Skip to content

Ca' Lucerna

Privacy notice for guests

Courtesy translation. The Italian text is the one that counts: where the two differ, the Italian version prevails.

Notice under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) for anyone booking a stay from the website of Ca' Lucerna.

1. Data controller

Ca' Lucerna, Località Ca' Lucerna, 61029 Urbino PU, email ciao@calucerna.example.

2. What data we handle

  • Booking data: name and surname, email, phone, arrival and departure dates, number of adults and children, the room chosen, any requests or messages.
  • Payment data: amounts, the status of the payment, of the refund and of the cancellation. Full card or account details never reach the Property or the website: Stripe handles those.
  • Technical data for security: technical information about the request when you book and when you cancel, to prevent fraud and abuse.
  • On arrival at the property: the identity document details of each guest, collected by the Property to meet its legal obligations. This data does not pass through the website.

3. Why, and on what legal basis

  • To handle the booking, the payment, communications about the stay, cancellation and refund: performance of the contract and pre-contractual steps (Art. 6(1)(b)), for the duration of the relationship.
  • Tax and accounting obligations: legal obligation (Art. 6(1)(c)), kept for 10 years (Art. 2220 of the Italian Civil Code).
  • Reporting guests' details to the public security authority and handling the tourist tax: legal obligation (Art. 6(1)(c)), under the rules for the sector.
  • Preventing fraud and defending against disputes: legitimate interest (Art. 6(1)(f)), up to 24 months after the stay or until the dispute is closed.

Providing your booking data is necessary: without it, booking is not possible. The data is not used for marketing or for automated decisions.

4. Who we share the data with

  • Punto Nero Studio (Pesaro, Italy), which provides the website and the booking system, as data processor. It uses these sub-processors: Vercel Inc. (hosting), Supabase Inc. (database, servers in the European Union), Resend Inc. (sending emails).
  • Stripe Payments Europe, Ltd. (Ireland), for payments and refunds. For some purposes, such as fraud prevention and legal obligations, Stripe handles the data as an independent controller, under its own privacy notice.
  • Public authorities (public security, the municipality for the tourist tax, the tax authorities), where the law requires it.
  • The Property's advisers, such as its accountant, bound by confidentiality.

5. Transfers outside the European Union

Some providers are based in the United States. Transfers take place with the safeguards of Chapter V of the GDPR: the EU-U.S. Data Privacy Framework for certified providers, standard contractual clauses in the other cases.

6. Your rights

At any time you can ask for access to your data, its correction or deletion, the restriction of processing, portability, or object to processing based on legitimate interest (Arts. 15-22 GDPR), by writing to ciao@calucerna.example. Deletion is not possible for data the Property has to keep by law.

If you believe your data is not being handled properly, you can lodge a complaint with the Italian Data Protection Authority or with the authority of the country where you live.

7. Cookies

The booking page uses no profiling cookies. During payment Stripe uses technical tools needed for the payment and to prevent fraud, described in its cookie notice.