Skip to main content

Last updated: January 2025


1. Data Controller

The Data Controller for personal data is:

Hotel Giugiù
Via del Viminale 8, 2nd floor
00184 Rome (RM)
VAT: 17918031000
Email: privacy@hotelgiugiu.it
Tel: +39 06 4827734

2. Data Collected

We collect the following categories of personal data:

  • Booking data: first name, last name, email, phone, stay dates, number of guests.
  • Navigation data: IP address, browser type, pages visited, visit duration (via technical cookies).
  • Communications: content of messages sent through the contact form.

3. Purposes and Legal Basis

  • Booking management — legal basis: performance of a contract (Art. 6.1.b GDPR).
  • Tax and legal obligations — legal basis: legal obligation (Art. 6.1.c GDPR).
  • Newsletter and commercial communications — legal basis: consent (Art. 6.1.a GDPR), withdrawable at any time.
  • Website improvement — legal basis: legitimate interest (Art. 6.1.f GDPR).

4. Cookies

We use:

  • Necessary technical cookies — for the functioning of the website (no consent required).
  • Anonymous analytical cookies — for aggregate traffic statistics (with consent).
  • Marketing cookies — only with explicit consent.

You can manage or withdraw cookie consent at any time via the cookie banner or your browser settings.


5. Data Retention

Booking data is retained for 10 years for tax obligations. Anonymised navigation data is retained for 13 months. Newsletter consents are retained until withdrawn.


6. Your Rights

Pursuant to Arts. 15–22 GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing based on legitimate interest

To exercise your rights write to: privacy@hotelgiugiu.it

You also have the right to lodge a complaint with the supervisory authority in your country of residence.


7. Transfers to Third Parties

Data is not sold to third parties. It may be disclosed to:

  • Technical service providers (hosting, email) bound by a GDPR-compliant DPA
  • Public authorities upon legal request
  • Booking intermediaries (OTAs) solely for bookings originated through them