Version 2026-09-18-draft-1
Privacy notice
Controller and scope
The intended controller is Fala Noleggi SRL, whose address and details appear in the Legal notice. The public privacy contact is to be designated. This draft describes the current code: processing records, legal bases, retention periods and vendor contracts must be approved before launch. It is not a certification of compliance.
Data and purposes
Support: subject, messages, author, dates, status and booking reference are stored in the portal and accessible to the requester and owner. Messages are not automatically sent to AI or the experience supplier. Retention and rights-handling procedures must be defined before launch. Accounts: name, email, protected credentials and sessions for access and security. Bookings: contact person, phone, participant ages and order details for suitability, capacity and delivery. Professionals: business details, documents, verification and commissions. Accounting: billing details when supplied and transaction records. Intended bases are service performance and precontractual steps, applicable legal obligations and documented, balanced legitimate security interests. Blanket consent does not replace the appropriate legal basis.
Location, requirements and AI
Location is requested only when you choose the dedicated feature and the browser permits it; you can remove it and search by destination. Preferences guide suggestions. Avoid health records, diagnoses and sensitive details in free text: use functional accessibility filters. Before enabling external AI, define transmitted data, notices and safeguards, including cases where text reveals sensitive data. The code supports OpenAI, currently unconfigured, and requests that responses are not stored using the store option. This does not guarantee that the vendor retains no data.
Recipients and external services
Suppliers receive necessary contacts for paid, confirmed or completed bookings; partners receive limited statements. The code supports Cloudflare Workers/D1/R2 (hosting, database and files), Resend (email), Stripe (payments and beneficiary verification), Google/Apple/Microsoft/Facebook (user-selected sign-in) and OpenAI (AI). Support in code does not mean all services are active. Processing locations, roles, subprocessors and safeguards for transfers outside the EEA must be checked for the actual contracted services and disclosed before launch.
Retention and security
Login sessions are configured for seven days and may renew with use. Accounts, orders, documents and logs have different requirements: a complete automatic deletion schedule is not implemented yet. Before launch, documented periods, applicable fiscal duties, request handling and backup retention must be established. Uploaded documents are access-controlled; clearing the browser does not delete server-held data.
Rights and requests
You may request access, correction and, where applicable, erasure, restriction, portability or objection; any consent may be withdrawn without retroactive effect. Requests may require proportionate identity verification. Do not send passwords. The dedicated contact and response procedure must be activated before launch; this draft provides the postal address in the Legal notice. You retain the right to contact the Italian data protection authority or another competent authority.