Last updated: 6 August 2026

This Privacy Policy describes how the personal data of users visiting www.casainpietra.eu are processed, pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”) and the applicable Italian legislation on the protection of personal data.

Data Controller

The Data Controller is:

[Daniela Baccagin] – Casa in Pietra
Via della Confraternita 3 e 5
09075 Santu Lussurgiu (OR) – Italia
E-mail: daniela@schimanski.ch
Telefono: +49 1511 1902545

For any request concerning the processing of personal data or the exercise of your rights, you may contact the Data Controller using the details provided above.

2. Types of data processed

Browsing data

During normal browsing, the computer systems and software procedures used to operate the website may automatically collect certain technical data, including:

  • IP address;
  • browser and device type;
  • operating system;
  • date and time of the request;
  • pages visited;
  • address of the referring page;
  • server response codes;
  • other information relating to the user’s computer environment.

These data are used exclusively to ensure the proper operation and security of the website, obtain technical information about its use and establish liability in the event of cybercrime or unlawful activities.

Data voluntarily provided by the user

The voluntary sending of messages to the email addresses or telephone numbers published on the website entails the collection of the user’s contact details and any other information included in the communication.

The data may include, by way of example:

  • name and surname;
  • email address;
  • telephone number;
  • information concerning availability or booking requests;
  • number and characteristics of guests;
  • any other information voluntarily provided.

Users are advised not to provide unnecessary personal data and, in particular, special categories of data, such as health information, unless this is strictly necessary to meet specific accommodation requirements.

3. Purposes and legal bases of processing

Personal data may be processed for the following purposes:

Operation and security of the website

Browsing data are processed to enable access to the website, ensure its security, prevent misuse and resolve technical problems.

The legal basis is the Data Controller’s legitimate interest in ensuring the proper and secure operation of the website, pursuant to Article 6(1)(f) of the GDPR.

Responding to user enquiries

Data provided by email or telephone are used to respond to questions, requests for information, availability enquiries and quotation requests.

The legal basis is the performance of pre-contractual measures taken at the request of the data subject, pursuant to Article 6(1)(b) of the GDPR.

Management of bookings and stays

If an enquiry results in a booking, the data will be processed to manage the contractual relationship, the stay, payments, service communications and the relevant administrative obligations.

The legal basis is the performance of a contract, pursuant to Article 6(1)(b) of the GDPR.

Compliance with legal obligations

Certain data may be processed to comply with tax, accounting, administrative, public security or other obligations imposed by applicable legislation.

The legal basis is compliance with a legal obligation, pursuant to Article 6(1)(c) of the GDPR.

Protection of legal rights

Data may be retained and used where necessary to establish, exercise or defend the Data Controller’s rights in judicial or out-of-court proceedings.

The legal basis is the Data Controller’s legitimate interest in protecting their rights, pursuant to Article 6(1)(f) of the GDPR.

4. Provision of personal data

Providing personal data by email or telephone is optional. However, failure to provide the necessary data may prevent the Data Controller from responding to an enquiry, checking the availability of the apartments or managing a booking.

5. Processing methods and security measures

Personal data are processed using electronic, telematic and, where necessary, paper-based tools. Appropriate technical and organisational measures are adopted to protect them against unauthorised access, loss, destruction, disclosure or unlawful use.

Data are processed in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy and storage limitation established by the GDPR.

6. Data retention period

Personal data are retained only for as long as necessary for the purposes for which they were collected. In particular:

  • browsing data and technical logs are retained for the period necessary to ensure the operation and security of the website, according to the retention periods applied by the hosting provider, unless they are required to investigate unlawful activities;
  • enquiries that do not result in a booking are retained for a maximum of 12 months after the end of the communication;
  • data relating to bookings, payments and administrative or tax documentation are retained for the period required by law, generally 10 years;
  • data required to protect the Data Controller’s rights may be retained until the relevant limitation periods have expired.

At the end of the applicable retention periods, the data will be deleted or anonymised.

7. Recipients of personal data

Personal data may be disclosed, only where necessary, to:

  • website hosting and maintenance providers;
  • tax, accounting, legal or IT consultants;
  • service providers involved in managing the property and bookings;
  • payment institutions or banking services, where necessary;
  • public authorities, law enforcement agencies or other parties to whom disclosure is required by law.

Providers that process personal data on behalf of the Data Controller are appointed, where necessary, as Data Processors pursuant to Article 28 of the GDPR.

Personal data are neither publicly disclosed nor sold to third parties.

8. Transfers outside the European Economic Area

The Data Controller gives preference to services that process personal data within the European Economic Area.

If any provider transfers personal data to a country outside the European Economic Area, the transfer will be carried out in accordance with Articles 44 and following of the GDPR, on the basis of an adequacy decision by the European Commission, Standard Contractual Clauses or another safeguard provided for by law.

9. Links to external websites

The website contains links to external platforms, including Booking.com.

When users select an external link, they leave www.casainpietra.eu and access a service operated by a third party. Any processing carried out by these platforms is governed by their respective privacy policies and is not controlled by the Data Controller of Casa in Pietra.

Users are therefore advised to read the privacy policy of the external service before providing personal data or making a booking.

10. Cookies

The website uses only technical cookies required for its operation and to store user preferences.

In particular, the following cookie may be used:

Name: pll_language
Purpose: To remember the language selected by the user and display the website in the appropriate language during subsequent visits.
Type: Technical and functional cookie.
Duration: 12 months.

User consent is not required for technical cookies, although appropriate information must still be provided.

According to the website’s current configuration, it does not use advertising, profiling or analytics cookies and does not directly embed maps, videos or social media content capable of installing third-party cookies.

Users may control, restrict or delete cookies through their browser settings. Disabling technical cookies may affect certain website features, such as remembering the selected language.

11. Automated decision-making and profiling

Users’ personal data are not subject to fully automated decision-making processes and are not used for profiling activities.

12. Rights of the data subject

Where provided for by law, data subjects may exercise the rights recognised by Articles 15–22 of the GDPR and, in particular, may request:

  • access to their personal data;
  • rectification of inaccurate data;
  • completion of incomplete data;
  • erasure of personal data;
  • restriction of processing;
  • data portability, where applicable;
  • objection to processing based on legitimate interests;
  • withdrawal of consent, where processing is based on consent.

Requests may be sent to daniela@schimanski.ch.

Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority, through the website www.garanteprivacy.it, or to bring proceedings before the competent courts.

13. Changes to this Privacy Policy

This Privacy Policy may be updated following regulatory, technical or organisational changes or the introduction of new services on the website.

The updated version will be published on this page, together with the date of the latest update.