PRIVACY POLICY

(pursuant to Article 13 of EU Regulation 2016/679 – GDPR)

1. Data Controller

The Data Controller is IT dreams S.r.l., with registered office at Via Pietro Panzeri, 4 – 20123 Milan (MI), VAT number 08835540967.

For any information regarding personal data protection, you may contact:
amministrazione@itdreams.it


2. Types of Data Collected

IT dreams S.r.l. processes the following personal data:

  • Identification data (name, surname)
  • Contact details (email address, phone number)
  • Data necessary for booking management
  • Payment data (processed through external providers)
  • Website browsing data

Data is provided directly by users via the website or during the booking process.


3. Purpose of Processing

Personal data is processed for the following purposes:

  1. Managing requests submitted through the contact form
  2. Managing bookings and guest stays
  3. Fulfilling contractual, legal, and tax obligations
  4. Processing payments

No marketing activities or newsletters are carried out.


4. Legal Basis for Processing

Processing is based on:

  • Performance of a contract or pre-contractual measures
  • Compliance with legal obligations
  • Legitimate interest of the Data Controller in properly managing its business

5. Processing Methods

Personal data is processed using electronic and/or paper-based tools, in accordance with the principles of fairness, lawfulness, transparency, and confidentiality as required by GDPR.

Appropriate technical and organizational measures are implemented to ensure data security.


6. Payments and Third-Party Services

Online payments are processed through external providers (e.g., Stripe and PayPal), which act as independent data controllers in accordance with their own privacy policies.

The online booking system is managed via external integration. Data entered during the booking process may also be processed by the relevant service provider according to its own privacy policy.


7. Data Transfers Outside the EU

Some service providers (e.g., payment systems) may process data outside the European Union. In such cases, transfers occur in compliance with GDPR safeguards (e.g., Standard Contractual Clauses or adequacy decisions).


8. Data Retention

Personal data is retained only for the time strictly necessary to achieve the purposes outlined above and, in any case, in compliance with applicable legal and tax obligations.


9. Data Subject Rights

Users may exercise their rights under Articles 15–22 of the GDPR at any time, including:

  • Access to their personal data
  • Rectification or updating
  • Erasure
  • Restriction of processing
  • Objection to processing
  • Data portability

Requests may be sent to: amministrazione@itdreams.it

Users also have the right to lodge a complaint with the Italian Data Protection Authority.


10. Changes to This Policy

This Privacy Policy may be updated periodically. Users are encouraged to review it regularly.

Last update: 21/02/2026

Scroll to Top