This notice describes how TILO CAPITAL MANAGEMENT SRL processes the personal data of guests who use the guest portal (the “Guest Portal” or “Portal”) for booking, online check-in and management of their stay at the managed properties, pursuant to Articles 13 and 14 of EU Regulation 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
1. Data Controller
TILO CAPITAL MANAGEMENT SRL (the “Controller”)
Registered office: Via Isonzo 27/7, Genoa (Italy)
VAT / Tax code: 02945640999
Email: [email protected] · Certified email (PEC): [email protected]
Phone: +39 010 9863324
Contact for data protection requests and exercise of rights: Giuseppe Parisii – [email protected].
2. Categories of personal data processed
Identity data: first name, surname, date and place of birth, citizenship, sex;
Identity document: document type, number, issuing authority and date of issue, and any copy/image of the document;
Contact data: email address, phone number, residential address;
Stay data: property/unit, arrival and departure dates, number and composition of the group (group/family leader and linked guests);
Payment and billing data: data needed for charges, deposits and tourist tax (card data is handled by payment service providers and is not stored by the Controller);
Technical and browsing data: IP address, device identifiers, access logs and the Portal's technical cookies;
Further data voluntarily provided by the guest through messages or assistance requests.
Minors: data relating to minors who stay at the property is provided by the responsible adult, under their own responsibility. The Portal is not intended for independent use by minors.
3. Purposes, legal bases and nature of provision
Purpose Legal basis Provision
a) Management of the booking and the accommodation contract, including online check-in Art. 6.1.b GDPR — performance of a contract Required; refusal prevents provision of the service
b) Communication of guest data to the Public Security Authority (Police HQ) via the “Alloggiati Web” portal Art. 6.1.c GDPR — legal obligation, under Art. 109 of the Italian Consolidated Public Security Act (R.D. 773/1931) Mandatory by law; sent within 24 hours of arrival (within 6 hours for stays of less than 24 hours)
c) Tourist tax obligations and reporting to the Municipality Art. 6.1.c GDPR — legal obligation (municipal regulation) Mandatory where the tax is due
d) Tax, accounting and administrative obligations (invoicing, mandatory records) Art. 6.1.c GDPR — legal obligation Mandatory
e) Guest assistance and service communications about the stay (access instructions, keybox codes, property information, request handling) Art. 6.1.b and 6.1.f GDPR Required to deliver the requested service
f) Portal security, fraud and abuse prevention, handling of disputes/litigation and protection of the Controller's rights Art. 6.1.f GDPR — legitimate interest Optional
g) Technical cookies necessary for the Portal to function Art. 6.1.f GDPR and cookie rules Required (see sec. 11)
h) Sending marketing communications, newsletters, offers and review requests Art. 6.1.a GDPR — consent (and Art. 130(4) D.Lgs. 196/2003 for similar services) Optional; can be withdrawn at any time
4. How data is processed
Processing is carried out mainly by electronic means, with technical and organisational measures adequate to ensure security and confidentiality, in accordance with Articles 5 and 32 GDPR. Data is not subject to solely automated decision-making producing legal effects within the meaning of Article 22 GDPR.
5. Recipients and categories of recipients
Data may be disclosed to or made accessible by:
Public Security Authorities (Police HQ / State Police) via Alloggiati Web and other competent Authorities;
the competent Municipality, for the tourist tax;
the tax administration (Italian Revenue Agency) and accounting/tax advisors;
providers of the property-management software and of the Portal, and cloud/IT hosting providers, appointed as Data Processors under Article 28 GDPR;
booking platforms/OTAs (e.g. Airbnb, Booking.com), limited to booking data, where the stay originates from those channels; each acts as an independent controller for its own purposes;
payment service providers and email/newsletter delivery providers;
authorised collaborators and suppliers for the operational management of the stay (e.g. cleaning, maintenance, check-in), bound by confidentiality.
Data is not disseminated or transferred to third parties for their own independent commercial purposes.
6. Transfers outside the EU
Data is normally processed within the EU/EEA. Where some providers (e.g. cloud services) involve transfers to third countries, the Controller ensures appropriate safeguards under Articles 44 et seq. GDPR (adequacy decisions or Standard Contractual Clauses).
7. Retention period
Booking/contract data and related documents: for the duration of the relationship and thereafter for as long as needed to meet legal obligations and protect the Controller's rights (generally up to 10 years for tax/accounting documents, Art. 2220 of the Italian Civil Code);
Copy of the identity document collected for check-in: kept only for the time strictly necessary for identification and related obligations and, in any case, deleted once those obligations are exhausted, unless needed to defend a legal right;
Data sent to Alloggiati Web: processed by the Authority under its own rules; the Controller keeps evidence of the communication for the required period;
Data processed for marketing/newsletter: until consent is withdrawn and, in any case, no longer than 24 months from the last contact, unless renewed;
Technical/log data and cookies: as set out in section 11.
At the end of the stated periods the data is deleted or anonymised.
8. Marketing and newsletter
Subject to the guest's specific and freely given consent, the Controller may process the email address (and possibly other contact details) to send direct marketing communications, newsletters, offers, promotions and invitations relating to TILO services, as well as satisfaction surveys and review requests. Legal basis: Art. 6.1.a GDPR (consent).
Provision is optional: lack of consent does not affect the booking or the stay in any way. For customers who have already used the services, the Controller may send communications about similar services under Art. 130(4) of Legislative Decree 196/2003, with the right to object at any time.
The guest may withdraw consent at any time, without affecting the lawfulness of processing before withdrawal, via the unsubscribe link in every communication or by writing to [email protected].
9. Your rights
Guests may exercise at any time the rights under Articles 15-22 GDPR: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where processing is based on it (without affecting the lawfulness of processing before withdrawal). Rights may be exercised by writing to [email protected]. The Controller replies within the legal time limits (generally within 30 days).
10. Complaint to the supervisory authority
You have the right to lodge a complaint with the Italian Data Protection Authority — Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) — or with the supervisory authority of your EU country of residence.
11. Cookies
The Portal uses technical cookies necessary for proper functioning (e.g. session, security, language preference), for which no consent is required. Should analytics or non-anonymised third-party cookies be used, this will be disclosed via a dedicated banner and, where necessary, prior consent will be requested. You can manage or disable cookies through your browser settings.
12. Changes to this notice
The Controller may update this notice. The current version is always published on the Portal, indicating the date of the latest update. .