Privacy Policy
Last updated: 16 July 2026
This notice is provided pursuant to Articles 12, 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and the applicable Italian data-protection legislation.
1. Data Controller
The Data Controller is MONTEBALDO SRL UNIPERSONALE, Italian Tax Code and VAT No. 01802790236, registered office at Via San Bernardo 137, 37016 Garda (VR), Italy.
- Email: booking@montebaldo.com
- Certified email: MONTEBALDO@PEC.GARDAMAIL.IT
No Data Protection Officer (“DPO”) has been appointed. If one is appointed, the relevant contact details will be published in this notice.
2. Scope and sources of Data
This notice applies to gardaresidences.com and its language versions. Data may be collected automatically, provided directly by the user, or received from booking-service providers to the extent necessary to manage a stay. Third-party websites and services are governed by their own notices.
3. Categories of Data processed
- Technical and browsing Data: IP address, request date and time, device, operating system, browser, requested URLs, technical logs, online identifiers and security data.
- Identification and contact Data: first name, surname, address, email, telephone number and message content.
- Availability and booking Data: selected property, stay dates, number and composition of guests, special requests, booking status and reference.
- Administrative and tax Data: information required for invoicing, accounting and legal obligations.
- Payment Data: where payment is handled by an external platform or payment provider, full card details are processed directly by that provider under its own notice. The Website receives only the information required to confirm or manage the booking, unless otherwise stated during payment.
- Cookie-choice Data: the choice made, date, policy version and technical identifier needed to document consent or refusal.
- Analytics Data: events and information concerning use of the Website, collected only within the limits of the preferences expressed through the cookie banner.
The Controller does not intentionally request special categories of Data under Article 9 GDPR. Users should not include health data or other particularly sensitive information in free-text requests unless strictly necessary and expressly requested.
4. Purposes, legal bases and whether providing Data is mandatory
- a) Operation, security and abuse prevention. Legal basis: legitimate interest, Article 6(1)(f) GDPR, and technical necessity to provide the requested service.
- b) Availability search. Legal basis: pre-contractual measures requested by the Data subject, Article 6(1)(b) GDPR.
- c) Booking management and performance. Legal basis: pre-contractual measures and performance of the contract, Article 6(1)(b) GDPR.
- d) Administrative, tax and regulatory obligations. Legal basis: compliance with a legal obligation, Article 6(1)(c) GDPR.
- e) Responding to enquiries. Legal basis: pre-contractual measures, Article 6(1)(b), or legitimate interest in managing communications, Article 6(1)(f) GDPR.
- f) Analytics. Non-essential analytics tools are activated only after consent. Legal basis: consent, Article 6(1)(a) GDPR and Article 122 of Italian Legislative Decree 196/2003.
- g) External content and services. Maps, fonts, booking systems and other external services may receive technical data, including the IP address, when loaded. Processing is limited to what is necessary for the requested function or subject to consent where non-technical tracking is used. Legal basis: legitimate interest or consent, depending on the service and configuration.
- h) Establishment, exercise or defence of legal claims. Legal basis: legitimate interest, Article 6(1)(f) GDPR.
Data marked as necessary are mandatory to provide the requested service. Analytics and any marketing purposes are optional. The Controller does not send its own or third-party promotional communications without separate, specific and demonstrable consent.
5. Processing methods and security
Data are processed in accordance with the principles of lawfulness, fairness, transparency, minimisation, accuracy, storage limitation, integrity and confidentiality. Appropriate technical and organisational measures are adopted, including access controls, updates, backups and system protection.
6. Recipients and providers
Data may be disclosed, strictly as necessary, to authorised staff, hosting and infrastructure providers, Ciaobooking/SmartPMS and other booking providers, IT and email providers, analytics providers including Google Analytics 4 according to user preferences, map/content/font providers, professional advisers, insurers and public or judicial authorities. Providers act as processors under Article 28 GDPR or as independent controllers, depending on the service.
7. Transfers outside the EEA
Where providers process Data outside the EEA, transfers rely on an adequacy decision, the EU–US Data Privacy Framework, Standard Contractual Clauses or another safeguard under Articles 44 et seq. GDPR.
8. Retention periods
- Technical/security logs: normally up to 6 months.
- Availability requests: up to 12 months, unless followed by a booking.
- Bookings and administrative records: for the relationship and up to 10 years after its end, or for the different statutory period.
- Contact requests: up to 12 months after closure.
- Analytics Data: for the configured period, no longer than 14 months unless a different lawful configuration is documented.
- Cookie preferences and proof of consent: for the period needed to document the choice; the banner is normally not shown again for at least 6 months unless material changes occur or the choice cannot be recognised.
- Legal disputes: until final resolution and expiry of limitation or appeal periods.
9. Automated decisions and profiling
The Controller does not make decisions based solely on automated processing that produce legal or similarly significant effects. Analytics or advertising tools are not used for the Controller’s own profiling without specific consent and prior notice.
10. Data-subject rights
Data subjects may exercise the rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, and may lodge a complaint with the Italian Data Protection Authority. Requests may be sent to booking@montebaldo.com.
11. Minors
Booking services are intended for adults. Data concerning minors that are necessary for a stay must be provided by a person exercising parental responsibility or another authorised person.
12. Changes to this notice
This notice may be updated following legal, technical or organisational changes. The version published on the Website, bearing its update date, is the current version.