1. Data Controller
The Data Controller of personal data is:
Colleverde SAS di Cangiotti Carlo & C
Via Bocca Trabaria Ovest, 96 — 61029 Urbino (PU) · Marche · Italy
VAT 02705160410
General email: info@colleverde-urbino.it
Dedicated privacy contact: amministrazione@colleverde-urbino.it
Phone: +39 0722 339213
The Controller has assessed and is not required to appoint a Data Protection Officer (DPO) under art. 37 GDPR. For any communication relating to the processing of personal data, please use the dedicated address amministrazione@colleverde-urbino.it: requests are routed directly to the person in charge of handling data subject rights.
2. Categories of data processed
The Controller processes the following categories of personal data:
- Personal and contact data: first name, surname, date and place of birth, address, email, telephone number, identity document (required for mandatory Public Security registration pursuant to art. 109 TULPS — Italian Royal Decree 773/1931);
- Booking data: stay dates, room type, number of guests, special requests, food/dietary preferences;
- Payment data: credit card data or other payment instruments (handled via PCI-DSS certified gateways; the Controller does not store full card details);
- Site navigation data: IP address, user-agent, pages visited, session duration, traffic source, data collected via cookies (see Cookie Policy);
- Communication data: content of emails, contact forms, WhatsApp messages, reviews and feedback;
- Newsletter data: email, possible name, preferences, consent logs, open/click data;
- SPA data (if applicable): age/date of birth for minor access verification, any health declarations voluntarily provided for safety purposes;
- Data collected via the AI conversational assistant "Colleverdino" (v2.0): first name, surname, email, telephone voluntarily provided by the user at the chatbot consent gate; content of messages exchanged with the assistant; session metadata (UUID identifier, language, source page, user-agent, SHA-256 hashed IP); preferences detected by the AI (intent: booking/information/other) and — when available — PMS quotation proposed in the chat. Important: users are invited not to enter into the chatbot any special category data (e.g. health) or data not strictly necessary; conversation content is transmitted to the external AI provider (see section 5).
3. Purposes of processing and legal bases
Data is processed for the following purposes:
| Purpose | Legal basis | Retention |
|---|---|---|
| Execution of the hotel contract, booking and stay management | Art. 6(1)(b) GDPR. contract execution | Duration of stay + 10 years (tax obligations) |
| Compliance with legal obligations (Public Security, tax, health) | Art. 6(1)(c) GDPR. legal obligation | According to applicable legal terms |
| Response to information requests and contact forms | Art. 6(1)(b) GDPR. pre-contractual measures | 24 months unless relationship continues |
| AI conversational assistance ("Colleverdino") and operation of the chatbot service | Art. 6(1)(a) GDPR. explicit consent at the chatbot gate Art. 6(1)(b) GDPR. pre-contractual measures (for chats aimed at booking/quote) | Session + 12 months (see section 6-bis) |
| Newsletter and promotional communications | Art. 6(1)(a) GDPR. explicit consent | Until withdrawal of consent |
| Statistical analysis and Site improvement | Art. 6(1)(f) GDPR. legitimate interest | 26 months |
| Personalised marketing, profiling | Art. 6(1)(a) GDPR. consent | Until withdrawal |
| IT security and abuse prevention (rate-limit, event logs) | Art. 6(1)(f) GDPR. legitimate interest + art. 32 GDPR | 12 months (hashed IP) |
| Legal defence | Art. 6(1)(f) GDPR. legitimate interest | Applicable limitation periods |
4. Nature of the data provision
Providing data required for booking and legal compliance is mandatory: refusal makes it impossible to confirm the stay. Providing data for marketing, newsletter, and use of the AI chatbot is optional: refusal does not in any way affect access to the services of the Property, which remain always available via phone, email and traditional contact forms.
5. Categories of recipients
Data may be communicated to:
- Staff of the Property (waiters, receptionists, maintainers), authorised to process data and trained on confidentiality;
- IT service providers, hotel management software (PMS Passepartout Welcome), payment gateways, booking platforms, OTAs — all appointed as Data Processors pursuant to art. 28 GDPR;
- Advertising and analytics platforms (Meta Platforms Ireland Ltd., Google Ireland Ltd., Microsoft Ireland, Cloudflare, Brevo) for conversion measurement and possible campaign delivery (see section 5-bis and Cookie Policy);
- Anthropic PBC (548 Market St, San Francisco, CA, USA), provider of the Claude AI model used by the conversational assistant "Colleverdino" on the Site. Anthropic receives in real-time, and only for the time strictly necessary to generate the response, the content of chat messages and session metadata. It is appointed Data Processor pursuant to art. 28 GDPR via Anthropic's standard DPA. Anthropic does not use chat content to train its models (setting applied via API header and commercial contract);
- Public Security authorities, tax authorities, health authorities (for mandatory legal compliance, in particular art. 109 of Italian Royal Decree 773/1931 TULPS);
- Professional advisors (accountant, lawyer) for management and defence needs;
- Insurance companies in case of claims.
5-bis. Server-side tracking and conversion measurement
To measure the effectiveness of its advertising campaigns, the Controller uses server-side tracking technologies that send confirmed booking information to advertising platforms via dedicated APIs (Meta Conversions API and Google Analytics 4 Measurement Protocol), in addition to traditional cookie-based tracking.
- Data transmitted: pseudonymised booking code, transaction value, stay dates, and optional customer contact data SHA-256 encrypted before sending (irreversible hashing). Platforms never receive cleartext data.
- With full marketing consent: encrypted data matched to user profile for measurement, optimisation and lookalike audiences.
- Without marketing consent: Meta's Limited Data Use activated + GA4 identifiers omitted. Aggregate measurement only, no profiling/retargeting.
- Total opt-out: no tracking at all, even aggregated (PMS flag isEscludiDaAutomatismi or direct request to amministrazione@colleverde-urbino.it).
Legal bases: art. 6.1.b (contract), art. 6.1.f (legitimate interest aggregate measurement, LDU), art. 6.1.a (marketing consent). Internal audit trail for accountability art. 5.2 GDPR.
5-ter. AI conversational assistant "Colleverdino"
The Site features an AI conversational assistant ("Colleverdino") based on the Claude language model from Anthropic PBC (USA). Processing details are as follows:
- Activation: the chatbot opens only after the user explicitly accepts the privacy notice via the consent gate (art. 7 GDPR). No data acquisition before consent.
- Data collected at the gate: first name, surname, email, telephone declared by the user + privacy flag + optional marketing flag. This data remains in the Site database.
- Message content: messages exchanged during the chat are sent to Anthropic (USA) to generate the AI response. Conversations are also stored on our DB to enable conversation continuity and for audit purposes.
- No training: by contract with Anthropic, content exchanged in the chatbot is not used to train new AI models.
- Encryption: the user's IP address is hashed (SHA-256 with salt) before being stored in the database; we never retain the IP in cleartext.
- Usage limits: maximum 30 messages per session, maximum 5 sessions/day per IP, capped monthly budget. These are technical defences against abuse and prompt injection.
- No automated decisions with legal effects: the chatbot does NOT make decisions producing legal effects on the user (no credit scoring, no automated contractual eligibility). Any booking still goes through human confirmation by the front office.
- Right to object: at any time, the user can close the chatbot and directly contact the front office via phone, WhatsApp or email to obtain the same service (no disadvantage).
6. Transfers outside the EU
Some third-party services involve data transfers to non-EU countries, in particular USA. Safeguards adopted for each transfer:
- EU-US Data Privacy Framework (Commission adequacy decision of 10/07/2023): Meta Platforms, Google LLC, Microsoft Corporation have adhered to the DPF — transfers are covered by the adequacy decision under art. 45 GDPR;
- Anthropic PBC (USA): Anthropic is certified under the EU-US Data Privacy Framework since August 2024. Chatbot-related transfers are therefore covered by the EU adequacy decision. As an additional measure, the Controller has signed Anthropic's standard Data Processing Agreement, which incorporates the Commission's Standard Contractual Clauses (SCC) as a supplementary safeguard;
- Standard Contractual Clauses (SCC) approved by the Commission + supplementary technical measures (SHA-256 hashing, pseudonymisation, IP truncation) for non DPF-certified providers;
- For bookings without marketing consent: Limited Data Use Meta + anonymised tracking Google.
A copy of DPAs and SCCs with individual Processors is available on request by writing to amministrazione@colleverde-urbino.it.
6-bis. Data retention periods
The Controller stores personal data only for the time strictly necessary to the processing purposes, according to the following schedule (arts. 5.1.e and 13.2.a GDPR):
| Data type | Retention | Legal basis |
|---|---|---|
| Generic leads (contact requests, unfulfilled quotes) | 6 months | art. 6.1.b GDPR |
| Leads in progress / actual customers | 10 years | Italian Civil Code art. 2220 (tax obligation) |
| Visitor IP and User-Agent | 6 months (then anonymised) | art. 6.1.f (security) |
| Newsletter subscribers | Until withdrawal + 12 months log | art. 6.1.a (consent) |
| Cookie consent banner | 12 months | Italian DPA Provision 10/06/2021 |
| Server-side tracking with full consent | 24 months (then anonymised) | art. 6.1.a |
| Server-side tracking LDU/anonymous | 6 months | art. 6.1.f |
| Consent audit trail | 24 months | art. 5.2 (accountability) |
| Colleverdino chatbot sessions (UUID, language, IP hash) | 12 months | art. 6.1.a / 6.1.b |
| Colleverdino chatbot messages (conversation content) | 12 months (cascade from session) | art. 6.1.a |
| Chatbot consent data (name/email/phone at gate, NO booking) | 12 months | art. 6.1.a |
| Chatbot data converted to lead/booking | as Lead in progress (10 years) | Italian Civil Code art. 2220 |
| Check-in records (art. 109 Italian R.D. 773/1931 TULPS) | 10 years | legal obligation |
| Digital consent signature (check-in) | 10 years | legal obligation + accountability |
| Admin access logs / security events | 12 months | art. 32 (security) |
Once these periods elapse, data is automatically deleted or anonymised by a scheduled daily routine. The data subject may request a copy of their retention audit trail by writing to amministrazione@colleverde-urbino.it.
7. Data subject rights
You may exercise the rights under arts. 15-22 GDPR (access, rectification, erasure, restriction, objection, portability) at any time. In particular:
- Right of access (art. 15) — view your data in self-service: colleverde-urbino.it/i-miei-dati-richiedi.php (you will receive a secure email link, valid 24h);
- Right to erasure (art. 17) — write to amministrazione@colleverde-urbino.it, we handle requests within 30 days (subject to legal tax retention obligations);
- Right to rectification, restriction, objection, portability — write to amministrazione@colleverde-urbino.it;
- Consent withdrawal — change your preferences from the cookie banner ("Manage cookie preferences" link in the website footer) or via the unsubscribe link in every newsletter email. Consent to the AI chatbot can be withdrawn at any time by closing the chatbot window and requesting conversation deletion via email;
- Complaint — to the Italian Data Protection Authority (www.garanteprivacy.it) or to the supervisory authority of your EU Member State.
You have the right at any time to:
- access your data (art. 15 GDPR);
- request rectification (art. 16 GDPR);
- request erasure, where no retention obligation applies (art. 17 GDPR);
- request restriction of processing (art. 18 GDPR);
- object to processing based on legitimate interest or marketing (art. 21 GDPR);
- receive your data in a structured format and port it to another controller (art. 20 GDPR);
- withdraw consent at any time, without prejudice to the lawfulness of the previous processing (art. 7 GDPR);
- lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
To exercise these rights, please write to amministrazione@colleverde-urbino.it, attaching a copy of an identity document.
8. Data security
The Controller adopts technical and organisational measures appropriate to ensure a level of security appropriate to the risk (art. 32 GDPR): HTTPS encryption on the Site (HSTS active), multi-factor authentication (2FA TOTP) for administrative staff with lockout after failed attempts, bcrypt cost 12 password hashing, SHA-256 IP address hashing, anti-injection sanitisation on all API endpoints, rate limiting to prevent abuse, regular backups, access logs retained for 12 months, staff training, Data Processor contracts with suppliers, incident management process.
9. Processing of data of minors
Pursuant to art. 8 of EU Regulation 2016/679 and art. 2-quinquies of Italian Legislative Decree 30 June 2003 No. 196 (Italian Privacy Code), consent to the processing of personal data for information society services (AI chatbot, newsletter, profiling) is valid if given by a minor who has reached at least 14 years of age. For minors under 14, consent must be given by the holders of parental responsibility. The Property does not knowingly collect data of minors under 14 years of age without parental/guardian consent. The Site's online forms and the Colleverdino AI assistant are intended for individuals who have reached at least 14 years of age. For legal check-in compliance (Public Security), minor data is provided directly by the parent/guardian.
10. Cookies
The Site uses technical, analytical and marketing cookies as described in the Cookie Policy, an integral part of this Policy. To change your preferences at any time, use the "Manage cookie preferences" button always present in the website footer.
11. Changes to this Policy
The Controller reserves the right to modify this Policy at any time to reflect regulatory or operational changes. Substantial changes will be communicated via a prominent notice on the Site; the version and effective date are always indicated at the top and bottom of this page. Please consult this section periodically.
Version 2.0 · Last update: 27/05/2026 · In force from 27/05/2026