Privacy
Privacy Notice regarding the processing of personal data (pursuant to Art. 13 of EU Regulation 2016/679 – GDPR).
This notice describes how the personal data of users visiting the Dimora delle Muse website and making information requests or booking stays is processed.
1. Data Controller:
Dimora delle Muse S.n.c. di Mazzoni Michele e Schergna Sara
Registered Office: Via del Calcinaio, 15 – 53024 Sant’Angelo in Colle, Montalcino (SI), Italy.
VAT Number: 01471650521
Tel: +39 0577 1697712 | WhatsApp: +39 333 1284745.
Contact Email: info@dimoradellemuse.it | Website: www.dimoradellemuse.it.
2. Collection Channels and Personal Data Processed.
Personal data is collected exclusively via:
- Online booking engine on an external platform (my.xenion.it):
To book a stay, the user interacts with the management and online booking platform provided by the technology partner, Xenion.
The following data is collected via this form:
- First name, Last name, Email, Mobile phone number with country code;
- Full address, City, Country of origin;
- Stay dates, accommodation details, and notes for the property;
- Credit card details for guarantee purposes.
Note on promotional activities: The property does not engage in marketing activities, does not send periodic newsletters, and does not perform commercial profiling of users.
3. Purposes of Processing and Legal Bases
The collected data are processed for the following exclusive purposes:
Management and execution of the stay reservation (Xenion): finalizing the booking process, checking availability, managing the reservation guarantee, and sending logistical communications. (Legal basis: performance of a contract or pre-contractual measures – Art. 6, para. 1, letter b, GDPR).
Compliance with legal, administrative, and public security obligations: accounting, tax compliance (invoicing/receipts), application of the tourist tax, and mandatory reporting of guest details to Public Security authorities pursuant to Art. 109 T.U.L.P.S. (Legal basis: legal obligation – Art. 6, para. 1, letter c, GDPR).
Protection of the Data Controller’s rights: handling legal disputes, enforcing agreed penalties (e.g., late cancellation or no-show), or preventing unlawful acts. (Legal basis: legitimate interest – Art. 6, para. 1, letter f, GDPR).
4. Nature of Data Provision:
Xenion reservation form: providing data for mandatory fields and credit card details for the guarantee is mandatory and binding; refusal makes it impossible to confirm the reservation.
5. Data Recipients and Xenion’s Role
Personal data are processed by authorized and duly trained personnel. Data may be disclosed to external parties appointed as Data Processors pursuant to Art. 28 GDPR or independent controllers, including:
Xenion (my.xenion.it): provider of the booking engine platform and hotel management software, designated as the Data Processor for reservation receipt and storage operations;
Interbank networks and institutions: for credit card pre-authorization or verification services (for guarantee purposes);
IT providers: responsible for website management and hosting;
Tax and accounting consultants: for mandatory tax and accounting compliance;
Public authorities and law enforcement agencies: to comply with reporting obligations under applicable regulations (Alloggiati Web portal, Municipality for tourist tax).
6. Data transfer outside the EU and retention period
Data is stored on servers within the European Economic Area (EEA). Any technical transfers to third countries will take place only in compliance with Chapter V of the GDPR (adequacy decisions or Standard Contractual Clauses). Retention periods are defined as follows:
Stay details and tax documents: retained for 10 years in compliance with statutory accounting and tax obligations.
Credit card data (for guarantee purposes): retained only for the time strictly necessary to enforce the cancellation policy and deleted at the end of the stay or upon completion of any penalty processing.
Cookies and site technical data: managed in accordance with the Cookie Policy. Preference choices are stored for a maximum of 6 months.
7. Data Subject Rights and Complaints
Pursuant to Articles 15 et seq. of EU Regulation 2016/679, the user may exercise their rights at any time:
Access and Rectification: Verify the data being processed and request its update or correction.
Erasure (Right to be Forgotten): Request the deletion of data, subject to statutory obligations.
Restriction and Objection: Request a restriction on processing or object to processing on legitimate grounds.
Portability: Receive the personal data provided in a structured and readable format.
Exercise of rights: Requests may be addressed directly to the Data Controller via email at info@dimoradellemuse.it.
Right to lodge a complaint: Should the data subject believe that the processing violates GDPR regulations, they have the right to lodge a complaint with the Italian Data Protection Authority (Piazza Venezia 11, Rome – www.garanteprivacy.it) or with the competent judicial authority.
