Privacy Policy
1. Data Controller
The Data Controller is Aludra S.r.l., with registered office in Via Albricci 9, 20122 Milan, VAT number 03367780834, certified email aludrasrl@legalmail.it (hereinafter "the Controller"), operating under the commercial brand "PhantomLink".
2. Types of data processed
The Controller processes the following categories of personal data:
a) personal and contact data: first name, last name, date of birth (where required for suitability verification or minors), email address, phone number, eventual identification document for the guest list; b) rental-related data: dates, itineraries, number of guests, special requirements, communications exchanged; c) payment data: managed directly by payment service providers; the Controller does not store full payment card data; d) health data (if any): if spontaneously communicated by the data subject in relation to suitability for rental. This is a special category pursuant to Art. 9 GDPR; e) browsing data: automatically collected by the website (see Cookie Policy).
3. Purposes and legal bases of processing
| Purpose | Legal basis |
|---|---|
| Execution of the rental contract and booking management | Art. 6.1.b GDPR (contract performance) |
| Fulfillment of legal obligations such as tax, accounting, administrative, and maritime safety requirements | Art. 6.1.c GDPR (legal obligation) |
| Management of requests, communications, complaints, and disputes | Art. 6.1.b and 6.1.f GDPR |
| Processing of health data for assessing suitability for rental | Art. 9.2.a GDPR (explicit consent) |
| Protection of the Controller's rights in judicial and extrajudicial proceedings | Art. 6.1.f GDPR (legitimate interest) |
| Sending commercial and marketing communications | Art. 6.1.a GDPR (consent) |
| Website IT security and fraud prevention | Art. 6.1.f GDPR (legitimate interest) |
4. Processing methods
Processing is carried out using electronic and, where necessary, paper tools, according to principles of lawfulness, fairness, transparency, minimization, and storage limitation. The Controller adopts appropriate technical and organizational measures to ensure data security and prevent unauthorized access, loss, destruction, or unlawful disclosure.
5. Provision of data
The provision of data indicated as mandatory is necessary for the conclusion and performance of the contract. Failure to provide such data makes it impossible to provide the service. The provision of data for marketing purposes is optional, and refusal will not affect the provision of the service.
6. Retention period
Data is retained for the following periods:
a) data related to the contract: for the duration of the relationship and for 10 years after its termination, in compliance with civil and tax obligations (Arts. 2220 c.c. and 22 DPR 600/1973); b) marketing data: until consent is revoked, and in any case no longer than 24 months from the last contact; c) data for litigation purposes: for the time necessary for the exercise or defense of rights, and in any case no longer than the statutory limitation periods; d) browsing data and cookies: as indicated in the Cookie Policy.
7. Data recipients
Data may be communicated to:
a) authorized and trained personnel of the Controller, as authorized processors; b) external technical service providers designated as Data Processors pursuant to Art. 28 GDPR (hosting, e-commerce platform, payment management, email services, management software); c) professional advisors of the Controller (law firm, accountant, labor consultant); d) insurance companies; e) Maritime Authorities, Law Enforcement Agencies, Judicial and Administrative Authorities, in case of request or legal obligation.
Data is not disseminated and is not subject to automated decision-making processes or profiling that produces legal effects on the data subject.
8. Transfer outside the EU
Some technical providers (for example: Shopify Inc., cloud service providers) may involve the transfer of data outside the European Economic Area. Such transfers only occur in the presence of adequate safeguards pursuant to Arts. 44 et seq. GDPR (adequacy decisions of the EU Commission, Standard Contractual Clauses, supplementary measures where necessary). The data subject can request a copy of the adopted safeguards by writing to the Controller's certified email address.
9. Data subject rights
The data subject has the right, at any time, to:
a) access their data (Art. 15 GDPR); b) obtain its rectification (Art. 16 GDPR); c) obtain its erasure (Art. 17 GDPR), within the limits of the law; d) obtain restriction of processing (Art. 18 GDPR); e) object to processing (Art. 21 GDPR); f) receive their data in a structured format and transmit it to another controller (Art. 20 GDPR); g) withdraw the consent given, without affecting the lawfulness of previous processing; h) lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
To exercise their rights, the data subject can write to the certified email address aludrasrl@legalmail.it.
10. Changes to the privacy policy
The Controller reserves the right to update this privacy policy. Updated versions will be promptly published on the website, indicating the date of the last update.