Privacy

Privacy and cookie notice

Last updated: 14 September 2026

In short: this site has no forms, sets no cookies, runs no analytics, tracks nobody and contacts no outside service. If you write to us, we use your address to answer you and to arrange what you ask for. Nothing else. Below, in full, how and why.

This notice is given under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Article 122 of Italian Legislative Decree 196/2003.

01

Who is the controller

The data controller is Simone Sergio Company, Via del Marrucco 69, 56012 Calcinaia (Pisa), Italy — VAT no. 02421030509 — certified email simone.sergio@arubapec.it.

«The Concierge — Tuscany» is a trading name of Simone Sergio Company: the contract you enter into, and the party answering for your data, is the company named above.

For anything concerning your personal data, write to info@theconciergetuscany.com.

We have not appointed a Data Protection Officer: the cases listed in Article 37 GDPR do not apply, as we carry out no regular and systematic monitoring on a large scale and process no special categories of data on a large scale.

02

Who this notice is for

  • anyone who visits this site;
  • anyone who writes to us;
  • guests who entrust us with a stay or an experience;
  • contacts at hotels, agencies and other intermediaries we work with;
  • the suppliers and collaborators in our network.

03

What data we handle

3.1 — Browsing data

As on every website, the server hosting this one automatically records your IP address, the date and time of the request, the page requested, and your browser and operating system. These logs keep the site running and protect it from abuse. We do not use them to identify you and we do not combine them with any other data.

3.2 — What you send us

Whatever you put in an email: your name, your address, possibly a telephone number, and the content of the message — dates, how many of you there are, preferences, budget.

3.3 — Special categories of data

Arranging a stay sometimes means you tell us about food allergies or intolerances, health or mobility needs, or religious dietary requirements. Those are special categories of data under Article 9 GDPR. We process them only with your explicit consent — which you give by sending them to us knowingly for this purpose, and which you can withdraw at any time. We pass them to the individual supplier (restaurant, villa, guide, driver) only to the extent needed to meet the request, and we keep them no longer than that requires.

Please do not send us health details beyond what is needed, and never send identity documents, card numbers or bank details by email.

3.4 — Other people's data

If you send us data about the people travelling with you — or, if you are a hotel or an intermediary, about your own clients — informing them, and obtaining their consent where required, remains your responsibility. We process that data solely to deliver the service requested.

04

Why we process it, and on what basis

  • Answering you and preparing a possible engagement — Art. 6(1)(b) GDPR, steps taken at your request before entering into a contract. For business contacts (hotels, agencies) the basis is our legitimate interest in replying to a commercial enquiry, Art. 6(1)(f).
  • Arranging and delivering the service — Art. 6(1)(b), performance of the contract. For the special categories described in 3.3, Art. 9(2)(a), explicit consent.
  • Tax, accounting and other legal obligations — Art. 6(1)(c), compliance with a legal obligation.
  • Site security, and establishing or defending a legal claim — Art. 6(1)(f), our legitimate interest in protecting the infrastructure and in asserting or defending a right.

We do no direct marketing, we have no newsletter and we add you to no list. If that ever changes we will ask you first, with separate consent you can withdraw.

05

If you give us nothing

No law and no contract obliges you to give us your data. But without an address to reply to we cannot reply, and without the necessary details we cannot arrange a stay.

06

Who sees your data

Nobody buys it and nobody sells it. The only ones who see it are:

  • our hosting provider and our email provider, appointed as processors under Article 28 GDPR;
  • the suppliers in our network — villas, hotels, restaurants, guides, drivers, skippers — who receive only what the single booking requires, and who act as separate controllers or as processors depending on the arrangement;
  • our professional advisers — accountant, and a lawyer where needed — for their own obligations;
  • public authorities, only where the law requires it.

The current list of appointed processors is available on request at info@theconciergetuscany.com.

07

Transfers outside the EEA

Some of our technology suppliers are established, or keep servers, outside the European Union. Where that happens, the transfer takes place only towards countries covered by an adequacy decision of the European Commission (Art. 45 GDPR) or on the basis of the Standard Contractual Clauses (Art. 46(2)(c)), with the assessments those require.

If we arrange something for you that involves a supplier outside the EU, the transfer is necessary to perform the contract concluded in your interest (Art. 49(1)(b) and (c)).

08

How long we keep it

  • Emails that lead to no engagement: 24 months from the last exchange, then deleted.
  • Correspondence and documents relating to an engagement: for the length of the relationship and 10 years after it ends — the term set by Article 2220 of the Italian Civil Code for accounting records, and the ordinary limitation period.
  • Special categories of data (3.3): deleted within 6 months of the end of the stay they relate to, unless needed to defend a legal claim.
  • Server logs: as per the hosting provider's policy, ordinarily no longer than 12 months.

09

Security

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): the site is served over an encrypted connection, mailbox access is protected by two-factor authentication, and access to data is limited to those who need it. No measure is perfect: if a breach occurred that posed a risk to your rights, we would tell you and notify the Italian supervisory authority within the time limits set by law (Arts. 33 and 34 GDPR).

10

Children

The service is addressed to adults. We do not knowingly collect data about children, other than what parents tell us in order to arrange a family trip, and only for that.

11

Automated decisions and profiling

There are none. No decision concerning you is taken by an automated system, and we build no profiles.

12

Your rights

At any time you may:

  • find out whether we process data concerning you and obtain a copy of it (Art. 15);
  • have it corrected (Art. 16) or erased (Art. 17);
  • ask us to restrict how we use it (Art. 18);
  • receive it in a machine-readable format and have it transferred elsewhere (Art. 20);
  • object to processing based on our legitimate interest (Art. 21);
  • withdraw your consent where the processing rests on it, without affecting what was done before (Art. 7(3)).

To exercise them, write to info@theconciergetuscany.com: a person answers, within one month (Art. 12(3)), extendable by two further months in complex cases, of which we would inform you. We charge nothing, save for manifestly unfounded or excessive requests.

If you believe the processing infringes the Regulation, you may lodge a complaint with the Italian supervisory authority — Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, tel. +39 06 696771, protocollo@gpdp.it, certified email protocollo@pec.gpdp.it, garanteprivacy.it — or bring proceedings before the courts.

14

Changes

If what we do changes, this page changes, and the date at the top says so. Material changes will be notified by email to anyone we are in a relationship with.

15

Language

This notice is published in Italian and in English. In the event of any discrepancy, the Italian version prevails.