Privacy policy

Personal data processing notice pursuant to EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003.

1. Data Controller

The Data Controller is Valerio Buti — Datanode Srl, Via Carraia 104, Empoli (FI), Italy. For any request concerning personal data: info@datanode.it.

2. Data processed and purposes

a) Booking requests: name, email address, phone number, number of guests, optional message, preferred language — processed to answer your request and manage the resulting booking (art. 6.1.b GDPR — pre-contractual and contractual measures).

b) Technical form data: IP address, browser identifier, date/time of consent — processed to prevent abuse and automated submissions and to document consent (art. 6.1.f GDPR — legitimate interest; art. 7 GDPR).

c) Guest data upon confirmed booking: data required by Italian law for accommodation providers, including guest notification to the State Police through the Alloggiati Web portal (art. 109 TULPS) and tourist-tax obligations where established by the municipality (art. 6.1.c GDPR — legal obligation).

d) Reserved-area accounts (staff): name, email, phone, for the operational management of the apartments (art. 6.1.b GDPR).

No profiling or marketing activity is carried out.

3. Processing methods

Data are processed electronically with appropriate security measures (encrypted transport, access control, data minimisation: operational staff can only see dates, apartment, reference name and number of guests — never contact details or amounts).

4. Cookies

The public website uses no profiling cookies and no third-party analytics. The reserved area uses a single technical session cookie, strictly necessary for authentication. The request form is protected by Cloudflare Turnstile, which processes technical data (including the IP address) for the sole purpose of telling real users from bots; provider notice: www.cloudflare.com/privacypolicy.

The full, up-to-date list of cookies in use is published in the cookie notice.

5. Recipients

Data may be processed by: the hosting provider (server located in the European Union); the email service provider; Cloudflare Inc., limited to the anti-abuse service described in section 4; public authorities where required by law. Data are never sold or shared for commercial purposes.

6. Retention

Unconfirmed booking requests are kept for 12 months, then deleted. Data of cancelled bookings are anonymised after 24 months. Data of confirmed bookings are kept for the duration of Italian tax obligations (10 years), with personal contact details anonymised 24 months after departure. Backups follow automatic rotation cycles.

7. Your rights

Under articles 15–21 GDPR you may request access to your data, rectification, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Requests: info@datanode.it. You may also lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali — www.garanteprivacy.it).

8. Provision of data

Fields marked as required in the request form are necessary to handle the request; failure to provide them makes the request impossible to process.

9. Changes to this notice

This notice may be updated; the current version is always published on this page together with its last-modified date.

Last modified: 20 August 2026