Privacy Policy
Privacy and online safety are important to Villa Monti. We process your personal data in strict compliance with Regulation (EU) 2016/679 (GDPR) and applicable data protection laws.
We process your data based on the following legal grounds:
-
Contract performance & pre-contractual measures: to answer your inquiries and process your bookings.
-
Legal obligations: to comply with statutory accounting, tax, and public security obligations (e.g., guest registration required by Italian law).
-
Consent: for non-essential cookies and analytics tracking, which you can manage or revoke at any time.
Data Controller
Villa Monti S.R.L., Via Roma n. 9/11, 23829 Varenna (LC), Italy.
Contact Email: privacy@visitvarenna.com
1. Personal Information We Collect and Why
1.1 Contact Form
-
Data collected: Name and email address.
-
Purpose & Legal Basis: Necessary to process your request prior to entering into a contract (Art. 6.1.b GDPR).
-
Storage & Transfer: Data is processed via our Content Management System (Wix.com) and transmitted via secure, encrypted TLS (SSL) email protocol.
-
Retention: Retention period is 6 months, after which inquiry records are deleted.
1.2 Booking Form
-
Data collected: First and Last Name, Billing Address, Phone Number, Email Address, and Payment/Credit Card details.
-
Purpose & Legal Basis: Required to finalize your booking, process payments, issue invoices, and fulfill statutory obligations (Art. 6.1.b & 6.1.c GDPR).
-
Processors & Storage:
-
Data is securely encrypted (HTTPS) and routed to our Property Management System (Sirvoy Ltd, Ireland).
-
Invoicing data is synchronized with Google Workspace (Google Ireland Ltd/Google LLC).
-
Credit card transactions are processed securely via Stripe Inc.
-
-
Retention: Booking details and invoices are retained for 10 years to meet statutory tax and accounting obligations under Italian law. Technical booking logs inside PMS/CMS are cleared after 18 months.
2. Payment & Cardholder Data Security (PCI-DSS)
Villa Monti complies with PCI-DSS standards. We do not store raw credit card numbers (PAN) or security codes (CVV) on our local servers.
-
Credit card details are encrypted in transit and at rest via Stripe (PCI Service Provider Level 1) and Sirvoy.
-
Full card numbers are masked (showing only the last 4 digits) for authorized staff.
-
Card details are retained only for the timeframe necessary to complete charges, process authorized deposits/refunds, or fulfill statutory anti-fraud regulations.
3. Third-Party Data Processors & International Transfers
We work with selected processors to operate our website and services. Transfers of personal data outside the European Economic Area (EEA) rely on EU Adequacy Decisions or Standard Contractual Clauses (SCCs), including the EU-U.S. Data Privacy Framework:
-
Wix.com Ltd. (Website Hosting & CMS) – Israel (EU Adequacy Decision) / USA (EU-U.S. DPF).
-
Sirvoy Ltd. (PMS) – Ireland (EEA).
-
Stripe Inc. (Payment Processor) – USA (EU-U.S. DPF certified).
-
Google Ireland Ltd. / Google LLC (Analytics & Infrastructure) – Ireland / USA (EU-U.S. DPF certified).
4. Your Data Rights
Under Articles 15–22 of the GDPR, you have the right to:
-
Access, update, or rectify your personal data.
-
Request erasure of your data (where processing is no longer legally required).
-
Restrict or object to data processing.
-
Request data portability.
-
Lodge a complaint with a supervisory authority (in Italy, Garante per la protezione dei dati personali).
To exercise your rights, email us at privacy@visitvarenna.com. We will handle your request within 30 days.
5. Data Breaches
In the event of a personal data breach liable to result in a high risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform affected users in accordance with GDPR requirements.
6. Cookies & Tracking Technologies
Our website uses cookies to ensure proper site function and improve user experience. Non-essential cookies are only loaded after you provide consent via our Cookie Banner.
-
Essential/Technical Cookies: Necessary for site security and navigation (e.g., Wix XSRF-TOKEN, hs session cookies).
-
Analytics Cookies: We use Google Analytics (_ga) to monitor aggregated, anonymized visitor metrics. Data retention is set to 14 months.
-
Managing Cookies: You can change your preferences at any time via the cookie settings banner on our site or through your web browser settings.
7. Changes to This Policy
We reserve the right to update this policy to reflect legal or operational changes.
Last updated: March 2026