Privacy policy

Privacy Policy – Summary

The data controller is Property Design, which operates in compliance with Regulation (EU) 2016/679 (GDPR) and the applicable Italian legislation on personal data protection.

Through the management system, personal and contact data of guests, property owners, and collaborators are processed, as well as data necessary for managing bookings and stays, and information required for administrative, tax, and legal obligations, including guests’ identification data and images of identity documents.

Personal data are processed exclusively for operational purposes, to comply with legal obligations (including public security requirements), for communications with guests and property owners, and for administrative and tax-related activities. Data are not used for marketing purposes nor shared with third parties for commercial purposes.

The data and images of identity documents provided by guests are used solely to comply with mandatory communications to the competent authorities (Police Headquarters / Alloggiati Web). Once the transmission has been correctly completed, images of documents and sensitive data are deleted from Property Design’s systems, unless different retention obligations are required by law.

Property Design does not store or retain guests’ identity documents beyond the time strictly necessary to fulfill legal obligations. Administrative and tax data are retained for the periods required by applicable legislation.

Data processing is carried out using IT and organizational tools suitable to ensure confidentiality, integrity, and availability of information. Access to the management system is protected by personal credentials and is granted exclusively to authorized personnel.

Use of the management system is permitted only for purposes related to the management of properties and stays. It is prohibited to use data for unauthorized purposes, copy, export, or disclose information without authorization, or access data not relevant to one’s role. Any improper use may result in revocation of access and the adoption of measures provided for by applicable legislation.

Data subjects may exercise their rights under Articles 15 et seq. of the GDPR at any time, including access, rectification, updating, erasure within legal limits, and restriction of processing, by contacting [email protected]