Privacy Policy

Last updated: 26 June 2026

This Privacy Policy explains how www.casadelgrivo.it processes the personal data of users who visit the website, submit information requests or make booking enquiries.

Data Controller

The Data Controller is:

Casa del Grivò
[Name / legal name of the Data Controller]
Borgo Canal del ferro, 19
33040 Faedis, Udine, Italy
Email: info@casadelgrivo.it
Phone: +39 379.181.5498

Types of personal data processed

The website may process the following categories of personal data.

Browsing data

The IT systems and software procedures used to operate the website acquire certain data whose transmission is implicit in the use of Internet communication protocols.

This may include IP address, browser type, operating system, pages visited, date and time of the visit and other parameters relating to the user’s device and IT environment.

Data submitted through the contact form

When users fill in the contact form available on the website, the following data may be processed:

  • name;
  • email address;
  • message content;
  • any further information voluntarily provided by the user.

Data provided by email or telephone

When users contact Casa del Grivò by email or telephone, the data necessary to respond to the request, manage the communication or provide information about the stay may be processed.

Booking-related data

In the event of a booking request or booking confirmation, data such as name, contact details, stay period, number of guests, booking information, organisational communications and data required for administrative and accounting purposes may be processed.

Data collected through cookies

The website may process data through cookies and similar technologies as described in the Cookie Policy.

Purposes and legal bases of processing

Personal data may be processed for the following purposes.

Website browsing and operation

Browsing data are processed to ensure the technical operation of the website, guarantee its security, prevent misuse or malfunctions and obtain aggregate technical statistics.

Legal basis: legitimate interest of the Data Controller.

Responding to user requests

Data submitted via form, email or telephone are processed to respond to information, availability or contact requests sent by the user.

Legal basis: performance of pre-contractual or contractual measures requested by the data subject.

Managing bookings and stays

Booking-related data are processed to manage the request, confirm the stay, organise hospitality services and provide the requested services.

Legal basis: performance of a contract or pre-contractual measures.

Administrative, tax and accounting obligations

Certain data may be processed to comply with legal obligations, including administrative, accounting and tax obligations or requests from competent authorities.

Legal basis: compliance with a legal obligation.

Use of non-technical cookies and third-party services

Any non-technical cookies, analytics tools not equivalent to technical cookies or third-party content are activated only with the user’s prior consent.

Legal basis: consent of the data subject.

Protection of the Data Controller’s rights

Data may be processed to establish, exercise or defend the Data Controller’s rights in judicial or extra-judicial proceedings.

Legal basis: legitimate interest of the Data Controller.

Processing methods

Personal data are processed using IT, electronic and, where necessary, paper-based tools, in accordance with the principles of lawfulness, fairness, transparency, minimisation and security.

The Data Controller adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, disclosure or unauthorised modification.

Recipients of personal data

Personal data may be processed by persons authorised by the Data Controller and by external providers supporting the management of the website and services, such as:

  • hosting and technical maintenance providers;
  • email service providers;
  • administrative, tax or legal consultants;
  • IT service providers;
  • public authorities, where required by law;
  • third-party service providers activated through consent, such as maps or embedded content.

Where necessary, these parties act as data processors pursuant to Article 28 GDPR or as independent data controllers.

Transfers outside the European Economic Area

Some technical or third-party services may involve the transfer of data to countries outside the European Economic Area.

In such cases, the transfer will take place in compliance with the safeguards provided by the GDPR, such as European Commission adequacy decisions, standard contractual clauses or other appropriate measures provided by applicable law.

Data retention period

Personal data are retained for the time necessary to achieve the purposes for which they were collected.

In particular:

  • data submitted through the contact form or by email are retained for the time necessary to manage the request and, as a rule, no longer than 12 months, unless further requirements connected to the relationship with the user apply;
  • data relating to bookings, payments, administrative and accounting documentation are retained for the period required by applicable tax and accounting laws;
  • technical browsing data are retained for the time strictly necessary to ensure the security and operation of the website;
  • data relating to cookie consent are retained for the period necessary to document the preferences expressed by the user and according to the settings of the consent management system.

Provision of data

Providing data through the form, email or telephone is optional, but necessary to allow the Data Controller to respond to user requests or manage bookings.

Failure to provide the necessary data may make it impossible to respond to the request or provide the requested service.

Data subject rights

Users, as data subjects, may exercise the rights provided for by Articles 15 et seq. of the GDPR, including:

  • right of access to personal data;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to object;
  • right to data portability, where applicable;
  • right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal.

To exercise these rights, users may contact the Data Controller at:

info@casadelgrivo.it

Users also have the right to lodge a complaint with the Italian Data Protection Authority.

Children’s data

The website is not specifically aimed at children. Any personal data relating to children must be provided by the person exercising parental responsibility or by authorised persons.

Links to external websites

The website may contain links to external websites or services, including social networks or map services. The Data Controller is not responsible for the privacy practices adopted by third-party websites. Users are invited to consult the relevant privacy policies.

Changes to this Privacy Policy

This Privacy Policy may be updated due to legal, technical or organisational changes. Users are encouraged to check this page periodically.