Palazzo Baj in Trastevere, Rome
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018
1. Data Controller
The Data Controller for the processing of personal data is Palazzo Baj in Trastevere, based at Lungotevere Ripa 6, 00153 Rome (RM), Italy, VAT number IT14127971001.
For any request concerning the processing of personal data, data subjects may contact the Data Controller:
- Email: [email protected]
- Phone: +39 3456800872
- Postal address: Palazzo Baj in Trastevere, Lungotevere Ripa 6, 00153 Rome, Italy
2. Data Protection Officer (DPO)
The Data Controller has not appointed a Data Protection Officer (DPO), as the conditions under Art. 37 GDPR do not apply (no large-scale processing of special categories of data and no large-scale systematic monitoring of data subjects). The Data Controller reserves the right to reassess this position should its processing activities change.
3. Categories of data processed, purposes and legal bases
3.1 Data collected for booking management
Data processed: first and last name, email address, phone number, home address, identity document details, stay preferences, any special requests.
Collection channels: direct website booking engine and online travel agencies (OTAs — e.g. Booking.com, Expedia, Airbnb).
Purpose: managing and fulfilling the booking request, performance of the accommodation contract, communications related to confirmation, modification or cancellation of the booking.
Legal basis: performance of a contract to which the data subject is party, or steps taken at the data subject’s request prior to entering into a contract (Art. 6(1)(b) GDPR).
Note on OTAs: when a booking is made through a third-party platform, that platform acts as an independent data controller for the initial collection of data on its own system; Palazzo Baj in Trastevere receives the data necessary to fulfil the stay in its capacity as controller for the purposes described above. Please refer to each platform’s own privacy policy for the processing it carries out.
3.2 Data collected for legal compliance — Guest registration (local police authority)
Data processed: identity and personal details of all guests, including minors.
Purpose: compliance with the legal obligation to report guest details to the Italian public security authorities via the Alloggiati Web portal, pursuant to Art. 109 of the Consolidated Public Security Act (Royal Decree 773/1931) and the Ministerial Decree of 7 January 2013.
Legal basis: compliance with a legal obligation to which the Controller is subject (Art. 6(1)(c) GDPR).
Retention: data submitted via Alloggiati Web is retained by the Controller for the period set out under public security regulations (generally 5 years, unless a different term is established by the competent authority).
3.3 Payment data
Method: payments are handled in two distinct ways:
- OTA bookings: the booking platform (OTA) provides the Controller with a virtual credit card, issued and managed directly by the OTA, which the Controller uses to collect the amount due. The Controller does not receive or store the guest’s actual credit card details, only the virtual card credentials generated by the OTA for that specific transaction, valid solely for the amount and period of the booking;
- Direct bookings (website): payment is made via physical POS terminal on site at check-in/check-out, with the guest’s card presented in person.
Purpose: performance of the contract (collection of the amount due).
Legal basis: performance of a contract (Art. 6(1)(b) GDPR). For the OTA virtual card flow, processing of payment data is limited to the credentials provided by the intermediary for the individual transaction; the OTA acts as an independent controller for managing the payment relationship with its own customer/guest.
Note: the Controller does not store complete payment card data (real or virtual) beyond the time strictly necessary to process the transaction. Payment data is not used for marketing purposes and is not shared with third parties beyond what is necessary to process the payment itself.
3.4 Video surveillance
Areas covered: entrance and common areas of the property. No video surveillance systems are present in guest rooms.
Purpose: protection of safety and property, prevention of unlawful acts.
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR), balanced against the fundamental rights and freedoms of data subjects.
Signage: the monitored area is indicated with dedicated signage, in accordance with the model set out in the Italian Data Protection Authority’s Order of 8 April 2010 (“Provisions on video surveillance”). The short-form sign is accompanied by an extended notice available at the reception desk upon request.
Retention: footage is retained for a maximum period of 24 hours, except where required for investigative purposes upon request by the judicial authority. This retention period is consistent with the proportionality principle set out in the Italian Data Protection Authority’s Order of 8 April 2010.
Access: footage is not accessible to third parties, except upon request by the competent authority.
3.5 Browsing data and technical cookies
The Palazzo Baj in Trastevere website does not use profiling cookies, third-party analytics cookies (e.g. Google Analytics), or advertising tracking pixels. A consent banner is therefore not present, as no technologies requiring one under the Italian Data Protection Authority’s Cookie Guidelines (Order of 10 June 2021) are in use.
The website may use only technical cookies strictly necessary for the operation of the booking engine and for managing the user session (e.g. session cookies from the Beddy booking system). These cookies do not require prior consent under Art. 122 of the Italian Privacy Code, as they are essential to providing the service requested by the user.
Note: should Google Analytics, Meta/Facebook pixels, email-tracking newsletters, or any other profiling tool be activated in the future, this policy and the website will need to be updated with a consent banner compliant with the Authority’s Guidelines (equally prominent “accept / reject / customise” options).
4. Categories of data recipients
For the purposes described above, personal data may be shared with the following categories of recipients:
- Beddy (Zucchetti Group), as provider of the property management system (PMS), appointed as Data Processor under Art. 28 GDPR;
- Rome Police Headquarters / Italian Ministry of the Interior, via the Alloggiati Web portal, for compliance with the legal obligation;
- Online travel agencies (OTAs), for the portion of data needed to manage bookings originating from them;
- Consultants and professionals (accountant, employment consultant, lawyer) for administrative, accounting and tax purposes related to the business;
- Public authorities, where required by law.
Data is not disclosed to the public or shared with third parties for marketing purposes.
5. Transfers of data outside the EU
The Controller does not currently carry out systematic transfers of personal data to countries outside the EU. Please note that some OTAs operate on global infrastructure; for processing carried out by such entities as independent controllers, please refer to their respective privacy policies.
6. Data retention periods
- Booking data: for the duration of the contractual relationship and subsequently for the period required to meet tax and accounting obligations (10 years, Art. 2220 of the Italian Civil Code);
- Alloggiati Web data: as set out under public security regulations;
- Video surveillance footage: as indicated in section 3.4;
- Payment data: limited to the time necessary to process the transaction.
7. Data subject rights
Under Articles 15–22 GDPR, data subjects have the right to:
- obtain confirmation of whether processing is taking place and access their personal data (right of access);
- obtain rectification of inaccurate data or completion of incomplete data;
- obtain erasure of data, in the cases provided for by law (right to be forgotten);
- obtain restriction of processing;
- object to processing based on the Controller’s legitimate interest;
- receive their data in a structured, commonly used format (right to data portability), where applicable;
- withdraw consent at any time, where previously given, without affecting the lawfulness of processing carried out before withdrawal.
Requests may be sent to the contact details listed in Section 1.
8. Right to lodge a complaint
Data subjects have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (Piazza Venezia 11, 00187 Rome, Italy — www.garanteprivacy.it), if they believe their data has been processed in violation of applicable law.
9. Changes to this policy
The Controller reserves the right to modify or update this policy, in whole or in part, including as a result of regulatory changes. Data subjects are encouraged to check this page periodically.
Last updated: 08.09.2026