Updated: 8 July 2026
1. Introduction
Il Bruco Bed and Breakfast (“we”, “us”, “our”) respects your privacy and is committed to protecting your personal data.
This Privacy Notice explains how we collect, use, store and protect your personal data when you:
- Visit our website
- Contact us
- Subscribe to our newsletter
- Make a booking directly or via third-party platforms
We act as Data Controller in accordance with Regulation (EU) 2016/679 (“GDPR”).
2. Personal Data We Collect
2.1 Data provided directly by you
We may collect and process:
- Identity data (name, surname)
- Contact data (email, telephone number, address)
- Booking data (dates, guests, preferences)
- Payment-related data (processed via secure providers)
- Any information you provide in communications
Sources include:
- Contact forms or emails
- Newsletter subscriptions (via Mailchimp)
- Booking systems and platforms
2.2 Data collected from third-party booking platforms
When you book via external platforms, we may receive personal data from:
These platforms may share information necessary to manage reservations, including identity, contact details, booking details and payment status.
2.3 Automatically collected data
When you browse the website, we may collect:
- IP address
- Device and browser information
- Usage data (pages visited, time spent)
3. Purposes and Legal Bases of Processing
Purpose – Legal Basis (GDPR)
- Managing bookings and guest services – Art. 6(1)(b)
- Payment processing and invoicing – Art. 6(1)(c)
- Customer communication – Art. 6(1)(b) / (f)
- Marketing communications (Mailchimp) – Art. 6(1)(f)
- Website analytics – Art. 6(1)(f)
- Legal compliance – Art. 6(1)(c)
3.1 Legitimate Interest Assessment
Where we rely on legitimate interests, we ensure they do not override your fundamental rights.
Our legitimate interests include:
- Promoting our services
- Maintaining customer relationships
- Improving services and communication
3.2 Right to Object to Marketing
You may object at any time to direct marketing processing.
To do so:
- Use the unsubscribe link in emails
- Email us at
This email address is being protected from spambots. You need JavaScript enabled to view it.
4. Third-Party Services and Data Sharing
We may share data with trusted providers, including:
We may also share data with payment providers, accountants and authorities where required.
We do not sell your personal data.
5. International Data Transfers
Some providers may process data outside the EEA. Safeguards include:
- EU Standard Contractual Clauses (SCCs)
- EU‑US Data Privacy Framework (where applicable)
6. Data Retention
- Booking records: up to 10 years
- Newsletter data: until unsubscribe
- Contact requests: 12–24 months
- Analytics: 6–24 months
7. Data Subject Rights
You have the right to:
- Access your data
- Correct inaccurate data
- Request deletion
- Restrict processing
- Data portability
- Object to processing
You may lodge a complaint with the Italian Data Protection Authority (Garante).
8. Data Security
We implement technical and organisational measures to protect your data.
9. Cookies
We use cookies to ensure functionality and improve user experience. We use CookieYes as our Consent Management Platform (CMP) to obtain and manage your consent for cookies used on our website. CookieYes acts as a data processor under GDPR and drops a strictly necessary cookie (cookieyes-consent) on your device to remember your privacy choices across sessions. To maintain a legally required "Proof of Consent" log, CookieYes processes limited, non-identifiable information, including your masked IP address, country location, browser type, and consent status. This data is retained securely for 12 months. For more information, please review the CookieYes Privacy Policy.
10. Contact Details
Data Controller:
Il Bruco B&B
Via Cortina, 12
03046 San Donato Val di Comino
Frosinone, Lazio, Italy
t: +39 3476416497
e:
11. Updates
We may update this Privacy Notice from time to time. The latest version will always be published on this page.
``




