
PRIVACY POLICY
1. General information
This Privacy Policy describes how the personal data of users who visit the Botanic Garden Luxury Rooms website and use the services made available through the website are processed.
This notice is provided pursuant to Regulation (EU) 2016/679 – GDPR and the applicable Italian legislation on the protection of personal data.
2. Data Controller
The Data Controller is:
LA.MA.VI. s.r.l.
Centro Direzionale Is. E7
80143 – Naples
VAT No. IT10490701215
E-mail: info@botanicgardenrooms.it
Telephone: +39 338 705 0839
For any request concerning the processing of personal data or the exercise of your rights, you may contact the Data Controller using the contact details indicated above.
3. Categories of data processed
Different categories of personal data may be processed through the website.
Data voluntarily provided by the user
When users use the forms available on the website or contact the property directly, data such as the following may be collected:
- first and last name;
- e-mail address;
- telephone number;
- check-in date;
- check-out date;
- number of adults;
- number of children;
- room or accommodation of interest;
- any information included in the message or additional requests.
Users are requested not to enter personal information in free-text fields unless it is necessary for handling their request.
Browsing data
The IT systems that enable the website to operate may automatically acquire certain technical information related to browsing.
Such data may include, for example:
- IP address;
- browser type;
- operating system;
- device used;
- date and time of the request;
- pages visited;
- technical information necessary for the operation and security of the website.
These data are processed primarily to ensure the proper operation of the website and its security.
4. Purposes of processing
Personal data may be processed for the following purposes.
A. Handling availability and information requests
Data provided through the website forms are used to:
- check room availability;
- respond to user requests;
- provide information about stays and services;
- prepare any quotations;
- manage communications prior to booking.
B. Managing bookings and stays
If a request results in a booking, the data may be processed to:
- manage the booking;
- organise check-in and check-out;
- provide the requested services;
- manage payments and administrative requirements;
- communicate with the guest during the stay;
- handle any requests following the booking.
C. Compliance with legal obligations
Data may be processed in order to comply with obligations imposed by the legislation applicable to accommodation facilities, including administrative, tax and public security requirements.
D. Website and property security
Certain data may be processed to:
- ensure the IT security of the website;
- prevent abusive or fraudulent use;
- protect systems, people and property;
- establish, exercise or defend legal claims.
The property also uses video surveillance systems exclusively in common areas for security purposes. Information relating to this processing is provided to data subjects in accordance with the procedures required by applicable law.
E. Management of additional services
When requested by the guest, certain data may be used to arrange additional services such as transfers, tours, excursions or other activities.
When such services are provided by external suppliers, only the data necessary to provide the requested service may be disclosed to them.
5. Legal basis for processing
Personal data are processed on the basis of the conditions set out in Article 6 of the GDPR.
In particular:
- to respond to user requests and take pre-contractual steps requested by the data subject, processing is necessary in order to take steps prior to entering into a contract;
- to manage the booking and the stay, processing is necessary for the performance of the contract;
- for administrative, tax and public security obligations, processing is necessary for compliance with legal obligations;
- for website security, prevention of abuse and protection of the property’s rights, processing may be based on the legitimate interests of the Data Controller;
- where specific processing requires the user’s consent, consent is requested in advance and may be withdrawn at any time.
6. Provision of data
Providing the data marked as required in the forms is necessary in order for the property to respond to the user’s request.
Failure to provide such data may make it impossible to:
- process an availability request;
- respond to a request for information;
- proceed with a booking;
- provide certain services.
Providing any data indicated as optional is voluntary.
7. Methods of processing
Personal data are processed using IT, electronic and, where applicable, paper-based tools, with appropriate technical and organisational measures adopted to protect them against:
- unauthorised access;
- loss;
- destruction;
- alteration;
- disclosure;
- unlawful or improper use.
Access to the data is limited to persons who need it in order to carry out their activities.
8. Recipients of the data
Personal data may be disclosed, within the limits strictly necessary, to parties that work with the Data Controller in managing the property or the website.
These may include:
- authorised staff of the property;
- IT and hosting service providers;
- providers of services used for the operation of the website;
- administrative, tax or legal advisers;
- payment institutions, where used;
- providers of transfers, tours or additional services requested by the guest;
- public authorities where required by law.
Depending on the circumstances, these parties process the data as processors, independent controllers or authorised persons.
Personal data are not disseminated.
9. Third-party services
The website may contain links or features made available by third parties.
These may include, for example, mapping services, technical tools, security systems or external platforms.
When users directly access an external service, the processing carried out by the relevant provider is governed by that provider’s privacy policy.
Information concerning the possible use of cookies and similar technologies is available in the website’s Cookie Policy.
10. Transfer of data outside the European Economic Area
Some technology providers that may be used by the website may be based or have infrastructure outside the European Economic Area.
If personal data are transferred to third countries, the transfer will be carried out in compliance with the conditions laid down by the GDPR, using the applicable legal safeguards.
11. Retention period
Data are retained for the time necessary to achieve the purposes for which they were collected.
In particular:
- data relating to simple requests for information or availability are retained for the time necessary to manage the request and any subsequent contacts;
- data relating to bookings and contractual relationships are retained for the period necessary to provide the stay and subsequently for the periods required by administrative, accounting and tax legislation;
- data necessary for the protection of any rights may be retained for the period provided for by the applicable limitation periods;
- technical and security data are retained for the period strictly necessary for the relevant purposes.
Data are not retained for longer than is necessary in relation to the purposes of the processing.
12. Data relating to minors
The website is not intended for the independent collection of personal data directly from minors.
Any information relating to minors that may be necessary for a booking is provided by the adult making the request or booking and is processed exclusively for managing the stay and complying with legal requirements.
13. Marketing communications
Data provided through availability request or contact forms are not automatically used to send newsletters or promotional communications.
If a newsletter service is offered in the future or marketing communications are sent on the basis of consent, users will be specifically informed and may withdraw their consent at any time.
14. Cookies and tracking technologies
The website may use cookies and similar technologies.
Cookies that are strictly necessary for the operation of the website may be used without consent where permitted by law.
Any cookies or tracking tools that require the user’s consent are activated only after the relevant choice has been made.
For detailed information on the categories of cookies used and how preferences can be managed, please refer to the Cookie Policy.
15. Rights of the data subject
In the cases provided for by the GDPR, the data subject may exercise the following rights:
- obtain confirmation as to whether or not personal data concerning them are being processed;
- access their personal data;
- request the rectification of inaccurate data;
- request the completion of incomplete data;
- request the erasure of data in the cases provided for;
- obtain restriction of processing;
- object to processing in the cases provided for by law;
- receive their data in a structured, commonly used and machine-readable format where the right to data portability applies;
- withdraw consent previously given at any time, without affecting the lawfulness of processing carried out before its withdrawal.
To exercise these rights, the Data Controller may be contacted at:
info@botanicgardenrooms.it
The Data Controller will respond to the request within the time limits provided for by applicable law.
16. Complaint to the supervisory authority
A data subject who believes that the processing of their personal data is in breach of applicable legislation has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures established by the Authority.
The right to seek judicial remedies before the competent courts remains unaffected.
17. Data security
Botanic Garden Luxury Rooms adopts technical and organisational measures appropriate to the risk in order to protect the personal data processed.
However, no IT system or transmission over the Internet can be considered completely free from risk.
In the event of a personal data breach, the Data Controller will act in accordance with applicable law.
18. Changes to the Privacy Policy
This Privacy Policy may be amended or updated following:
- changes in legislation;
- changes to the services offered;
- introduction of new website features;
- changes to the methods of data processing.
The updated version will be published on this page.
Last updated: August 2026
