Privacy policy
How we process the personal data collected through this website, pursuant to Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003.
This website collects personal data only when you write to us through the contact form. We do not use profiling cookies or advertising tools.
Data controller
The data controller is MABY HOLIDAY S.R.L. (Hotel Miramare), Corso Italia 2, 17026 Noli (SV), Italy, VAT no. 01849770092.
Email: info@hotelmiramarenoli.it · Telephone: +39 019 748926.
What data we collect
Through the contact/request form we collect the data you enter: first and last name, email, telephone (optional), dates and number of guests for the stay, subject of the request and the text of your message.
For security reasons we also record, in one-way encrypted (hashed) form and therefore not traceable back to you, the IP address and the browser (user agent) of whoever submits the form.
Please do not include special category data in your message (for example information about health, allergies or medical needs): if this is necessary for your stay, please tell us when booking or by telephone.
Why we process the data (purposes and legal bases)
- Responding to your request and managing any booking: performance of pre-contractual measures and of the contract (art. 6.1.b GDPR).
- Website security and prevention of abuse/spam (honeypot, submission limit, hashing of IP/browser): legitimate interest (art. 6.1.f GDPR).
- Legal, tax and accounting obligations, in the event of a stay: legal obligation (art. 6.1.c GDPR).
Who processes the data for us (processors and providers)
To run the website and handle requests we rely on providers acting as data processors pursuant to art. 28 GDPR:
- Vercel Inc.: website hosting and server functions.
- Neon Inc.: database in which requests are stored.
- Resend (Plus Five Five, Inc.): sending the notification email for the request.
- Cloudflare, Inc.: aggregated traffic statistics without cookies (Web Analytics) and anti-spam protection of the contact form (Turnstile), which receives your IP address and some browser signals in order to tell people from bots.
- CARTO: maps on the "Contact" and "Where to eat" pages; the provider receives your IP address in order to serve the map tiles.
When you click "Book" you are directed to the RoomRaccoon booking system, which acts as an independent data controller with its own privacy policy.
Transfers outside the European Union
Some of the providers listed above are based in the United States. Transfers take place with appropriate safeguards pursuant to arts. 44-49 GDPR (adherence to the EU-U.S. Data Privacy Framework, where applicable, or Standard Contractual Clauses). The database is configured to reside in a European Union region.
How long we keep the data
- Requests that did not lead to a booking: up to 24 months from the last contact, then deleted.
- Data relating to stays and to tax/accounting obligations: for the period required by law (generally 10 years).
Your rights
At any time you may request access to, rectification, erasure, restriction or portability of your data, and object to the processing (arts. 15-22 GDPR), by writing to info@hotelmiramarenoli.it.
You also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it).
Provision of the data
Providing the form data is optional, but necessary in order for us to follow up on your request: without it we cannot reply to you.
Cookies
This website does not use profiling cookies. For details of the technical cookies and tools used, see the Cookie Policy.
Last updated: June 2026.
This is a courtesy translation. In the event of any discrepancy between this version and the Italian version, the Italian version prevails.
