PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA
SERVICE RESERVATIONS
Partenhotels S.r.l. (hereinafter also referred to as the “Controller”) provides the data subject, meaning the person to whom the personal data refer, with the following information pursuant to Articles 13 and 14 of Regulation (EU) No. 2016/679 of 27 April 2016 (hereinafter GDPR), to describe the characteristics of the processing activities carried out in relation to the personal data of guests and users of the services available at the hotel facility, and the measures adopted to protect their rights.
Data Controller
The Data Controller is Partenhotels S.r.l.
Registered Office: Via Mergellina n. 23, 80122 Naples
Business Location: Hotel Terme della Regina Isabella, Piazza S. Restituta, 80076 Lacco Ameno (NA)
Contacts: Tel. +39 081 994322 – privacy@reginaisabella.it
Data Subject to Processing
The Controller essentially collects the following data:
-
Identity document, tax code
-
Contact details
-
Banking or credit card information
-
Stay-related data
-
Data related to electronic devices used to connect to the hotel's network
-
Data related to telephone calls
Purposes and Legal Basis of the Processing
The data provided to the Controller will be processed for the following purposes:
a) Responding to customer requests
b) Managing reservations and any stay at the hotel
c) Managing any additional services chosen by the guest
d) Administrative, accounting, and tax management
e) Handling of any disputes
f) Management of customer care services
g) Marketing activities
Why Our Processing is Lawful
Processing is lawful because it is:
-
Carried out in relation to pre-contractual measures (e.g. responding to information requests)
-
Carried out to fulfill contractual obligations and provide the services requested by the data subject (e.g. booking management; reservations for services such as restaurants, treatments, transportation)
-
Carried out to comply with legal obligations in tax and public security matters (e.g. data disclosure to the police)
-
Based on consent, which is always optional and revocable when required
Data Retention Period
Personal data will be retained for the time strictly necessary to carry out the activities related to the purposes stated in this notice. Specifically, data will be retained:
-
For the entire duration of the stay, and for an additional period of 10 years and 6 months, to allow the Controller to possibly assert its rights in legal proceedings and comply with legal document retention obligations
-
Up to 3 months from the check-out date for credit card data
-
Up to 3 months from the last check-out for personal, sensitive, and stay-related data, personal preferences, or data provided in relation to services used
-
Up to 3 months from check-out for telephone traffic data
-
Up to 3 months from pre-contractual requests
The Controller may retain personal data for longer periods if required by specific legal regulations. In case of disputes, data will be retained until the statutory limitation period for the protection of rights related to the contractual relationship.
Processing Methods
Personal data are processed both on paper and electronically (e.g. servers, cloud databases, software applications). Data will be stored within the European Economic Area (EEA).
Mandatory or Optional Nature of Data Provision
Providing the data requested for the "Processing Purposes" listed in this notice is mandatory, in the sense that failure to provide them will prevent the Controller from fulfilling the data subject's requests or establishing/managing the contractual relationship.
When processing is based on consent (e.g. marketing activities), such consent is always optional and revocable.
Categories of Recipients of Personal Data
The processing of the provided personal data may be carried out, under the principle of strict necessity, by:
-
Employees of the Controller, acting under its authority and instructions pursuant to Article 29 of the GDPR, or appointed under Article 2-quaterdecies of Legislative Decree No. 101/2018
-
Public Entities to which the Controller must disclose data in compliance with legal obligations
-
Individuals or legal entities used by the Controller for tasks instrumental to achieving the aforementioned purposes (e.g. guest transport services, IT service providers, security services), or to whom data must be disclosed under legal or contractual obligations.
External service providers appointed as data processors are subject to contractual and legal obligations to ensure data confidentiality and will only have access to data necessary to perform their functions.
A list of Data Processors is available at the operational headquarters.
Disclosure
The Controller will not disclose the personal data of the data subject.
Rights of the Data Subject
In relation to the processing of personal data, under the GDPR, the data subject has the following rights:
-
Right of access: to obtain a copy of their personal data held and processed by the Controller
-
Right to rectification: to have inaccurate or outdated personal data corrected
-
Right to withdraw consent: to revoke consent for a specific processing activity at any time
-
Right to lodge a complaint with the Data Protection Authority, if concerned about the processing of personal data by the Controller
Under certain conditions, the data subject may also exercise the following rights:
-
Right to erasure: to request deletion of personal data when processing purposes no longer exist and there are no legitimate interests or legal obligations requiring continued processing
-
Right to object to processing: to request that the Controller stop a specific data processing activity. This does not apply when processing is based on contractual obligations
-
Right to data portability: to receive personal data in a structured, commonly used, and machine-readable format and to request direct transmission of the data to another controller
-
Right to restriction of processing: to request limitation of processing activities on their personal data
To exercise any of these rights, the data subject can send an email or write to the following address, specifying the request and providing the Controller with the information necessary for proper identification (including a copy of an identity document):
-
By mail: at the operational headquarters, Hotel Terme della Regina Isabella, Piazza S. Restituta, 80076 Lacco Ameno (NA)
-
By email: privacy@reginaisabella.it
The Controller will respond within one month. If we are unable to respond within this period, we will provide a detailed explanation as to why your request cannot be fulfilled.
You may also file a report or complaint with the Italian Data Protection Authority at:
Piazza di Monte Citorio n. 121 – 00186 Rome
Email: urp@gpdp.it
This notice may be subject to updates or changes over time; therefore, we invite you to periodically consult the Controller’s website.





