Domus Livia
di Tambascia Manuela
Website Privacy and Cookie Policy
Information notice pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR) — www.domuslivia.com
-
Introduction
This page describes how this website is managed with regard to the processing of the personal data of the users who consult it. This Policy is provided, pursuant to Article 13 of Regulation (EU) 2016/679, to those who interact with the web services accessible at the address www.domuslivia.com.
This Policy is provided in respect of the above website only and not in respect of any other websites that the user may consult via links. The processing of the personal information concerning you is carried out in accordance with the principles of fairness, lawfulness, transparency and protection of confidentiality.
This Policy covers the processing operations carried out by the Data Controller identified below.
-
Data Controller and place of processing
| Data Controller | Domus Livia di Tambascia Manuela |
| Registered office | Via Nazionale 230, 00184 Rome (RM), Italy |
| Tax code / VAT no. | TMBMNL84S68H501T / 08203771004 |
| Contact details | Tel. +39 06 48989686 — E-mail info@domuslivia.com — Certified e-mail (PEC) info@pec.domuslivia.com |
| DPO | Not appointed: the obligations set out in Article 37 GDPR do not apply. |
| Privacy contact | To exercise your rights: info@domuslivia.com |
The processing operations connected with the web services of this website take place at the Data Controller’s premises and are carried out solely by authorised personnel, or by persons entrusted with occasional maintenance operations. The hosting servers are located at Aruba S.p.A. (privacy notice: www.aruba.it/gdpr-regolamento-europeo-privacy.aspx).
-
Categories of data processed
3.1 Browsing data
In the course of their normal operation, the IT systems and software procedures responsible for the functioning of this website acquire certain personal data whose transmission is implicit in the use of Internet communication protocols: IP addresses, browser type and operating system, URI addresses of the resources requested, time of the request, method used in submitting the request, size of the file obtained in response and status code. Such data are used for the sole purpose of obtaining anonymous statistical information on the use of the website and of monitoring its correct functioning and security.
3.2 Data voluntarily provided by the user
The optional, explicit and voluntary sending of messages through the contact and booking request form, or to the e-mail addresses indicated on the website, entails the acquisition of the data necessary to reply: first name and surname, e-mail address, telephone number, dates and features of the stay requested, as well as any other personal data included in the message.
3.3 Special categories of data
The website does not require the provision of special categories of data within the meaning of Article 9 GDPR. Users are asked not to enter information relating to health or to other special categories in the forms: any requirements of this kind will be dealt with during the stay in accordance with the dedicated privacy notice for guests.
3.4 Data relating to minors
The website is not intended for an audience of minors. The data of any minors included in a booking request are provided by the person exercising parental responsibility, who assumes responsibility for them.
-
Cookies
Technical and session cookies, which are necessary for the functioning and security of the website, do not require consent pursuant to Article 122 of the Italian Privacy Code (Legislative Decree No. 196/2003, as amended). For non-technical cookies (statistical and marketing cookies), consent is collected through the banner displayed on the website and may be withdrawn at any time from the preference management panel or through the browser settings.
4.1 Website cookies
| Cookie | Provider | Category | Purpose | Duration |
| pll_language | First party (Polylang) | Technical | Stores the language selected by the user for the correct display of the website | 1 year |
| cookieyes-consent | First party (CookieYes) | Technical | Stores the consent preferences expressed through the banner | 1 year |
4.2 Booking engine cookies (third party)
| Cookie | Provider | Category | Purpose | Duration |
| JSESSIONID | RoomCloud (third party) | Technical | Maintains the user’s session during the booking process | Session |
| CookieScriptConsent | CookieScript (third party) | Technical | Stores the consent preferences on the booking engine domain | 1 day * |
* Duration set by the service provider.
-
Purposes of the processing and legal basis
| Purpose | Legal basis | Retention |
| Responding to requests for information sent through the contact form or by e-mail | Art. 6(1)(b) — steps taken at the data subject’s request prior to entering into a contract | Time necessary to handle the request |
| Handling of the direct booking request | Art. 6(1)(b) — performance of the contract | As set out in the privacy notice for guests |
| Operation, maintenance and security of the website (browsing data and technical cookies) | Art. 6(1)(f) — legitimate interests | Limited period, save where required for the investigation of criminal offences |
| Statistical measurement and marketing (non-technical cookies) — not active as at the date of this assessment | Art. 6(1)(a) — consent | Lifetime of the cookie; consent requested again after approx. 6 months |
| Compliance with legal obligations and defence of rights in legal proceedings | Art. 6(1)(c) and (f) | Statutory time limits and limitation periods |
-
Mandatory or optional provision of data and consequences of refusal
Save as specified in relation to browsing data, the user is free to provide the personal data set out in the request forms. However, the provision of the data marked as mandatory is necessary in order to act upon the request: refusal, even in part, makes it impossible to respond to the request or to handle the booking.
-
Duration of the processing and retention
Personal data are retained for as long as is necessary to achieve the purposes for which they were collected or for another legitimate related purpose. Access is restricted to those persons who need to use them. Data that are no longer necessary, or in respect of which there is no longer a legal basis for retention, are irreversibly anonymised or securely destroyed.
-
Processing methods, disclosure and dissemination
Processing is carried out by electronic means and, where necessary, on paper, with technical and organisational measures that are appropriate pursuant to Article 32 GDPR and suitable to prevent the loss of data, unlawful or improper use and unauthorised access.
The data are not disseminated. They may be disclosed to:
- persons authorised to carry out the processing within the Data Controller’s organisation (Article 29 GDPR);
- the website hosting provider and the e-mail service provider;
- the channel manager provider, where the request results in a booking;
- parties who may access the data by virtue of provisions of law or regulation;
- consultants and third-party service providers, to the extent necessary for the performance of their assignment, appointed as external data processors by means of a letter of appointment imposing confidentiality and security obligations.
-
Data transfers
As a rule, data are managed and stored on servers located within the European Union. Certain ancillary services, such as the web fonts and the location map provided by Google, entail the transmission of the IP address to providers established outside the EU. Where a transfer to third countries becomes necessary, the Data Controller ensures that it takes place in accordance with Articles 45 and 46 GDPR, on the basis of an adequacy decision or by means of standard contractual clauses adopted by the European Commission.
-
Rights of the data subject and how to exercise them
As a data subject you have, pursuant to Articles 15 to 22 GDPR, the rights listed below, which you may exercise by submitting a request to the Data Controller.
| Art. | Right | Content |
| 15 | Access | To obtain confirmation as to whether processing of your data is taking place and to access them, together with the information on the processing. |
| 16 | Rectification | To obtain the correction of inaccurate data and the completion of incomplete data. |
| 17 | Erasure | To obtain the erasure of the data concerning you, in the cases provided for (right to be forgotten). |
| 18 | Restriction | To obtain the restriction of the processing in the cases provided for by law. |
| 20 | Portability | To receive the data provided in a structured and commonly used format and to transmit them to another controller. |
| 21 | Objection | To object at any time, on grounds relating to your particular situation, to processing based on legitimate interests. |
| 22 | Automated decision-making | Not to be subject to a decision based solely on automated processing. The Data Controller does not carry out automated decision-making or profiling. |
Where the processing is based on consent, you may withdraw it at any time without affecting the lawfulness of the processing carried out prior to the withdrawal. Requests should be addressed to info@domuslivia.com; the Data Controller will reply without undue delay and in any event within one month.
-
Updates
The Data Controller reserves the right to update this Policy; the version in force is always published on this page.
Version 1.0 — 15 July 2026
