skip to Main Content

Welcome House

di Rossi Maria

Website Privacy and Cookie Policy

Information notice pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR) — www.domuslivia.com

  1. Introduction

This page describes how this website is managed with regard to the processing of the personal data of the users who consult it. This Policy is provided, pursuant to Article 13 of Regulation (EU) 2016/679, to those who interact with the web services accessible at the address www.domuslivia.com.

This Policy is provided in respect of the above website only and not in respect of any other websites that the user may consult via links. The processing of the personal information concerning you is carried out in accordance with the principles of fairness, lawfulness, transparency and protection of confidentiality.

This Policy covers the processing operations carried out by the Data Controller identified below.

  1. Data Controller and place of processing

Data Controller Welcome House di Rossi Maria
Registered office Via Nazionale 230, 00184 Rome (RM), Italy
Tax code / VAT no. ?? / 06295621004
Contact details Tel. +39 06 48913080 — E-mail welcomehouserome@gmail.com — Certified e-mail (PEC) welcomehouse@pec.it
DPO Not appointed: the obligations set out in Article 37 GDPR do not apply.
Privacy contact To exercise your rights: welcomehouserome@gmail.com

The processing operations connected with the web services of this website take place at the Data Controller’s premises and are carried out solely by authorised personnel, or by persons entrusted with occasional maintenance operations. The hosting servers are located at Aruba S.p.A. (privacy notice: www.aruba.it/gdpr-regolamento-europeo-privacy.aspx).

  1. Categories of data processed

3.1 Browsing data

In the course of their normal operation, the IT systems and software procedures responsible for the functioning of this website acquire certain personal data whose transmission is implicit in the use of Internet communication protocols: IP addresses, browser type and operating system, URI addresses of the resources requested, time of the request, method used in submitting the request, size of the file obtained in response and status code. Such data are used for the sole purpose of obtaining anonymous statistical information on the use of the website and of monitoring its correct functioning and security.

3.2 Data voluntarily provided by the user

The optional, explicit and voluntary sending of messages through the contact and booking request form, or to the e-mail addresses indicated on the website, entails the acquisition of the data necessary to reply: first name and surname, e-mail address, telephone number, dates and features of the stay requested, as well as any other personal data included in the message.

3.3 Special categories of data

The website does not require the provision of special categories of data within the meaning of Article 9 GDPR. Users are asked not to enter information relating to health or to other special categories in the forms: any requirements of this kind will be dealt with during the stay in accordance with the dedicated privacy notice for guests.

3.4 Data relating to minors

The website is not intended for an audience of minors. The data of any minors included in a booking request are provided by the person exercising parental responsibility, who assumes responsibility for them.

  1. Cookies

Technical and session cookies, which are necessary for the functioning and security of the website, do not require consent pursuant to Article 122 of the Italian Privacy Code (Legislative Decree No. 196/2003, as amended). For non-technical cookies (statistical and marketing cookies), consent is collected through the banner displayed on the website and may be withdrawn at any time from the preference management panel or through the browser settings.

4.1 Website cookies

Cookie Provider Category Purpose Duration
pll_language First party (Polylang) Technical Stores the language selected by the user for the correct display of the website 1 year
cookieyes-consent First party (CookieYes) Technical Stores the consent preferences expressed through the banner 1 year

4.2 Booking engine cookies (third party)

Cookie Provider Category Purpose Duration
JSESSIONID RoomCloud (third party) Technical Maintains the user’s session during the booking process Session
CookieScriptConsent CookieScript (third party) Technical Stores the consent preferences on the booking engine domain 1 day *

* Duration set by the service provider.

  1. Purposes of the processing and legal basis

Purpose Legal basis Retention
Responding to requests for information sent through the contact form or by e-mail Art. 6(1)(b) — steps taken at the data subject’s request prior to entering into a contract Time necessary to handle the request
Handling of the direct booking request Art. 6(1)(b) — performance of the contract As set out in the privacy notice for guests
Operation, maintenance and security of the website (browsing data and technical cookies) Art. 6(1)(f) — legitimate interests Limited period, save where required for the investigation of criminal offences
Statistical measurement and marketing (non-technical cookies) — not active as at the date of this assessment Art. 6(1)(a) — consent Lifetime of the cookie; consent requested again after approx. 6 months
Compliance with legal obligations and defence of rights in legal proceedings Art. 6(1)(c) and (f) Statutory time limits and limitation periods
  1. Mandatory or optional provision of data and consequences of refusal

Save as specified in relation to browsing data, the user is free to provide the personal data set out in the request forms. However, the provision of the data marked as mandatory is necessary in order to act upon the request: refusal, even in part, makes it impossible to respond to the request or to handle the booking.

  1. Duration of the processing and retention

Personal data are retained for as long as is necessary to achieve the purposes for which they were collected or for another legitimate related purpose. Access is restricted to those persons who need to use them. Data that are no longer necessary, or in respect of which there is no longer a legal basis for retention, are irreversibly anonymised or securely destroyed.

  1. Processing methods, disclosure and dissemination

Processing is carried out by electronic means and, where necessary, on paper, with technical and organisational measures that are appropriate pursuant to Article 32 GDPR and suitable to prevent the loss of data, unlawful or improper use and unauthorised access.

The data are not disseminated. They may be disclosed to:

  • persons authorised to carry out the processing within the Data Controller’s organisation (Article 29 GDPR);
  • the website hosting provider and the e-mail service provider;
  • the channel manager provider, where the request results in a booking;
  • parties who may access the data by virtue of provisions of law or regulation;
  • consultants and third-party service providers, to the extent necessary for the performance of their assignment, appointed as external data processors by means of a letter of appointment imposing confidentiality and security obligations.
  1. Data transfers

As a rule, data are managed and stored on servers located within the European Union. Certain ancillary services, such as the web fonts and the location map provided by Google, entail the transmission of the IP address to providers established outside the EU. Where a transfer to third countries becomes necessary, the Data Controller ensures that it takes place in accordance with Articles 45 and 46 GDPR, on the basis of an adequacy decision or by means of standard contractual clauses adopted by the European Commission.

  1. Rights of the data subject and how to exercise them

As a data subject you have, pursuant to Articles 15 to 22 GDPR, the rights listed below, which you may exercise by submitting a request to the Data Controller.

Art. Right Content
15 Access To obtain confirmation as to whether processing of your data is taking place and to access them, together with the information on the processing.
16 Rectification To obtain the correction of inaccurate data and the completion of incomplete data.
17 Erasure To obtain the erasure of the data concerning you, in the cases provided for (right to be forgotten).
18 Restriction To obtain the restriction of the processing in the cases provided for by law.
20 Portability To receive the data provided in a structured and commonly used format and to transmit them to another controller.
21 Objection To object at any time, on grounds relating to your particular situation, to processing based on legitimate interests.
22 Automated decision-making Not to be subject to a decision based solely on automated processing. The Data Controller does not carry out automated decision-making or profiling.

Where the processing is based on consent, you may withdraw it at any time without affecting the lawfulness of the processing carried out prior to the withdrawal. Requests should be addressed to welcomehouserome@gmail.com; the Data Controller will reply without undue delay and in any event within one month.

  1. Updates

The Data Controller reserves the right to update this Policy; the version in force is always published on this page.

Version 1.0 — 15 July 2026

Fill the form

    Back To Top