privacy policy

Information on the processing of personal data

pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”)

This Privacy Policy describes how the personal data of users who browse and use the website of Garnì Pluème di Schneider Luca, built with WordPress and Elementor and hosted on VHosting, including its multilingual versions, is processed.

The website is mainly intended for informational purposes and for business contact requests, including requests for information and availability related to the accommodation.

1. Data Controller

The Data Controller is:

Garnì Pluème di Schneider Luca
Business name: Schneider Luca
Address: Frazione Sauris di Sotto 26/A – 33020 – Sauris (UD) – Italy
REA: 226553
Tax Code: SCHLCU72P04L483D
VAT No.: 01984750305
Certified Email (PEC): lucaschneider@sicurezzapostale.it
Email contact: info@hotelplueme.it

For any request regarding the processing of personal data, data subjects may contact the Controller at: info@hotelplueme.it.

2. Types of data processed

The Controller may process the following categories of personal data:

a) Browsing data

During normal website operation, certain technical data may be collected automatically, including:

  • IP address;

  • date and time of the request;

  • requested pages;

  • server response status code;

  • browser used;

  • operating system;

  • referrer;

  • technical information relating to the device and connection.

This data is necessary for the proper functioning of the website, for security purposes, technical maintenance, and the prevention of misuse.

b) Data voluntarily provided by the user

When a user fills out the contact form, the Controller processes the data entered by the user, namely:

  • first name;

  • last name;

  • email address;

  • phone number;

  • message.

c) Data related to website security

For cybersecurity and website protection purposes, the following data may be processed:

  • IP address;

  • login attempts;

  • security logs;

  • abnormal events;

  • technical information useful for detecting attacks, unauthorized access, or malicious behavior.

d) Data relating to cookie preferences and language settings

The website may store preferences relating to cookies and the user’s selected language. In particular, Polylang may use a language preference cookie for this purpose.

3. Purposes of processing and legal bases

Personal data is processed for the following purposes:

a) Enabling browsing and the technical operation of the website

Legal basis: Art. 6(1)(f) GDPR – the Controller’s legitimate interest in ensuring the proper functioning, stability, and security of the website.

b) Responding to requests for information or availability

The data entered in the contact form is processed in order to respond to the user’s requests.

Legal basis: Art. 6(1)(b) GDPR – processing is necessary in order to take steps at the request of the data subject prior to entering into a contract.

c) Managing the technical sending of emails from the website

The website uses WP Mail SMTP to improve the correct delivery of emails generated by the website.

Legal basis: Art. 6(1)(f) GDPR – the Controller’s legitimate interest in ensuring the proper delivery of communications.

d) Preventing spam, abuse, and automated submissions

The website uses Google reCAPTCHA v2 and Google reCAPTCHA v3 to distinguish requests made by real persons from those generated automatically by bots or abusive systems.

Legal basis: Art. 6(1)(f) GDPR – the Controller’s legitimate interest in protecting the website and its forms against spam and automated attacks.
The management of cookies and any tracking tools remains subject to the consent system implemented on the website, where required.

e) Collecting technical and usage statistics

The website uses WP Statistics in its basic configuration.

Legal basis: Art. 6(1)(f) GDPR – the Controller’s legitimate interest in obtaining aggregated statistics and improving the website.

f) Technical connection with Google services through Site Kit

The website uses Site Kit by Google. Based on the information currently available, Site Kit is considered here as a technical/administrative connection tool to Google services and not as an independent profiling tool.

Legal basis: Art. 6(1)(f) GDPR – the Controller’s legitimate interest in the technical management and search engine visibility of the website.

g) Protecting the website against unauthorized access and cyber threats

The website uses Wordfence Security for firewall protection, login protection, technical monitoring, and defense against attacks.

Legal basis: Art. 6(1)(f) GDPR – the Controller’s legitimate interest in ensuring website and data security.

h) Managing SEO and website metadata

The website uses Rank Math SEO for technical SEO purposes, metadata management, sitemaps, and related functions.

Legal basis: Art. 6(1)(f) GDPR – the Controller’s legitimate interest in the technical optimization of the website.

 

4. Summary table

 

Purpose Data processed Legal basis Retention Recipients
Browsing and technical operation IP address, technical logs, browser/device data Art. 6(1)(f) GDPR 30 days Hosting provider, authorized technicians
Response to contact form requests First name, last name, email, phone number, message Art. 6(1)(b) GDPR 12 months Controller, email/hosting provider
Technical email sending Data contained in emails and technical metadata Art. 6(1)(f) GDPR 30 days only if temporary technical logs are enabled; otherwise, for the time necessary for transmission Hosting provider, SMTP/email service
Anti-spam and form protection IP address, technical data, interactions, reCAPTCHA tokens Art. 6(1)(f) GDPR 30 days, unless different retention periods apply by the provider Google
Internal statistics Statistical and technical data in pseudonymized/aggregated form Art. 6(1)(f) GDPR 24 months Controller, authorized technicians
Website security IP address, security logs, login attempts, technical events Art. 6(1)(f) GDPR 30 days, unless longer retention is necessary in case of incidents or defense of rights Wordfence, hosting provider, authorized technicians
Cookie consent management Privacy/cookie preferences, timestamp, language Art. 6(1)(c) and 6(1)(f) GDPR 12 months Complianz, authorized technicians
Technical SEO Technical data and website metadata Art. 6(1)(f) GDPR For the time necessary for the technical purpose Controller, authorized technicians
Widgets and external content Technical data, IP address, possible interaction data Art. 6(1)(f) GDPR and, where required, consent Depending on the service involved and website configuration Google, Trustindex, possible third parties

5. Browsing and technical logs

The IT systems and software procedures used to operate the website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.

The website is hosted by VHosting.

This data is processed in order to:

  • make the website available;

  • ensure proper technical functioning;

  • maintain infrastructure security;

  • prevent unlawful or fraudulent use;

  • perform diagnostic and maintenance activities.

6. Contact form / information and availability requests

Through the contact form on the website, users may send requests for:

  • information;

  • availability;

  • contact by the accommodation.

The data collected through the form is:

  • first name;

  • last name;

  • email address;

  • phone number;

  • message.

Providing such data is optional, but failure to provide the required information may make it impossible for the Controller to respond to the request.

The data is received in the domain email mailbox managed through the hosting provider and is processed exclusively to respond to the request submitted.

Retention period: up to 12 months from receipt of the request, unless further retention is necessary due to continuation of the relationship or legal obligations.

7. Emails sent from the website – WP Mail SMTP

To improve the reliability of emails generated by the website, WP Mail SMTP is used.

Based on the prudent standard setting adopted in this Privacy Policy:

  • WP Mail SMTP is used exclusively for technical email delivery purposes;

  • no extended retention system for email content is provided beyond what is necessary for transmission and normal mailbox management;

  • if temporary technical logs are enabled for debugging or security purposes, they will be retained for a limited period, generally not exceeding 30 days.

8. Anti-spam – Google reCAPTCHA

The website uses Google reCAPTCHA v2 (checkbox “I’m not a robot”) and Google reCAPTCHA v3 to protect forms and prevent automated submissions, spam, and abuse.

The data processed may include, by way of example:

  • IP address;

  • browser data;

  • device information;

  • technical behavior/interactions with the page;

  • reCAPTCHA verification tokens and parameters.

As the service is provided by Google, the related processing may involve the disclosure of data to companies within the Google group and, depending on the service configuration, transfers to countries outside the EEA, as further described in the section on international data transfers.

9. Statistics and analytics

9.1 WP Statistics

The website uses WP Statistics in its basic configuration to obtain statistics about website usage and performance.

In this Privacy Policy, statistical processing is therefore described as:

  • focused on technical/statistical data;

  • not aimed at commercial profiling;

  • limited to monitoring visits, pages viewed, and aggregated information useful for improving the website.

Standard retention period: up to 24 months, unless earlier anonymization or aggregation applies.

9.2 Site Kit by Google

The website uses Site Kit by Google. Based on the information currently provided, Site Kit is treated here as a technical-administrative tool connected to Google services.

In this version of the policy, in the absence of confirmation that Google Analytics/GA4 or other frontend measurement/advertising modules are active:

  • Site Kit is treated as a technical-administrative tool;

  • it is not described as an independent user profiling system;

  • any future Google tools involving cookies or frontend tracking will also need to be described in the separate Cookie Policy and managed through the consent banner.

10. Security – Wordfence Security

The website uses Wordfence Security for security functions such as application firewall, login protection, detection of suspicious activity, and monitoring of security events.

Within these functions, the following data may be processed:

  • IP address;

  • event timestamps;

  • logs relating to login attempts;

  • technical information relating to suspicious traffic;

  • data necessary to identify and block harmful activity.

Standard retention period adopted: 30 days, unless longer retention is required in the event of security incidents, technical investigations, or defense of the Controller’s rights.

11. Google Reviews widget, Google Maps, WhatsApp and other external content

The website uses the Google Reviews Widget by Trustindex.io and may also include:

  • Google Maps;

  • WhatsApp button;

  • Tripadvisor button/link.

When such content or widgets are loaded, they may involve the transfer of technical data to the relevant third-party providers, including:

  • IP address;

  • browser information;

  • technical connection data;

  • possible data relating to interaction with the embedded content.

For this reason, the loading and management of such content must be coordinated with the consent management system implemented on the website, where required by applicable law.

12. SEO – Rank Math SEO

The website uses Rank Math SEO to manage technical SEO functions, metadata, sitemaps, structured data, and related optimizations.

In this Privacy Policy, Rank Math is considered to be used mainly for technical SEO purposes, unless a different configuration is implemented in the future.

13. Cookies and tracking tools

The website uses Complianz | GDPR/CCPA Cookie Consent to manage the cookie banner and users’ consent preferences.

The management of cookies and tracking tools is therefore entrusted to Complianz.

The website has a separate Cookie Policy, which provides detailed and updated information regarding:

  • the types of cookies used;

  • categories;

  • purposes;

  • duration;

  • any third parties involved;

  • how consent is given and withdrawn.

Strictly necessary technical cookies may be used without consent, within the limits permitted by applicable law. For non-technical cookies, third-party tools, or tracking technologies, processing takes place according to the preferences expressed by the user through the banner and consent management tools.

14. Nature of data provision

Providing browsing data is necessary to enable the technical functioning of the website.

Providing the data requested in the contact form is optional, but failure to provide the required fields may make it impossible to respond to the user’s request.

15. Recipients of personal data

Personal data may be disclosed or made accessible, within the limits strictly relevant to the purposes indicated above, to:

  • internal staff authorized by the Controller;

  • hosting and infrastructure service providers;

  • email or SMTP service providers;

  • security tool providers;

  • widget and embedded content providers;

  • Google service providers where involved;

  • technical consultants, webmasters, developers, or system administrators duly authorized.

Personal data is not subject to unrestricted public dissemination.

16. Transfers of data outside the EU / EEA

Some services used by the website may involve transfers of data outside the European Union or the European Economic Area, particularly in the case of providers such as Google or Wordfence/Defiant.

Where this occurs, the Controller adopts or requires the adoption of the safeguards provided for in Articles 44 et seq. GDPR, such as:

  • adequacy decisions, where applicable;

  • Standard Contractual Clauses;

  • any additional contractual, technical, and organizational measures.

17. Retention periods

Unless otherwise required by law or necessary for the protection of the Controller’s rights, personal data is retained according to the following standard criteria:

  • browsing data and technical logs: up to 30 days;

  • data submitted through the contact form: up to 12 months;

  • security data / Wordfence logs: up to 30 days;

  • cookie preferences / proof of consent: up to 12 months;

  • internal statistical data: up to 24 months;

  • temporary technical email logs: up to 30 days, if enabled.

Longer retention may occur only where necessary to comply with legal obligations, protect the Controller’s rights, or manage specific technical or security incidents.

18. Rights of the data subject

Data subjects may exercise, where applicable, the rights granted by Articles 15-22 GDPR, including:

  • right of access;

  • right to rectification;

  • right to erasure;

  • right to restriction of processing;

  • right to object;

  • right to data portability, where applicable;

  • right to withdraw consent, where processing is based on consent.


 

19. How to exercise your rights

To exercise their rights, data subjects may contact the Controller at:

info@hotelplueme.it

The Controller may request additional information, where necessary, to verify the identity of the requester and properly handle the request.

20. Complaint to the supervisory authority

Any data subject who believes that the processing of their personal data is carried out in breach of applicable law has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or with the competent supervisory authority in their country of residence.

21. Security measures

The Controller adopts appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, improper disclosure, or unlawful use.

Such measures include, by way of example:

  • protection of the hosting infrastructure;

  • regular updates of WordPress, theme, and plugins;

  • use of security systems and firewall tools;

  • restricted access to authorized users only;

  • strong credentials;

  • data minimization;

  • controlled management of website administration tools.

22. Minors

The website is not specifically directed at minors.

Where consent is the legal basis for processing, Italian law provides that minors aged 14 or older may validly consent to the processing of their personal data in relation to information society services; below that age, consent must be given or authorized by the holder of parental responsibility.

23. Updates to this Privacy Policy

This Privacy Policy may be subject to amendments or updates, including as a result of:

  • changes in legislation;

  • technical updates to the website;

  • activation or deactivation of plugins, services, or functionalities;

  • different configuration of third-party tools.

Users are invited to check this page periodically.

Last updated: March 15, 2026

Data Processors / service providers involved

Depending on the actual configuration of the website, the Controller may rely on the following providers, appointed or appointable as data processors where necessary:

  • VHosting Solution s.r.l. – hosting/infrastructure

  • Complianz B.V. – cookie banner and consent preference management

  • Google Ireland Limited / Google LLC – reCAPTCHA, Site Kit, Google Maps, and any other Google services activated

  • Defiant, Inc. / Wordfence – website security, firewall, login protection

  • Trustindex Ltd. – Google Reviews widget

  • Rank Math / ONE.COM INDIA PRIVATE LIMITED – SEO plugin

  • WP Statistics – local statistics plugin

  • Domain email provider / configured SMTP service – technical management of website email

Separate Cookie Policy

The website has a separate Cookie Policy, distinct from this Privacy Policy.

Consent management for cookies and tracking tools is handled through Complianz. For full and updated details on cookies, tracking tools, categories, duration, and how preferences can be managed, users should refer to the dedicated Cookie Policy.