Privacy Policy

Data Controller

EFB2 S.r.l. – Via Fieschi 8/9 – 16121 Genova (GE) – Italy

VAT No. 03031750999

Email: efb2srl@legalmail.it

Personal Data processed for the following purposes and using the following services:

Contacting the User

Contact Form

  • Personal Data collected: Name, email, phone number, and any other data voluntarily provided by the User.
  • Purpose: To respond to requests for information, quotes, or other types of communication.


Mailing list or newsletter

  • Personal Data collected: Email address.
  • Purpose: Sending promotional or informative communications, subject to the User’s prior consent.
  • Provider: Specialized newsletter service provider (appointed as Data Processor pursuant to Art. 28 GDPR).


Advertising

Google Ads conversion tracking and Query Click

  • Personal Data: Usage Data; Tracking Tools.


Tag Management

Google Tag Manager and tracking tools

  • Personal Data: Usage Data.
  • Purpose: Centralized management of tags or scripts for monitoring and analyzing the Website.
  • Place of processing: EU / USA (based on the servers used by Google LLC).
  • Privacy Policy: https://policies.google.com/privacy


Hosting and backend infrastructure

Personal data provided by the user to make a reservation may be collected directly on our site or through external booking platforms (“OTAs” – Online Travel Agencies, e.g., Booking.com, Airbnb). For the management of reservations and payments, we use an external platform (channel manager/booking engine).

Personal data provided by the user for the request and/or confirmation of the reservation is shared with this provider, who acts as a Data Processor pursuant to Art. 28 GDPR, and is processed exclusively for purposes related to the management of the stay and payments. OTAs act as independent Data Controllers and transmit to us the data necessary for the management of the reservation and stay.

  • Purpose: Management of reservation requests and the stay, invoicing, and communications related to the booking.


Worldline (online payment service)

Note: The Controller does not have access to full payment card details. Such data is processed exclusively by the Payment Service Provider (PSP) via encrypted channels compliant with the PCI-DSS standard. The PSP acts as an independent Data Controller for payment data, while EFB2 S.r.l. only receives limited information regarding the success of the transaction.

Netsons S.r.l.

  • Personal Data: Usage Data; IP addresses; system logs; any other technical data necessary for the operation and security of the Site.
  • Purpose: To ensure the provision, maintenance, and security of the Website’s hosting infrastructure.
  • Privacy Policy: https://www.netsons.com/privacy-policy/


WebToffee – GDPR Cookie Consent Plugin


Public Security Requirements (Check-in)

  • Personal Data collected: Personal identification data (first name, last name, place and date of birth), identity document details, and citizenship.
  • Method: This data is collected upon arrival at the facility, including through external partners tasked with managing hospitality and check-in.
  • Purpose: Exclusive fulfillment of the obligation provided by Art. 109 of the TULPS (communication of staying guests to the Public Security Authorities via the “Alloggiati Web” portal).
  • Nature of provision: Mandatory by law. Failure to provide this data makes it impossible to proceed with the stay.


Statistics

Google Analytics (Universal Analytics and Google Analytics 4)

  • Personal Data: Cookies; Usage Data; browser and device information; number of Users.
  • Purpose: Analysis of navigation statistics and interactions with the Site.
  • Place of processing: EU / USA.
  • Privacy Policy: https://policies.google.com/privacy


Meta Events Manager


Displaying content from external platforms

Google Fonts


Information on how to opt-out of interest-based advertising

In addition to any opt-out feature provided by the individual services listed in this document, Users can find more information on how to opt-out of interest-based advertising in the Cookie Policy of this Website.

Mode and place of processing Data

Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated.

In addition to the Controller, in some cases, other parties involved in the organization of the Site (administrative, commercial, marketing, legal staff, system administrators) or external parties (third-party technical service providers, mail carriers, hosting providers, IT companies, communication agencies) may have access to the Data, appointed if necessary as Data Processors pursuant to Art. 28 GDPR.

Legal basis of processing

The Controller processes the User’s Personal Data in the following cases:

  • When processing is necessary for the performance of a contract with the User and/or for the execution of pre-contractual measures;
  • When processing is necessary to comply with a legal obligation (specifically the obligation to communicate guest details to Public Security Authorities under Art. 109 TULPS and tax/fiscal regulations);
  • When the User has given consent for one or more specific purposes;
  • When processing is necessary for the legitimate interest of the Controller or third parties (e.g., cybersecurity, anonymous statistical analysis).


Retention period

Data is processed and stored for the time required by the purposes for which it was collected:

  • Contact Data: up to 24 months or until a deletion request is made;
  • Contractual and Fiscal Data: up to 10 years (legal obligations);
  • Navigation and Analytical Data: up to 12 months;
  • Marketing Data: until consent is withdrawn.


Data transfer abroad

Data may be transferred outside the EU in compliance with Art. 44 et seq. of the GDPR. For Google LLC and Meta Platforms, Inc. services, transfers are made to entities adhering to the EU-U.S. Data Privacy Framework (DPF), ensuring a level of protection equivalent to European standards.

User Rights

Users may exercise the rights provided by Articles 15-22 of the GDPR at any time, including:

  • Right of access, rectification, erasure, and restriction of processing;
  • Right to data portability;
  • Right to object to processing for legitimate reasons;
  • Right to withdraw consent at any time;
  • Right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).

Requests should be addressed to the Data Controller at: efb2srl@legalmail.it

Details on the right to object

Where Personal Data is processed in the public interest, in the exercise of official authority vested in the Controller, or for the purposes of the legitimate interests pursued by the Controller, Users may object to such processing by providing a ground related to their particular situation to justify the objection.

Changes to this privacy policy

The Controller reserves the right to make changes to this Privacy Policy at any time by notifying Users on this page and, if possible, via email notification. If the changes affect processing activities based on consent, the Controller shall collect new consent from the User, where necessary.

Data Controller

EFB2 S.r.l. – Via Fieschi 8/9, 16121 Genova (GE), Italy – VAT No. 03031750999

Email: efb2srl@legalmail.it

Last modified: 28/04/2026