menu
altlogo
/
Cancel/modify
reservation
GPS
Book
Call
Privacy Policy 2

Privacy Policy

Dear Customer, pursuant to Articles 13 and 14 of EU Regulation 2016/679 (GDPR) on the protection of natural persons with regard to the processing of personal data, the Data Controller hereby informs you that the personal data you provide will be processed in accordance with the principles of fairness, lawfulness, and transparency, and with due regard for your privacy and your rights.

Pursuant to the aforementioned articles, we provide you with the following information:


1. Data Controller

The Data Controller is Granea S.r.l., with its registered office at Via Li Pultali No. 10, Santa Teresa di Gallura (OT), VAT Number: 03069370900.


2. Purpose of Data Processing
The Data Controller processes personal data (including your personal details, those of the people staying with you, your bank account information, your contact information, billing information, cell phone number, residential or domicile address, and email address), which you provided when entering into a contractual relationship for the provision of hotel and/or restaurant services, in order to process and confirm your reservation for lodging and ancillary services, and to provide the requested services.

The Data Controller informs you that, in order to provide the services requested in relation to your specific needs—including to report a health-related need—special categories of personal data may also be processed, such as those relating to your health status (e.g., food intolerances, use of services dedicated to vulnerable individuals or people with disabilities).


3. Purposes of Data Processing and Legal Bases
Your personal data will be processed for:

A. purposes strictly connected with and necessary for the fulfillment of obligations arising from the implementation of pre-contractual measures (e.g., providing a quote) and contractual obligations, compliance with legal obligations, and specifically for:

- providing hotel and/or restaurant services, to process and confirm your reservation for lodging and ancillary services, and to provide the requested services;
- entering personal information into the company’s management software;
- carrying out pre-contractual and contractual measures aimed at providing the requested services;
- processing data necessary to comply with the obligation set forth in the “Consolidated Law on Public Safety” (Article 109 of Royal Decree No. 773 of June 18, 1931), which requires us to report to the Police Headquarters, for public safety purposes, the personal details of guests staying at the hotel in accordance with the procedures established by the Ministry of the Interior (Decree of January 7, 2013);
- management of administrative, accounting, and tax matters;
- to defend and exercise a right in court to assert a legitimate interest of the Data Controller.
B. Additional purposes, which may be fulfilled based on your optional, separate consent for each purpose listed below:
- B1) processing of special categories of personal data, such as those relating to health status (e.g., food intolerances, use of services dedicated to vulnerable or disabled individuals) for the provision of services requested in relation to your specific needs, in order to report a health-related need of yours;
- B2) processing of personal data to request an “authorization for a charge” on your credit card as a guarantee for extras not included in the cost of your stay (phone calls, refreshments, etc.) by the Data Controller;
- B3) to handle the receipt of messages and phone calls addressed to you during your stay; for this purpose, your consent is required, which you may revoke at any time;
- B4) to provide you with advertising materials, catalogs, and the Hotel’s price lists, as well as to keep you updated on our initiatives and promotional offers for direct marketing purposes, subject to your consent, which may be revoked at any time;
- B5) to bring a feedback form to your attention, in which you may indicate your level of satisfaction with the services provided by the Data Controller.

Please note that, if you are already a customer of ours, we may send you commercial communications—using only the email address provided during the contractual process—regarding the Data Controller’s services or products similar to those you have already used, unless you expressly and freely object at any time by contacting the Data Controller in the manner set forth in this privacy notice (Art. 130, paragraph 4 of Legislative Decree 196/2003—Privacy Code).


4. Methods of Data Processing and Retention
Data processing will be carried out using paper and electronic media, in compliance with all precautionary measures that ensure confidentiality and security.
At check-in, at the front desk, you will be asked to present your identification document, a copy of which will be made to expedite the check-in process. The data will be uploaded to the company’s management system, and at the end of the day, a file will be generated to be sent to the Police Headquarters via the Alloggiati Portal. The photocopy of the document will be destroyed upon completion of the registration.
In addition, you will be asked to provide a “pre-authorization” on your credit card as a guarantee for any extras not included in the cost of your stay (phone calls, beverages, etc.). The pre-authorization slip will be kept at the reception desk.
- B5) to bring a feedback form to your attention, in which you may indicate your level of satisfaction with the services provided by the Data Controller.
Please note that, if you are already a customer of ours, we may send you commercial communications—using only the email address provided during the contractual process—regarding the Data Controller’s services or products similar to those you have already used, unless you expressly and freely object at any time by contacting the Data Controller in the manner set forth in this privacy notice (Art. 130, paragraph 4 of Legislative Decree 196/2003—Privacy Code).
4. Methods of Data Processing and Retention
Data processing will be carried out using paper and electronic media, in compliance with all precautionary measures that ensure confidentiality and security.
At check-in, at the front desk, you will be asked to present your identification document, a copy of which will be made to expedite the check-in process. The data will be uploaded to the company’s management system, and at the end of the day, a file will be generated to be sent to the Police Headquarters via the Alloggiati Portal. The photocopy of the document will be destroyed upon completion of the registration.

In addition, you will be asked to provide a “charge authorization” on your credit card as a guarantee for any extras not included in the cost of your stay (phone calls, beverages, etc.). The authorization form will be kept at the front desk in special locked files, to which only authorized personnel have access, and will be returned to you at the end of your stay at the “Granèa” hotel. The Data Controller informs you that your data will be retained for the entire duration of the relationship and subsequently for 10 years for the administrative and accounting purposes outlined in section 3.A); any personal data and specific details you provide will be retained exclusively for the time strictly necessary to perform the requested service until your departure from the hotel for the purposes described in sections 3.B2 and B3); Data processed for marketing purposes (section 3.B4) and to assess customer satisfaction (section 3.B5) will be processed for a maximum period of 24 months from the date of registration and until consent is revoked, which may be done at any time.

5. Methods of Providing Data and Consequences of Refusal to Provide Data
The provision of your personal data for the purposes set forth in Section 3.A is mandatory in order to fulfill contractual and legal obligations. Failure to provide such data would make it impossible for us to fulfill our contractual and legal obligations and prevent us from providing you with the requested services.
The provision of your personal data for the purposes set forth in Section 3.B, items 1, 2, 3, and 4, is optional. You may therefore choose not to provide any data or subsequently withdraw consent to the processing of data already provided; in such cases, you will still retain the right to use the services referred to in Section 3.A.


6. Disclosure and Sharing of Data
For the purposes of performing the contract and for the purposes indicated in section 3A, your personal data will be disclosed to:
- public security authorities, in compliance with the relevant disclosure obligation set forth in Article 109 of the Consolidated Law on Public Security;
- our trusted tax consulting firm for the purposes of complying with mandatory tax obligations under the law;
- to banking institutions for the management of collections;
- to our employees who have been specifically assigned and authorized to handle such matters within the scope of their duties.
Apart from these obligations, your data will not be disclosed or shared with third parties, nor will it be transferred to a third country or to an international organization outside the European Union.


7. Video Surveillance
The undersigned Company hereby informs you that a closed-circuit video surveillance system, which records images, is in operation in certain areas of the hotel. To this end, several surveillance cameras have been installed, the presence of which is indicated by appropriate signage on the walls.
The audiovisual system was installed to ensure the safety of both staff and guests and to protect the company’s assets. Your consent is not required for this processing, as it serves the legitimate interest of the Data Controller in protecting people and property from potential assaults, thefts, robberies, damage, and acts of vandalism, as well as for fire prevention and workplace safety purposes.
The system records only the images that are strictly necessary and consists of cameras aimed at the areas most exposed to the risk of theft or damage.
The recordings will be retained for a maximum period of 24 hours, except on holidays or other occasions when the business is closed, and in any case for no longer than one week; the images will be stored on a dedicated server and will be automatically deleted via a system that allows for overwriting.
The name of the Granèa Srl employee responsible for the storage and processing of the images is available at our offices.
The recorded images will never be disclosed or shared with third parties, except in cases where we are required to comply with a specific investigative request from a judicial authority or law enforcement agency.


8. Minors (Art. 8 GDPR)
The Data Controller’s services are not intended for minors, and the Data Controller does not intentionally collect personal information relating to minors. The processing of a minor’s personal data is lawful only if and to the extent that consent is provided or authorized by the holder of parental responsibility.
In the event that information regarding minors is inadvertently recorded, the Data Controller will delete it promptly.


9. Rights of the Data Subject

The data subject has the right to request from the Data Controller access to their personal data (Art. 15 GDPR), rectification of such data (Art. 16 GDPR), erasure of such data (Art. 17 GDPR), and restriction of processing (Art. 18 GDPR); they also have the right to object to the processing of their data and to request data portability.
The data subject has the right to lodge a complaint with a supervisory authority.
No automated decision-making processes, including profiling as referred to in Article 22 of the GDPR, are used.


10. Data Controller and Data Processor
The Data Controller, pursuant to the GDPR, is GRANEA S.R.L., Via Li Pultali, 10, Santa Teresa di Gallura (OT) 07028, in the person of its Legal Representative.


11. How to Exercise Your Rights
Requests to exercise your rights may be submitted by registered letter, fax, or email to GRANEA S.R.L., Via Li Pultali, 10, Santa Teresa di Gallura 07028 (OT), tel. 0039 331 430 6934 – email: direzione@graneaboutiquehotel.it The Data Controller hereby informs you that it has appointed a Data Protection Officer, who may be contacted—including for requests to exercise the rights of data subjects—at the following email address: direzione@graneaboutiquehotel.it


Privacy Policy updated on July 3, 2026.