applicable legislation
- EU Regulation 2016/679 (GDPR)
- Italian Legislative Decree no. 196 of 30 June 2003 (Privacy Code), as amended by Legislative Decree 101/2018
- Decisions of the Italian Data Protection Authority
- Italian Legislative Decree no. 70 of 9 April 2003 (e-commerce)