Legal information
Privacy Policy
Last updated: 12 September 2026
This privacy policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and of Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the “Italian Personal Data Protection Code”). It sets out in detail how the il Girasole holiday home processes the personal data of those who visit the website www.ilgirasoleputignano.com, of those who contact us for information or bookings, and of those who stay at the property.
We have chosen to write a text that reflects the reality of this website: we do not use profiling cookies, we do not use statistics or traffic-analysis tools, we do not use social network pixels, we have no online contact forms and we load no resource from third-party domains. What follows describes exactly the few processing operations that actually take place.
1. Data controller
The data controller is Margherita Capozzi (Italian tax code CPZMGH96B60C134V), owner of the holiday home il Girasole, with its registered office at Via Nuova 15, 70017 Putignano (BA), Italy — CIN IT072036C200125324.
Contact details for any matter relating to the protection of personal data: email ilgirasole.putignano@gmail.com, telephone and WhatsApp +39 380 373 4277.
2. Data Protection Officer (DPO)
The controller has not appointed a Data Protection Officer, as the mandatory conditions set out in Article 37 of the GDPR do not apply: the property is not a public authority, does not carry out core activities requiring regular and systematic monitoring of data subjects on a large scale, and does not process special categories of data on a large scale. For any request concerning personal data you may contact the controller directly using the details given in point 1.
3. Categories of personal data processed
a) Browsing data (technical logs). The computer systems and software procedures responsible for the operation of the site acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of internet communication protocols: the IP address of the device used, the type of browser and operating system (user agent), the date and time of the request, the URLs of the requested resources, the server response code, the volume of data transferred and any referring page. This data is generated and stored by the hosting provider and is not used by the controller to identify users, nor cross-referenced with other information.
b) Data voluntarily provided by the user. The site contains no contact form whatsoever. If you decide to write or call us using the published contact details (email, telephone, WhatsApp), we will process the data you spontaneously provide: name, email address, telephone number, the dates and features of the desired stay, the number and — where relevant for pricing purposes — the age of the guests, as well as any other information contained in your message.
c) Guest data at the booking and stay stage. Personal details, identity or identification document details, nationality, contact details, arrival and departure dates, and data required for invoicing and for the collection of the tourist tax. Full details are given in point 5.
d) Language preference. If you select a language from the site menu (Italian or English), your browser saves locally on your device, via localStorage, an entry named ig-lang with a value of it or en. This is a technical item, with no identifying content, which is not transmitted to our servers or to third parties and serves solely to show you the site in the language you have chosen on subsequent visits. Full details are in the Cookie Policy.
e) Data possibly provided by third parties. If you book through an online booking portal (for example Booking.com), we receive from that portal the data required to manage the booking: name, contact details, stay data and, where applicable, payment data. In this case Article 14 of the GDPR applies and the categories of data are those that the portal transmits to the property under its own contractual terms and privacy policy.
4. Purposes of the processing, legal bases and retention periods
4.1 Provision and security of the site. Browsing data is processed to allow the pages to be viewed, to ensure the stability of the service and to protect the infrastructure from abusive use (attacks, malicious automated traffic). Legal basis: the controller's legitimate interest under Article 6(1)(f) of the GDPR in the security and correct functioning of its own site. Technical logs are kept by the hosting provider for the time strictly necessary for these purposes, as a rule no longer than a few days, and are not downloaded, stored or reprocessed by us. The only exception to this rule concerns the investigation of computer crimes, in which case the data may be requested by the judicial authority.
4.2 Responding to requests for information and availability. The data you send us by email, telephone or WhatsApp is processed to answer your enquiry, check room availability and prepare a quotation. Legal basis: performance of pre-contractual measures taken at the data subject's request under Article 6(1)(b) of the GDPR. Retention: if the enquiry is not followed by a booking, the data is kept for a maximum of 12 months from the last contact, unless you ask us to delete it earlier.
4.3 Managing the booking and the stay. We process the data required to confirm the booking, welcome you, provide any requested services and manage any changes or cancellations. Legal basis: performance of the hospitality contract under Article 6(1)(b) of the GDPR. Retention: for the duration of the relationship and thereafter for the periods laid down by law on accounting, tax and ordinary limitation matters.
4.4 Legal obligations. We process data to fulfil the public-security, statistical, tax, accounting and fiscal obligations described in point 5. Legal basis: compliance with a legal obligation to which the controller is subject, under Article 6(1)(c) of the GDPR. Retention: for the periods laid down by the respective regulations, in particular 10 years for accounting records and tax documents pursuant to Article 2220 of the Italian Civil Code and tax legislation.
4.5 Defence of rights. In the event of disputes, damages or breaches, data may be processed to establish, exercise or defend a right in or out of court. Legal basis: legitimate interest under Article 6(1)(f) of the GDPR. Retention: for the duration of the dispute and until the expiry of the time limits for appeal.
4.6 Language preference. Saving your chosen language locally responds to an explicit request by the user and is essential to provide the service in the requested manner. It therefore falls among the tools that are strictly necessary within the meaning of Article 122 of Legislative Decree 196/2003 and does not require consent. The data remains on your device until you clear your browser's browsing data.
We do not carry out any direct marketing. We do not send newsletters, we keep no contact lists for promotional purposes and we do not use your data to offer you commercial deals, save at your specific request.
5. Processing of guest data: the accommodation facility's legal obligations
Anyone staying at the il Girasole holiday home is subject to certain processing operations that the property is required by law to carry out. Your consent is not required, because the legal basis is compliance with a legal obligation (Article 6(1)(c) of the GDPR); refusal to provide the data makes it impossible for us to accommodate you.
5.1 Notification to the Police Headquarters (Questura) via the “Alloggiati Web” portal. Pursuant to Article 109 of Royal Decree No. 773 of 18 June 1931 (the Consolidated Public Security Act — TULPS) and the Ministry of the Interior Decree of 7 January 2013, operators of accommodation facilities must personally identify every guest by means of an identity document and communicate the guests' particulars to the territorially competent Police Headquarters (Questura), through the “Alloggiati Web” portal of the Italian State Police, within 24 hours of arrival (within 6 hours for stays of less than 24 hours). The data communicated is: first name and surname, sex, date and place of birth, nationality, and the type, number and place of issue of the document, date of arrival and length of stay. Recipient: the Ministry of the Interior — Italian State Police, which processes the data as an independent controller. A copy of the guest registration form is kept by the property for the periods laid down by public-security legislation.
5.2 Statistical survey of tourist movement. Pursuant to Legislative Decree 322/1989 and Apulian regional legislation, the property is required to transmit monthly the data on arrivals and overnight stays as part of the statistical survey coordinated by ISTAT (the Italian National Institute of Statistics) and included in the National Statistical Programme, through the SPOT system of the Puglia Region's Destination Management System, managed by the regional tourism agency Pugliapromozione (ARET). The data transmitted is aggregated and anonymous as regards the identity of guests (number of arrivals and overnight stays, place of origin, room type, length of stay) and does not allow individual persons to be identified.
5.3 Tourist tax. The Municipality of Putignano applies a municipal tourist tax. As the party responsible for payment of the tax, the property collects and keeps the data required for its collection, reporting and annual declaration to the Municipality (number of overnight stays per guest, any documented grounds for exemption, issue of the named receipt). Legal basis: legal obligation under Article 4 of Legislative Decree 23/2011 and the applicable municipal regulation. Further information in the Legal notice.
5.4 Tax and accounting obligations. Issuing receipts and invoices, accounting entries, communications to the Italian Revenue Agency (Agenzia delle Entrate) and document retention pursuant to Presidential Decree 633/1972, Presidential Decree 600/1973 and Article 2220 of the Italian Civil Code.
5.5 Special categories of data. We do not ask for or record health-related data. Should you spontaneously provide us with information of this kind — for example to request an accessible room or to document an exemption from the tourist tax — such data will be processed solely to fulfil your request or to comply with the tax obligation, on the basis of your explicit consent (Article 9(2)(a) of the GDPR) or of the legal obligation, and will be deleted as soon as the need ceases to exist.
6. No resources loaded from third-party domains
When you open a page of this site, your browser connects exclusively to the domain www.ilgirasoleputignano.com. All the resources needed to display the pages — style sheets, scripts, images and fonts — are hosted on that same domain.
In particular, the Caveat, Marcellus, Outfit and Spectral fonts are installed directly on our server as woff2 files and called by the site's style sheet. They are not fetched from Google Fonts or from any other external distribution network: the pages make no requests to the fonts.googleapis.com and fonts.gstatic.com domains.
The practical consequence, and the reason we adopted this configuration, is that during simple browsing of the site no data concerning you is communicated to external providers. Your IP address is not transmitted to any third party: it remains known only to the hosting provider, which processes it as a processor on our behalf within the limits described in points 4.1 and 8.
Nor does the site embed any third-party content: no interactive maps, no videos, no social widgets, no externally loaded review system, no advertising network, no statistics or traffic-analysis service. The only connections to third parties are those you choose to activate by clicking a link, as described in the following point.
7. Third-party services activated only on your own initiative
As explained in point 6, the site does not embed widgets, interactive maps, videos or social buttons that load third-party content when the page opens. There are instead simple hyperlinks, which are activated only if you voluntarily decide to click them:
WhatsApp — the “Message us on WhatsApp” buttons open the wa.me domain and then the WhatsApp application. From that moment the processing of the conversation data is also governed by the privacy policy of WhatsApp Ireland Limited (Meta group), which acts as an independent controller as regards the metadata of the messaging service. The content of the message you send us is processed by us in accordance with point 4.2 of this policy.
Google Maps — the “Open directions in Google Maps” link takes you to Google's navigation service, which will process your data as an independent controller in accordance with its own privacy policy. No map is embedded in our pages.
Instagram — the link to the @ilgirasole_putignano profile opens the Instagram website or app, operated by Meta Platforms Ireland Limited, which processes your data as an independent controller in accordance with its own privacy policy.
Booking.com and Google — the “Read more on Booking” and “Read more on Google Maps” buttons take you to the review pages published on those platforms, which process your data as independent controllers in accordance with their respective privacy policies. No review is loaded from outside into our pages.
Telephone and email — the tel: and mailto: links open, respectively, the phone application and the email client on your device. No data is sent until you decide to call or send the message.
We invite you to consult the privacy policies of the respective providers before using these services. The controller is not responsible for the processing carried out by such parties.
8. Recipients of the data and processors
Personal data is not disseminated and is not transferred to third parties for commercial purposes. It may be communicated solely to the following parties, each within its own remit:
Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) and its European affiliates, as a processor under Article 28 of the GDPR, being the provider of the Cloudflare Pages hosting service, the content delivery network (CDN) and the infrastructure security and protection services. Cloudflare processes the technical logs described in point 3(a). The relationship is governed by Cloudflare's Data Processing Addendum, which incorporates the Standard Contractual Clauses approved by the European Commission.
Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and its parent company Google LLC, as processors, being the providers of the Gmail email service on which the mailbox given in point 1 is hosted: the messages you send us by email pass through and remain stored on the provider's infrastructure for the periods indicated in point 4.2. The mailbox is used solely for correspondence with guests: it does not feed any contact list, it is not used for marketing purposes and it gives rise to no profiling on our part.
The Ministry of the Interior — Italian State Police, as an independent controller, for the mandatory notifications referred to in point 5.1.
The Puglia Region and the regional tourism agency Pugliapromozione (ARET), as well as ISTAT, as independent controllers, for the statistical survey referred to in point 5.2.
The Municipality of Putignano, as an independent controller, for the tourist-tax obligations referred to in point 5.3.
The Italian Revenue Agency (Agenzia delle Entrate) and other public bodies, as independent controllers, for tax and fiscal obligations.
The property's tax and accounting advisor, acting as a processor or as an independent controller depending on the professional role held.
Online booking portals (for example Booking.com B.V.), as independent controllers, limited to bookings made through their channels and in accordance with the privacy notices they provide to users.
As noted in point 6, Cloudflare is the only external provider that processes data during the simple browsing of the site: no other party receives data as a result of a page being opened. The other recipients listed above are involved only at the booking and stay stage.
An up-to-date list of the processors may be requested at any time by writing to the controller's contact details.
9. Transfer of data to third countries
The processing operations described ordinarily take place within the European Economic Area. The only transfer to a third country that may occur as a result of browsing the site is the one connected with Cloudflare's services (hosting and content delivery network), a company based in the United States of America, and with the countries in which its sub-processors operate. Since the fonts are hosted on our own domain, as indicated in point 6, there is no longer any transfer of data to Google connected with browsing.
The transfer is supported by the appropriate safeguards laid down in Chapter V of the GDPR and, in particular:
a) Adequacy decision. On 10 July 2023 the European Commission adopted the adequacy decision relating to the EU-U.S. Data Privacy Framework: transfers to US organisations that adhere to the Framework and are actively certified take place towards a country deemed to offer an adequate level of protection, pursuant to Article 45 of the GDPR. Cloudflare declares that it adheres to the Framework. The decision is still in force as at the date on which this policy was last updated; for the sake of transparency, we note that it is the subject of a pending legal challenge before the Court of Justice of the European Union, following which this policy will be updated if necessary.
b) Standard Contractual Clauses (SCC). In addition and independently, relations with Cloudflare are governed by the Standard Contractual Clauses adopted by the European Commission by Implementing Decision (EU) 2021/914, supplemented by the technical and organisational additional measures put in place by the provider, pursuant to Article 46(2)(c) of the GDPR. This safeguard operates independently of the adequacy decision and would continue to have effect even if the latter were to cease.
A separate transfer may concern email correspondence: the Gmail service is provided by Google Ireland Limited, based in the European Union, but the data may also be processed by Google LLC in the United States of America. Google LLC is certified under the EU-U.S. Data Privacy Framework and is also bound by the Standard Contractual Clauses referred to in point (b). This transfer occurs only if you choose to write to us by email and bears no relation to the simple browsing of the site.
Transfers possibly carried out by the third-party services you voluntarily choose to activate by clicking the links described in point 7 fall outside this provision: in that case the relevant providers act as independent controllers, in accordance with their own privacy policies.
You may ask the controller for information on the safeguards adopted and a copy of the relevant documentation by writing to the contact details given in point 1.
10. Nature of the provision of data
Browsing the site. The provision of browsing data is implicit in the use of internet protocols and cannot be avoided if you wish to view the pages.
Requests for information. Provision is optional; failure to provide the data means only that you cannot receive a reply or a quotation.
Booking and stay. The provision of the data required to enter into and perform the hospitality contract and to comply with legal obligations is mandatory: without it, it is not possible to confirm the booking or to accommodate the person at the property.
Language preference. Provision is optional and occurs only if you actively select a language; otherwise the site will simply be displayed in the language of the page you have opened.
11. No automated decision-making or profiling
The controller does not carry out any automated decision-making, including profiling, within the meaning of Article 22(1) and (4) of the GDPR. No user or guest profiles are built, no scores are assigned and no decision producing legal effects or similarly significantly affecting individuals is taken on a solely automated basis.
12. Rights of the data subject
In relation to the processing operations described, you may exercise at any time the following rights granted by Articles 15 to 22 of the GDPR:
Right of access (Article 15). To obtain confirmation as to whether your data is being processed, to access that data and the information on the purposes, the recipients, the retention period and the origin of the data, and to receive a copy of the data processed.
Right to rectification (Article 16). To obtain, without undue delay, the correction of inaccurate data and the completion of incomplete data.
Right to erasure — the “right to be forgotten” (Article 17). To obtain the erasure of data where it is no longer necessary, where you withdraw consent on which the processing was based, or where you successfully object to the processing. This right cannot be exercised over data that we are required to keep by law (in particular the data indicated in point 5).
Right to restriction (Article 18). To obtain the restriction of processing in the cases provided for, for example while the accuracy of contested data is being verified.
Right to data portability (Article 20). To receive, in a structured, commonly used and machine-readable format, the data processed by automated means on the basis of consent or of a contract, and to transmit it to another controller.
Right to object (Article 21). To object at any time, on grounds relating to your particular situation, to processing based on the controller's legitimate interest.
Right to withdraw consent (Article 7(3)). Where processing is based on consent, to withdraw it freely at any time, without prejudice to the lawfulness of processing carried out before the withdrawal.
How to exercise your rights. It is enough to contact us by telephone or WhatsApp at +39 380 373 4277 or send a request by post to il Girasole — Holiday home, Via Nuova 15, 70017 Putignano (BA). To allow us to identify you, we may ask you for some additional information. We will reply without undue delay and in any case within one month of receiving the request, extendable by a further two months in cases of particular complexity, of which we will inform you. Exercising your rights is free of charge, save for manifestly unfounded or excessive requests, in particular where they are repetitive.
13. Right to lodge a complaint with the supervisory authority
If you consider that the processing of your personal data breaches the applicable legislation, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), pursuant to Article 77 of the GDPR, or to bring proceedings before the competent court pursuant to Article 79 of the GDPR.
Authority's contact details: Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Rome — switchboard +39 06 696771 — fax +39 06 69677 3785 — email protocollo@gpdp.it — certified email protocollo@pec.gpdp.it — website www.garanteprivacy.it.
14. Security measures
The controller adopts technical and organisational measures that are appropriate under Article 32 of the GDPR and proportionate to the nature and scale of the processing: connection to the site protected by the HTTPS/TLS protocol, access to devices and mailboxes restricted and protected by credentials, storage of paper documents in a place not accessible to the public, and access to data limited to authorised persons instructed under Article 29 of the GDPR. However, no security measure can guarantee the absolute inviolability of computer systems.
15. Data relating to minors
The site is not aimed at minors and does not knowingly collect data from minors through its pages. The data of minors staying at the property is processed solely for the legal obligations referred to in point 5 and for the performance of the contract, and is provided by parents or by those exercising parental responsibility.
16. Amendments to this policy
The controller reserves the right to update this policy to bring it into line with legislative changes, rulings of the supervisory authorities or changes to the technical services used. The version in force is always the one published at this address, with the last-updated date shown at the top. We invite you to consult this page from time to time.
For any clarification on the content of this policy you may contact us by telephone or WhatsApp at +39 380 373 4277: we will be glad to help.