Informativa sulla privacy

Personal Data Processing Notice
Version 2.0 · June 2026 · Articles 13 and 14 of EU Regulation 2016/679 (GDPR)


1. Data Controller
Castello di Velona – Podere Castello 1997 S.r.l.
Località Monte Amiata Scalo n° 14-21, 53024 Montalcino (SI) – Italy
VAT No.: IT05377821003 | Tel.: +39 0577 839002
Email: info@castellodivelona.it | reservation@castellodivelona.it


2. Scope of Application
This Notice applies to all processing of personal data carried out through the website www.castellodivelona.it and its online booking platform, as well as to all activities connected with the services offered by the property:
— 5-star Resort with rooms and suites overlooking the Val d'Orcia
— OLISPA Thermal Spa (wellness treatments, day spa, thermal pools)
— Restaurants & Bars (Settimo Senso, Dolce Vita Pool Restaurant, Il Silene, Walter Redaelli)
— Organization of events, weddings, meetings and conferences
— Winery and online sale of wine (Brunello di Montalcino) and organic extra virgin olive oil
— Experiences and recreational activities in the Val d'Orcia
— Loyalty programs and gift vouchers


3. Categories of Data Processed and Collection Methods

3.1 Data provided directly by the data subject
a) Room and suite bookings — first name, surname, address, phone number, email, credit card details, stay dates, number of guests, special requests (allergies, accessibility, preferences).
b) Purchase of gift vouchers or experiences online — buyer's and beneficiary's details, address, phone number, email, payment details, any personal message.
c) Purchase of wine and oil online (Wine & Oil Shop) — name, shipping and billing address, phone number, email, payment details.
d) Information requests and contact — first name, surname, email, phone number, message content.
e) Requests for events, weddings and meetings — first name, surname, company, email, phone number, type of event, number of participants, dates, budget.
f) Newsletter subscription — first name, surname, email address.
g) Contact via WhatsApp — phone number and content of the communication, managed through Meta Platforms Ireland Ltd.

3.2 Data collected automatically during browsing
While browsing, the following data is automatically collected through cookies and similar technologies: IP address, browser type, operating system, pages visited, duration of visit, referring site, and profiling data for advertising purposes. For full details, please refer to the Cookie Policy.

3.3 Special category data
The Data Controller does not intentionally collect special category data (Art. 9 GDPR). However, in connection with Spa bookings, the data subject may voluntarily provide information relating to health conditions or allergies; such data will be processed solely to provide the requested service.


4. Purposes and Legal Bases of Processing
Managing bookings for rooms, suites and stay packages: Performance of a contract (Art. 6(1)(b))

Purchase of vouchers, experiences, wine and oil: Performance of a contract (Art. 6(1)(b))

Responding to information and quote requests: Pre-contractual measures (Art. 6(1)(b))

Tax, accounting and administrative obligations: Legal obligation (Art. 6(1)(c))

Managing complaints, disputes and legal claims: Legitimate interest / legal obligation (Art. 6(1)(c) and (f))

Sending newsletters and promotional communications: Consent (Art. 6(1)(a))

Statistical analysis and improvement of the Website: Consent (Art. 6(1)(a))

Personalized advertising and remarketing: Consent (Art. 6(1)(a))

Performance monitoring and IT security: Legitimate interest (Art. 6(1)(f))

Management of the IPrefer / Preferred Hotels loyalty program: Contract / consent (Art. 6(1)(b) and (a))


5. Processing Methods and Security
Personal data is processed using automated and/or manual tools, in compliance with appropriate technical and organizational security measures (Arts. 25 and 32 GDPR). Financial transactions are carried out via SSL/TLS encrypted connections; credit card data is handled exclusively by PCI-DSS certified payment providers.


6. Recipients and Disclosure of Data
Data Processors (Art. 28 GDPR)
— Blastness S.r.l. — website CMS and booking/voucher platform
— Sabre Corporation / SynXis — hotel booking platform
— Payment providers — for secure processing of transactions (PCI-DSS certified)
— Google LLC — Google Analytics, Google Ads, Google Hotel Ads (USA – standard contractual clauses)
— Meta Platforms Ireland Ltd. — Facebook Pixel and WhatsApp Business
— Microsoft Corporation — Microsoft Clarity, Bing Ads, Application Insights
— Email marketing providers — for sending newsletters (subject to consent)
— IPrefer / Preferred Hotels & Resorts — loyalty program (subject to consent)

Independent Controllers
Judicial and tax authorities, in cases provided for by law; credit institutions, for the processing of payments.
The Data Controller does not sell or transfer personal data to third parties for the latter's own purposes.


7. Transfer of Data to Third Countries
Some recipients (Google LLC, Meta Platforms, Microsoft Corporation) are based in the USA or in other countries outside the EEA. Such transfers take place in compliance with Art. 46 GDPR, on the basis of:
— Adequacy decisions of the European Commission (including the EU-US Data Privacy Framework)
— Standard contractual clauses approved by the European Commission


8. Data Retention Period
Booking and stay data: 10 years (tax and accounting obligations)
Purchase data (wine, oil, vouchers): 10 years from the date of the transaction
Newsletter subscription: Until consent is withdrawn, max. 5 years from the last interaction
Information requests not followed by a contract: 12 months from receipt
Cookie data: As specified in the Cookie Policy
Data processed for legal defense: For the entire duration of the proceedings


9. Rights of the Data Subject
— Access (Art. 15) obtain confirmation that processing is taking place and a copy of your personal data.
— Rectification (Art. 16) correct inaccurate data or complete incomplete data.
— Erasure (Art. 17) obtain deletion of your data in the cases provided for by the GDPR.
— Restriction (Art. 18) restrict processing in the cases provided for by law.
— Portability (Art. 20) receive your data in a structured, commonly used, machine-readable format.
— Objection (Art. 21) object to processing, in particular for direct marketing purposes.
— Withdrawal of consent (Art. 7(3)) withdraw consent given at any time.
— Complaint to the Supervisory Authority lodge a complaint with the competent Data Protection Authority.

To exercise your rights
Send a written request to: info@castellodivelona.it or reservation@castellodivelona.it
The Data Controller will respond within 30 days of receipt (extendable by a further 60 days in cases of particular complexity).
Italian Data Protection Authority (Garante Privacy): Piazza Venezia 11, 00187 Rome – www.garanteprivacy.it


10. Secure Online Booking
For online bookings, the user is redirected to the booking engine of Blastness S.r.l. and/or SynXis (Sabre Corporation), acting as Data Processors pursuant to Art. 28 GDPR. All information is protected by SSL/TLS encryption. Credit card data is handled exclusively by PCI-DSS certified operators.


11. Minors
The Website is not intended for individuals under 18 years of age. The Data Controller does not knowingly collect personal data from minors. Should such data be collected inadvertently, the Data Controller will proceed to its immediate deletion. Parents or guardians may contact the Data Controller using the details set out in Section 1.


12. Links to Third-Party Websites
The Website may contain links to third-party websites (partner booking platforms, social media, review sites). The Data Controller is not responsible for the privacy practices of such sites and invites users to review their respective notices before providing any personal data.


13. Updates
The Data Controller reserves the right to update this Notice at any time. The updated version will be published on the Website, indicating the date of last revision.