Privacy Policy


1. Data Controller

The Data Controller is:

2. Types of data collected

The website collects the following categories of data:

The website is an informational showcase site: it does not feature an online booking form, nor a database or any system for storing user data. Requests are made exclusively through the direct contact channels indicated above (email, phone, WhatsApp), and the related data is handled by the Controller through those tools, not on the website.

The processing of the data of guests staying at the property (e.g. mandatory registration with the public security authorities) is covered by a specific privacy notice, which is also provided at check-in.

3. Purposes and legal basis of the processing

4. Methods of processing

Data is processed using electronic and/or manual tools, according to logic strictly related to the stated purposes and, in any case, in such a way as to guarantee the security and confidentiality of the data, in compliance with Article 32 of the GDPR. Appropriate technical and organisational measures are adopted to prevent unauthorised access, loss or unlawful use of the data.

5. Cookies and third-party services

The website does not install any first-party cookies, whether technical or profiling. Third-party cookies may be installed only with the user's explicit consent, solely when loading the Google Maps map described below. For this reason, the website does not require a cookie banner.

The typographic fonts and graphic libraries (Bootstrap and its icons) are hosted directly on our website: loading them does not involve any requests to third-party servers nor the transfer of the user's IP address.

The website relies on the following third-party services, activated only following an action by the user:

For more information on the processing of data by these parties, please refer to their respective privacy policies.

6. Recipients of the data

Personal data may be processed by persons authorised by the Controller and, where necessary, disclosed to:

The data is not subject to dissemination.

7. Transfer of data outside the EU

Some of the third-party service providers (in particular Google and Meta) may transfer data to countries located outside the European Economic Area. In such cases, the transfer takes place on the basis of the appropriate safeguards provided for in Articles 44 et seq. of the GDPR, such as the standard contractual clauses adopted by the European Commission or adequacy decisions.

8. Data retention period

Personal data is kept for the time strictly necessary to achieve the purposes for which it was collected:

9. Rights of the data subject

As a data subject, you have the right to exercise, within the limits and under the conditions set out in Articles 15-22 of the GDPR:

To exercise your rights, you may write to the Controller at the email address aguafriasas@gmail.com.

10. Complaint to the supervisory authority

If you believe that the processing of your personal data is carried out in breach of the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the supervisory authority of the Member State in which you habitually reside or work.

11. Changes to this privacy policy

The Controller reserves the right to modify or update this privacy policy at any time, including in order to bring it into line with any regulatory changes. Changes will be published on this page together with the date of the last update.