M
M

Privacy Policy

Privacy Policy 

Information on the Processing of Personal Data pursuant to Regulation (EU) 2016/679 (“GDPR”) Last updated: 11 August 2026 

Premorae respects your privacy and is committed to protecting the personal data of its guests, clients  and website visitors. This Privacy Policy explains how Premorae collects, uses, stores, shares and  protects your personal data when you visit our website, submit an enquiry, make a reservation,  subscribe to our newsletter, communicate directly with us or use our services. 

Personal data will be processed in accordance with Regulation (EU) 2016/679 (“GDPR”), Italian  Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018, and any other  applicable data protection legislation. We are committed to processing personal data lawfully, fairly and  transparently, and to collecting only the information that is adequate, relevant and necessary for the  purposes described in this Privacy Policy. 

  1. DATA CONTROLLER 

Premorae 

Via di Baccano 4 

50014 Fiesole (FI), Italy 

Email: info@premorae.it 

For any enquiry concerning this Privacy Policy, the processing of your personal data or the exercise of  your privacy rights, you may contact Premorae using the details provided above. 

  1. SCOPE OF THIS PRIVACY POLICY 

This Privacy Policy applies to personal data collected through: 

∙ the Premorae website; 

∙ online contact and enquiry forms; 

∙ online reservations and booking requests; 

∙ newsletter subscriptions; 

∙ email, telephone, messaging services and other direct communications with Premorae; ∙ interactions relating to accommodation, guest services, experiences, events and other services  offered or arranged by Premorae; 

∙ cookies and similar technologies used on the Premorae website, where applicable. This Privacy Policy does not govern the independent processing activities of third-party websites,  platforms or services that may be accessible through links on our website. 

  1. PERSONAL DATA WE COLLECT 

Depending on how you interact with Premorae, we may collect different categories of personal data. Information You Provide Directly 

∙ name and surname; 

∙ email address; 

∙ telephone number; 

∙ postal or billing address, where required; 

∙ booking and accommodation details; 

∙ arrival and departure information; 

∙ number and details of guests included in a reservation, where necessary; 

∙ billing and transaction information; 

∙ correspondence and communications with Premorae; 

∙ preferences and requests relating to your stay; 

∙ information concerning experiences, activities, events or additional services requested; ∙ information voluntarily provided through contact forms, booking forms, email, telephone or  messaging services. 

Where required by Italian law in connection with accommodation services, Premorae may also collect  identification and guest registration information necessary to fulfil statutory and public-security  obligations. 

Technical and Browsing Information 

∙ Internet Protocol (IP) address; 

∙ browser type and version; 

∙ device type; 

∙ operating system; 

∙ language and time-zone settings; 

∙ pages visited; 

∙ date, time and duration of visits; 

∙ interactions with pages and website features; 

∙ referring and exit pages; 

∙ other technical information concerning the use and performance of the website. Where possible, such information may also be processed in aggregated or anonymised form for  statistical, analytical and website-improvement purposes. 

  1. HOW WE COLLECT YOUR PERSONAL DATA 

Direct Interactions 

We may collect personal data when you: 

∙ complete a contact or enquiry form; 

∙ make or request a reservation; 

∙ subscribe to our newsletter; 

∙ communicate with us by email, telephone or messaging service; 

∙ request an experience, event, activity or additional guest service; 

∙ provide information necessary for the organisation or delivery of your stay. 

Automated Technologies 

As you navigate our website, certain information may be collected automatically through cookies and  similar technologies. Further information regarding these technologies is provided in our Cookie Policy  and through our cookie consent management system, Complianz. 

Third-Party Services 

In certain circumstances, Premorae may receive personal data through third-party platforms or service  providers used in connection with reservations, payments, communications or other requested services.  Such processing will take place in accordance with applicable data protection legislation and the  respective roles of Premorae and the third-party provider.

  1. PURPOSES AND LEGAL BASIS OF PROCESSING 

Reservations and Accommodation Services 

We process personal data to respond to booking enquiries; manage and confirm reservations;  administer payments and billing; provide accommodation; communicate with guests before, during and  after their stay; organise requested guest services, activities and experiences; and manage requests  relating to a reservation. 

Legal basis: performance of a contract or steps taken at your request prior to entering into a contract. Guest Services and Direct Communications 

We process personal data to respond to enquiries, provide assistance and communicate information  regarding Premorae, its properties, services and experiences. 

Legal basis: performance of a contract, pre-contractual measures and, where applicable, Premorae’s  legitimate interest in providing efficient and personalised guest service. 

Legal and Regulatory Obligations 

We may process and communicate personal data where necessary to comply with legal, tax,  accounting, administrative and public-security obligations, including mandatory guest registration  requirements. 

Legal basis: compliance with a legal obligation. 

Website Operation, Security and Improvement 

Technical and browsing data may be processed to operate and maintain the website; ensure website  and information-system security; diagnose technical issues; prevent fraud or misuse; analyse website  performance; and improve functionality and user experience. 

Legal basis: legitimate interest where applicable and, for non-essential cookies or tracking technologies,  consent where required by law. 

Newsletter and Marketing Communications 

Subject to the consent required under applicable law, Premorae may use your contact details through  ActiveCampaign to send occasional newsletters, news and updates, invitations, information about  Premorae properties and experiences, special initiatives and promotional communications. You may  withdraw your consent at any time. Withdrawal from marketing communications will not affect  communications necessary for an existing reservation or a service requested by you. 

  1. SPECIAL CATEGORIES OF PERSONAL DATA 

Premorae does not ordinarily request or intentionally collect special categories of personal data. 

However, in connection with the personalised nature of our hospitality services, guests may voluntarily  provide information concerning food allergies or intolerances, dietary requirements, accessibility requirements or other information necessary to accommodate a particular request. 

Where such information constitutes a special category of personal data under Article 9 GDPR,  Premorae will process it only where an appropriate legal basis exists and solely to the extent necessary  to provide the requested service or comply with applicable legal requirements. 

  1. COOKIES AND SIMILAR TECHNOLOGIES 

The Premorae website uses cookies and similar technologies for website operation, security,  functionality and, subject to the user’s consent where required, analytics and other non-essential  purposes.

The website’s current technical configuration includes services and technologies associated with  Google Analytics, Google Maps, Google reCAPTCHA, Google Fonts, Google Site Kit, ActiveCampaign,  Stripe, Cloudflare, WordPress, Divi / Elegant Themes, Complianz and WP Booking System. The  presence of a service or technology does not necessarily mean that it places a cookie in every case. 

Cookies and similar technologies may include: 

∙ strictly necessary and security-related technologies; 

∙ functional technologies; 

∙ analytics technologies; 

∙ marketing or communication-related technologies, where implemented and permitted. Where required by applicable law, cookies and tracking technologies that are not strictly necessary will  only be activated after obtaining your consent. Premorae uses Complianz as its cookie consent  management solution, through which you may manage or withdraw your cookie preferences. 

For detailed and up-to-date information regarding the cookies and similar technologies actually detected  on the website, including their purposes, providers and retention periods where available, please refer  to the Cookie Policy and the cookie consent interface made available on the Premorae website. 

  1. THIRD-PARTY WEBSITES AND SERVICES 

The Premorae website may contain links to third-party websites, booking platforms, social networks,  payment services or other external services. 

When you follow a link to a third-party website or interact with an external service, that third party may  independently collect and process your personal data. 

Premorae does not control the privacy practices of independent third parties and encourages users to  review the privacy policies of any external website or service they choose to use. 

  1. DISCLOSURE OF PERSONAL DATA 

Premorae does not sell personal data. 

Where necessary for the purposes described in this Privacy Policy, personal data may be disclosed to  carefully selected third parties, including: 

∙ payment service providers, including Stripe and PayPal, for the secure processing and  management of payments and related transactions; 

∙ booking and reservation service providers, including WP Booking System; 

∙ website hosting and infrastructure providers, including GoDaddy and, where used in the website’s  technical configuration, Cloudflare; 

∙ newsletter and communication platforms, including ActiveCampaign; 

∙ website, analytics and technical service providers, including Google services where applicable; ∙ website software and technology providers associated with WordPress, Divi / Elegant Themes and  Complianz; 

∙ accountants, tax advisers, legal advisers and other professional consultants; ∙ suppliers and service providers involved in providing an experience, activity, event or guest service  specifically requested by you; 

∙ public authorities, law enforcement bodies and other competent authorities where disclosure is  required by law. 

Payment information processed through Stripe or PayPal is also subject to the respective privacy  policies and data protection practices of those providers. 

Where required under the GDPR, third parties processing personal data on behalf of Premorae will be  appointed as Data Processors pursuant to Article 28 GDPR. Certain third parties may process personal data as independent Data Controllers in accordance with their own legal obligations and privacy  policies. 

  1. INTERNATIONAL DATA TRANSFERS 

Premorae primarily processes personal data within the European Economic Area (“EEA”). 

However, certain third-party service providers used by Premorae operate internationally. These may  include, depending on the relevant service and processing activity, providers such as Stripe, PayPal,  ActiveCampaign, Google and other technical service providers identified in this Privacy Policy. As a  result, personal data may, in certain circumstances, be processed or transferred outside the EEA. 

Where such international transfers take place, they are carried out in accordance with the requirements  of the GDPR and on the basis of appropriate safeguards recognised under applicable data protection  legislation, which may include European Commission adequacy decisions, the EU-U.S. Data Privacy  Framework, Standard Contractual Clauses, Binding Corporate Rules or other legally recognised  transfer mechanisms, as applicable. 

Users are encouraged to consult the privacy policies of the relevant third-party providers for further  information regarding their processing activities and international data transfers. 

  1. DATA SECURITY 

The security and confidentiality of personal data are of great importance to Premorae. 

We implement appropriate technical and organisational measures designed to protect personal data  against accidental or unlawful destruction, accidental loss, unauthorised access, alteration,  unauthorised disclosure, misuse or unlawful processing. 

Access to personal data is limited to individuals and service providers who require such information for  legitimate operational, contractual, administrative or legal purposes. 

While Premorae takes appropriate measures to safeguard personal data, no method of electronic  transmission or storage can guarantee absolute security. 

  1. DATA RETENTION 

Premorae retains personal data only for as long as reasonably necessary to fulfil the purposes for which  it was collected and to comply with applicable legal, tax, accounting and regulatory obligations. 

Reservation, transaction and contractual information may therefore be retained for the period required  under applicable Italian law. 

Personal data processed for marketing purposes will be retained until consent is withdrawn or until the  data is no longer necessary for the relevant purpose, subject to applicable legal requirements. 

Where appropriate, personal data may be anonymised so that it can no longer be associated with an  identifiable individual. Anonymous and aggregated information may subsequently be used for statistical,  analytical and legitimate business purposes. 

  1. ACCURACY OF PERSONAL DATA 

Premorae seeks to ensure that the personal data it processes is accurate and up to date. 

We kindly ask you to inform us if your personal information changes or if you become aware that  information held by Premorae is inaccurate or incomplete. 

You may request correction or updating of your personal data at any time by contacting  info@premorae.it.

  1. YOUR RIGHTS UNDER THE GDPR 

Subject to the conditions established by applicable law, you have the right to: 

∙ obtain confirmation as to whether Premorae processes personal data concerning you; ∙ request access to your personal data; 

∙ request correction of inaccurate or incomplete personal data; 

∙ request deletion of your personal data; 

∙ request restriction of processing; 

∙ object to processing where applicable; 

∙ request data portability where the applicable legal requirements are met; 

∙ withdraw your consent at any time where processing is based on consent; 

∙ object at any time to the processing of your personal data for direct marketing purposes. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal. 

Certain rights may be subject to limitations where continued processing or retention is required by law  or is necessary for the establishment, exercise or defence of legal claims. 

  1. EXERCISING YOUR RIGHTS 

To exercise your rights or request further information regarding the processing of your personal data,  please contact Premorae at info@premorae.it. 

For security purposes, Premorae may request information reasonably necessary to verify your identity  before responding to a request concerning personal data. 

Premorae will respond to requests within the timeframes established by the GDPR and applicable data  protection legislation. 

  1. WITHDRAWAL OF CONSENT AND MARKETING PREFERENCES Where processing is based on your consent, you may withdraw that consent at any time. 

If you no longer wish to receive newsletters or promotional communications from Premorae, you may  use the unsubscribe option provided in the relevant communication or contact us at info@premorae.it. 

Withdrawal of marketing consent will not prevent Premorae from contacting you regarding an existing  reservation, payment, contractual relationship or service requested by you. 

  1. RIGHT TO LODGE A COMPLAINT 

If you believe that the processing of your personal data infringes applicable data protection legislation,  you have the right to lodge a complaint with the competent supervisory authority. 

In Italy, the competent authority is the Garante per la Protezione dei Dati Personali. 

This right is without prejudice to any other administrative or judicial remedy available under applicable  law. 

  1. CHANGES TO THIS PRIVACY POLICY 

Premorae may update this Privacy Policy from time to time to reflect changes in applicable legislation,  changes to our website or services, the introduction of new technologies or service providers, or  changes in the way personal data is collected or processed. 

The most recent version will always be made available on the Premorae website, together with the date  of the latest update. 

We encourage users to review this Privacy Policy periodically.

  1. CONTACT US 

We welcome questions, comments and requests regarding this Privacy Policy and the way Premorae  processes personal data. 

Premorae 

Via di Baccano 4 

50014 Fiesole (FI), Italy 

Email: info@premorae.it 

Important notice: This Privacy Policy has been prepared to reflect the information and technical  configuration provided for the Premorae website as of the date above. Because privacy compliance  depends on the website’s actual configuration and processing practices, professional legal/privacy  review is recommended before or after publication, particularly following material changes to services,  cookies or providers.