Privacy Policy
Last update: August 11, 2026
Privacy Policy
This notice, drafted pursuant to art. 13 of Regulation (EU) 2016/679 (GDPR) and, for any personal data not obtained from the data subject, pursuant to art. 14 of the same Regulation, describes the methods of processing personal data of users interacting with the website of Hotel Palace Gestione SRL and the related services.
Data Controller
The Data Controller for personal data processing is:
Hotel Palace Gestione SRL
Via Cavour 2/4, 39012 Merano (BZ), Italia
VAT: IT01513520211
Email: info@palace.it
Phone: +39 0473 271 000
Personal Data Collected
Depending on your interaction with the Site, the Controller may collect the following categories of personal data:
Identification and contact data
- First and last name (or nickname, if applicable)
- Email address
- Phone number (optional in most forms)
- Company name, VAT number and address (for business users)
Navigation and technical data
- IP address (for security, fraud prevention and diagnostic purposes)
- Browser type and version, operating system, screen resolution
- Pages visited, session duration, interaction sequence
- Cookie identifiers and other tracking tools (see Cookie Policy)
Voluntarily provided data
- Content of messages sent via contact forms or reserved area
- Any attachments or documents uploaded
- Preferences expressed on the Site (language, theme, consent choices)
The actual data processed depends on the services active on the Site at the time of visit. For details on individual purposes, please refer to the "Purposes of Processing" section.
Nature of Data Provision
Pursuant to art. 13(2)(e) GDPR we specify that:
Mandatory data: some data are necessary for the provision of the requested service and are generally marked as such in forms (e.g. with asterisk or "required" label). They typically include identification, contact and service-functional data. Failure to provide them means the Controller cannot fulfil the user's request.
Optional data: other data (e.g. phone, business details, additional details) are optional and serve to improve service quality or enable accessory features. Failure to provide them does not prevent the use of base services.
Consent to promotional purposes (marketing, newsletter, profiling) is always optional and separate. Refusal of consent does not in any way affect the use of the requested services.
Consequences of refusal in summary:
- Refusal of mandatory data → inability to deliver the requested service
- Refusal of optional data → no consequence on base services; possible inability to access accessory features
- Refusal of marketing consent → no promotional communications, free use of all services
Purposes of Processing
Personal data are processed for the following purposes, each based on a specific legal basis under art. 6 GDPR:
Purposes necessary for the service (performance of contract or pre-contractual measures — art. 6(1)(b) GDPR)
- Responding to information requests, quotes or assistance submitted by the user
- Delivering the specific services offered by the Site (e.g. account management, bookings, purchases, content downloads)
- Managing operational communications related to the requested service
Legal compliance (legal obligation — art. 6(1)(c) GDPR)
- Tax, accounting and administrative compliance (in case of economic transactions)
- Documentary retention required by Italian law
- Response to requests from competent Authorities
Security and defence (legitimate interest — art. 6(1)(f) GDPR, subject to balancing assessment)
- IT security, abuse and fraud prevention
- Defence of the Controller's rights in court or out of court
Statistics, marketing and profiling (consent — art. 6(1)(a) GDPR and, for cookies and other tracking tools, art. 122(1) of Italian Legislative Decree 196/2003)
- Aggregated statistics on Site usage carried out through cookies or other tracking tools; consent is not required where the tool is configured so as to fall among those assimilated to technical ones under the Guidelines on cookies and other tracking tools of the Italian Data Protection Authority (Garante) of 10 June 2021 (masked IP address, aggregated statistics relating to this Site only, no cross-linking with other data and no onward transmission to further third parties by the measurement service provider)
- Sending newsletters, promotional communications and event invitations
- Personalisation of content and offers based on interests and behaviour
- Advertising remarketing on third-party platforms
Consent for non-exempt statistical, marketing and profiling purposes is always optional and separate for each purpose. Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before the withdrawal (art. 7(3) GDPR). Legitimate interest is never relied upon as a legal basis for cookies or other tracking tools that are not strictly necessary, which always require consent.
Legal Basis for Processing
Processing of personal data is based on one of the following legal bases under art. 6 GDPR:
- Consent (art. 6(1)(a) GDPR): for marketing, profiling and newsletter purposes, as well as for the installation of cookies and other tracking tools that are not strictly necessary, for which consent is also required by art. 122(1) of Italian Legislative Decree 196/2003. Consent is always optional and granular (separate per purpose). Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before the withdrawal (art. 7(3) GDPR).
- Performance of contract (art. 6(1)(b) GDPR): for the provision of services requested by the user and for the performance of pre-contractual measures (e.g. response to quote requests).
- Legal obligation (art. 6(1)(c) GDPR): for tax, accounting and administrative compliance, for any anti-money laundering obligations where applicable to the Controller, and for responding to requests from competent Authorities.
- Legitimate interest of the Controller (art. 6(1)(f) GDPR): for Site security, fraud prevention, the legitimate exercise of the right of defence and for aggregated technical analysis of how the service operates, carried out on system logs only and without the use of cookies or other tracking tools. Legitimate interest is never relied upon as a legal basis for cookies or other tracking tools that are not strictly necessary, which always require consent. Where processing is based on legitimate interest, the Controller carries out a balancing exercise between its own interest and the rights and freedoms of data subjects, in line with the indications of the European Data Protection Board (EDPB). Further information on the legitimate interests pursued and on the assessment carried out may be requested by writing to info@palace.it.
Automated decision-making (art. 22 GDPR)
The Controller does not subject the data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her (art. 22(1) GDPR).
Any marketing profiling (described, where applicable, in the dedicated section) affects only the personalisation of commercial content and produces neither legal effects nor similarly significant consequences for the data subject.
Data Recipients
Pursuant to Article 13.1.e) of the GDPR, your personal data may be disclosed to the following categories of recipients, always within the declared purposes:
- Technical service providers (hosting, CDN, security, application maintenance) — acting as Data Processors under Art. 28 GDPR;
- Mail and communication providers (transactional emails, newsletter, customer support) — Processors under Art. 28 GDPR;
- Analytics and marketing providers (see Trackers and cookies section) — Processors under Art. 28 GDPR unless otherwise stated;
- Artificial intelligence service providers (conversational assistants, automated content generation or analysis tools) — where the Site integrates such tools, the relevant providers act as Processors under Art. 28 GDPR unless otherwise stated;
- Joint controllers (Art. 26 GDPR) — where the Site embeds pixels, plugins or widgets of advertising or social media platforms, those platforms determine together with the Controller the purposes and means of the collection and transmission of data carried out through such tools (see CJEU, case C-40/17);
- Payment service providers (gateway, PSP) — Independent Controllers for data strictly necessary to the transaction;
- Consultants, accountants, legal advisors — Processors or Independent Controllers depending on the contractual relationship;
- Public authorities (judicial, tax, supervisory) — only upon specific legitimate request and within statutory limits.
The up-to-date list of Processors appointed under Art. 28 GDPR and the essential content of any joint controllership arrangements (Art. 26.2 GDPR) are available upon request at info@palace.it.
Your data is not sold, transferred or disclosed to third parties for purposes other than those declared in this notice.
Emerge Italia (Manuele Fonte) — Data Processor pursuant to art. 28 GDPR — website development, technical maintenance and management of the privacy notice — based in Bolzano (Italy) — info@emergeitalia.it.
Retention Period
Personal data is retained only for the time strictly necessary for the purposes for which it was collected, according to the specific terms set out below. After the term, data is erased or anonymised, save where retention is required for the establishment, exercise or defence of legal claims (Arts. 2946 and 2947 of the Italian Civil Code) or for regulatory obligations.
| Data category | Retention period | Legal basis |
|---|---|---|
| Contact data (information requests, quotations) | 24 months from last interaction | Legitimate interest — request management and commercial follow-up (Art. 6.1.f GDPR) |
| Contractual and tax data (invoices, receipts, contracts) | 10 years | Legal obligation — Art. 2220 Italian Civil Code and tax rules on document retention |
| Marketing and profiling data | 24 months from last consent or interaction | Consent (Art. 6.1.a GDPR) |
| System logs and security data | as a rule no longer than 30 days, according to the hosting provider's settings | Legitimate interest — IT security (Art. 6.1.f GDPR, in compliance with Art. 32 GDPR) |
| AI assistant conversations (where present on the Site) | 12 months | Performance of the contract or pre-contractual measures and legitimate interest (Art. 6.1.b/f GDPR) |
| Statistical and analytics data | 14 months, or the different period configured in the tool used | Consent (Art. 6.1.a GDPR and Art. 122(1) of Italian Legislative Decree 196/2003), except analytics tools which, where configured under the conditions set out in the Guidelines on cookies and other tracking tools of the Italian Data Protection Authority of 10 June 2021, are treated as technical cookies |
| Cookies and tracking identifiers | See the Cookie Policy | Consent (Art. 6.1.a GDPR and Art. 122(1) of Italian Legislative Decree 196/2003); technical cookies are exempt from consent |
| Proof of consent (record of the choice expressed in the banner and of consent to promotional communications) | for as long as necessary to discharge the burden of proof and in any case no longer than 10 years from withdrawal or from the end of the relationship | Burden of proof under Art. 7.1 GDPR |
The data subject may at any time request early erasure of their data by writing to info@palace.it, except where the Controller is required to retain it by law.
Extra-EU Data Transfers
Some providers and Data Processors (see "Data Recipients") are based outside the European Economic Area (EEA). The Controller ensures that such transfers take place in compliance with arts. 44-49 GDPR through one of the following safeguards:
- Adequacy decision under art. 45 GDPR: for countries recognised as adequate by the European Commission; the up-to-date list is published by the Commission and, as at the date of this notice, includes among others the United Kingdom, Switzerland, Andorra, Argentina, Canada (commercial sector), the Faroe Islands, Guernsey, Israel, the Isle of Man, Jersey, New Zealand, Uruguay, Japan and the Republic of Korea
- EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795 of 10 July 2023): for US providers that are DPF-certified at the time of the transfer; where certification is absent or ceases to apply, the transfer is covered by the Standard Contractual Clauses
- Standard Contractual Clauses (SCC) under Implementing Decision (EU) 2021/914 of the European Commission, as appropriate safeguards under art. 46 GDPR: for providers not covered by an adequacy decision, supplemented — where necessary following the transfer impact assessment — by additional technical measures (encryption in transit and of stored data, pseudonymisation, logical data segregation), in line with the CJEU Schrems II judgment (C-311/18 of 16 July 2020)
- Binding Corporate Rules (BCR) under art. 47 GDPR, for providers that have adopted them
The data subject may request a copy of the safeguards adopted and the updated list of processing countries by writing to info@palace.it.
Personal data breach notification
In the event of a personal data breach pursuant to art. 4(12) GDPR, the Controller:
- Notifies the supervisory authority (art. 33 GDPR): the breach is communicated to the competent supervisory authority — in Italy the Garante per la protezione dei dati personali — without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
- Communication to the data subject (art. 34 GDPR): where the breach is likely to result in a high risk to the rights and freedoms of the data subject, the Controller communicates the breach to the data subject without undue delay, describing its nature and providing the name and contact details of the data protection officer or other contact point, the likely consequences and the measures taken or proposed to remediate it; the communication is not required in the cases set out in art. 34(3) GDPR.
All breaches are documented by the Controller in a breach register pursuant to art. 33(5) GDPR.
A data subject who believes they have been affected by a breach of their data may contact the Controller at info@palace.it for information on the measures taken.
Marketing and Profiling
Subject to the data subject's explicit and separate consent, the Controller may process data for commercial and profiling purposes.
What we mean by profiling
Pursuant to art. 4(4) GDPR, profiling consists of automated analysis of personal data to evaluate aspects relating to the person, preferences, interests, behaviour. On the Site, profiling materialises in:
- Analysis of pages visited and Site interactions
- Creation of user segments with similar interests
- Personalisation of commercial communications based on segments
- Display of relevant ads on third-party platforms (remarketing)
Your specific rights (arts. 21 and 22 GDPR)
- Objection: you may object at any time and without having to give reasons to processing for direct marketing purposes, including profiling related to such marketing (art. 21(2)-(3) GDPR); for processing based on legitimate interest you may object on grounds relating to your particular situation (art. 21(1) GDPR)
- Not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you (art. 22(1) GDPR)
- Request human intervention, express your view and contest the automated decision
How to withdraw consent
- By clicking the unsubscribe link included in every promotional email
- By contacting the Controller at info@palace.it
- Through the cookie preferences control available on the Site
Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before the withdrawal (art. 7(3) GDPR).
Data Security
Hotel Palace Gestione SRL adopts technical and organisational measures appropriate under art. 32 GDPR to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing.
Measures adopted, depending on the platform and services used, include:
- Encryption in transit: HTTPS connections with up-to-date TLS protocols (TLS 1.2 or higher) for all communications
- Encryption of stored data: encryption of data persisted on databases and backup systems, where supported by the services used
- Credentials management: strong, securely stored credentials, multi-factor authentication for admin accounts, least-privilege principle
- Pseudonymisation and minimisation of data where technically feasible (art. 32(1)(a) GDPR)
- Periodic backups and procedures for timely restoration of availability and access to personal data in case of physical or technical incident (art. 32(1)(c) GDPR)
- Periodic checks: regular evaluation and verification of the effectiveness of security measures (art. 32(1)(d) GDPR)
- Access traceability: logging of access to systems processing personal data, within the limits allowed by the platform used
- Timely security updates on the systems and services used
- Instructions and confidentiality obligations for persons authorised to process personal data (art. 32(4) GDPR)
- Data breach management procedure: notification to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (art. 33 GDPR), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons
System logs
For IT security, abuse prevention, debugging and technical diagnostics, the infrastructure hosting the Site (the hosting provider and, where present, the CDN provider, appointed Data Processors under art. 28 GDPR) automatically records certain data relating to the requests received by the servers (so-called system logs):
- visitor IP address;
- browser type and version (user-agent);
- date and time of the request;
- URL of the requested page and HTTP response code;
- any referrer URL.
Legal basis: legitimate interest of the Data Controller in Site security and abuse prevention (art. 6.1.f GDPR), in compliance with the security obligations set out in art. 32 GDPR.
Retention: system logs are kept for a limited period, as a rule no longer than 30 days, according to the hosting provider's settings, unless further retention is required for ascertainment, dispute or legal defence purposes.
Recipients: logs are not disclosed to third parties, unless requested by judicial or other competent Authorities.
Children
The Site is not directed to children under 14. Pursuant to Art. 8 of Regulation (EU) 2016/679 and Art. 2-quinquies of Italian Legislative Decree 196/2003, consent to the processing of personal data for information society services is validly given by minors aged 14 or older; for younger children, consent must be given or authorised by the holder of parental responsibility.
The Controller does not knowingly collect personal data of children under 14. If we become aware of having collected such data without valid parental consent, we will delete it without delay.
Parents or guardians who believe that a minor has submitted personal data without authorisation may contact us at info@palace.it to request removal.
Data Subject Rights
As a data subject, pursuant to arts. 15-22 GDPR, you have the right to:
- Access (art. 15) — obtain confirmation of processing and a copy of your personal data
- Rectification (art. 16) — correct inaccurate data or complete incomplete data
- Erasure (art. 17) — request erasure of data ("right to be forgotten"), within the limits provided by law
- Restriction (art. 18) — restrict processing in certain cases
- Notification (art. 19) — have rectifications, erasures and restrictions communicated by the Controller to the recipients of the data and, upon your request, be told who those recipients are
- Portability (art. 20) — receive your data in a structured, commonly used and machine-readable format, where processing is based on consent or on a contract and is carried out by automated means
- Objection (art. 21) — object at any time and without giving any reason to processing for direct marketing purposes, including profiling related to such marketing (art. 21(2)-(3) GDPR); for processing based on legitimate interest you may object on grounds relating to your particular situation (art. 21(1) GDPR)
- Automated decision-making (art. 22) — not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you
- Withdrawal of consent (art. 7(3)) — withdraw consent at any time and as easily as it was given; withdrawal does not affect the lawfulness of processing carried out before the withdrawal
How to exercise your rights: write to info@palace.it. The Controller provides a reply without undue delay and in any event within one month of receipt of the request; that period may be extended by two months, taking into account the complexity and number of the requests, informing the data subject of the extension, together with the reasons for the delay, within one month of receipt of the request (art. 12(3) GDPR). Replies are free of charge, except for manifestly unfounded or excessive requests (art. 12(5) GDPR).
Complaint to the supervisory authority: you also have the right to lodge a complaint with the competent supervisory authority (art. 77 GDPR). In Italy, the Garante per la Protezione dei Dati Personali:
- Address: Piazza Venezia 11, 00187 Rome
- Website: www.garanteprivacy.it
- Email: garante@gpdp.it
- PEC: protocollo@pec.gpdp.it
Changes to the Privacy Policy
Hotel Palace Gestione SRL reserves the right to amend this Privacy Policy at any time to comply with regulatory, organisational or technological developments. Changes will be published on this page with the indication of the date of last update.
In the event of substantial changes affecting processing, data subjects will be informed by means of a clear notice on the Site or by email, if a contact address is available.
Users are invited to consult this page periodically to stay informed about the processing carried out.
Contacts
For any question regarding the processing of your personal data or to exercise the rights under arts. 15-22 GDPR, you can contact the Controller:
Email: info@palace.it
Phone: +39 0473 271 000
Address: Via Cavour 2/4, 39012 Merano (BZ), Italia
The Controller provides a reply without undue delay and in any event within one month of receipt of the request; that period may be extended by two months, taking into account the complexity and number of the requests, informing the data subject of the extension, together with the reasons for the delay, within one month of receipt of the request (art. 12(3) GDPR).
Dedicated Cookie Policy
For detailed information about cookies and tracking tools installed on the Site, their purposes, durations, providers and how to manage or withdraw consent, please refer to the Cookie Policy, which is an integral part of this Privacy Policy.