Privacy Policy

This privacy policy describes how the website www.lafelicina.com manages the personal data of users who consult it and use its services. The information is provided in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR).


1. Data Controller

Azienda Agricola La Felicina – Società Semplice
FRAZIONE SAN BARTOLOMEO, 27
12062 CHERASCO (CN)
Email Address: agriturismolafelicina@gmail.com


2. Categories of Collected Data

The web infrastructure acquires, independently or through external providers, specific categories of personal data, including: first name, last name, email address, phone number, navigation metrics, and tracking identifiers. The user may voluntarily provide such data (e.g., by filling out forms), or they may be automatically generated by network communication protocols during navigation.

Providing data for contractual purposes (e.g., bookings) is a mandatory requirement; failure to provide it will result in the inability to deliver the service. The Controller assumes no responsibility for third-party data published or shared by the user on the site without prior authorization.


3. Methods, Security, and Location of Processing

Security and Methods

The Controller applies strict technical and organizational measures to mitigate the risks of unauthorized access, disclosure, alteration, or destruction of data. Processing is carried out using IT systems, with logic strictly related to the stated purposes. Where necessary, access is granted to authorized internal personnel or external entities formally appointed as Data Processors.

Legal Basis

Data processing is based on one of the following legal conditions:

  • Free and explicit consent provided by the user for specific purposes.
  • Execution of pre-contractual or contractual measures (e.g., booking management).
  • Compliance with legal or tax obligations.
  • Pursuit of a legitimate interest of the Controller (e.g., infrastructure security, fraud prevention).

Location and Transfer

Primary databases reside at the Controller's operating facilities. Some data flows may be routed to servers located outside the European Economic Area (EEA). In such scenarios, the transfer is safeguarded by the adoption of Standard Contractual Clauses (SCCs) or adequacy decisions issued by the European Commission (e.g., Data Privacy Framework).

Retention

Records are maintained in the database for the time strictly necessary to fulfill the original purpose. Data linked to commercial transactions are retained in compliance with tax law obligations. Once the legal basis expires or upon a legitimate request, the data will be deleted or irreversibly anonymized.


4. Purposes and Details of External Providers (Data Processors)

The infrastructure uses third-party services to ensure operational continuity. The data flow mapping is as follows:

A. Interaction and Contact

Internal communication forms: Entering data into contact forms authorizes the system to use these details exclusively to process the user's request (quotes, information). Processed data: personal details and contact info.

B. Booking Management and Financial Transactions

Booking system: Accommodation data acquisition occurs via applications residing on the local server. Monetary transactions are delegated to external encrypted gateways. The Controller does not process or store credit card numbers.

C. Infrastructure Monitoring and Analytics

Google Analytics 4 (Google Ireland Limited): Traffic measurement system with native server-side IP anonymization protocol. Analytical data is used for technical site optimization. Processing location: EU/USA - Privacy Policy.

D. Security, Antispam, and Disaster Recovery

  • Google reCAPTCHA (Google Ireland Limited): Behavioral analysis algorithm used to distinguish legitimate traffic from bot-generated traffic and prevent form abuse. Processing location: USA - Privacy Policy.
  • Google Drive (Google Ireland Limited): Cloud architecture used for remote storage of encrypted database backups for disaster recovery. Processing location: USA - Privacy Policy.

E. External Assets and Cartography

These services make direct API calls to the provider's servers to render visual elements, resulting in the transmission of the client's IP address.

  • Google Maps and Google Fonts (Google Ireland Limited): Provision of interactive maps and typographic libraries. Processing location: USA - Privacy Policy.

5. Data Subject Rights

Individuals to whom the personal data refer hold the rights set out in Articles 15-22 of the GDPR, including:

  • Right of Access and Rectification: Obtain confirmation of the existence of data and request updates.
  • Right to Erasure (Right to be Forgotten): Demand the deletion of records from the Controller's databases.
  • Restriction and Objection: Block data processing for legitimate reasons or withdraw given consent.
  • Portability: Request a dump of their data in a structured, machine-readable format.

Technical requests to exercise these rights must be forwarded to the Controller's email address and will be processed within the statutory timeframe (maximum 30 days).


6. Additional Technical Information

Network Logs and Debugging

The server infrastructure generates log files (access log and error log) necessary to maintain IT security (e.g., DDoS attack mitigation) and diagnostics. These files record the IP address, timestamp, and user agent, constituting processing based on legitimate interest.

Legal Defense

Logs and navigation data may be produced as digital evidence upon explicit request by Judicial Authorities to determine liability in the event of cybercrimes committed against the site.

"Do Not Track" Directives

The current protocols of this site do not decode "Do Not Track" HTTP headers sent by browsers. To control tracking, refer to the cookie preference management panel.

Document Versioning

The Controller reserves the right to apply patches and updates to this document to reflect changes in software architecture or legislation. Users are required to monitor the "Last updated" timestamp at the bottom.


7. Definitions and Legal References

  • Personal Data: Any piece of information that allows the identification, directly or through correlation, of a natural person.
  • Usage Data: Payload of information implicitly transmitted by TCP/IP protocols (IP, URI, operating system parameters).
  • Data Subject: The identifiable natural person to whom the database records refer.
  • Data Processor: The external entity performing calculations or storage on the data on behalf of the Controller.
  • Cookies/Tracking Technologies: Text strings or scripts injected into the client to maintain session state or profile interaction.

Legal Basis: This document is drafted in strict compliance with Articles 13 and 14 of the European Regulation 2016/679 (GDPR).

Last updated: March 21, 2026