Transparency

Privacy Policy

Last updated: 2026

Data Controller

The Data Controller for the personal data collected through this website is:

Armando Chiola

Via Materna n. 26, 65010 Collecorvino (PE)

lanticaquerciabb@gmail.com

P.IVA 01924880683CIN IT068015B4PGFOTTFVCIR 068015BBI0001

The Data Controller has not appointed a Data Protection Officer (DPO), as the conditions set out in art. 37 GDPR are not met (processing is not carried out on a large scale and does not involve special categories of data).

Navigation Data

The computer systems and software procedures used to operate this website acquire, in the course of their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category includes: IP addresses, browser type and operating system, URI (Uniform Resource Identifier) of the resources requested, the time of the request, the method used to submit the request to the server and other parameters relating to the operating system and IT environment of the user. This data is used solely for the purpose of obtaining anonymous statistical information on the use of the site and to monitor its correct functioning. The data may be used to ascertain liability in the event of hypothetical computer crimes against the site.

The website is hosted on a virtual private server (VPS) managed by a third-party hosting provider, acting as Data Processor pursuant to art. 28 GDPR. Access logs reside physically on that provider's servers.

Navigation data is retained for no more than 7 days, unless necessary to investigate computer crimes, in which case retention may be extended for the strictly necessary period (Italian DPA Decision no. 360/2024).

Legal basis: legitimate interest of the Data Controller pursuant to art. 6.1.f GDPR (IT security and service operation).

Interactive Map

The Contacts page includes an interactive map provided by OpenFreeMap (openfreemap.org), an open-source digital cartography service. When you visit that page, your browser makes direct requests to OpenFreeMap servers to load map tiles. In this context, your IP address is transmitted to OpenFreeMap servers. OpenFreeMap does not use tracking cookies and declares that it does not retain IP addresses under normal operating conditions.

Legal basis: legitimate interest of the Data Controller pursuant to art. 6.1.f GDPR (provision of map functionality).

For more information, see the OpenFreeMap Privacy Policy: openfreemap.org/privacy

Booking Requests and Contact

The website does not collect or transmit users' personal data to its own servers through contact forms. The buttons and links on the website (WhatsApp, email, phone) open the corresponding application on the user's device. Any personal data shared by users in the context of an information or booking request (name, stay dates, number of guests, preferences) is transmitted directly to the B&B via the channels chosen by the user (WhatsApp or email) and is processed exclusively for the management of the request.

Inquiry / contact

Legal basis: performance of pre-contractual measures at the data subject's request (art. 6.1.b GDPR). Retention: until the request is fulfilled and for the following 12 months.

Confirmed booking

Legal basis: performance of a contract (art. 6.1.b GDPR). Retention: for the duration of the relationship and up to 10 years thereafter for tax and accounting obligations under D.P.R. 600/1973 and D.P.R. 633/1972.

Recipients of personal data

Personal data collected through this website may be disclosed to the following categories of recipients:

Hosting provider (VPS)

The provider supplying the virtual server hosting this website receives navigation data (access logs). It acts as a Data Processor pursuant to art. 28 GDPR, under a dedicated data processing agreement.

Provider name: to be updated upon server configuration.

OpenFreeMap

Receives the user's IP address when the interactive map is loaded on the Contacts page. Acts as an independent data controller for the data it receives on its own servers. No data is transferred to OpenFreeMap outside of this specific technical interaction.

No other party receives users' personal data. Data is not sold, transferred or disclosed to third parties for marketing, profiling or advertising purposes.

Transfers of data to third countries

The Data Controller does not systematically transfer personal data to countries outside the European Economic Area (EEA). The following details situations in which a transfer may occur:

Hosting provider (VPS)

The server is expected to be hosted with a provider whose infrastructure is located within the European Union. In that case, no extra-EEA transfer occurs. Should the chosen provider operate servers outside the EEA, the transfer will take place on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to art. 46.2.c GDPR, or another appropriate safeguard.

OpenFreeMap

OpenFreeMap's main servers are located in Europe. However, the service uses globally distributed CDN nodes for tile delivery: some requests may therefore pass through servers located outside the EEA, resulting in the user's IP address being transmitted to those servers.

OpenFreeMap is currently unable to provide adequate safeguards under art. 46 GDPR for non-EEA nodes. Where it occurs, the transfer is based on the derogation under art. 49.1.c GDPR (transfer necessary to provide the service requested by the data subject). Users can avoid any such transfer by not visiting the Contacts page of the website.

Cookies

This website uses only technical and functional cookies, necessary for the correct functioning of the site. No profiling or tracking cookies are used. For a detailed list of cookies used, please see the Cookie Policy.

Profiling and automated decisions

The Data Controller does not carry out any profiling activities nor make decisions based solely on automated processing of personal data, including profiling, which produce legal effects or similarly significantly affect the data subject (art. 13.2.f GDPR).

Rights of the Data Subject

Pursuant to arts. 15–22 of the GDPR, you have the right to:

  • Access your personal data
  • Obtain the rectification or erasure thereof
  • Request the restriction of processing
  • Object to processing
  • Request data portability
  • Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it)

Requests will be processed within 30 days of receipt, extendable up to 90 days in cases of particular complexity (art. 12.3 GDPR). The Data Controller will reply to the email address from which the request was received, unless otherwise indicated.

To exercise your rights, please write to:

lanticaquerciabb@gmail.com

Changes to this Policy

The Data Controller reserves the right to make changes to this policy at any time. Changes will be published on this page with an updated date at the bottom.