Privacy Policy
Hotel Settefiori

This Privacy Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and describes how the website www.hotelsettefiori.com processes users’ personal data.

1. Data Controller

The Data Controller is:
Settefiori Srl
Registered office: Via Panzani 10, 50123 Florence (FI), Italy
VAT: 07486060481
Email: info@hotelsettefiori.com

No Data Protection Officer (DPO) has been appointed.

2. Types of Personal Data Processed

2.1 Data voluntarily provided by users

The website features two contact forms that may collect the following data:

  • email address
  • first and last name (only in one of the forms)

Providing your data is optional, yet necessary in order to receive a reply.

2.2 Browsing data

The website collects anonymous and aggregated browsing data through:

  • Google Analytics 4
  • Google Tag Manager
  • Meta Pixel

Such data cannot identify users and are used exclusively for statistical and analytical purposes.
Cookies are managed through a consent banner provided by Complianz, and only technical cookies are used.

No profiling is performed.

2.3 Data processed outside the website

The hotel processes additional personal data—such as booking details, payment data, special requests, and stay information—only through the hotel’s internal management systems, including:

  • WuBook (booking engine)
  • Hotel CRM

These systems are separate from the website and have their own data processing policies.

3. Purpose and Legal Basis of Processing

User data collected through the website are processed for the following purposes:

  • Responding to contact requests submitted through the forms
    Legal basis: Article 6(1)(b) GDPR — performance of pre-contractual measures requested by the user.
  • Sending booking confirmations and operational communications via external platforms (e.g., WuBook)
    Legal basis: Article 6(1)(b) GDPR.
  • Compliance with legal, administrative, accounting, and tax obligations
    Legal basis: Article 6(1)(c) GDPR.
  • Anonymous statistical analysis to monitor website traffic and improve performance
    Legal basis: Article 6(1)(f) GDPR — legitimate interest of the controller.
  • Post-stay communications, such as review requests
    Legal basis: Article 6(1)(f) GDPR.

No marketing activities, newsletters, or profiling systems are implemented via the website.

4. Methods of Processing

Personal data are processed using manual, electronic, and telematic tools, in compliance with data protection principles, confidentiality, and security measures as required by the GDPR. No automated decision-making processes are used.
5. Data Retention

  • Contact form submissions:
    The hotel does not store these data on the website. They are only kept for the time necessary to reply to the user’s message.
  • Booking and guest data:
    These are managed exclusively through WuBook or the hotel CRM and retained in accordance with legal obligations (e.g., 10 years for accounting purposes).
    The website does not store booking or payment data.
6. Data Recipients

Data may be processed by:

  • authorized hotel staff
  • the website hosting provider: Serverplan Srl (Italy)
  • WuBook (booking engine provider)
  • the hotel’s CRM system
  • analytics and traffic measurement tools (Google Analytics 4, Google Tag Manager)
  • marketing platforms (Meta and Google)

Only anonymous data are processed through analytics tools.

No other third-party recipients are involved.

7. International Data Transfers

According to the current configurations of the services used, no personal data are transferred outside the European Union. Analytics tools are set to anonymize traffic data and operate in compliance with GDPR requirements.
8. User Rights

Users may exercise the rights provided by Articles 15–22 GDPR, including:

  • the right to access their data
  • the right to rectification
  • the right to erasure
  • the right to restriction of processing
  • the right to data portability
  • the right to object
  • the right to withdraw consent (if applicable)

Requests can be submitted to:
📧 info@hotelsettefiori.com

Users also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

9. Data Security

The website adopts adequate security measures, including:

  • secure hosting located in Italy
  • HTTPS encryption
  • protection systems offered by the hosting provider

Further measures may be applied by external platforms such as WuBook and the hotel CRM.

10. Minors

The website and the hotel’s services are not intended for users under 18 years of age. The hotel does not intentionally collect data from minors.
11. Cookies

Cookies are managed through a dedicated consent system provided by Complianz. Since the website uses only technical cookies, no marketing or profiling cookies are activated. The full Cookie Policy is available on the dedicated page.
12. Amendments to This Privacy Policy

This Privacy Policy may be updated at any time. Changes will be published on this page.

Last update: December 2025