Data Controller: for the purposes of this privacy policy, Controller means Five Stars Rome Tour di Federico Doria, VAT no. 18573691005, with registered office at Via Ignazio Guidi 88, 00147 Rome (RM), Italy, e-mail: info@fivestarsrometour.com , tel: +39 371 320 5966, whatsapp contact: +39 371 320 5966.
*****
Pursuant to and for the purposes of Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “Regulation” or the “GDPR”) and of Italian Legislative Decree no. 196 of 30 June 2003, the Personal Data Protection Code (the “Code”) (the Code and the Regulation jointly referred to as the “Applicable Law”), data subjects (“Data Subjects”) are hereby informed that their Personal Data will be processed in compliance with the Applicable Law and as further specified below.
Definitions
- Authorised Persons, the natural persons authorised to carry out Processing operations under the direct authority of the Controller or of the Processor, pursuant to Art. 29 of the Regulation and Art. 2-quaterdecies of the Code.
- Communication, disclosing Personal Data to one or more identified persons other than the Data Subject, the Controller’s representative in the territory of the State, the Processor and the Authorised Persons, in any form, including by making such data available or accessible for consultation.
- Cookies, the small text strings that the websites visited send to the User’s terminal, where they are stored so as to be transmitted back to the same websites on the User’s next visit. In this Privacy Policy the term also covers any further tracking technology that allows the User or the User’s device to be identified.
- Designated Persons, the natural persons entrusted with specific tasks and functions relating to the processing of Personal Data, acting under the authority of the Controller or of the Processor, pursuant to Art. 2-quaterdecies of the Code.
- Personal Data or Data, any information relating to an identified or identifiable natural person, including indirectly identifiable by reference to any other information, and in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
- Dissemination, disclosing Personal Data to unidentified persons, in any form, including by making such data available or accessible for consultation.
- Garante, the supervisory authority referred to in Art. 51 of the Regulation, namely the Italian Data Protection Authority.
- Privacy Policy, this document.
- Data Subject, the natural person to whom the Personal Data relate. For the purposes of this Privacy Policy the terms “Data Subject”, “User” and “Customer” are used interchangeably.
- Security Measures, the set of technical, IT, organisational, logistical and procedural measures adopted by the Controller in order to ensure a level of security appropriate to the risk of the Processing, pursuant to Art. 32 of the Regulation.
- Participant, the natural person taking part in the booked Service, including where such person is other than the Data Subject who made the Booking.
- Booking, the request by which the User reserves a Service through the Website for a specific date and time slot.
- Processor, the natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
- Services, the tourist services offered and provided by the Controller, and in particular the private golf cart tours in the city of Rome that may be booked through the Website.
- Website, the website available at https://fivestarsrometour.com/.
- Controller, the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data; where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law. For the purposes of this Privacy Policy the terms “Controller” and “Organiser” are used interchangeably.
- Processing, any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, Communication by transmission, Dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Information on the Processing of Personal Data
1. Context of the Processing
This Privacy Policy is provided by the Controller in relation to the following context: the website and online booking platform of Five Stars Rome Tour di Federico Doria, offering the distance sale of private golf cart tours in the city of Rome.
2. Processing operations carried out
The Data collected, the purposes for which they are processed, the legal bases and the retention periods are set out in detail below.
| Data processed | Purpose | Legal basis | Retention period |
| IP address browsing data | Provision of the services offered through the Website. | Processing is necessary for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract [Art. 6(1)(b) GDPR] | Browsing Data are deleted within 30 days of collection, without prejudice to any need for the investigation of criminal offences by the judicial authority. |
| IP address Whatsapp user name content of the messages | Provision of the whatsapp chat service accessible from the Website. | Processing is necessary for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract [Art. 6(1)(b) GDPR] | Messages received by the Controller are retained for a maximum period of 24 months. |
| Name e-mail address subject and content of the message | Responding to requests for information and for quotations submitted through the contact form available on the Website. | Processing is necessary for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract [Art. 6(1)(b) GDPR] | 24 months from the last relevant contact with the Data Subject. |
| Name Surname e-mail address telephone number date and time slot selected names of the Participants hotel or pick-up address preferred language | Management of the Booking, confirmation thereof, organisation and performance of the Service, including collection of the Data Subject and of the Participants at the indicated location. | Processing is necessary for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract [Art. 6(1)(b) GDPR] | 10 years from performance of the Service (expiry of the applicable statutory limitation period). |
| Name Surname billing details Data relating to the purchase made | Accounting management and compliance with tax and accounting obligations. | Processing is necessary for compliance with a legal obligation to which the Controller is subject [Art. 6(1)(c) GDPR] | 10 years from issue of the relevant accounting document (Art. 2220 of the Italian Civil Code). |
| data concerning health, mobility requirements or intolerances voluntarily communicated by the Data Subject | Adapting the Service to the requirements of the Data Subject or of the Participants and safeguarding their safety during the tour. | Processing is carried out on the basis of the Data Subject’s explicit consent [Art. 9(2)(a) GDPR] | Until performance of the Service and, in any event, no longer than 12 months thereafter, save where necessary to establish, exercise or defend legal claims. |
| IP address browsing data data relating to interaction with the pages of the Website (pointer movements, clicks, scrolling, session recording) | Statistical and behavioural analysis of the use of the Website in order to improve the Services offered and the user experience, by means of the Microsoft Clarity tool. | Processing is carried out on the basis of the Data Subject’s consent [Art. 6(1)(a) GDPR and Art. 122 of the Code] | 12 months from collection or, if earlier, until consent is withdrawn by the Data Subject. |
| e-mail address | Sending the Data Subject commercial communications by e-mail relating to Services similar to those already purchased by the User (so-called soft spam). | Processing carried out for this purpose is based on a legitimate interest of the Controller (Recital 47 of the Regulation and Art. 130(4) of Legislative Decree no. 196/2003) and does not require the Data Subject’s consent, without prejudice to the right to object at any time | 48 months from the last purchase. |
| Name Surname e-mail address | Sending the Data Subject commercial communications by e-mail. | Processing carried out for this purpose is based on the Data Subject’s consent | 48 months from the giving of consent or, if earlier, until consent is withdrawn by the Data Subject. |
| identification and contact data data relating to the Booking and to the Service provided | Establishing, exercising or defending the Controller’s legal claims in court or out of court, including in connection with complaints and disputes. | Processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party [Art. 6(1)(f) GDPR] | For the entire duration of the dispute and until expiry of the time limits for appeal, or until expiry of the applicable limitation period. |
3. Methods of Processing and categories of Recipients.
- Save as otherwise expressly provided in this Privacy Policy, the Data Subject is informed that the Processing of his or her Personal Data is carried out by manual means and/or by IT, telematic or otherwise automated means, in compliance with the principles of relevance, lawfulness, fairness and purpose limitation laid down by the Applicable Law.
- The Controller processes the Data Subject’s Personal Data by adopting appropriate Security Measures aimed at minimising the risks of unauthorised access, Dissemination, loss and destruction of such Data, in accordance with the Applicable Law.
- The Data Subject is further informed that the Processing of Personal Data for the purposes indicated above may be carried out by the Controller directly or with the assistance of other parties acting as Processors, Designated Persons or Authorised Persons (for example the Controller’s employees and/or collaborators, and the guides and drivers appointed to carry out the tours).
- The Data Subject is informed that Personal Data may be disclosed to the following categories of external Processors:
- Providers of hosting and website maintenance services
- Providers of the booking management platform (Tour Booking Manager)
- Providers of behavioural and statistical analysis services (Microsoft Clarity)
- Providers of e-mail and e-mail marketing services
- Providers of messaging services
- Tourist guides, drivers and collaborators appointed to perform the Services
- Accountant
- Legal and insurance advisers
The Data Subject is informed that the processing operations carried out by the following categories of recipients are performed by them as independent data controllers:
- third-party payment service providers. The Data Subject is informed that, where payment is made through third-party payment services (namely Stripe Payments Europe Ltd.), the Personal Data provided by the Data Subject in order to make the payment will be processed exclusively by such providers and will not pass through the Controller’s servers;
- instant messaging service providers, with regard to the data processed on their own platform following activation of the chat by the User (WhatsApp Ireland Ltd.);
- providers of libraries and technical services supplied by third parties and called by the pages of the Website, with regard to the data collected directly by their own servers (Google Ireland Ltd. for the Google Fonts service).
- A complete and up-to-date list of the Processors may be obtained at any time by sending a request to the e-mail address indicated at the beginning of this Privacy Policy.
4. Transfer of Data
- The Data Subject is informed that the Personal Data processed by the Controller may be transferred to other countries within the European Union.
- The Data Subject is informed that the Personal Data processed by the Controller may be transferred to countries outside the European Union in respect of which an adequacy decision of the Commission exists, or in respect of which further security measures are applied following an assessment by the Controller of the impact of the transfer on the rights and freedoms of the Data Subject.
- In particular, some of the providers engaged by the Controller are established in the United States of America or may transfer Data there. Such transfers take place on the basis of the European Commission’s adequacy decision of 10 July 2023 concerning the EU-U.S. Data Privacy Framework, where the provider is certified thereunder, or otherwise on the basis of the standard contractual clauses adopted by the European Commission pursuant to Art. 46(2)(c) of the Regulation, supplemented by any additional measures required following the transfer impact assessment.
- A copy of the safeguards adopted may be requested from the Controller at the e-mail address indicated at the beginning of this Privacy Policy.
5. Cookies and tracking technologies
- The Website uses technical cookies, which are necessary for its operation and for the provision of the services requested by the User (including those relating to session management, the shopping cart and the booking process); no consent is required for such cookies pursuant to Art. 122 of the Code.
- The Website also uses third-party cookies and tracking technologies for behavioural analysis and profiling purposes (in particular Microsoft Clarity), which are installed exclusively upon the Data Subject’s prior consent, given through the dedicated banner displayed on first access to the Website.
- The Data Subject may at any time amend or withdraw the consent given by accessing the preference panel available on the Website, and may disable cookies through the settings of his or her browser; disabling technical cookies may however impair the proper functioning of the Website.
- A detailed list of the cookies used, indicating the issuing party, the purpose and the duration of each of them, is set out in the Cookie Policy published on the Website, which forms an integral part of this Privacy Policy.
6. Data relating to minors and to Participants
- The Services are not intended for persons under 18 years of age: Bookings may be made exclusively by persons of full age. The Controller does not knowingly collect Personal Data of minors through the Website, save as set out in the following paragraph.
- Where the Data Subject provides the Controller with Personal Data relating to other Participants, including minors in respect of whom he or she holds parental responsibility, the Data Subject represents that he or she is entitled to do so and undertakes to provide such persons with this Privacy Policy, holding the Controller harmless from any resulting claim.
7. Rights of the Data Subject
- The Data Subject may at any time exercise the rights provided for by Arts. 15 to 22 of the Regulation by sending a communication to the addresses indicated at the beginning of this Privacy Policy. In particular:
- The Data Subject has the right to request from the Controller access to his or her Personal Data, in accordance with and within the limits of Art. 15 of the Regulation.
- The Data Subject has the right to request from the Controller the rectification of inaccurate Personal Data, in accordance with and within the limits of Art. 16 of the Regulation.
- The Data Subject has the right to request from the Controller the erasure of Personal Data, in accordance with and within the limits of Art. 17 of the Regulation.
- The Data Subject has the right to request from the Controller the restriction of the Processing of Personal Data, in accordance with and within the limits of Art. 18 of the Regulation.
- The Data Subject has the right to request from the Controller that his or her Personal Data be provided in a structured, commonly used and machine-readable format, in accordance with and within the limits of Art. 20 of the Regulation.
- The Data Subject has the right to object to the Processing carried out by the Controller, in accordance with and within the limits of Art. 21 of the Regulation.
- The Data Subject has the right to lodge a complaint with a supervisory authority and, in particular, with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy – garante@gpdp.it).
- The Data Subject has the right to withdraw consent in respect of those Processing operations which are based on that legal basis. Pursuant to Art. 7(3) and Art. 13(2)(c) of the Regulation, the Data Subject is informed that, in any event, the withdrawal of consent does not affect the lawfulness of Processing based on consent before its withdrawal.
8. Amendments to this Privacy Policy
1. The Controller reserves the right to amend this Privacy Policy at any time, giving notice thereof to Data Subjects by publication on the Website.
This Privacy Policy was published on 22/07/2026.