Privacy Notice — Personal Data Processing

Deze pagina is nog niet in jouw taal beschikbaar: je leest de EN-versie.

Gepubliceerd op 13 aug 2026 · Bijgewerkt op 29 aug 2026

"Buy Italy by Guiness" Platform — www.buyitalybyguiness.com

Notice provided pursuant to Arts. 13 and 14 of Regulation (EU) 2016/679 (the "GDPR") and Italian Legislative Decree No. 196 of 30 June 2003 (the "Italian Privacy Code"), as amended by Legislative Decree No. 101 of 10 August 2018.

Last updated: August 2026

1. Data controller and contact details

The data controller is Guiness Travel S.p.A., with registered office at Via Conte Rosso 52, 86100 Campobasso (CB), Italia, VAT No. 01478350703 — REA CB 111505 (the "Controller"), which operates the e-commerce platform "Buy Italy by Guiness" (the "Platform").

For any matter relating to the processing of personal data and to exercise the rights described in section 9, data subjects may contact the Controller at info@buyitalybyguiness.com or by post at the registered office indicated above.

This notice is drafted in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in accordance with Art. 12 GDPR.

2. Categories of data processed

Through the Platform, the Controller processes the following categories of personal data:

a) Identification and contact data: first name, surname, e-mail address, telephone number, billing and shipping addresses; b) Account data: login credentials (passwords are stored exclusively in encrypted form), preferences, language, order history, wallet balance, loyalty points and gift cards; c) Order and travel data: products and services purchased, bookings of packages and travel services, travel dates, number of participants and — where strictly necessary for the provision of the service (e.g. bookings on behalf of third parties) — participants' details, as well as any requirements spontaneously communicated for service delivery purposes (e.g. dietary requirements, which may reveal special categories of data under Art. 9 GDPR and are processed only with the data subject's explicit consent or within the limits of Art. 9(2) GDPR); d) Payment data: outcome and references of the transaction. Full payment card data are neither processed nor stored by the Controller: they are collected directly by Stripe (see section 6); e) Tax and accounting data: data required for invoicing and tax compliance; f) Browsing data and technical logs: IP address, device identifiers, access and error logs, data collected through cookies and similar technologies (see section 12); g) Communication data: customer service requests, correspondence, newsletter subscription.

The Controller does not request or intentionally process special categories of data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR), except as indicated under letter c).

3. Purposes and legal bases of processing

The Controller processes personal data for the following purposes, each grounded on the legal basis indicated:

• (a) Performance of the contract and pre-contractual measures: account registration and management; management of orders, shipments and returns; booking and provision of packages, travel services and experiences; management of wallet, gift cards and points; customer support; service communications relating to the order — Art. 6(1)(b) GDPR (processing necessary for the performance of a contract to which the data subject is party, or for pre-contractual measures taken at the data subject's request)

• (b) Compliance with legal obligations: invoicing, bookkeeping, tax compliance, obligations concerning package travel, responses to requests from authorities — Art. 6(1)(c) GDPR (legal obligation to which the Controller is subject)

• (c) Fraud prevention and security: anti-fraud checks on payments, prevention of abuse of the Platform and of the wallet, IT security of systems, defence of the Controller's rights in and out of court — Art. 6(1)(f) GDPR (legitimate interest of the Controller in protecting its assets, systems and customers against fraud and abuse; data subjects may object pursuant to Art. 21 GDPR)

• (d) Marketing and newsletter: sending of newsletters, promotional communications, offers and event invitations by e-mail or equivalent channels; personalisation of offers — Art. 6(1)(a) GDPR (consent — free, specific and documented, revocable at any time as easily as it was given, pursuant to Art. 7(3) GDPR and Art. 130 of the Italian Privacy Code)

It remains understood that, pursuant to Art. 130(4) of the Italian Privacy Code ("soft spam"), the Controller may use the e-mail address provided in the context of a sale to offer similar products or services, unless the data subject objects, which they may do at any time, including via the unsubscribe link included in every communication.

4. Whether the provision of data is required

The provision of the data requested for the purposes under letters (a) and (b) of section 3 is necessary: failure to provide them makes registration, conclusion of the contract or provision of the service impossible. The provision of data for marketing purposes (letter d) is optional, and refusal of consent does not in any way affect the ability to purchase on the Platform.

5. Processing methods and security

Data are processed mainly by electronic means, in compliance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality (Art. 5 GDPR). The Controller adopts appropriate technical and organisational measures pursuant to Art. 32 GDPR, including: encryption of communications (HTTPS/TLS), storage of passwords in encrypted form, need-to-know access controls, periodic backups, and logging of system access. Persons authorised to process data act under the authority of the Controller and receive instructions pursuant to Art. 29 GDPR.

6. Recipients of the data

Personal data may be disclosed, for the purposes indicated above and to the extent necessary, to the following categories of recipients:

a) Stripe (Stripe Payments Europe, Ltd., established in Ireland, and Stripe group companies): management of electronic payments. For payment processing, fraud prevention and compliance with its own regulatory obligations, Stripe acts as an independent data controller; for certain ancillary activities carried out on behalf of the Platform it acts as a processor under Art. 28 GDPR. Stripe's privacy policy is available at stripe.com/privacy; b) Carriers and logistics operators entrusted with the delivery of products, as recipients of only the data necessary for shipping (name, address, telephone number), acting as independent controllers or processors depending on the processing carried out; c) Travel service suppliers and partners (accommodation providers, carriers, guides, producers, local experience organisers), limited to the data necessary for the provision of the booked services, acting as independent controllers for the processing within their respective remit; d) DigitalOcean, as provider of the Platform's hosting and cloud infrastructure services, with servers located in the European Union, acting as a processor under Art. 28 GDPR; e) Technical and professional service providers: Platform maintenance, transactional e-mail and newsletter services, tax, legal and accounting advisors, banks; where they process data on behalf of the Controller, they are appointed processors under Art. 28 GDPR; f) Public authorities and supervisory bodies, in the cases provided for by law.

The updated list of processors is available on request at info@buyitalybyguiness.com. Personal data are neither disseminated nor sold to third parties for their own commercial purposes.

7. Transfers outside the EU

Data are processed primarily within the European Union. Certain providers (for example, Stripe or DigitalOcean group companies established in the United States, or travel service suppliers located in the country of destination of the trip or of residence of the customer) may entail the transfer of data to third countries. In such cases, the transfer takes place exclusively:

a) to countries covered by an adequacy decision of the European Commission pursuant to Art. 45 GDPR (including, for certified US providers, the EU-U.S. Data Privacy Framework); or b) on the basis of the appropriate safeguards under Art. 46 GDPR, in particular the Standard Contractual Clauses (SCCs) approved by the European Commission by Decision 2021/914, supplemented where necessary by additional measures; or c) in residual cases, on the basis of the derogations under Art. 49 GDPR, in particular where the transfer is necessary for the performance of the contract concluded with the data subject or of measures taken at the data subject's request (Art. 49(1)(b) and (c): e.g. disclosure of data to a non-EU supplier indispensable to provide a requested travel service or to ship products to a non-EU address).

A copy of the safeguards applied may be requested at info@buyitalybyguiness.com.

8. Retention periods

Data are retained for no longer than is necessary for the purposes for which they are processed (Art. 5(1)(e) GDPR), and in particular:

• accounting and tax data (invoices, transport documents, records): ten years from recording, pursuant to Art. 2220 of the Italian Civil Code and tax legislation;

• account data: until the account is deleted by the data subject or closed for prolonged inactivity notified by the Controller, without prejudice to the longer retention periods for contractual and accounting data indicated above;

• order, booking and contract data: ten years from the end of the relationship, in line with the ordinary limitation period for contractual rights (Art. 2946 of the Italian Civil Code);

• data processed for marketing purposes: until consent is withdrawn or the data subject objects, with periodic verification that the consent remains current;

• technical logs and browsing data: as a rule no longer than twelve months from collection, save for security needs or the investigation of unlawful acts;

• data relating to disputes or claims: until the dispute is settled and the relevant appeal periods have expired.

Upon expiry of these periods, data are erased or irreversibly anonymised.

9. Rights of the data subject

Pursuant to Arts. 15–22 GDPR, the data subject has the right to:

a) obtain access to their data and the information listed in Art. 15 GDPR, with a copy of the data undergoing processing; b) obtain the rectification of inaccurate data and the completion of incomplete data (Art. 16); c) obtain the erasure of data in the cases provided for by Art. 17; d) obtain the restriction of processing in the cases provided for by Art. 18; e) receive, in a structured, commonly used and machine-readable format, the data provided and processed by automated means on the basis of the contract or of consent, and transmit them to another controller (portability, Art. 20); f) object at any time, on grounds relating to their particular situation, to processing based on legitimate interest (Art. 21(1)) and, without needing to state any reason, to processing for direct marketing purposes (Art. 21(2)); g) not be subject to decisions based solely on automated processing which produce legal effects or similarly significantly affect them (Art. 22), subject to what is stated in section 14.

Requests may be addressed at any time to info@buyitalybyguiness.com, without formalities. The Controller responds within one month of receipt of the request, extendable by two further months in cases of particular complexity pursuant to Art. 12(3) GDPR. The exercise of these rights is free of charge, save for manifestly unfounded or excessive requests (Art. 12(5)).

10. Withdrawal of consent and objection to marketing

Consent given for marketing purposes may be withdrawn at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR), by: (a) the unsubscribe link at the bottom of every communication; (b) the account settings; (c) a request to info@buyitalybyguiness.com. Withdrawal takes immediate effect on subsequent promotional communications.

11. Complaint to the Supervisory Authority

Data subjects who consider that the processing infringes the GDPR have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), pursuant to Art. 77 GDPR and Arts. 140-bis et seq. of the Italian Privacy Code, or with the supervisory authority of the EU Member State of their habitual residence, place of work or place of the alleged infringement, without prejudice to any judicial remedy (Arts. 78 and 79 GDPR).

12. Cookies and similar technologies

The Platform uses:

a) technical cookies (navigation, session and functionality cookies: e.g. cart, authentication, language preferences), which are necessary for the operation of the site and may be used without consent, pursuant to Art. 122 of the Italian Privacy Code; b) analytics and marketing cookies, installed only upon consent given through the banner displayed on first access, in accordance with the Guidelines of the Italian Data Protection Authority of 10 June 2021.

Detailed information (list of cookies, duration, third parties, how to withdraw and change choices at any time) is contained in the Cookie Policy accessible from the banner and from the footer of the Platform. Closing the banner without giving consent results in the installation of technical cookies only.

13. Minors

The Platform and its purchasing services are intended for adults (18+). The Controller does not knowingly collect personal data of children under fourteen, the minimum age for consent to processing in relation to information society services under Art. 8 GDPR and Art. 2-quinquies of the Italian Privacy Code. Data of minors participating in trips or experiences are processed exclusively upon provision by the holder of parental responsibility, to the extent necessary for the provision of the service.

14. Automated decision-making

The Controller does not carry out processing involving decisions based solely on automated processing which produce legal effects concerning the data subject or similarly significantly affect them within the meaning of Art. 22 GDPR. Anti-fraud checks on payments performed by Stripe may rely on automated risk-assessment systems; any blocked transaction may be reviewed with human intervention by contacting customer service.

15. Updates to this notice

This notice may be updated to reflect regulatory, organisational or service changes. The version in force, with its last update date, is always published on the Platform; substantial changes are communicated to registered users by appropriate means.

Guiness Travel S.p.A. — Via Conte Rosso 52, 86100 Campobasso (CB)
Btw-nr.
IT01478350703