Privacy Policy

Last updated: September 2026.

Information provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)

This notice describes how personal data of users visiting the website www.ricasolistays.com, interacting with its services and booking a stay under the Ricasoli Stays brand are processed.

Ricasoli Group S.r.l. is a single company operating on the market through several brands, each specialised by sector and none of which has separate legal personality: Ricasoli Travel (travel and mobility services), Ricasoli Realty (real estate services) and Ricasoli Stays (short lets and property management). Any reference to a brand in this document is to be understood as a reference to Ricasoli Group S.r.l.

1. Data controller

The controller of personal data is:

Controller: Ricasoli Group S.r.l.
Registered office: Via Senato 29, 20121 Milan (MI), Italy
Tax code, VAT number and registration number with the Companies Register of Milano Monza Brianza Lodi: 08638750961
R.E.A. (Economic and Administrative Index): MI - 2038959
Share capital: EUR 10,000.00 fully paid up
Certified e-mail (PEC): ricasoliconsulting@legalmail.it
E-mail: contact@ricasolistays.com
Telephone: +39 327 441 7425
Brands and divisions of the company: Ricasoli Travel, Ricasoli Realty, Ricasoli Stays.

The Controller has not appointed a Data Protection Officer, the conditions set out in Article 37 GDPR not being met. Any request concerning the processing of personal data may be sent to the e-mail address indicated above.

2. Single controller and use of data across the brands

The websites www.ricasoligroup.com, www.ricasolitravel.com, www.ricasolirealty.com and www.ricasolistays.com all belong to a single data controller, Ricasoli Group S.r.l., which operates through the Ricasoli Travel, Ricasoli Realty and Ricasoli Stays brands. Those brands are not separate companies but operating divisions of the same company.

Accordingly, the use of personal data across the different divisions does not constitute disclosure to third parties, but processing internal to the same controller, and in any event takes place solely within the limits of the purposes and legal bases set out in this notice. In particular, data collected through one website is not used to send promotional communications concerning the services of another division without the specific consent of the data subject.

3. Categories of data processed

The Controller processes the following categories of personal data:

  • contact and identification data — first name, surname, e-mail address, telephone number and any other information voluntarily provided through the contact or enquiry forms on the website;
  • data relating to enquiries and bookings — property, dates of stay, number and names of guests, additional services requested, preferences and any information necessary to provide the service;
  • identification data of guests and identity document data — first name, surname, date and place of birth, nationality, sex, type, number and place of issue of the identity document of each guest accommodated, necessary to comply with reporting obligations towards the public security authorities;
  • payment and billing data — billing details and transaction data necessary to process payments, including additional charges and any security deposit. Full card details are entered directly with the payment service provider and are not stored by the Controller;
  • data relating to the stay — communications with guests, assistance requests, reports concerning the property and any damage;
  • browsing data and data collected through cookies and similar technologies — as described in the Cookie Policy published on the website.

4. Data of guests other than the person making the booking and its source (Article 14 GDPR)

A booking usually concerns more than one person. Personal data of guests other than the person making the booking, including minors, are provided to the Controller by the person making the booking, who declares that they are authorised to provide them and undertakes to bring the content of this notice to the attention of the data subjects or of the holders of parental responsibility.

The source of the data is therefore the person making the booking or, for bookings made through online travel agencies, the booking platform. The categories of data are those set out in paragraph 3; the processing takes place for the performance of the accommodation contract and for compliance with the legal obligations connected with hospitality.

Data of minors staying with their family are processed solely to manage the stay and to comply with reporting obligations towards the public security authorities, which concern all persons accommodated regardless of age.

5. Purposes and legal bases of the processing

Personal data are processed for the purposes and on the legal bases set out below.

  • Responding to enquiries — following up on requests for information, availability and quotations sent through the website. Legal basis: performance of pre-contractual measures taken at the data subject’s request and the Controller’s legitimate interest in replying (Article 6(1)(b) and (f) GDPR).
  • Management of the booking and of the stay — processing bookings, managing check-in and check-out, providing additional and concierge services and assisting guests. Legal basis: performance of a contract (Article 6(1)(b) GDPR); for guests other than the person making the booking, legitimate interest in the performance of the accommodation contract (Article 6(1)(f) GDPR).
  • Reporting of guest data to the public security authorities — transmitting to the competent Police Headquarters (Questura), through the “Alloggiati Web” portal, the particulars of the persons accommodated, pursuant to Article 109 of the Italian Consolidated Public Security Act (Royal Decree No. 773 of 18 June 1931). The report is made within twenty-four hours of arrival and, for stays not exceeding twenty-four hours, within six hours of arrival. Legal basis: legal obligation (Article 6(1)(c) GDPR). Providing such data is mandatory: failing that, the stay cannot take place.
  • Collection and payment of the tourist tax — collecting the tourist tax, where applicable, paying it to the competent municipality and submitting the declarations and data required by the relevant municipal regulation. Legal basis: legal obligation (Article 6(1)(c) GDPR).
  • Reporting of tourism flow data — transmitting to the competent Region and to the Italian National Institute of Statistics (ISTAT) data, as a rule in aggregate form, on arrivals and overnight stays, pursuant to applicable statistical and regional legislation. Legal basis: legal obligation (Article 6(1)(c) GDPR).
  • Short-let and property identification requirements — complying with the obligations connected with the National Identification Code (CIN) and with the further obligations laid down by the rules on short lets and accommodation facilities. Legal basis: legal obligation (Article 6(1)(c) GDPR).
  • Payment management — processing payments, security deposits and refunds and complying with accounting and tax obligations. Legal basis: performance of a contract and compliance with legal obligations (Article 6(1)(b) and (c) GDPR). Payments are processed through the GuestyPay functionality, based on Stripe, and concern the tourist tax, extra services, any ancillary amounts due from guests whose bookings originate from online travel agencies and, where enabled, direct bookings. Full card details are entered directly with the payment service provider and are not accessible to the Controller.
  • Fraud prevention and payment checks — preventing and detecting fraudulent or unauthorised transactions, verifying the payer’s identity and complying with payment services and anti-money laundering requirements. Such checks are also carried out by the payment service provider acting as a separate controller. Legal basis: the legitimate interest of the Controller and of the payment service provider in the security of transactions, and compliance with legal obligations incumbent on the latter (Article 6(1)(f) and (c) GDPR).
  • Marketing of similar services — sending communications concerning services similar to those already used by the guest. Legal basis: the Controller’s legitimate interest under Article 130(4) of Italian Legislative Decree 196/2003, with the data subject’s right to object at the time of collection and in every communication; for other recipients, consent (Article 6(1)(a) GDPR).
  • Legal compliance and legal claims — complying with legal obligations and establishing, exercising or defending legal claims, including in relation to damage to the property. Legal basis: legal obligation and the Controller’s legitimate interest (Article 6(1)(c) and (f) GDPR).

6. Nature of the provision of data and how consent is collected

Providing the data requested through the website forms is optional; failure to provide the data marked as mandatory, however, makes it impossible to follow up on the request or to provide the service. Providing the identification data of all guests accommodated and their identity documents is required by law and is a condition for access to the property.

The forms on the website include a non-pre-ticked acknowledgement box confirming that the user has read this notice; ticking it is a condition for submitting the request. That box does not constitute consent to the processing: a privacy notice is an information document, and the processing operations connected with handling the request rely on the legal bases set out in the preceding paragraph.

Choices concerning cookies and similar technologies are collected through the dedicated banner on first access and may be changed or withdrawn at any time through the Cookie preferences control in the website footer, as described in the Cookie Policy.

7. Recipients and processors

Personal data may be disclosed, for the purposes set out above, to the following parties, which process them as processors or as separate controllers:

  • providers of technical, hosting and content delivery services for the website (Vercel Inc. for hosting and page delivery);
  • providers of e-mail services and of contact form management services;
  • providers of website analytics services (Google Ireland Ltd., for Google Tag Manager and connected services), within the limits of the consent given through the cookie banner and as described in the Cookie Policy;
  • Guesty Inc., a company incorporated under the laws of the United States, as provider of the booking management platform and of the GuestyPay payment functionality, appointed as processor under Article 28 GDPR. The provider’s privacy policy is available at https://www.guesty.com/privacy-policy/;
  • Stripe Payments Europe, Ltd., established in Ireland, as payment service provider processing card payments in compliance with the PCI-DSS standard. Stripe processes payment data as a processor on behalf of the Controller and, for the purposes of fraud prevention, identity verification and compliance with its own payment services and anti-money laundering obligations, as a separate controller. The provider’s privacy policy is available at https://stripe.com/privacy;
  • online travel agencies and booking platforms (by way of example Booking.com, Airbnb, Expedia), as separate controllers, for bookings made through their respective channels;
  • the competent Police Headquarters (Questura), through the “Alloggiati Web” portal operated by the Italian Ministry of the Interior, for the reporting of the particulars of persons accommodated;
  • the competent municipality, for the collection and payment of the tourist tax and the related reporting obligations;
  • the competent Region and ISTAT, for tourism flow statistics;
  • the owners of the managed properties, limited to the data necessary to report on the management and to handle any damage, and in any event on a non-excessive basis;
  • cleaning companies, maintenance providers and suppliers of additional services, to the extent necessary to provide the service requested;
  • consultants, professionals and service providers of the Controller (for example in accounting, tax and legal matters), to the extent necessary to carry out their respective engagements;
  • public and supervisory authorities, where required by law or by an order of the authorities.

Parties processing data on behalf of the Controller are appointed as processors under Article 28 GDPR. An up-to-date list of processors is available on request by writing to the addresses set out in paragraph 1. Personal data are not disseminated.

Sharing with other Group companies

With your explicit and optional consent, we may also share your contact details with the other companies of the Ricasoli Group and with PVJets, so that they can send you coordinated commercial offers and communications (legal basis: your consent, Art. 6(1)(a) GDPR). This consent is optional and is never required to submit any form on our website. You can withdraw it at any time, and for individual companies, from our Preference Center, with no consequences.

8. Transfers of data to third countries

Some of the providers listed in the preceding paragraph may process personal data outside the European Economic Area. In that case, the transfer takes place solely subject to appropriate safeguards under Articles 44 et seq. GDPR, such as an adequacy decision of the European Commission (including the decision concerning the EU-U.S. Data Privacy Framework, for US providers certified thereunder) or the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional measures. A copy of the safeguards adopted may be requested at the addresses set out in paragraph 1.

In particular, the booking management platform is provided by Guesty Inc., a company established in the United States of America. The related transfer of personal data takes place on the basis of the European Commission’s adequacy decision of 10 July 2023 concerning the EU-U.S. Data Privacy Framework, where the provider appears on the list of certified organisations, or, failing that, on the basis of the Standard Contractual Clauses adopted by the European Commission, supplemented by the additional measures deemed necessary following the assessment carried out by the Controller.

9. Retention period

Personal data are retained for no longer than is necessary to achieve the purposes for which they were collected and, in particular:

  • contact data and enquiries not followed by a booking are retained for a maximum of 24 months from the last contact;
  • data relating to bookings and stays are retained for ten years from the end of the stay, in view of the ordinary limitation periods and of accounting and tax obligations;
  • identification data of guests reported through “Alloggiati Web” are retained by the Controller for as long as necessary to evidence compliance with the obligation; any copies of identity documents obtained solely for the purposes of the report are deleted once the report has been submitted and in any event within seven days of check-out, their retention not being necessary for compliance;
  • data relating to the tourist tax are retained for the period laid down by the applicable municipal regulation and by tax legislation;
  • payment and billing data are retained for the period required by applicable tax and accounting legislation (as a general rule, ten years);
  • data necessary to establish, exercise or defend legal claims are retained for as long as necessary for that purpose.

10. No automated decision-making

The Controller does not carry out automated decision-making, including profiling, producing legal effects concerning the data subject or similarly significantly affecting them within the meaning of Article 22 GDPR. Should the Controller intend to introduce such processing in the future, it will give prior notice by updating this notice, setting out the logic involved as well as the significance and the envisaged consequences for the data subject.

11. Data relating to minors

Minors may not make bookings independently: the booking must be made by a person of full age. Data of minors staying at the property are processed within the limits set out in paragraph 4 and, as regards reporting to the public security authorities, in compliance with a legal obligation covering all persons accommodated.

12. Security of processing

The Controller implements appropriate technical and organisational measures under Article 32 GDPR to protect personal data against unauthorised destruction, loss, alteration, disclosure or access, including encryption of communications through the HTTPS protocol, restriction of access to authorised personnel instructed under Article 29 GDPR, and the appointment of providers as processors under Article 28 GDPR.

13. Rights of the data subject

Data subjects have the right to obtain from the Controller, in the cases provided for by Articles 15 et seq. GDPR: access to their personal data; rectification of inaccurate data; erasure of data (right to be forgotten); restriction of processing; data portability; and objection to processing based on legitimate interest. Data subjects have in any event the right to object at any time, without giving reasons, to the processing of their data for direct marketing purposes. Where processing is based on consent, data subjects have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.

To manage or withdraw the consent to sharing data with the companies of the Ricasoli Group and PVJets, data subjects may also use the Preference Center.

These rights may be exercised by writing to the addresses set out in paragraph 1. The Controller replies without undue delay and in any event within one month of the request, extendable by two months where the request is particularly complex. Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the Member State of their habitual residence or place of work.

14. Language of this notice

The website is also published in languages other than Italian. This notice is drafted in Italian and is made available, for transparency purposes under Article 12 GDPR, also in the other languages in which the website is available. In the event of any discrepancy between versions, the Italian version prevails.

15. Amendments to this notice

The Controller reserves the right to amend or update this notice at any time, giving notice by publication on the website. The version in force is the one published on this page on the date of consultation; the date of the last update is shown at the top of the document.