Privacy Policy

1. Data Controller

The Data Controller is Aludra S.r.l., with registered office in Via Albricci 9, 20122 Milan, VAT number 03367780834, certified email aludrasrl@legalmail.it (hereinafter "the Controller"), operating under the commercial brand "PhantomLink".

2. Types of data processed

The Controller processes the following categories of personal data:

a) personal and contact data: first name, last name, date of birth (where required for suitability verification or minors), email address, phone number, eventual identification document for the guest list; b) rental-related data: dates, itineraries, number of guests, special requirements, communications exchanged; c) payment data: managed directly by payment service providers; the Controller does not store full payment card data; d) health data (if any): if spontaneously communicated by the data subject in relation to suitability for rental. This is a special category pursuant to Art. 9 GDPR; e) browsing data: automatically collected by the website (see Cookie Policy).

3. Purposes and legal bases of processing

Purpose Legal basis
Execution of the rental contract and booking management Art. 6.1.b GDPR (contract performance)
Fulfillment of legal obligations such as tax, accounting, administrative, and maritime safety requirements Art. 6.1.c GDPR (legal obligation)
Management of requests, communications, complaints, and disputes Art. 6.1.b and 6.1.f GDPR
Processing of health data for assessing suitability for rental Art. 9.2.a GDPR (explicit consent)
Protection of the Controller's rights in judicial and extrajudicial proceedings Art. 6.1.f GDPR (legitimate interest)
Sending commercial and marketing communications Art. 6.1.a GDPR (consent)
Website IT security and fraud prevention Art. 6.1.f GDPR (legitimate interest)

4. Processing methods

Processing is carried out using electronic and, where necessary, paper tools, according to principles of lawfulness, fairness, transparency, minimization, and storage limitation. The Controller adopts appropriate technical and organizational measures to ensure data security and prevent unauthorized access, loss, destruction, or unlawful disclosure.

5. Provision of data

The provision of data indicated as mandatory is necessary for the conclusion and performance of the contract. Failure to provide such data makes it impossible to provide the service. The provision of data for marketing purposes is optional, and refusal will not affect the provision of the service.

6. Retention period

Data is retained for the following periods:

a) data related to the contract: for the duration of the relationship and for 10 years after its termination, in compliance with civil and tax obligations (Arts. 2220 c.c. and 22 DPR 600/1973); b) marketing data: until consent is revoked, and in any case no longer than 24 months from the last contact; c) data for litigation purposes: for the time necessary for the exercise or defense of rights, and in any case no longer than the statutory limitation periods; d) browsing data and cookies: as indicated in the Cookie Policy.

7. Data recipients

Data may be communicated to:

a) authorized and trained personnel of the Controller, as authorized processors; b) external technical service providers designated as Data Processors pursuant to Art. 28 GDPR (hosting, e-commerce platform, payment management, email services, management software); c) professional advisors of the Controller (law firm, accountant, labor consultant); d) insurance companies; e) Maritime Authorities, Law Enforcement Agencies, Judicial and Administrative Authorities, in case of request or legal obligation.

Data is not disseminated and is not subject to automated decision-making processes or profiling that produces legal effects on the data subject.

8. Transfer outside the EU

Some technical providers (for example: Shopify Inc., cloud service providers) may involve the transfer of data outside the European Economic Area. Such transfers only occur in the presence of adequate safeguards pursuant to Arts. 44 et seq. GDPR (adequacy decisions of the EU Commission, Standard Contractual Clauses, supplementary measures where necessary). The data subject can request a copy of the adopted safeguards by writing to the Controller's certified email address.

9. Data subject rights

The data subject has the right, at any time, to:

a) access their data (Art. 15 GDPR); b) obtain its rectification (Art. 16 GDPR); c) obtain its erasure (Art. 17 GDPR), within the limits of the law; d) obtain restriction of processing (Art. 18 GDPR); e) object to processing (Art. 21 GDPR); f) receive their data in a structured format and transmit it to another controller (Art. 20 GDPR); g) withdraw the consent given, without affecting the lawfulness of previous processing; h) lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

To exercise their rights, the data subject can write to the certified email address aludrasrl@legalmail.it.

10. Changes to the privacy policy

The Controller reserves the right to update this privacy policy. Updated versions will be promptly published on the website, indicating the date of the last update.