Privacy Policy
Last updated: 05.07.2026
Introduction
This Privacy Policy ("Policy") describes how the personal data of users visiting the Fiemme Fassa Appartments website is collected, used and processed.
The Site is a showcase for the non-hotel accommodation facilities (holiday apartments) hosted and managed by Thomas Deflorian, functioning as an informational display; actual bookings are handled through the third-party booking engine Krossbooking, as further specified in point 6.
This Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and applicable national legislation (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018, the "Privacy Code"), to anyone interacting with the Site.
1. Data Controller
The Data Controller is:
Thomas Deflorian-Thomas Deflorian Apartments
Registered address: Via Caltrezza 8
Email: apartments@thomasdeflorian.it
For any request concerning the processing of personal data, users may contact the Controller at the details above.
2. Types of data collected
Depending on how users interact with the Site, the following categories of data may be collected:
2.1 Browsing data During normal operation, the IT systems and software procedures used to run the Site acquire, in their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols (e.g. IP addresses, browser type, operating system, device domain name, access times, pages visited). This data is used solely to derive anonymous statistical information on the use of the Site and to check its correct functioning, and is deleted immediately after processing or kept only for as long as strictly necessary for IT security purposes.
2.2 Data voluntarily provided by the user Where the Site includes contact forms, WhatsApp/email enquiries, or data collection forms (e.g. first name, last name, email address, phone number, message content), such data is processed solely to respond to the requests received.
2.3 Data collected via cookies and similar technologies The Site uses technical cookies and, subject to consent, statistical analysis cookies. For full details, please refer to the Cookie Policy, which forms an integral part of this Policy.
2.4 Data processed by the booking engine (Krossbooking) The Site does not directly handle bookings or payments. By clicking the "View apartment" or "Book" buttons, users are redirected to the external booking engine Krossbooking (domain thomasdeflorian.kross.travel), operated by a third party independent of the Controller. From that point on, data processing (e.g. personal details, payment data, booking-related data) is governed by Krossbooking's own privacy policy, which users are invited to review directly on that platform before proceeding. The Controller of this Site has no access to or control over such data and bears no responsibility for it.
3. Purposes and legal basis of processing
The personal data collected is processed for the following purposes:
Purpose Legal basis Enabling normal browsing and use of the Site Legitimate interest of the Controller (Art. 6.1.f GDPR) Responding to information/contact requests Pre-contractual measures at the data subject's request (Art. 6.1.b GDPR) Anonymous/aggregate statistics on Site usage User consent, where required via the cookie banner (Art. 6.1.a GDPR) Compliance with legal obligations (e.g. requests from authorities) Legal obligation (Art. 6.1.c GDPR) IT security and fraud prevention Legitimate interest of the Controller (Art. 6.1.f GDPR)
Providing data to respond to contact requests is optional, but failure to provide it may make it impossible to process the request.
4. How data is processed
Processing is carried out using IT and/or telematic tools, with organisational and logical methods strictly related to the purposes stated, and in any case in a way that ensures the security, integrity and confidentiality of the data, in compliance with the organisational, physical and logical measures required by applicable law.
5. Place of processing and data retention
The Site is hosted on infrastructure provided by Hostinger (Hostinger International Ltd. or a company within the Hostinger group), which acts as data processor/technical provider for hosting services. Servers may be located outside the European Union; in such cases, the provider guarantees adequate safeguards in accordance with Chapter V of the GDPR (e.g. standard contractual clauses). For further details, please refer to Hostinger's privacy policy, available at hostinger.com/privacy.
Browsing data is kept for as long as technically necessary and in any case no longer than 12 months, unless needed to establish possible IT crimes against the Site. Data voluntarily provided through contact requests is kept for as long as necessary to handle the request and in any case no longer than 24 months, unless otherwise required by law.
6. Data disclosure and recipients
Personal data may be disclosed, for the purposes described above, to the following parties/categories of parties, acting as data processors or independent controllers:
Hostinger – provider of the hosting service and the Site's related technical functions (including the cookie banner, where present);
Krossbooking – external booking engine to which the user is redirected to complete a booking (independent controller, see point 2.4);
Google LLC – limited to loading the Site's typefaces via Google Fonts (fonts.googleapis.com / fonts.gstatic.com), a service that involves transmitting the user's IP address to Google's servers when the page loads;
CARTO / OpenStreetMap Foundation – limited to loading the interactive maps present on the Site (where present), resulting in the transmission of the IP address to the servers providing the map "tiles";
unpkg / open-source software library providers (CDN) – for loading the technical libraries needed to run the interactive maps.
Data is never sold or transferred to third parties for the marketing purposes of parties other than the Controller.
7. Transfer of data outside the EU
Some of the third parties listed in point 6 (e.g. Google, CDN providers) may transfer data to countries outside the European Economic Area. Where this occurs, such transfers rely on safeguard mechanisms recognised by the GDPR (e.g. European Commission adequacy decisions or Standard Contractual Clauses). Users are invited to consult the respective privacy policies for further details.
8. Rights of the data subject
At any time, users may exercise, against the Controller, the rights provided for by Articles 15-22 of the GDPR, including in particular:
Right of access: to obtain confirmation of the existence of processing and details thereof;
Right to rectification: to obtain correction of inaccurate data or completion of incomplete data;
Right to erasure ("right to be forgotten"): to obtain deletion of one's data, in the cases provided for by law;
Right to restriction: to obtain restriction of processing in certain circumstances;
Right to data portability: to receive one's data in a structured, readable format, where technically possible;
Right to object: to object to processing based on the Controller's legitimate interest;
Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Requests may be sent to the email address indicated in point 1.
Users also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it), if they believe their data has been processed in violation of applicable law.
9. Minors
The Site is not directed at persons under 16 years of age, and the Controller does not knowingly collect data relating to minors. Should it come to light that data has been collected from a minor without the consent of a parent or legal guardian, such data will be promptly deleted.
10. Data security
The Controller adopts technical and organisational security measures adequate to prevent loss, unlawful or improper use, and unauthorised access to data, in line with technical developments, the nature of the data, and the specific risks of processing.
11. Changes to this Policy
The Controller reserves the right to modify, update, supplement or remove parts of this Policy at its own discretion and at any time, including as a result of regulatory changes. Users are invited to check this page periodically. The last update date is shown at the top of the document.
12. Contact
For any questions regarding this Policy or the processing of personal data, please write to: apartments@thomasdeflorian.it
Reservations Angelica: + 39 3202935070
Managment Thomas: +39 348 405 1191
apartments@thomasdeflorian.it
© 2026. All rights reserved. IT02360140228
Find your apartment
Check available dates and book directly through our official website.
