Privacy Policy
How we protect your personal data
The data controller is BEATRICE SCAURI srls, registered at Largo S.M.S. dell'Evangelizzazione 6, 00144 Roma (RM) — Italy, reachable at ilmareingiardino@gmail.com.
BEATRICE SCAURI srls informs you (the User or Customer) that Regulation (EU) 2016/679 (GDPR) provides for the protection of natural persons with regard to the processing of personal data. All processing is carried out in accordance with the principles of lawfulness, fairness and transparency.
Data processing related to the web services of this site takes place at the registered offices of BEATRICE SCAURI srls and is carried out by specifically authorised personnel.
Our IT systems automatically collect certain personal data whose transmission is implicit in the use of Internet communication protocols (IP addresses, domain names, request timestamps). This data is used solely to ensure the correct functioning of the site and is deleted immediately after processing.
Voluntary submission of data through the site's contact form results in the collection of the sender's email address, which is necessary to respond to enquiries.
The site does not use profiling cookies. Visit statistics are collected with Vercel Analytics, which uses no cookies and does not track individual users. Some pages show a map provided by Google Maps: when it loads, your browser contacts Google's servers, which receive your IP address and may set their own cookies under their own policy (policies.google.com/privacy). This is a third-party service we do not control.
Purposes of processing and legal bases
- Handling of enquiries and of the contractual relationship. To conclude, manage and fulfil contact, quotation and booking requests, and to provide the services connected with the stay. Legal basis: performance of a contract to which the data subject is party, or of pre-contractual measures taken at their request, Art. 6(1)(b) of Regulation (EU) 2016/679 (GDPR).
- Organisation of the service with third-party providers. To organise and manage said requests, including by sharing data with third-party providers acting as data processors. Legal basis: performance of the contract, Art. 6(1)(b) GDPR.
- Legal obligations. To comply with legal, accounting and tax obligations and with the requirements of the competent authorities, including reporting guest details to the public security authority. Legal basis: compliance with a legal obligation, Art. 6(1)(c) GDPR.
- Informational and promotional communications. To send informational and promotional communications about our services. Legal basis: freely given consent, Art. 6(1)(a) GDPR, which may be withdrawn at any time without affecting the lawfulness of prior processing.
- Handling of complaints, disputes and litigation relating to the contractual relationship, and the exercise and protection of the Controller's rights out of court and before the courts. Legal basis: legitimate interest of the Controller under Art. 6(1)(f) of Regulation (EU) 2016/679 (GDPR), consisting in legal defence and in the protection of its contractual, financial and reputational position.
Categories of data processed
Depending on the relationship in place, the Controller processes the following categories of data:
- browsing data automatically collected by our IT systems (IP address, domain name, request timestamp);
- contact data voluntarily provided through the site's forms (name, email address, telephone number, content of the message);
- contract and booking data (dates of stay, house booked, number and names of guests, amounts, booking history);
- payment and accounting data (invoices, receipts, transaction details, data needed to collect payment);
- personal and identity-document data of guests, collected to comply with public security obligations (see the dedicated section);
- data needed to handle complaints and disputes (correspondence, contractual and payment documentation).
Guests' identity documents
Everyone staying in our houses is registered as required by art. 109 of the Italian Consolidated Law on Public Security: within twenty-four hours of arrival the details of each guest are reported to the police (Questura) through the Alloggiati Web portal. The legal basis for this processing is therefore a legal obligation; for the photo or scan of the document, which serves to verify the details recorded, the basis is the guest's consent.
For each guest we collect first and last name, gender, date and place of birth, citizenship, type and number of the identity document and place of issue. In online check-in it is the guest who uploads the photo or scan, giving consent before submitting; at the desk the staff inform the guest and take the images with their agreement, or copy the details by hand if the guest prefers.
Where the document carries at the bottom a strip of characters that can be read automatically (electronic identity card, passport), it is read to fill in the fields without copying errors. The reading takes place on the device that took the photo: the image is not sent to any external recognition service.
Images of documents are held with Cloudinary, a cloud service provider acting as data processor, in separate folders per booking, not indexed by search engines; they are deleted within seven days of departure. The personal and document details are kept for as long as legal obligations require, are not passed to third parties for commercial purposes and are not used for profiling.
Retention periods
Data is kept only for as long as necessary for the purposes for which it was collected, according to the periods set out below:
| Category of data | Retention period | Reference |
|---|---|---|
| Accounting and tax data (invoices, receipts) | 10 years | Art. 2220 of the Italian Civil Code |
| Images of identity documents | 7 days after departure | guest's consent, Art. 6(1)(a) GDPR |
| Personal data for the guest register (TULPS) | the period required by legal obligations towards the police authority | Art. 109 TULPS |
| Contract data (name, contact details, booking history) | duration of the contractual relationship plus 10 years, for tax and accounting obligations | Art. 2220 of the Italian Civil Code and defence needs |
| Data for informational and promotional communications | 24 months from the last contact, or until consent is withdrawn | consent, Art. 6(1)(a) GDPR |
| Data needed for legal defence | until the right becomes time-barred (10 years) | Art. 6(1)(f) GDPR |
Data subject rights (Arts. 15-22 GDPR)
You may exercise at any time the rights granted by Arts. 15-22 of Regulation (EU) 2016/679:
- right of access to your personal data and to information about the processing (Art. 15);
- right to rectification of inaccurate data and completion of incomplete data (Art. 16);
- right to erasure of your data (Art. 17);
- right to restriction of processing (Art. 18);
- right to data portability (Art. 20);
- right to object to processing, including processing based on the Controller's legitimate interest (Art. 21);
- right not to be subject to a decision based solely on automated processing, including profiling (Art. 22).
You also have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal, and to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
How to exercise your rights
Requests may be sent to the data controller by post or by email:
Largo S.M.S. dell'Evangelizzazione 6
00144 Roma (RM) — Italy
Last updated: 28 August 2026