1. Data controller
The data controller is Directel — [LEGAL ENTITY / RAGIONE SOCIALE — PLACEHOLDER], VAT / P.IVA [PLACEHOLDER], with registered office at Via Bonifacio Lupi 14, 50129 Firenze, Italy. For any question about this policy or your personal data, please write to info@directelhotels.com.
2. What data we collect
• Data you provide via the “Book a consultation” form: name, hotel name, email address, number of rooms and the content of your message.
• Data collected automatically when you use the site: IP address, browser and device information, pages viewed, referring page, approximate location derived from IP, and (only with your consent) cookies and similar technologies for analytics and marketing.
• Any additional data you send us by email or another channel.
3. Purposes and legal bases
• Respond to your enquiry and provide the requested consultation — legal basis: pre-contractual measures at your request (Art. 6(1)(b) GDPR) and our legitimate interest in replying to prospects (Art. 6(1)(f) GDPR).
• Operate, secure and improve the site (server logs, spam/abuse prevention) — legal basis: legitimate interest (Art. 6(1)(f) GDPR).
• Analytics and marketing cookies — legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time from the cookie preferences.
• Comply with legal obligations — legal basis: Art. 6(1)(c) GDPR.
4. Data recipients and processors
We use a small number of trusted providers who act as data processors on our behalf:
• Lovable / Supabase — website hosting, database and backend services that store the form submissions and site content.
• Our transactional email service — used to deliver notification emails from notify.directelhotels.com to our internal inbox.
• Any professional advisors (accountants, lawyers) bound by confidentiality, if strictly necessary.
We do not sell your personal data. We do not share it for third-party marketing.
5. International transfers
Some of our processors may process data outside the European Economic Area. When this happens, transfers are protected by an adequacy decision of the European Commission or by Standard Contractual Clauses (SCCs) adopted under Art. 46 GDPR, together with any additional safeguards required. You can request a copy of the safeguards by writing to info@directelhotels.com.
6. Retention
• Enquiry form data: kept for up to 24 months from your last interaction, then deleted or anonymised, unless a longer period is required to answer follow-up questions or to comply with legal obligations.
• Server / security logs: up to 12 months.
• Cookie consent record: up to 12 months, then re-asked.
7. Your rights
Under Articles 15–22 GDPR you have the right to: access your data, obtain rectification or erasure, restrict or object to processing, receive your data in a portable format, and — where processing is based on consent — withdraw that consent at any time without affecting the lawfulness of prior processing. To exercise any of these rights, email info@directelhotels.com. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or the authority of your country of residence.
8. Security
We use HTTPS across the site, access controls, encrypted storage on our providers' infrastructure, and least-privilege database policies to protect your data. No system is 100% secure, but we work to keep the risk as low as reasonably possible.
9. Children
This site is not directed at children under 16. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top shows the most recent revision. Material changes will be highlighted on the site.