Privacy Policy
1. Controller
Controller within the meaning of Art. 4(7) GDPR:
Garni Steffi di Pattis Stefan, Schlossweg 7, I-39050 Völs am Schlern (BZ)
VAT No. 02758220210 | Email: info@garni-steffi.it
2. General
We treat personal data confidentially and in accordance with the GDPR (Regulation (EU) 2016/679), Italian data protection law (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018) and the guidelines of the Garante Privacy.
3. Legal Bases (Art. 6 GDPR)
- Consent (lit. a)
- Performance of a contract and pre-contractual measures (lit. b)
- Legal obligation (lit. c)
- Legitimate interests (lit. f)
4. Server Log Files
Each time the website is accessed, technically necessary data is stored: IP address (truncated/anonymised), date and time, page accessed, browser, operating system, referrer. Purpose: technical provision and security (Art. 6(1)(f)). Retention: max. 14 days.
5. Cookies and Tracking
For details, see the separate Cookie Policy. Cookies that are not technically necessary are only set after explicit consent.
6. Contact Form and Email
When you contact us via form, email or telephone, we process the data you provide (name, email, phone, enquiry content) to handle your request (Art. 6(1)(b) or (f)). Retention: until final processing + 6 months, then deletion — unless statutory retention obligations apply.
7. Contract and Billing Data
When a contract is concluded, we process master data, contract data and billing data for contract performance and invoicing. Retention: 10 years (mandatory Italian tax and accounting law, Art. 2220 c.c.).
8. Integrated Third-Party Services
The following services are used on our website (where active):
- Google Analytics 4 (Google Ireland Ltd.) — only loaded after your consent in the cookie banner
- Google Maps (Google Ireland Ltd.) — the map only loads when you actively open it
A complete, up-to-date list can be found in our cookie banner under “Show details”.
9. Third-Country Transfers
Data transfers to third countries (in particular the USA) are only carried out on the basis of the EU-U.S. Data Privacy Framework (DPF), Standard Contractual Clauses (SCC, EU 2021/914) or your explicit consent (Art. 49 GDPR).
10. Retention Periods (Overview)
- Server logs: 14 days
- Contact enquiries: until completion + 6 months
- Contract and accounting data: 10 years (mandatory)
- Cookie consents: 12 months (then re-consent)
11. Your Rights (Art. 15–22 GDPR)
Confirmation as to whether data is being processed, and access (Art. 15), rectification, erasure, restriction, data portability, objection, withdrawal of consent, as well as the right not to be subject to a decision based solely on automated processing, including profiling (Art. 22). Without prejudice to the right to complain, you also have the right to an effective judicial remedy (Art. 79 GDPR). Requests to: info@garni-steffi.it.
12. Right to Complain
You have the right to lodge a complaint with the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it.
13. Security
We use TLS encryption, access restrictions, regular backups and continuously review our security measures.
14. Minors
This website is not directed at persons under 16 years of age.
15. Changes
This policy may be updated to reflect changes in law or services. The current version is always available here.
16. Web analytics
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The measurement ID used is G-BBCMEDYN91. Google Analytics is only loaded after you have consented to the optional “Statistics” category in the cookie banner (Art. 6(1)(a) GDPR). Without consent, no statistics cookies are set and no data is transmitted to Google. Google Analytics 4 does not store IP addresses. Data may be transferred to the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework. You can withdraw your consent at any time via the cookie settings.
17. Integration of Google Maps
On this website we use Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to display interactive maps.
The map is not loaded automatically. Only when you actively open the map (click on “Load map”) is a connection to Google’s servers established; in doing so, data (including your IP address) is transmitted to Google. The legal basis is your consent expressed by the click (Art. 6(1)(a) GDPR). Without this click, no data is transmitted to Google.
Google also processes your personal data in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework. Further information: policies.google.com/privacy.
18. Processors
We use external service providers (processors) for the technical operation of the website. They have been carefully selected, are bound by our instructions and operate on the basis of data processing agreements pursuant to Art. 28 GDPR:
- Hosting: Hostinger (server infrastructure of the website)
- Email delivery: Resend (technical dispatch of messages submitted via the enquiry form to our mailbox)
19. Conditions — Südtirol Alto Adige Guest Pass
Upon completion of the accommodation contract, the guest receives the Südtirol Alto Adige Guest Pass (hereinafter Guest Pass), which, in accordance with South Tyrolean provincial government resolution No. 732/2022, is valid for the entire duration of the stay and from 00:00 on the day of arrival until 24:00 on the day of departure.
The Guest Pass includes the use of all public transport within the Südttirolmobil network area as well as additional services. Detailed information can be found at: suedtirol-guestpass.info
20. Data Protection — Südtirol Alto Adige Guest Pass
Purpose
The personal data transmitted is forwarded to the unified coordination office of the Guest Pass in order to enable the creation and use of the Guest Pass and to provide the associated services.
Recipient
In connection with the issuance of the Guest Pass, your data is transmitted to the Mobility Consortium with VAT No. 02735170215. For further information: privacy@moko.bz.it
Legal Basis
The legal basis for processing is Art. 6(1)(b) GDPR.
Last updated: July 2026