Transparency and personal data

Privacy notice.

Notice provided under Article 13 of Regulation (EU) 2016/679 for availability enquiries relating to Suite Il Mulino, Via Ottaviano 34, Sperlonga, Italy.

Last updated: 31 July 2026 · Version 1.1

1. Who processes your data

Data ControllerMaria Vittoria Levantini

Owner of Suite Il Mulino, Via Ottaviano 34, 04029 Sperlonga (LT), Italy. To exercise your rights or make a privacy enquiry, you may use the Manager’s contact details shown alongside.

Data Processor and contact pointEleonora Russo — sole trader

Registered office: Via Pierpaolo Pasolini 19, 20151 Milan (MI), Italy
VAT number: 13066850960
Email: suiteilmulino@libero.it

The Manager handles enquiries on behalf of the owner under the property management appointment. Requests concerning data protection rights will be handled through this contact point and, where necessary, forwarded to the Controller.

2. Data collected

  • identity and contact data: first name, surname, email address and any other contact details included in the message;
  • details of the requested stay: dates, number of guests and preferred contact method;
  • the free-text message and subsequent correspondence;
  • technical data generated by email services and, after publication, by the hosting provider, such as IP address, connection date and time, and security logs.

Please do not include identity documents, health information, religious beliefs, sexual orientation or any other special-category data that is not necessary for a simple availability enquiry.

3. Purposes and legal bases

PurposeLegal basisData concerned
To reply to enquiries about availability, price and stay conditions.Steps taken at the data subject’s request prior to entering into a contract, Article 6(1)(b) GDPR.Identity, contact details, dates, guests and message.
To continue managing a booking if the user accepts a subsequent offer.Performance of a contract and pre-contractual steps, Article 6(1)(b) GDPR; applicable legal obligations, Article 6(1)(c).Contact and booking data, together with any additional data required by law at a later stage.
To prevent misuse, protect systems and establish, exercise or defend legal claims.The Controller’s legitimate interest in security and the protection of rights, Article 6(1)(f) GDPR.Strictly necessary communications and logs.

Acknowledging this notice is required before the enquiry can be prepared, but it is not “privacy consent”: the processing needed to reply is based on pre-contractual steps requested by the user. Data will not be used for newsletters or marketing without a separate legal basis and, where required, specific consent.

4. Providing your data

Name, email address, acknowledgement of this notice and acceptance of the terms are required to send a complete enquiry and allow a reply. A phone number is optional when email contact is selected, but becomes mandatory when phone contact is requested. Dates, number of guests and the message are optional, although omitting them may require further contact. If required data is not provided, the form cannot send the enquiry.

5. How the form works

After “Send enquiry” is selected, the data is transmitted over HTTPS to an endpoint hosted on the same domain. The endpoint validates the required fields and forwards the summary to the Manager’s operational email address. The website does not use a database to store the form content; technical and security logs generated by the hosting provider and data retained by the recipient’s email systems may remain. The page then displays the outcome and an enquiry reference without opening the user’s email application.

6. Recipients and service providers

Within the limits of their functions, data may be accessed by the Controller, the Manager and authorised collaborators. It may also be processed by technical providers acting as independent controllers or processors, including:

  • the email service provider used by the recipient of the enquiry;
  • the hosting and technical maintenance provider that receives the form and forwards its summary;
  • professional advisers, public authorities or other entitled parties, only where necessary to comply with the law or protect legal rights.

Data is neither sold nor made public.

7. Transfers outside the European Economic Area

The landing page uses locally hosted fonts and does not contact Google Fonts. Some email or hosting providers may process data outside the European Economic Area. Any such transfer must rely on an adequacy decision, standard contractual clauses approved by the European Commission or another safeguard provided by Articles 44 and following of the GDPR.

8. Retention periods

  • Enquiries that do not become bookings: up to 12 months after the last communication, unless a dispute needs to be handled.
  • Enquiries that become bookings: for the duration of the relationship and subsequently for the periods required by applicable administrative, accounting, tax and public-security obligations.
  • Disputes or protection of rights: for the time required to handle the matter and until the relevant limitation periods have expired.
  • Technical logs: for the period set by the hosting provider and limited to what is necessary for security and operation.

9. Cookies and similar technologies

The current landing page does not install profiling cookies, perform analytics or embed maps, videos, social widgets or remote fonts. A consent banner is therefore not currently required. The hosting provider may generate technical logs necessary for security, delivery of the site and handling the form submission. If non-essential tools are added, this notice and any consent mechanism must be updated before they are enabled.

10. Your rights

Where provided by the GDPR, you may request access, rectification, erasure, restriction of processing, data portability and object to processing based on legitimate interests. You may also request information about the source and recipients of the data.

Requests may be sent to suiteilmulino@libero.it, using “Privacy — Suite Il Mulino” as the subject. A response will be provided without undue delay and generally within one month, subject to any extension permitted by the GDPR.

You may lodge a complaint with the Italian Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, email protocollo@gpdp.it, certified email protocollo@pec.gpdp.it, website www.garanteprivacy.it.

11. Minors and automated decision-making

The enquiry must be submitted by an adult. The form is not intended to collect children’s data directly. No profiling or solely automated decision-making producing legal or similarly significant effects is carried out.

12. Security and updates

Data is processed using organisational and technical measures appropriate to the risk. However, no electronic transmission can be guaranteed as completely secure; users should not send excessive information or documents that have not been requested.

This notice may be updated if the form, providers or purposes change. The current version is identified by the date shown above.

Official legal sources