Privacy Policy

1. Data Controller

The data controller responsible for the processing of personal data on this website is:

Visit Noto Stays
Fabrizio Bonina
Via Galileo Galilei 34
96017 Noto (SR)
Italy

Email: fabrizio@visitnotostays.com


2. Scope of this Privacy Policy

This Privacy Policy applies to all users of visitnotostays.com and governs the collection, processing, and storage of personal data obtained through:

  • Website browsing
  • Booking requests and reservations
  • Contact forms
  • Email communication
  • WhatsApp communication
  • Online check-in procedures
  • Third-party booking systems and embedded services


3. Categories of Personal Data Processed

3.1 Identity Data

We may process:

  • Full name
  • Date of birth
  • Nationality
  • Contact details (email address and telephone number)
  • Identification information required under Italian law for accommodation providers


3.2 Booking Data

We may process:

  • Arrival and departure dates
  • Number of guests
  • Accommodation selected
  • Special requests related to the stay
  • Reservation history


3.3 Communication Data

We may process:

  • Messages sent via contact forms
  • Email correspondence
  • WhatsApp communications
  • Customer support requests


3.4 Contact Form Data

When submitting a contact request through our website, we collect:

  • Name
  • Email address
  • Message content

This information is used solely for responding to enquiries and providing customer support.


3.5 Technical Data

We may automatically collect:

  • IP address
  • Browser type and version
  • Device information
  • Operating system
  • Referring URLs
  • Date and time of access


3.6 Usage Data

We may collect information relating to:

  • Pages visited
  • Time spent on pages
  • Navigation behaviour
  • Interactions with website features


3.7 Cookie Data

We may use:

  • Necessary cookies
  • Functional cookies
  • Analytics cookies (where consent is provided)
  • Booking-related cookies


4. Purpose of Processing

Personal data is processed for the following purposes:

  • Managing booking enquiries and reservations
  • Providing accommodation services
  • Completing legally required guest registration procedures
  • Communicating with guests before, during, and after their stay
  • Providing customer support
  • Managing payments and reservations
  • Improving website functionality and user experience
  • Ensuring technical security and fraud prevention
  • Complying with legal, tax, and regulatory obligations


5. Legal Basis for Processing

Personal data is processed on the following legal grounds under Article 6 GDPR:


Contractual Necessity

Processing required for booking management and accommodation services.


Legal Obligations

Processing required to comply with Italian legal obligations, including guest registration, tax requirements, and tourism regulations.


Legitimate Interests

Including:

  • Website management
  • Service improvement
  • Security and fraud prevention
  • Communication with guests


Consent

Where required, including:

  • Analytics cookies
  • Non-essential cookies
  • Future marketing technologies, if introduced


6. Booking System (Smoobu)

Visit Noto Stays uses Smoobu GmbH as its booking management and reservation platform.

Personal data may be processed through Smoobu for:

  • Booking management
  • Availability management
  • Reservation administration
  • Guest communications

Processing is carried out under GDPR-compliant agreements.


7. Guest Identification Documents

Italian law requires accommodation providers to register guest information with the competent public authorities through the Alloggiati Web system.

Guests may be required to provide identification information before arrival in order to fulfil these legal obligations.

Where copies or images of identification documents are temporarily collected for verification and registration purposes, they are processed exclusively for compliance with applicable legal requirements.

Once the legally required registration process has been completed, copies or images of identification documents are permanently deleted without undue delay, unless a longer retention period is required by law.

Visit Noto Stays does not retain identification document copies longer than necessary for legal compliance.


8. Cookies and Similar Technologies

Necessary Cookies

Required for website functionality, security, and booking processes.


Functional Cookies

Used to support website features and booking services.


Analytics Cookies

Where consent is provided, analytics services may be used to understand website performance and visitor behaviour.


Consent Management

Visitors may accept, reject, or customise cookie preferences through the cookie banner presented when accessing the website.

Consent may be withdrawn at any time.


9. Third-Party Services

The website may use services provided by third parties, including:

  • Smoobu Booking Engine
  • Google Maps
  • WhatsApp
  • Google Analytics (if enabled)
  • Google Search Console
  • Payment service providers

These providers may process personal data according to their own privacy policies.


10. WhatsApp Communication

If you contact Visit Noto Stays via WhatsApp, personal data may also be processed by:

WhatsApp Ireland Limited and/or Meta Platforms entities.

Visit Noto Stays has no control over the independent processing activities of these providers.

Please consult WhatsApp's own Privacy Policy for additional information.


11. Data Sharing

Personal data is never sold.

Data may be shared only where necessary with:

  • Booking system providers
  • Payment service providers
  • IT and hosting providers
  • Tax, legal, and regulatory authorities
  • Public authorities where required by law

All service providers are required to implement appropriate safeguards for personal data protection.


12. International Data Transfers

Certain service providers may process personal data outside the European Economic Area (EEA).

Where such transfers occur, appropriate safeguards are implemented, including:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions where applicable
  • Other legally recognised transfer mechanisms


13. Data Retention

Personal data is retained only for as long as necessary to:

  • Fulfil contractual obligations
  • Comply with legal and tax requirements
  • Meet guest registration obligations under Italian law
  • Resolve disputes or enforce agreements

When retention periods expire, personal data is securely deleted or anonymised.


14. Data Security

Appropriate technical and organisational measures are implemented to protect personal data, including:

  • Secure hosting environments
  • Access controls
  • Encrypted communications where applicable
  • Regular software and security updates


15. Your Rights Under GDPR

Subject to applicable law, you have the right to:

  • Access your personal data
  • Rectify inaccurate information
  • Request erasure of personal data
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent where processing is based on consent

Requests may be submitted using the contact details provided in this Privacy Policy.


16. Third-Party Websites

This website may contain links to external websites.

Visit Noto Stays is not responsible for the content, security, or privacy practices of third-party websites.


17. Changes to This Privacy Policy

This Privacy Policy may be updated from time to time to reflect legal, operational, or technical developments.

The most recent version will always be published on this page.

18. Contact

For questions relating to this Privacy Policy or the processing of personal data, please contact:

Visit Noto Stays

Fabrizio Bonina

Via Galileo Galilei 34

96017 Noto (SR)

Italy

Email: fabrizio@visitnotostays.com


- Last updated: 14.06.2026 -