Privacy Policy for Eternal City SRLs
1. Data Controller Contact Information
The Data Controller responsible for processing your Personal Data in accordance with this
Privacy Policy and the GDPR is:
● Company Name: Eternal City SRLs
● Legal Address: Via Serafino Belfanti 22Z 00166 Rome Italy
● VAT/Fiscal Code (P. IVA): IT17898631001
● Email for Privacy Concerns: [email protected]
2. Types of Data Collected
A. Data Provided Directly by You (Booking and Enquiries)
When you book a tour, request a quote, or contact us, you provide:
● Identity Data: First Name, Last Name.
● Contact Data: Email Address, Phone Number, Residential Address.
● Travel Data: Group Size, Desired Dates, Pickup/Drop-off locations (e.g., hotel name).
● Payment Data: Necessary information to process payments (typically processed securely by a third-party payment processor, see Section 4).
● Special Categories of Data (Sensitive Data): Only if necessary for the tour (e.g., dietary restrictions, mobility issues) and only collected with your explicit consent.
When you browse our website, we may collect:
● Usage Data: IP address, browser type, operating system, pages visited, time spent on the site, and referring URL.
● Cookies: Data collected via cookies and other tracking technologies (See the separate Cookie Policy linked in the footer.
3. Purposes and Legal Basis for Processing
| Purpose of Processing | Type of Data Used | Legal Basis (GDPR) |
|---|---|---|
| A. Tour Booking and Execution | Identity, Contact, Travel, Payment | Performance of a Contract (Art. 6(1)(b)) -Necessary to fulfil your booking and provide the requested service. |
| B. Handling Pre-Contract Enquiries | Identity, Contact, Travel | Performance of a Contract (Art. 6(1)(b)) - Necessary to respond to your quote requests and service questions. |
| C. Marketing & Newsletters | Identity, Contact, (Email) | Consent (Art. 6(1)(a)) - Only when you explicitly opt-in to receive promotional material. |
| D. Website Security & Analytics | Usage, IP Address | Legitimate Interest (Art. 6(1)(f)) - To maintain website security and improve our service offerings. |
| E. Legal and Administrative Compliance | All relevant data | Legal Obligation (Art. 6(1)(c)) - For tax, invoicing, or mandatory registration with local authorities (e.g., guest registration/police forms) |
4. Sharing and Disclosure of Personal Data
To effectively provide your private tour services, we may share your data with the following categories of recipients:
● Drivers/Chauffeurs: Your name, contact number, pickup location, and timing are shared to execute the transfer service.
● Service Providers (Data Processors): Companies that provide essential services to us (e.g., web hosting, email marketing platforms, accounting services).
● Third-Party Suppliers: When your tour requires specific third-party services (e.g. museum ticket providers, restaurant reservations).
● Payment Processors: Nexi to securely handle credit card transactions. We do not store full credit card details.
5. Data Retention
We retain your Personal Data only for as long as is strictly necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements.
● Booking Data: Retained for 10 years from the booking completion date to comply with Italian civil and tax law obligations.
● Marketing Consent: Retained until you withdraw your consent.
● Enquiry Data: Retained for a maximum of 12 months if no booking follows.
6. International Data Transfers
7. Your GDPR Rights
Under the GDPR, you have the right to
1. Right of Access: Request a copy of the data we hold about you.
2. Right to Rectification: Request correction of inaccurate or incomplete data.
3. Right to Erasure (Right to be Forgotten): Request the deletion of your data (where legal retention obligations do not apply).
4. Right to Restriction of Processing: Request temporary limitations on processing your data.
5. Right to Data Portability: Request that your data be transferred to you or another controller in a structured, commonly used format.
6. Right to Object: Object to processing based on legitimate interest (e.g., direct marketing).
7. Right to Withdraw Consent: You can withdraw your consent at any time where processing is based on consent (e.g., for newsletters).
To exercise any of these rights, please contact us using the dedicated email address provided in Section 1.