Privacy policy

Information Notice on the Processing of Personal Data

Pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”)

Last updated:: 06/05/2026

1. DATA CONTROLLER

The Data Controller of personal data is:

APULIA PRIVE’ S.r.l.
Corso Umberto I, 10
74123 Taranto (TA)
Italy

(hereinafter referred to as the “Data Controller”)

2. TYPES OF PERSONAL DATA COLLECTED

While browsing the website and using the services provided, the following categories of personal data may be collected and processed:

a) Browsing Data

The computer systems and software procedures used to operate this website automatically acquire certain technical data whose transmission is inherent in the use of Internet communication protocols, including but not limited to:

  • IP address;
  • browser and device information
  • date and time of access;
  • visited pages;
  • technical data necessary for the proper functioning of the website.

b) Data Voluntarily Provided by the User

Through the forms available on the website, users may voluntarily provide personal data such as:

  • first and last name;
  • e-mail address;
  • telephone number
  • content of submitted requests
  • information entered to request, customize, or receive proposals related to the tourism experiences offered.

3. PURPOSES OF PROCESSING AND LEGAL BASIS

Personal data are processed for the following purposes:

a) To enable website navigation and ensure the proper functioning and security of the website.

Legal basis: the legitimate interest of the Data Controller (Art. 6(1)(f) GDPR).

To manage information requests submitted through the website forms.

Legal basis: implementation of pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR).

c) To process requests relating to tourism experiences, customized proposals, availability inquiries, quotations, or other information requested by the user.

Legal basis: implementation of pre-contractual and/or contractual measures (Art. 6(1)(b) GDPR).

d) To comply with legal obligations, regulations, or requests from competent authorities.

Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).

e) To establish, exercise, or defend legal claims.

Legal basis: the legitimate interest of the Data Controller (Art. 6(1)(f) GDPR).

4. METHODS OF PROCESSING

Personal data are processed using electronic and telematic tools and, where necessary, paper-based means.

The Data Controller adopts appropriate technical and organizational measures to ensure data security and prevent unauthorized access, disclosure, alteration, or destruction of personal data.

5. PROVISION OF DATA

The provision of personal data through the contact forms is voluntary.

However, failure to provide data marked as mandatory may prevent the Data Controller from responding to the user’s requests or processing requests relating to tourism experiences.

6. RECIPIENTS OF PERSONAL DATA

Personal data may be disclosed to parties acting as data processors or independent data controllers, including:

  • hosting and IT infrastructure service providers;
  • email service providers;
  • consultants and professionals assisting the Data Controller in administrative, legal, or tax matters;
  • public authorities and competent bodies where required by law.

Personal data will not be publicly disclosed.

7. DATA RETENTION

Personal data collected through the website forms will be retained for the time necessary to manage the user’s request and, in any event, for no longer than 24 months from the conclusion of communications, unless a longer retention period is required by law or necessary for the protection of the Data Controller’s rights.

Data processed to comply with legal obligations will be retained for the period required by applicable legislation.

8. TRANSFER OF DATA OUTSIDE THE EUROPEAN UNION

Personal data are primarily processed within the European Economic Area (EEA).

Should it become necessary to transfer personal data to countries outside the EEA, such transfers will be carried out in accordance with Articles 44 et seq. of the GDPR and subject to the appropriate safeguards required by applicable law.

9. DATA SUBJECT RIGHTS

Data subjects may exercise the rights granted by Articles 15–22 GDPR at any time, including the right to:

  • obtain confirmation as to whether personal data concerning them are being processed;
  • access their personal data;
  • request rectification of inaccurate data;
  • request erasure of personal data;
  • request restriction of processing;
  • object to processing where permitted by law;
  • receive personal data in a structured, commonly used format and request data portability, where applicable.

Requests relating to the exercise of these rights may be sent to the email address of the Data Controller indicated in this Privacy Policy.

10. RIGHT TO LODGE A COMPLAINT

If a data subject believes that the processing of their personal data infringes applicable data protection laws, they have the right to lodge a complaint with the competent supervisory authority.

11. CHANGES TO THIS PRIVACY POLICY

The Data Controller reserves the right to update or modify this Privacy Policy at any time. Any changes will be published on this page together with the updated revision date.

For any information regarding this Privacy Policy or the processing of personal data, please contact us through one of the following methods: