Privacy Policy

1. Data Controller

The Controller of the personal data collected through this website isLa Collina Verde S.r.l., based at Via Collina Verde 2, 24023 Clusone (BG), Italy, VAT and Tax Code IT04656800168 (hereinafter also “Collina Luxury Relais” or the “Controller”).

For any request regarding the processing of personal data, the Controller can be contacted at: emailinfo@collinarelais.com, phone +39 0346 39511, postal address Via Collina Verde 2, 24023 Clusone (BG).

2. Types of Data Processed

In connection with the use of the website and the services offered, the Controller may process the following categories of personal data:

  • Browsing data:IP address, browser type, operating system and other technical parameters automatically collected during browsing;
  • Data provided voluntarilythrough the contact and information request forms on the website (first name, last name, email, phone, message content);
  • Booking dataentered through the online booking engine (first name, last name, email, phone, stay details, any special requests, payment card data required to guarantee the booking);
  • Data relating to purchases made on the online shop(Collina Shop): billing and shipping details, address, email, phone, order history, customer account data;
  • Payment dataprocessed in connection with purchases on the website or payments relating to the stay, handled directly by the payment service providers (Nexi XPay, PayPal); the Controller does not store nor have access to full payment card data;
  • Data relating to Gift Cards(gift vouchers): email and name of the sender and recipient of the voucher;
  • Data collected through cookies and similar technologies, as described in theCookie Policy.

3. Purposes and Legal Basis of Processing

Personal data is processed for the following purposes:

  • Handling information requests and communications with users (legal basis: performance of pre-contractual measures requested by the data subject, art. 6.1.b GDPR);
  • Managing bookings for stays, dining, spa and events, including the provision of the requested services (legal basis: performance of a contract, art. 6.1.b GDPR);
  • Managing purchases made through the online shop and Gift Cards, including invoicing, shipping and after-sales assistance (legal basis: performance of a contract, art. 6.1.b GDPR);
  • Compliance with accounting, tax and administrative obligations required by law (legal basis: legal obligation, art. 6.1.c GDPR);
  • Marketing activities and sending promotional communications, only with the data subject’s specific prior consent (legal basis: consent, art. 6.1.a GDPR), revocable at any time;
  • Website improvement, aggregated statistical analysis and IT security (legal basis: the Controller’s legitimate interest, art. 6.1.f GDPR, and/or consent where required for non-technical cookies);
  • Protection of the Controller’s rights in legal proceedings (legal basis: legitimate interest, art. 6.1.f GDPR).

Providing data for purposes related to information requests, bookings and purchases is necessary: failure to provide it makes it impossible to process the relevant requests. Providing data for marketing purposes is instead optional.

4. Method of Processing

Processing is carried out using IT and/or paper-based tools, following logics strictly related to the purposes indicated and, in any case, in a manner that ensures the security and confidentiality of the data, adopting technical and organisational measures suitable to prevent loss, unlawful use or unauthorised access to the data.

5. Disclosure and Sharing of Data with Third Parties

Personal data may be disclosed, for the purposes indicated above, to the following parties, acting as data processors or independent controllers:

  • The provider of the online booking engine used to manage booking requests;
  • Payment institutions and payment gateways (Nexi XPay, PayPal) for managing financial transactions;
  • The provider of the website hosting and technical maintenance service;
  • Providers of translation and multilingual website management services;
  • Consultants, accountants and other parties carrying out administrative and accounting activities on behalf of the Controller;
  • Public authorities, where required by law.

Data is not disclosed to third parties for their own commercial purposes, except with the data subject’s prior specific consent.

Please note that, for the purpose of managing the fonts used on the website, the Controller hosts Google Fonts directly on its own servers, avoiding the transmission of browsing data to Google for this specific functionality.

6. Transfer of Data Outside the EU

Some of the providers indicated above (for example PayPal) may process data also in countries outside the European Economic Area. In such cases, the transfer takes place on the basis of European Commission adequacy decisions or adequate safeguards such as Standard Contractual Clauses, in accordance with articles 44 et seq. of the GDPR.

7. Data Retention Period

Personal data is retained for the time necessary to achieve the purposes for which it was collected, in compliance with statutory time limits (for example, accounting and tax documents are retained for 10 years). Data processed on the basis of consent is retained until such consent is withdrawn.

8. Rights of the Data Subject

As a data subject, the user may exercise, at any time, by contacting the Controller at the details indicated in point 1, the rights provided for by articles 15-22 of the GDPR, including:

  • the right to access their own personal data;
  • the right to rectification of inaccurate data;
  • the right to erasure of data (“the right to be forgotten”), within the limits provided by law;
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object to processing;
  • the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal.

The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it), should they believe that the processing of their data is contrary to applicable law.

9. Minors

The services offered through the website are not intended for minors under 18 years of age. The Controller does not knowingly collect personal data of minors without the consent of whoever exercises parental responsibility.

10. Cookies

The website uses technical cookies and, subject to consent, functional, statistical and marketing cookies. For more information, please refer to theCookie Policy.

11. Changes to this Policy

The Controller reserves the right to modify or simply update, in whole or in part, this policy, including as a result of regulatory changes. Any changes will be communicated by publishing them on the website and will take effect from the date of publication.

Last updated: August 20, 2026.

Close
ChiamaPrenota ora