This notice explains how Ammare Trani – B&B processes the personal data of people who visit ammaretrani.it, send a booking request and stay at the property, under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and the Italian Personal Data Protection Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018).
1. Data controller
Fattibene Nicola, sole proprietorship, VAT no. IT08740190726, operating Ammare Trani – B&B, Via Lungomare Cristoforo Colombo 47, 76125 Trani (BT), Italy.
Privacy contact: info@ammaretrani.it · phone +39 375 877 9005.
The controller is not required to appoint a Data Protection Officer (Art. 37 GDPR).
2. Processor for the website
The website and booking system are hosted, run and maintained by Origami di Gabriella Ruta, Corso Vittorio Emanuele II 148, 76125 Trani (BT), Italy, VAT no. IT07402320720, appointed as data processor under Art. 28 GDPR. Privacy requests are always sent to info@ammaretrani.it. Origami uses the hosting provider listed in section 6.
3. What data we process, why, and on what legal basis
a) Booking requests and managing your stay
Data: first and last name, e-mail, phone, country, arrival and departure dates, number of guests, room, extras chosen, any notes you write (e.g. arrival time), site language, date and time of the request and booking code.
Purpose: to answer your request, check availability, confirm or decline the booking, send service e-mails (request received, confirmation, cancellation), organise your arrival and manage your stay.
Legal basis: performance of a contract to which you are party or steps taken at your request before entering into it (Art. 6(1)(b) GDPR). The “I have read the privacy notice” box in the form confirms you received this information: it is not a request for consent.
To stop automated submissions the site keeps an encrypted fingerprint (hash) of the sending IP address for 10 minutes and limits the number of requests: this is our legitimate interest in the security of the service (Art. 6(1)(f) GDPR).
b) Contact by phone, e-mail and WhatsApp
Data: what you send us (name, number, e-mail address, message).
Purpose: answering your questions before or during your stay.
Legal basis: pre-contractual steps or performance of the contract (Art. 6(1)(b) GDPR); for simple enquiries, our legitimate interest in replying (Art. 6(1)(f) GDPR).
If you write to us on WhatsApp, the service is provided by WhatsApp Ireland Limited as an independent controller under its own privacy policy. The WhatsApp button on the site is a plain link: until you use it, WhatsApp receives nothing from the site.
c) Legal obligations of accommodation providers
- Guest registration with the police (Questura) (Art. 109 of the Italian Public Security Act, Royal Decree 773/1931, and Ministry of the Interior Decree of 7 January 2013, Alloggiati Web portal): on arrival we ask for a valid identity document for every guest, including minors, and send the personal and document details within the legal deadlines.
- Tourism statistics (ISTAT, through the Apulia Region’s system): we report arrivals and overnight stays with guests’ origin, in aggregate or anonymous form.
- Tourist tax, if applied by the Municipality of Trani: details of liable or exempt guests and returns to the Municipality.
- Tax and accounting obligations: issuing and keeping receipts and invoices.
Legal basis: compliance with legal obligations (Art. 6(1)(c) GDPR). Providing this data is mandatory: without it we cannot host you.
d) Website security and browsing
Data: technical data your browser sends when you visit the site (IP address, date and time, page requested, browser type), recorded in the server logs.
Purpose: running the site, protecting it from abuse and attacks, finding faults.
Legal basis: legitimate interest in the security and operation of the site (Art. 6(1)(f) GDPR).
e) Record of cookie choices
When you make a choice in the cookie banner (accept, reject, customise or withdraw), the site records: a random consent ID, the choice, date and time, banner and policy version, language, browser, the page (without parameters) and your truncated IP address (last part removed, so it does not point to a single device).
Legal basis: the obligation to demonstrate consent (Art. 7(1) GDPR) and our legitimate interest in being able to prove it (Art. 6(1)(c) and (f) GDPR).
f) Visit statistics (not yet active)
Today the site uses no statistics tools. If we start using Google Analytics 4, we will do so only with your consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code), given through the cookie banner and revocable at any time, and we will update this notice and the cookie policy first.
g) Google map
In the How to get here section and on the Contacts page the Google map loads only if you accept third-party cookies in the banner, or if you click “Show the map” (in that case, for that map only). From then on Google receives your IP address and may use its cookies, as an independent controller. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw from Cookie preferences. Without consent, Google receives nothing.
4. Booking portals (Booking.com, Airbnb)
If you book through Booking.com or Airbnb, the portal is an independent controller of the data you give it and passes on to us what is needed for the booking, which we process for the purposes in sections 3.a and 3.c. To avoid double bookings, the site exchanges with the portals only a calendar of booked dates (iCal format): no guest names, contacts or other guest data pass from the site to the portals.
4-bis. CCTV
The property is protected by security cameras, for the safety of people and property (legitimate interest of the controller, Art. 6.1.f GDPR). Areas under surveillance are marked by signs before you enter the camera’s field of view. Footage is kept for no more than 72 hours, unless requested by the judicial authority or the police and is viewed only by the controller or authorised persons. Cameras do not film inside the rooms.
5. No marketing
We do not use your data to send newsletters or promotions and we do not pass it to third parties for commercial purposes. Should we wish to do so, we will first ask for your consent where the law requires it.
6. Who receives the data
- Processors acting on our behalf and on our instructions: Origami di Gabriella Ruta (hosting, technical management and maintenance of the site and booking system) and, as its sub-processor, the server provider Netsons s.r.l., Via Tirino 99, 65129 Pescara, Italy, VAT no. IT01838660684, with servers in Italy; Aruba S.p.A., Via San Clemente 53, 24036 Ponte San Pietro (BG), Italy, provider of the info@ammaretrani.it mailbox, which also sends the site’s e-mails; the property’s tax adviser.
- Public authorities, as required by law: Questura (Alloggiati Web), ISTAT and the Apulia Region for statistics, the Municipality of Trani for the tourist tax, the Italian Revenue Agency and, on request, judicial or police authorities.
- Independent controllers, only if you use them: Booking.com, Airbnb, WhatsApp, Google (map), Meta for the Instagram and Facebook pages linked from the site.
Data is not made public.
Payments: today the stay is paid by bank transfer; payment data is handled by your bank and ours. The site does not ask for or store any payment card data. If we enable card payments, we will update this notice first.
7. Transfers outside the European Union
The site and booking data are stored on servers in Italy. A transfer outside the European Economic Area may occur only if you use third-party services that involve one (e.g. the Google map or WhatsApp, whose groups are based in the United States). In those cases the provider acts as an independent controller and the transfer relies on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (10 July 2023), to which Google LLC and Meta Platforms, Inc. adhere, or on standard contractual clauses.
8. How long we keep data
- Requests and bookings made on the site: up to 24 months after the departure date; then the system automatically deletes name, e-mail, phone and notes, leaving only anonymous data (dates, room, number of guests, country) for calendar management and internal statistics. Unconfirmed requests follow the same rule.
- Accounting and tax records: 10 years (Art. 2220 of the Italian Civil Code and tax rules).
- Police registration: data is transmitted and not kept by the property beyond what the law provides; the transmission receipt is kept for 5 years.
- Tourist tax and statistics: for the periods set by law and municipal regulations.
- Contact messages (e-mail, WhatsApp) not followed by a booking: up to 12 months.
- Server logs: no more than 6 months.
- Record of cookie choices: 5 years from the choice, then automatic deletion. The cookie that stores your choice in your browser lasts 180 days.
Longer periods may apply where needed to establish or defend legal claims.
9. How we protect data
The site uses an encrypted connection (HTTPS), the back office is accessible only to the controller and the processor with personal credentials, software is kept up to date and backups are made. Fonts and scripts are served from our own server, with no calls to external services while you browse.
10. Providing data
The fields marked as required in the booking form are needed to handle your request: without them we cannot proceed. Identity document details are required by law. Notes and extras are optional.
11. No automated decision-making
We do not take decisions based solely on automated processing, including profiling, that produce legal effects on you (Art. 22 GDPR). Bookings are confirmed by a person.
12. Your rights
You may at any time request access to your data, rectification, erasure, restriction of processing, portability of the data you provided, and object to processing based on legitimate interest (Arts. 15-21 GDPR). Where processing is based on consent, you may withdraw it at any time without affecting earlier processing; for cookies, use the “Cookie preferences” link at the bottom of every page.
Write to info@ammaretrani.it: we reply within one month (Art. 12 GDPR). Data processed under legal obligations cannot be erased before the legal periods expire.
If you believe the processing breaches the law, you may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it, or with the authority of the country where you live or work, or go to court.
13. Minors
Bookings must be made by adults. Data of minors staying with their families is processed only for the legal obligations in section 3.c.
14. Changes
We may update this notice, for example when we introduce a new service. The version in force is always on this page, with the date of the last update.
Last updated: 29 September 2026.