Dolomites Escapes Privacy Policy (Last updated 13/09/2026 · Version 1.0)
This notice explains how we collect and use personal data when you visit dolomitesescapes.com, send us an enquiry, book a stay, or stay with us. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended (Codice Privacy).
1. Who we are
Data Controller (Titolare del trattamento) Dolomites Adventures di Casaccia Laura Via Serdes 49, 32046 San Vito di Cadore (BL), Email: [email protected]
We are a small family business. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. All privacy requests are handled directly at the address above.
If you booked through Airbnb, Booking.com or Vrbo, that platform is an independent controller for the data you gave it. This notice covers only what we do with your data.
2. What data we collect
When you use the website Pages visited, approximate location derived from IP address, device and browser type, referral source, and interactions with the site. See our Cookie Policy for detail.
When you send an enquiry or use a contact form Name, email address, telephone number (if given), travel dates, party size, and anything you choose to write in your message.
When you book directly with us Booking details, billing name and address, payment confirmation data (we never see or store full card numbers — see §4), arrival and departure times, special requests, and any accessibility requirements you tell us about.
When you check in The identification details of every guest, including minors, which Italian law requires us to record and transmit to the Police authorities (see §3).
During your stay
Messages you send us, guest Wi-Fi connection data, and footage from external CCTV cameras (see §6). There are no cameras of any kind inside the apartments or in the internal common areas.
We do not knowingly collect data from children through the website. Data about minors staying with us is provided by the responsible adult in the booking party.
3. Why we use your data, and on what legal basis
What we do | Why | Legal basis |
|---|---|---|
Answer your enquiry and send quotes | To respond to you and take steps before a contract | Art. 6(1)(b) — pre-contractual measures |
Manage your booking, arrival, stay and departure | To perform the accommodation contract | Art. 6(1)(b) — contract |
Take payment, issue invoices and receipts, keep accounts | Tax and accounting obligations | Art. 6(1)(c) — legal obligation (Art. 2220 Civil Code; DPR 600/1973) |
Record and transmit guest identification to the Questura via the Alloggiati Web portal within 24 hours of arrival | Mandatory guest registration for all accommodation providers | Art. 6(1)(c) — Art. 109 TULPS (R.D. 773/1931) |
Report anonymous/aggregate guest movement statistics via ROSS1000 | Regional tourism statistics obligation | Art. 6(1)(c) — L.R. Veneto 11/2013 |
Collect the imposta di soggiorno (tourist tax) and declare it to the Comune di San Vito di Cadore | Municipal tax obligation | Art. 6(1)(c) — municipal tourist tax regulation |
Display our CIN and comply with short-term rental registration rules | Legal obligation | Art. 6(1)(c) |
Handle complaints, damage, insurance claims and legal disputes | To establish, exercise or defend legal claims | Art. 6(1)(f) — legitimate interest |
Operate external CCTV for property and guest security | To protect people and property | Art. 6(1)(f) — legitimate interest |
Secure and manage the guest Wi-Fi network | Network security and fair use | Art. 6(1)(f) — legitimate interest |
Send you our newsletter or seasonal offers | To keep in touch with people who want to hear from us | Art. 6(1)(a) — consent (or Art. 130(4) Codice Privacy for our own past guests, always with an unsubscribe link) |
Ask for a review after your stay | To improve and promote our business | Art. 6(1)(f) — legitimate interest |
Analytics and marketing cookies | To understand and improve the site | Art. 6(1)(a) — consent |
Accessibility and health information. If you voluntarily tell us about a disability, mobility need, allergy or dietary requirement so that we can prepare the property for you, that is special category data under Article 9 GDPR. We process it only on the basis of your explicit consent (Art. 9(2)(a)), only to accommodate your request, and we delete it after your stay. Please do not send us medical detail beyond what we need.
Providing your data. Data marked as required on our forms, and the identification data required at check-in, are necessary — we cannot take a booking or lawfully host you without them. Everything else is optional.
4. Who we share your data with
We share only what is necessary, and only with:
We do not sell your data and we do not share it for third-party advertising.
Transfers outside the EEA. Our operations are based in Italy and we keep data in the EEA wherever we can. Some providers (for example Google, Stripe) may process data in the United States or elsewhere. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, by an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified), or by another safeguard under Chapter V GDPR. You can ask us for a copy of the safeguards in place.
5. How long we keep it
Data | Retention |
|---|---|
Enquiries that do not become bookings | 24 months from last contact |
Booking, invoicing and accounting records | 10 years (Art. 2220 Civil Code) |
Guest identification data for Alloggiati Web | Transmitted to the Questura, then deleted from our systems. We do not keep photocopies or scans of identity documents. We retain only the portal transmission receipt, for 2 years |
Tourist tax records | 5 years, as required by the municipal regulation |
External CCTV footage | 7 days, then automatically overwritten |
Guest Wi-Fi connection logs | 7 days], then deleted |
Website analytics | As set out in the Cookie Policy |
Records relating to a dispute or claimlytics | Until the matter is closed and the relevant limitation period has expired |
6. CCTV
External cameras cover entrance, and side courtyard. They exist to protect guests, the building and guests' equipment.
7. Your rights
Under Articles 15–22 GDPR you have the right to:
Write to [email protected]. We reply within one month, extendable by two months for complex requests. There is no charge unless a request is manifestly unfounded or excessive.
Complaints. If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to the Italian supervisory authority:
Garante per la protezione dei dati personali Piazza Venezia 11, 00187 Roma, Italy [www.garanteprivacy.it]
If you live in another EEA country or the United Kingdom, you may also complain to your local supervisory authority.
8. Security
We use encrypted connections (HTTPS), access-controlled accounts with multi-factor authentication where available, and reputable processors bound by data processing agreements. No system is perfectly secure, but we take these obligations seriously and will notify you and the Garante of any breach where the law requires it.
9. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. Our pricing varies by season and demand; it is not based on a profile of you as an individual.
10. Changes to this notice
We will post any changes on this page and update the version date. Where changes are significant, we will tell affected guests by email.