Privacy policy

Privacy Policy and below Cookie Policy of www.theboutiquehouses.com

Privacy Policy
(pursuant to Articles 13 and 14 of EU Regulation 2016/679 – GDPR)

1. Data Controller
The Data Controller of personal data is Niccoló Maria Moretti, with registered office at Piazza Cinque Giornate 7, 20129 Milan (MI), contact e-mail: [email protected]. Jurisdiction: Milan.

2. Types of Data Processed
The Controller processes the following categories of personal data:
Personal and contact data: name, surname, e-mail address, phone number.
Booking data: stay dates, selected unit, special preferences or requests.
Payment data: credit card or other payment details, processed by certified PCI-DSS external providers; the Controller does not retain full data.
Navigation data: IP addresses, technical logs, device identifiers, browser and operating system information.
Cookies and tracking tools: as specified in the relevant Cookie Policy.

3. Purpose and Legal Basis of Processing
Data is processed for the following purposes and legal bases:
Booking management and contractual fulfillment (Art. 6(1)(b) GDPR).
Compliance with legal and fiscal obligations (Art. 6(1)(c) GDPR).
Handling complaints, disputes, or legal defense (Art. 6(1)(f) GDPR – legitimate interest).
Direct marketing and commercial profiling only with explicit consent (Art. 6(1)(a) GDPR).
Data sharing with third-party business partners in tourism, real estate, insurance, and finance, only with explicit and separate consent (Art. 6(1)(a) GDPR).
Statistical analysis and website usage monitoring via cookies and similar tools (Art. 6(1)(a) – consent; Art. 6(1)(f) – legitimate interest for technical/anonymous cookies).

4. Nature of Data Provision
Provision of personal data:
is mandatory for contractual and legal purposes (points 1 and 2); refusal prevents provision of requested services;
is optional for marketing, profiling, and sharing with third parties; refusal does not affect core services.

5. Methods of Processing and Security
Processing is carried out electronically and on paper, using organizational procedures and security measures pursuant to Articles 24 and 32 GDPR, to ensure confidentiality, integrity, and availability of data.

6. Data Retention
Contractual and booking data: stored for 10 years, according to civil and fiscal obligations.
Marketing and profiling data: retained until consent is revoked, or for a maximum of 24 months.
Navigation and cookie data: according to the Cookie Policy.

7. Communication and Data Transfer
Data may be shared with:
Tax, legal, and accounting consultants;
IT providers, hosting providers, booking system managers (Kross Travel), electronic payment processors;
Competent authorities, as required by law.
If third-party tools are used (e.g., Google, Meta), data may be transferred outside the EU (e.g., USA). The Controller ensures adoption of Standard Contractual Clauses (SCC) or other GDPR safeguards.

8. Rights of the Data Subject
The Data Subject may exercise the rights under Articles 15–22 GDPR, including:
Access to personal data;
Rectification and erasure (“right to be forgotten”);
Restriction of processing;
Data portability;
Objection to processing, including for marketing;
Revocation of consent without affecting lawfulness before revocation;
Complaint to the Data Protection Authority (www.garanteprivacy.it).
Requests must be sent to the Controller at: [email protected].

9. Minors
The Site and services are not intended for persons under 16 years of age.

10. Updates
The Controller reserves the right to update this notice at any time. Changes will be published on the Site with an updated date.
Last update: 08/09/2025
Cookie Policy
(pursuant to EU Regulation 2016/679 – GDPR and Italian Privacy Authority Provision 10.06.2021)

1. What Are Cookies
Cookies are small text strings that websites send to the user’s device (usually the browser) and store for subsequent retransmission on the user’s next visit. Cookies collect navigation information and ensure proper website functionality.

2. Types of Cookies Used
Technical cookies (necessary): Ensure website functionality (e.g., booking, authentication, security). No user consent required.
Functional cookies: Remember user choices (e.g., language, region). Can be managed via the consent banner.
Analytical cookies: Collect aggregated data about site visits (e.g., Google Analytics). Anonymous cookies are treated as technical; otherwise, user consent is required.
Profiling and marketing cookies: Track user navigation to create profiles and send advertising based on preferences. Only installed with explicit consent.

3. Third-Party Tools
Third-party cookies may be transmitted to the user’s device, possibly using data for their own purposes, including:
Google LLC (Analytics, Maps, Ads)
Meta Platforms Inc. (Facebook Pixel)
Kross Travel (integrated booking engine)
Other commercial partners or social plugins
Users are advised to consult third-party privacy policies.

4. Legal Basis for Processing
Technical cookies: necessary for service provision (Art. 6(1)(b) GDPR).
Analytical and profiling cookies: based on user consent (Art. 6(1)(a) GDPR).

5. Consent Collection
A banner appears at first access allowing the user to:
Accept all cookies, reject them, or manage preferences;
Save and modify choices anytime via a link in the footer (“Review cookie preferences”).
Cookies can also be managed via browser settings.

6. Data Retention
Technical cookies: session duration or up to 12 months.
Analytical cookies: up to 24 months, unless anonymized.
Profiling cookies: up to 12 months.

7. Extra-EU Data Transfer
Third-party cookies (e.g., Google, Meta) may involve data transfer outside the EU (e.g., USA). Providers apply Standard Contractual Clauses (SCC) or other GDPR-compliant safeguards.

8. Rights of the User
Users may exercise rights under Articles 15–22 GDPR (access, rectification, erasure, restriction, objection, portability, revocation) by contacting the Controller: [email protected].
Users may also lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).

9. Updates
This Cookie Policy may be updated. Significant changes will be published on the Site.
Last update: 08/09/2025