Privacy Policy
Information notice on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
Last updated: September 2026
Data controller
The data controller is Croce del Sud S.r.l., registered office at Via Montenero 1, 47814 Bellaria-Igea Marina (RN), Italy, VAT no. 00368110409, entered in the Rimini Companies Register under REA no. RN-157729. The property’s National Identification Code (CIN) is IT099001A1E83ZQ9UL.
For any question about this notice you can write to us or call us:
+39 0541 344282
[email protected]
Lungomare C. Colombo 10, 47814 Bellaria-Igea Marina (RN)
What data we collect
We only collect the data we need in order to answer enquiries and welcome guests to the hotel:
- contact and booking details: first name, surname, telephone, email address, dates of the stay, number and age of the guests, special requests;
- data required by law at check-in: personal details and identity document data of every guest;
- administrative and accounting data needed to issue receipts and invoices;
- technical browsing data recorded by the provider hosting the site (IP address, date and time of the visit, page requested), used only for the security and the working of the site.
We do not collect special categories of data, such as health data, unless you tell us yourself for the needs of your stay, for example a food intolerance.
If you book through a portal such as Booking.com or through an agency, we do not collect your data directly from you: it reaches us from them, and it is your name, your contact details and the booking details.
Why we process your data
- to answer requests for information and quotes and to manage the booking and the stay: performance of the contract and of pre-contractual measures (Art. 6.1.b GDPR);
- to comply with legal obligations, including reporting guest data to the public security authorities, the tourist tax and tax obligations (Art. 6.1.c GDPR);
- for the security of the website and the prevention of abuse, on the basis of our legitimate interest (Art. 6.1.f GDPR);
- to send promotional messages about our offers to travel agencies and group organisers: on the basis of consent, or of our legitimate interest where the address was given to us in the course of an existing business relationship (art. 6.1.a and 6.1.f of the GDPR, art. 130 of the Italian Privacy Code).
Without the minimum data indicated we cannot answer the request or confirm the booking.
Promotional messages
We send emails about our offers to travel agencies and to those who organise group stays, at the addresses they gave us while working with us. To stop receiving them, simply reply to the message or write to us at the contact details above: the address is removed from the list.
How long we keep the data
Enquiries and quotation requests stay filed on the hotel’s computers and are not deleted after a set period; you can, however, ask us to delete them at any time and we will do so. Accounting and tax documents are kept for ten years, as the law requires; guest registration data for the time set by public security rules. The addresses used for promotional messages stay in our files until you ask to stop receiving them.
Who we share the data with
The data is handled by hotel staff. It may be passed to the suppliers who work on our behalf, appointed as data processors under article 28 of the GDPR: Zucchetti Hospitality, which provides the Hotel 2000 Cloud property management system; the accountancy firm Casadei e Partners; the Montanari firm. To these are added the supplier hosting the website and, in the cases provided for by law, the authorities. Your data is never disclosed publicly nor sold to third parties.
Where the data is kept
Booking and stay data are processed at the hotel and stored in the Hotel 2000 Cloud property management system supplied by Zucchetti Hospitality. Should one of the suppliers process them outside the European Union, the transfer takes place with the safeguards required by art. 44 and following of the GDPR.
The site, on the other hand, is published on the Cloudflare network, spread across the world: pages may therefore be served from servers outside the European Union, and with them the technical browsing data. The transfer takes place on the basis of the standard contractual clauses approved by the European Commission (art. 44 and following of the GDPR).
Your rights
At any time you can ask us for access to your data, its correction or erasure, the restriction of processing and data portability; you can also object to processing based on legitimate interest, including promotional messages. Where processing is based on consent, you can withdraw it whenever you like, without affecting what was done beforehand.
You also have the right to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it) if you believe that the processing of your data breaches the rules.
To exercise these rights write to us or call the contacts shown above: we reply within one month of the request. To verify your identity we may ask you for some further information.
No automated decisions
We take no automated decisions about you and we do no profiling: behind every reply and every confirmation there is a person.
Cookies
The site uses no cookies and loads no third-party tools. Full details are in the Cookie Policy.
Updates to this notice
This notice may be updated: the version published on this page is always the one in force and shows the date of the last change at the top.
