Privacy Policy - Villa InCanto Rome Opera Experience

Last updated: September 18, 2025

1. Data Controller

Villa InCanto, di Alessandro Fantini
Tax Code: FNTLSN61H!/H501R
VAT: 12196891001
Email: privacy@villaincantoroma.com
Phone: +39 06 333 62 48

2. Data We Collect

Contact Form Data

When you contact us through our website form:

Required data:
  • First and last name
  • Email address
  • Message content
Optional data:
  • Phone number
Booking Data

When you make a reservation (via Airbnb or our booking system):

  • Full name and contact details
  • Payment information (processed securely by third parties)
  • Dietary restrictions and special requests
  • Attendance and experience feedback
Automatic Data Collection

When you visit our website, we automatically collect:

  • IP address and approximate location
  • Browser type and version
  • Device information
  • Pages visited and time spent
  • Referring website
  • Language preference
We do not collect sensitive data or special categories of personal data unless strictly necessary for dietary requirements.

3. Processing Purposes

We process your personal data for the following purposes:

Communication
  • Responding to information requests
  • Booking assistance and support
  • Customer service and follow-up
Service Delivery
  • Managing reservations and attendance
  • Handling dietary restrictions
  • Personalizing your Villa InCanto experience
Analytics & Improvement
  • Website usage analysis
  • Service improvement
  • User experience optimization
Marketing (Optional)
  • Commercial communications (with consent)
  • Newsletter and updates
  • Personalized advertising

4. Legal Basis

Data processing is based on:

  • Consent (Art. 6(1)(a) GDPR) - for marketing communications and optional services
  • Contractual necessity (Art. 6(1)(b) GDPR) - for booking management and service delivery
  • Legitimate interest (Art. 6(1)(f) GDPR) - for website analytics and service improvement
  • Legal obligation (Art. 6(1)(c) GDPR) - for tax and accounting requirements

5. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your browsing experience:

Essential Cookies

Required for website functionality. Always active.

  • Session management
  • Language preferences
  • Cookie consent status
Analytics Cookies

Help us understand website usage. Optional.

  • Google Analytics
  • Performance monitoring
  • User behavior analysis
Marketing Cookies

Enable personalized advertising. Optional.

  • Facebook Pixel
  • Google Ads
  • Retargeting campaigns
Functional Cookies

Enhanced features and personalization. Optional.

  • YouTube videos
  • Interactive maps
  • Social media integration
You can manage your cookie preferences at any time using the settings button on our website or through your browser settings.

6. Processing Methods

Data is processed:

  • With electronic and telematic tools
  • With organizational and logical methods strictly related to the purposes
  • With appropriate security measures to ensure data confidentiality and integrity
  • Through automated and manual processes as appropriate
  • Following data minimization principles - collecting only necessary data

7. Data Retention

Personal data will be kept for the time strictly necessary to achieve the purposes for which it was collected:

Data Type Retention Period Reason
Contact requests 2 years from collection Follow-up and service improvement
Booking data 7 years from service delivery Legal and tax obligations
Marketing data Until consent is withdrawn Consent-based processing
Analytics data 26 months (Google Analytics default) Website optimization
Legal obligations As required by applicable law Compliance with Italian law

8. Data Sharing

We may share your data with the following third parties:

Service Providers:
  • Web hosting - for website operation
  • Email services - for communication management
  • Booking platforms - Airbnb, FareHarbor for reservation management
  • Payment processors - for secure payment processing
Analytics Providers:
  • Google Analytics - website performance analysis
  • Facebook/Meta - advertising effectiveness measurement
Legal Requirements:

We may disclose your data if required by law, court order, or to protect our rights and safety.

We do not sell, rent, or trade your personal data to third parties for their marketing purposes.

9. Your Rights

Under the GDPR (Articles 15-22), you have the following rights:

Right of Access

Obtain confirmation of data processing and access to your personal data

Right of Rectification

Correct inaccurate data or complete incomplete data

Right to Erasure

Request deletion of your data (right to be forgotten)

Right to Restriction

Limit processing under specific conditions

Right to Data Portability

Receive your data in a structured, machine-readable format

Right to Object

Object to processing based on legitimate interests

Withdrawing Consent

You can withdraw consent at any time without affecting the lawfulness of processing based on consent given before withdrawal

How to Exercise Your Rights

To exercise any of these rights, contact us at:

  • Email: privacy@villaincantoroma.com
  • Phone: +39 06 333 62 48 or +39 338 11 11 398

We will respond within 30 days of your request.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

Technical Measures
  • SSL/TLS encryption for data transmission
  • Secure hosting infrastructure
  • Access controls and authentication
  • Regular security updates and backups
Organizational Measures
  • Staff training on data protection
  • Limited access on need-to-know basis
  • Internal privacy policies and procedures
  • Data breach response procedures

These measures protect your data from:

  • Unauthorized access
  • Alteration or corruption
  • Unauthorized disclosure
  • Accidental or unlawful destruction
In case of a data breach affecting your rights and freedoms, we will notify you and relevant authorities within 72 hours as required by GDPR.

11. Updates

This Privacy Policy may be updated periodically to reflect changes in our services, legal requirements, or best practices. The most recent version will always be available on our website with indication of the last update date.

How We Notify You

For material changes to this policy, we will notify you by email (if you have provided one) or through a prominent notice on our website at least 30 days before the changes take effect.

12. Contact & Complaints

Contact Us

For questions about this Privacy Policy or your personal data:

Villa InCanto, di Alessandro Fantini
Email: privacy@villaincantoroma.com
Phone: +39 06 333 62 48
Mobile: +39 338 11 11 398
File a Complaint

You have the right to lodge a complaint with the Data Protection Authority:

Garante per la Protezione dei Dati Personali
Piazza di Monte Citorio, 121 - 00186 Roma
Email: garante@gpdp.it
Tel: +39 06 69677.1
www.gpdp.it

This Privacy Policy has been drafted in compliance with EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

Villa InCanto is committed to environmental sustainability. This policy covers data processing for our eco-friendly operations powered by 100% renewable energy.

Cookie Settings

Manage your cookie preferences

Your Data

Request a copy of your data

Request Data
Delete Data

Request deletion of your data

Delete Data