Legal information
Privacy Policy
Last updated: 22 July 2026
This privacy notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (hereinafter the “GDPR”) and to D.lgs. 196/2003 as amended by D.lgs. 101/2018 (the Italian Personal Data Protection Code). It sets out precisely how B&B Villa Cassandra processes the personal data of those who visit the website villacassandracastellana.com, of those who contact us for information or bookings and of those who stay at the property.
We have chosen to write a text that reflects what this website actually does: we do not use profiling cookies, we do not use any statistics or traffic analysis tools, we do not use social network pixels, we have no online contact forms and we load no resources from third-party domains. What follows describes exactly the few processing operations that genuinely take place.
1. Data Controller
The Data Controller is B&B Villa Cassandra, with its registered office at Via Turi 54, 70013 Castellana Grotte (BA), Italy — VAT number (P. IVA) 08196100724 — CIN IT072017B400027290 — CIR 072017B400027290.
Contact details for any matter relating to the protection of personal data: email donatomanghisi@gmail.com, telephone and WhatsApp +39 338 798 5003.
2. Data Protection Officer (DPO)
The Data Controller has not appointed a Data Protection Officer, since the mandatory conditions laid down in Article 37 of the GDPR do not apply: the property is not a public authority, its core activities do not require regular and systematic monitoring of Data Subjects on a large scale and it does not process special categories of data on a large scale. Any request concerning personal data may be addressed directly to the Data Controller using the contact details given in section 1.
3. Categories of personal data processed
a) Browsing data (technical logs). The computer systems and software procedures used to operate this website acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: the IP address of the device used, browser type and operating system (user agent), the date and time of the request, the URL of the resources requested, the server response code, the volume of data transferred and any referring page. These data are generated and stored by the hosting provider and are not used by the Data Controller to identify users, nor are they cross-referenced with any other information.
b) Data provided voluntarily by the user. This website contains no contact form of any kind. If you decide to write to us or call us using the contact details published here (email, telephone, WhatsApp), we will process the data you send us of your own accord: name, email address, telephone number, the dates and features of the stay you are looking for, the number of guests and — where this is relevant to the rate or to extra beds — their age, together with any other information contained in your message.
c) Guest data at the time of booking and during the stay. Personal particulars, details of the identity or identification document, nationality, contact details, arrival and departure dates, and the data required for invoicing and for the collection of the tourist tax. Full details are given in section 5.
d) Language preference. If you select a language from the website menu (Italian, English or French), your browser saves an entry named vc-lang locally on your device, through localStorage, with the value it, en or fr. This is a purely technical item of data, with no identifying content, which is not transmitted to our servers or to any third party and serves solely to show you the website in the language you have chosen on your subsequent visits. Full details are given in the Cookie Policy.
e) Data that may be provided by third parties. If you book through an online booking portal (for example Booking.com), we receive from that portal the data needed to manage the booking: name, contact details, details of the stay and, where applicable, payment data. In this case Article 14 of the GDPR applies and the categories of data are those which the portal transmits to the property under its own contractual terms and its own privacy notice.
4. Purposes of the processing, legal bases and retention periods
4.1 Delivery and security of the website. Browsing data are processed in order to allow the pages to be viewed, to ensure the stability of the service and to protect the infrastructure against abusive use (attacks, malicious automated traffic). Legal basis: the legitimate interest of the Data Controller under Article 6(1)(f) of the GDPR in the security and proper functioning of its own website. Technical logs are retained by the hosting provider for the time strictly necessary for those purposes, as a rule no longer than a few days, and are not downloaded, stored or further processed by us. The only exception to this rule concerns the investigation of computer crime, where the data may be requested by the judicial authorities.
4.2 Responding to requests for information and availability. The data you send us by email, telephone or WhatsApp are processed in order to answer your enquiry, check room availability and prepare a quotation. Legal basis: the performance of pre-contractual measures taken at the Data Subject's request under Article 6(1)(b) of the GDPR. Retention: where an enquiry is not followed by a booking, the data are kept for a maximum of 12 months from the last contact, unless you ask us to erase them sooner.
4.3 Managing the booking and the stay. We process the data needed to confirm the booking, welcome you, provide the services requested (breakfast, shuttle, extra beds, transfers) and handle any changes or cancellations. Legal basis: performance of the contract of accommodation under Article 6(1)(b) of the GDPR. Retention: for the duration of the relationship and thereafter for the periods laid down by accounting and tax law and by the ordinary limitation period.
4.4 Statutory obligations. We process the data in order to comply with the public security, statistical, tax and accounting obligations described in section 5. Legal basis: compliance with a legal obligation to which the Data Controller is subject, under Article 6(1)(c) of the GDPR. Retention: for the periods laid down by the relevant legislation, in particular 10 years for accounting records and tax documents pursuant to art. 2220 c.c. (Italian Civil Code) and to tax legislation.
4.5 Defence of rights. In the event of disputes, damage or breach of contract, the data may be processed in order to establish, exercise or defend a legal claim in or out of court. Legal basis: legitimate interest under Article 6(1)(f) of the GDPR. Retention: for the duration of the dispute and until the time limits for appeal have expired.
4.6 Language preference. Saving the chosen language locally responds to an explicit request by the user and is indispensable in order to deliver the service in the manner requested. It therefore falls among the tools that are strictly necessary within the meaning of art. 122 of D.lgs. 196/2003 and requires no consent. The data remain on your device until you clear your browser's browsing data.
We do not carry out any direct marketing. We do not send newsletters, we keep no contact lists for promotional purposes and we do not use your data to send you commercial offers, unless you specifically ask us to.
5. Processing of guest data: the statutory obligations of an accommodation provider
Anyone staying at B&B Villa Cassandra is subject to certain processing operations which the property is required by law to carry out. Your consent is not required, because the legal basis is compliance with a legal obligation (Article 6(1)(c) of the GDPR); refusal to provide the data makes it impossible for us to accommodate you.
5.1 Notification to the Questura through the Alloggiati Web portal. Pursuant to art. 109 of R.D. 773/1931 (Testo Unico delle Leggi di Pubblica Sicurezza — TULPS, the Italian Consolidated Public Security Act of 18 June 1931) and to the D.M. Interno (Ministry of the Interior Decree) of 7 January 2013, operators of accommodation facilities must personally identify every person lodged by means of an identity document and report the guests' particulars to the territorially competent Questura (provincial police headquarters), through the Polizia di Stato portal “Alloggiati Web”, within 24 hours of arrival (within 6 hours for stays of less than 24 hours). The data reported are: first name and surname, sex, date and place of birth, nationality, type, number and place of issue of the document, date of arrival and length of stay. Recipient: the Ministero dell'Interno — Polizia di Stato (Italian Ministry of the Interior — State Police), which processes the data as an independent Data Controller. The copy of the guest registration form is kept by the property for the periods laid down by public security legislation.
5.2 Statistical survey of tourist flows. Pursuant to D.lgs. 322/1989 and to Apulian regional legislation, the property is required to submit monthly data on arrivals and overnight stays as part of the statistical survey coordinated by ISTAT (the Italian National Institute of Statistics) and included in the National Statistical Programme, through the SPOT system of the Destination Management System of the Regione Puglia, operated by the regional tourism agency Pugliapromozione (ARET). As far as the identity of guests is concerned, the data submitted are aggregated and anonymous (number of arrivals and overnight stays, place of origin, room type, length of stay) and do not make it possible to trace individual persons.
5.3 Tourist tax. The Comune di Castellana Grotte (Municipality of Castellana Grotte) levies a municipal tourist tax. As the party responsible for payment of the tax, the property collects and keeps the data required for collection, reporting and the annual declaration to the Municipality (number of overnight stays per guest, any documented grounds for exemption, issue of a named receipt). Legal basis: legal obligation under art. 4 of D.lgs. 23/2011 (of 14 March 2011) and the municipal regulation in force. Further information is given in the Legal notices.
5.4 Tax and accounting obligations. Issue of receipts and invoices, accounting entries, reports to the Agenzia delle Entrate (Italian Revenue Agency) and record retention pursuant to D.P.R. 633/1972, D.P.R. 600/1973 and art. 2220 c.c. (Italian Civil Code).
5.5 Special categories of data. We do not ask for and do not record any data concerning health. Should you spontaneously give us information of this kind — for example in order to request an accessible room, the free shuttle to the IRCCS “Saverio de Bellis” or to document an exemption from the tourist tax — such data will be processed solely in order to meet your request or to comply with the tax obligation, on the basis of your explicit consent (Article 9(2)(a) of the GDPR) or of the legal obligation, and will be erased as soon as they are no longer needed.
6. No resources loaded from third-party domains
When you open a page of this website, your browser connects solely to the villacassandracastellana.com domain. All the resources needed to display the page — style sheets, scripts, images and typefaces — are hosted on that same domain.
In particular, the typefaces Italianno, Marcellus, Outfit and Spectral are installed directly on our own server as woff2 files and called from the website's style sheet. They are not fetched from Google Fonts, nor from any other external distribution network: the pages send no requests to the domains fonts.googleapis.com and fonts.gstatic.com.
The practical consequence, and the very reason why we have adopted this set-up, is that while you are simply browsing the website no data concerning you is disclosed to any external provider. Your IP address is not transmitted to any third party: it remains known only to the hosting provider, which processes it as a Data Processor on our behalf within the limits described in sections 4.1 and 8.
Nor does the website embed any content originating from third parties: no interactive map, no video, no social widget, no externally loaded review system, no advertising network, no statistics or traffic analysis service. The only connections to third parties are those you choose to activate by clicking a link, as described in the following section.
7. Third-party services activated only on your own initiative
As explained in section 6, the website embeds no widgets, interactive maps, videos or social buttons that would load third-party content when a page is opened. What it does contain are plain hyperlinks, which are activated only if you deliberately choose to click on them:
WhatsApp — the “Message us on WhatsApp” buttons open the wa.me domain and then the WhatsApp application. From that moment on, the processing of the conversation data is also governed by the privacy notice of WhatsApp Ireland Limited (Meta group), which acts as an independent Data Controller as regards the metadata of the messaging service. The content of the message you send us is processed by us in accordance with section 4.2 of this notice.
Google Maps — the “Open directions in Google Maps” link leads to Google's navigation service, which will process your data as an independent Data Controller in accordance with its own privacy notice. No map is embedded in our pages.
Telephone and email — the tel: and mailto: links open, respectively, the telephone application and the mail client on your device. No data are sent until you decide to place the call or send the message.
We encourage you to read the privacy notices of the respective providers before using these services. The Data Controller is not responsible for the processing carried out by those parties.
8. Data recipients and Data Processors
Personal data are not disseminated and are not transferred to third parties for commercial purposes. They may be disclosed solely to the following parties, each within its own remit:
Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) and its European affiliates, acting as a Data Processor under Article 28 of the GDPR, as the provider of the Cloudflare Pages hosting service, of the content delivery network (CDN) and of the security and infrastructure protection services. Cloudflare processes the technical logs described in section 3(a). The relationship is governed by Cloudflare's Data Processing Addendum, which incorporates the Standard Contractual Clauses approved by the European Commission.
Ministero dell'Interno — Polizia di Stato (Italian Ministry of the Interior — State Police), as an independent Data Controller, for the mandatory notifications referred to in section 5.1.
Regione Puglia and the regional tourism agency Pugliapromozione (ARET), as well as ISTAT, as independent Data Controllers, for the statistical survey referred to in section 5.2.
Comune di Castellana Grotte, as an independent Data Controller, for the tourist tax obligations referred to in section 5.3.
Agenzia delle Entrate and other public bodies, as independent Data Controllers, for tax and fiscal obligations.
The property's tax and accounting adviser, acting either as a Data Processor or as an independent Data Controller depending on the professional role performed.
Online booking portals (for example Booking.com B.V.), as independent Data Controllers, limited to bookings made through their channels and in accordance with the privacy notices they provide to users.
As made clear in section 6, Cloudflare is the only external provider that processes data when you simply browse the website: no other party receives data as a result of a page being opened. The other recipients listed above are involved only at the booking and stay stage.
An up-to-date list of the Data Processors may be requested at any time by writing to the Data Controller's contact addresses.
9. Transfers of data to third countries
The processing operations described here ordinarily take place within the European Economic Area. The only transfer to a third country that can occur as a result of browsing this website is the one connected with the services of Cloudflare (hosting and content delivery network), a company based in the United States of America, and with the countries in which its sub-processors operate. Since the typefaces are hosted on our own domain, as stated in section 6, there is no longer any transfer of data to Google connected with browsing.
The transfer is covered by the appropriate safeguards provided for in Chapter V of the GDPR, and in particular:
a) Adequacy decision. On 10 July 2023 the European Commission adopted its adequacy decision on the EU-U.S. Data Privacy Framework: transfers to US organisations that adhere to the Framework and hold an active certification are made to a country deemed to afford an adequate level of protection, within the meaning of Article 45 of the GDPR. Cloudflare states that it adheres to the Framework. The decision is still in force as at the date on which this notice was updated; in the interests of transparency we note that it is the subject of a pending action for annulment before the Court of Justice of the European Union, following which this notice will be updated if necessary.
b) Standard Contractual Clauses (SCCs). As a further and independent safeguard, the relationship with Cloudflare is governed by the Standard Contractual Clauses adopted by the European Commission in implementing decision (EU) 2021/914, supplemented by the technical and organisational measures put in place by the provider, pursuant to Article 46(2)(c) of the GDPR. This safeguard operates independently of the adequacy decision and would continue to have effect even if that decision were to cease to apply.
Transfers that may be carried out by the third-party services you voluntarily choose to activate by clicking the links described in section 7 fall outside the scope of this section: in that case the providers concerned act as independent Data Controllers, in accordance with their own privacy notices.
You may ask the Data Controller for information about the safeguards adopted and for a copy of the relevant documentation by writing to the contact addresses given in section 1.
10. Whether the provision of data is mandatory
Visiting the website. The provision of browsing data is implicit in the use of Internet protocols and cannot be avoided if you wish to view the pages.
Requests for information. Provision is optional; failure to provide the data merely makes it impossible for you to receive an answer or a quotation.
Booking and stay. Provision of the data required to enter into and perform the accommodation contract and to comply with statutory obligations is mandatory: without it the booking cannot be confirmed and the person cannot be accommodated at the property.
Language preference. Provision is optional and occurs only if you actively select a language; if you do not, the website will simply be displayed in the language of the page you have opened.
11. No automated decision-making or profiling
The Data Controller carries out no automated decision-making, including profiling, within the meaning of Article 22(1) and (4) of the GDPR. No user or guest profiles are built, no scores are assigned and no decision producing legal effects or similarly significantly affecting individuals is taken solely by automated means.
12. Rights of the Data Subject
In relation to the processing described here, you may exercise at any time the following rights granted by Articles 15 to 22 of the GDPR:
Right of access (Article 15). To obtain confirmation as to whether your data are being processed, to access those data and to obtain information about the purposes, the recipients, the retention period and the source of the data, as well as to receive a copy of the data processed.
Right to rectification (Article 16). To obtain, without undue delay, the correction of inaccurate data and the completion of incomplete data.
Right to erasure — the “right to be forgotten” (Article 17). To obtain the erasure of your data where they are no longer necessary, where you withdraw a consent on which the processing was based, or where you successfully object to the processing. This right cannot be exercised over data which we are required by law to retain (in particular those referred to in section 5).
Right to restriction (Article 18). To obtain restriction of the processing in the cases provided for, for example while the accuracy of contested data is being verified.
Right to data portability (Article 20). To receive, in a structured, commonly used and machine-readable format, the data processed by automated means on the basis of consent or of a contract, and to transmit them to another controller.
Right to object (Article 21). To object at any time, on grounds relating to your particular situation, to processing based on the legitimate interest of the Data Controller.
Right to withdraw consent (Article 7(3)). Where processing is based on consent, to withdraw that consent freely at any time, without affecting the lawfulness of the processing carried out before the withdrawal.
How to exercise your rights. Simply send a request, even an informal one, to donatomanghisi@gmail.com or by post to B&B Villa Cassandra, Via Turi 54, 70013 Castellana Grotte (BA), Italy. In order to identify you, we may ask you for some additional information. We will reply without undue delay and in any event within one month of receiving the request; this period may be extended by a further two months where the request is particularly complex, in which case we will inform you. Exercising your rights is free of charge, except in the case of manifestly unfounded or excessive requests, in particular because of their repetitive character.
13. Right to lodge a complaint with the supervisory authority
If you believe that your personal data are being processed in breach of the applicable legislation, you have the right to lodge a complaint with the Garante per la protezione dei dati personali (the Italian Data Protection Authority), pursuant to Article 77 of the GDPR, or to bring proceedings before the competent courts pursuant to Article 79 of the GDPR.
Contact details of the Authority: Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Roma, Italy — switchboard +39 06 696771 — fax +39 06 69677 3785 — email protocollo@gpdp.it — certified email (PEC) protocollo@pec.gpdp.it — website www.garanteprivacy.it.
14. Security measures
The Data Controller applies technical and organisational measures that are appropriate under Article 32 of the GDPR and proportionate to the nature and scale of the processing: connection to the website protected by the HTTPS/TLS protocol, access to devices and mailboxes restricted and protected by credentials, paper records kept in a place not accessible to the public, and access to data limited to persons who are authorised and instructed under Article 29 of the GDPR. No security measure can, however, guarantee the absolute inviolability of computer systems.
15. Data relating to minors
The website is not aimed at minors and does not knowingly collect data relating to minors through its pages. Data relating to minors staying at the property are processed solely for the statutory obligations referred to in section 5 and for the performance of the contract, and are provided by their parents or by those exercising parental responsibility.
16. Changes to this privacy notice
The Data Controller reserves the right to update this notice in order to bring it into line with legislative changes, with decisions of the supervisory authorities or with changes to the technical services used. The version in force is always the one published at this address, with the date of the last update shown at the top. We encourage you to check this page from time to time.
For any clarification about the content of this notice you can write to us at donatomanghisi@gmail.com: we will be glad to reply.