Italy Official Tour
Privacy Policy
Last update: 2 September 2026
This privacy notice describes how Italy Official Tour processes the personal data of users of the website and customers of its tourism services, pursuant to articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
1. Data Controller
The data controller is:
- Company name: [DA COMPLETARE]
- Registered office: [DA COMPLETARE]
- VAT number and Tax ID: [DA COMPLETARE]
- PEC: [DA COMPLETARE]
- Email for the exercise of privacy rights: [DA COMPLETARE]
- Data Protection Officer (DPO), where appointed: [DA COMPLETARE]
2. Personal Data Processed
Depending on the relationship with the user, we process the following categories of data:
- Booking data: first name, surname, email address, telephone number, nationality, address, city, province, postal code and country.
- Billing data: company name, VAT number, tax ID, PEC address and SDI recipient code, when an invoice is requested.
- Participant data": names of persons participating in the service, provided by the customer making the booking.
- Preferences and requests": meeting point or pickup address, special requests and responses to booking questions.
- Information on particular needs": allergies, food intolerances, reduced mobility or other requirements that the customer decides to communicate to us. This information may reveal health-related data and is processed only with the explicit consent of the data subject, solely for the purpose of verifying the compatibility and safety of the service.
- Account data": credentials managed by our identity provider, profile data and saved content such as the wishlist.
- Contact data": information sent via contact forms and quotation requests for packages.
- Technical data": IP address, browser and device type, server logs and technical cookies, necessary for the functioning and security of the website.
3. Origin of data
Data is collected directly from the data subject at the time of booking, registration or submission of a request. When the booking is made through a partner tourism distribution platform, we receive from it the data necessary for the provision of the service.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Management of the booking, provision of the tourism service and customer assistance | Performance of the contract or pre-contractual measures (art. 6.1.b GDPR) |
| Management of payments and fraud prevention | Performance of the contract (art. 6.1.b) and legitimate interest (art. 6.1.f) |
| Billing, accounting, tax and documentary retention obligations | Legal obligation (art. 6.1.c GDPR) |
| Management of particular needs that may relate to health | Explicit consent of the data subject (art. 9.2.a GDPR) |
| Creation and management of the account and reserved area | Performance of contract (art. 6.1.b GDPR) |
| Response to requests submitted through contact forms | Pre-contractual measures or legitimate interest (art. 6.1.b and 6.1.f) |
| Website and systems security, and legal defence | Legitimate interest of the controller (art. 6.1.f GDPR) |
5. Recipients of data
Data may be communicated to the following parties, acting as processors or as independent controllers:
- Tourist service providers (guides, carriers, accommodation facilities, restaurants, vessel operators), limited to what is necessary to provide the booked service.
- Payment service provider: payments by card are managed directly by the payment service provider. Full card details do not pass through our systems and are not retained by us.
- Transactional email service provider, used to send confirmations, vouchers and service communications, with infrastructure located in the European Union.
- Hosting and infrastructure provider, with servers located in Germany (European Union).
- Identity and authentication provider, for secure account and credentials management.
- Partner tourism distribution platforms, when the booking occurs or is distributed through such channels.
- Tax, accounting and legal consultants, and competent authorities in cases provided for by law.
We do not sell personal data to third parties and do not communicate it for marketing purposes of third parties.
6. Transfers outside the European Union
The technical infrastructure used for the website, the database and email sending is located in the European Union. Should a supplier involve a transfer of data to third countries, such transfer shall occur exclusively in the presence of the safeguards provided for in Chapter V of the GDPR, such as an adequacy decision by the European Commission or standard contractual clauses.
7. Retention periods
| Data Category | Retention |
|---|---|
| Contractual, accounting and billing data | 10 years from contract conclusion, for civil and tax obligations |
| Booking data not followed by contract | 24 months from the request |
| Customer account data | Until request for account deletion, except data to be retained by legal obligation |
| Requests sent through contact forms | 24 months from last contact |
| Information on special needs | Until completion of the service to which they refer, unless prior withdrawal of consent |
| Technical and security logs | 12 months |
8. Nature of data provision
The provision of data necessary for booking and billing is mandatory in order to conclude and perform the contract: refusal makes it impossible to provide the service. The provision of information relating to special needs is optional, but failure to communicate them may prevent us from ensuring the compatibility and safety of the service.
9. Rights of the data subject
The data subject has the right, within the limits provided by law, to obtain access to their data and its rectification or deletion, the restriction of processing, data portability, as well as to object to processing based on legitimate interest. When processing is based on consent, the data subject may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Rights may be exercised by writing to: [DA COMPLETARE]. We respond without undue delay and in any case within one month from the request.
10. Complaint to the supervisory authority
The data subject who believes that the processing of their data violates the GDPR has the right to lodge a complaint with the Guarantor for the protection of personal data (Piazza Venezia 11, 00187 Rome — garanteprivacy.it) or to the supervisory authority of the Member State of residence.
11. Automated decision-making processes
We do not carry out processing based on entirely automated decision-making processes, including profiling, which produce legal effects on the data subject or impact their person in an analogously significant manner.
12. Cookies
The website uses exclusively technical cookies. Detailed information is provided in the Cookie Policy.
13. Amendments to this privacy notice
This privacy notice may be updated to adapt to regulatory or organisational changes. The updated version is always published on this page, with indication of the date of last update.
