Privacy Policy
1. Data Controller
The Data Controller for personal data collected via this website is:
Wesley Beerendonk — Casa Mario
Via Roma 22 · 56046 Riparbella (PI) · Toscana · Italia
Email: info@casa-mario.it
Tel / WhatsApp: +39 331 212 8059
CIN: IT050030C2PKJC6NMG
For non-business owners, no Data Protection Officer (DPO) is appointed under Art. 37 GDPR. For privacy-related questions, contact the Data Controller via email above.
2. Categories of Personal Data Processed
- Identification: first name, last name, country of residence;
- Contact: email, phone number;
- Booking: arrival/departure dates, number of guests (adults, children, infants, pets), special requests;
- Payment: payment information is processed directly by Stripe Payments Europe Ltd (we never see your card details, only payment status, last 4 digits, brand);
- Identification documents at check-in: ID type, ID number, full name, date of birth, place of birth, nationality — collected for police registration only;
- Technical: IP address, browser, device, language preferences, cookie ID (where applicable);
- Communication content: messages you send via email or contact forms.
3. Purposes and Legal Bases
| Purpose | Legal basis (GDPR) | Retention |
|---|---|---|
| Execute your booking (reservation management, communication, refund processing) | Art. 6(1)(b) — performance of a contract | 10 years (Italian civil + tax law) |
| Police registration via Alloggiati Web (Art. 109 TULPS) | Art. 6(1)(c) — legal obligation | As long as required by Italian law |
| Tax compliance (imposta di soggiorno, IVA, IRPEF) | Art. 6(1)(c) — legal obligation | 10 years (Italian fiscal law) |
| Payment processing + fraud prevention | Art. 6(1)(b) — contract / Art. 6(1)(f) — legitimate interest | As required by PSD2 and Stripe data retention policy |
| Anonymised analytics (PostHog, where applicable) | Art. 6(1)(a) — consent (where required) | 13 months (or sooner on withdrawal) |
| Email confirmations + reminders | Art. 6(1)(b) — contract | 10 years |
4. Recipients and Data Processors
Your data is shared with the following processors under Art. 28 GDPR data processing agreements:
| Processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Beds24 (Beds24.com Pty Ltd) | Property management system, reservation storage | Australia | Standard Contractual Clauses (SCC) — Art. 46 GDPR |
| Stripe Payments Europe Ltd | Payment processing, fraud detection | Ireland (EU) | EU-based processor |
| Resend (Resend Inc.) | Transactional email delivery | USA | SCC + EU-US Data Privacy Framework |
| Vercel Inc. | Website hosting, CDN, serverless functions | USA (EU edge regions) | SCC + EU-US Data Privacy Framework |
| Polizia di Stato (via Alloggiati Web) | Mandatory guest registration under Art. 109 TULPS | Italy | Public authority — Art. 6(1)(c) GDPR |
| Comune di Riparbella | Tourist tax reporting (imposta di soggiorno) | Italy | Public authority — Art. 6(1)(c) GDPR |
| Agenzia delle Entrate (Italian tax authority) | Annual tax declarations (CU 2024+) | Italy | Public authority — Art. 6(1)(c) GDPR |
5. Data Transfers Outside the EU
Some processors (Beds24, Resend, Vercel) are located outside the European Economic Area. Transfers are protected by Standard Contractual Clauses (Art. 46 GDPR) and, where applicable, the EU-US Data Privacy Framework. A copy of the safeguards can be requested via info@casa-mario.it.
6. Your Rights
Under Arts. 15–22 GDPR and Codice Privacy, you have the right to:
- Access your personal data (Art. 15);
- Rectify incorrect or incomplete data (Art. 16);
- Erase your data ("right to be forgotten") where no legal retention obligation applies (Art. 17);
- Restrict processing (Art. 18);
- Data portability in machine-readable format (Art. 20);
- Object to processing based on legitimate interest (Art. 21);
- Withdraw consent at any time without affecting prior lawful processing (Art. 7(3));
- Lodge a complaint with the supervisory authority — in Italy: Garante per la Protezione dei Dati Personali.
To exercise your rights, contact info@casa-mario.it. We respond within 30 days (Art. 12(3) GDPR).
7. Police Registration (Schedine Alloggiati)
Italian law (Art. 109 Testo Unico delle Leggi di Pubblica Sicurezza, R.D. 18 giugno 1931 n. 773) requires accommodation providers to transmit guest identification data to the Italian State Police within 24 hours of arrival (or 6 hours for stays under 24 hours). This is a non-negotiable legal obligation. Refusal to provide ID documents at check-in prevents us from fulfilling our legal duty and will result in the booking being cancelled without refund of payment already made.
8. Cookies
This website uses only strictly necessary technical cookies for site functionality (no consent required under Art. 5(3) ePrivacy Directive / GPDP Linee Guida 10 giugno 2021). If any analytics or marketing cookies are added in the future, an explicit cookie banner with prior opt-in will be displayed in line with the Garante guidelines.
9. Changes to This Policy
We may update this Privacy Policy to reflect changes in law or our practices. The latest version is always available at casa-mario.it/privacy. Material changes will be notified by email to past guests where appropriate.
10. Contact
For any privacy-related question, including exercise of your rights:
Wesley Beerendonk — Casa Mario
Via Roma 22 · 56046 Riparbella (PI) · Toscana · Italia
info@casa-mario.it · Tel / WhatsApp: +39 331 212 8059