Privacy Policy – Mazzamurello B&B
Last updated: 03 March 2026
This privacy notice is provided pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR) to users who
browse and use the official website www.Mazzamurello.it.
1) Data Controller
The Data Controller is:
- Mazzamurello B&B
- Registered office: Caldarola (MC), Italy
- Email: info@mazzamurello.it
- Phone: +39 389 271 7990
The Controller processes personal data in compliance with the principles of lawfulness, fairness, transparency, and protection of
confidentiality.
2) Types of data processed
Depending on the features used, the site may process the following categories of data:
- Browsing data (e.g., IP address, device/browser type, technical logs, pages visited).
- Data provided voluntarily from the user (e.g., first name, last name, email, phone, message contents).
- Booking data (e.g., stay dates, number of guests, preferences, notes requested by the user).
- Payment-related data: the site does not store full card details; any payments
are managed by payment providers (e.g., PayPal / Stripe / payment institution) according to their respective policies.
3) Purposes of processing and legal bases
Personal data are processed for the following purposes:
- Managing contact requests (quotes, questions, information).
Legal basis: performance of pre-contractual measures (Art. 6(1)(b) GDPR) and/or consent (Art. 6(1)(a)) if required. - Managing bookings and stays (confirmations, operational communications, any changes/cancellations).
Legal basis: performance of the contract (Art. 6(1)(b) GDPR). - Administrative, accounting and tax compliance.
Legal basis: legal obligation (Art. 6(1)(c) GDPR). - Website security and prevention of abuse/fraud (technical logs, protection from attacks).
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR). - Statistics and traffic measurement (in aggregated/anonymized form or via cookies, if enabled).
Legal basis: consent for non-essential cookies (Art. 6(1)(a) GDPR) or legitimate interest for strictly necessary measures. - Marketing/Newsletter (only if enabled and with voluntary subscription).
Legal basis: consent (Art. 6(1)(a) GDPR), revocable at any time.
4) Methods of processing and security measures
Processing is carried out using IT and/or paper tools, with logic strictly related to the purposes indicated,
adopting appropriate technical and organizational security measures to prevent unauthorized access, disclosure,
alteration or destruction of data.
5) Provision of data
The provision of data is:
- necessary to manage bookings and requests: without it, it will not be possible to provide the service;
- optional for marketing purposes: failure to provide consent does not affect use of the site.
6) Recipients of the data (processors and authorized persons)
The data may be disclosed to:
- authorized personnel of the Data Controller;
- technical suppliers (hosting, maintenance, security, email) appointed Data Processors pursuant to Art. 28 GDPR;
- providers of the booking system and/or plugins used by the site (e.g., availability/booking engine), if active;
- payment providers (e.g., PayPal/Stripe), if the user makes a payment;
- administrative/tax consultants and entities required by law;
- competent authorities, in the cases provided for by the law.
The updated list of Data Processors can be requested by contacting the Data Controller at the contact details provided.
7) Data transfers outside the EU
Some providers (e.g., email, analytics, payment services) may process data outside the European Economic Area.
In such cases, the transfer will take place in compliance with the GDPR, through adequacy decisions, Standard Contractual Clauses
or other appropriate safeguards.
8) Retention periods
Data are retained for the time necessary to pursue the purposes for which they were collected, in particular:
- Requests via form/email: up to 12 months, unless further handling is required.
- Bookings and stay management: for the duration of the relationship and subsequently in accordance with statutory terms.
- Tax/accounting obligations: for the periods provided for by the applicable legislation.
- Security logs: for limited periods proportionate to protection and auditing purposes.
- Marketing/newsletter (if active): until consent is withdrawn.
9) Rights of the data subject
The user may exercise the rights provided for by Arts. 15–22 GDPR, including:
- access to data;
- rectification and updating;
- erasure (“right to be forgotten”), within the limits provided;
- restriction of processing;
- data portability (when applicable);
- objection to processing based on legitimate interest;
- withdrawal of consent (without affecting the lawfulness of processing prior thereto).
To exercise these rights, you can contact the Data Controller at:
info@mazzamurello.it .
10) Complaint to the Supervisory Authority
If you believe that the processing of personal data violates the GDPR, you have the right to lodge a complaint with the
Italian Data Protection Authority (Italy) or the competent authority of your country.
11) Cookies and tracking technologies
The site may use technical cookies necessary for operation and, if enabled, preference, statistical and/or marketing cookies.
If non-technical cookies are present, they will be used only after consent via banner/cookie manager.
Operational note: if you wish, I can also generate the Cookie Policy separate (recommended) and a short text
for the cookie banner.
12) Changes to this privacy notice
The Data Controller may update this Privacy Policy at any time. Updates will be published on this page
indicating the revision date.
For information: info@mazzamurello.it
