Privacy policy
Notice provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003. Last updated: 24 September 2026.
This is a courtesy translation. In the event of any discrepancy, the Italian version prevails.
In short. We use your data only to manage your booking and stay, to comply with legal obligations (guest registration, tourist tax, accounting) and to reply to your requests. We do not sell data to third parties and we do not carry out profiling. The site does not use advertising tracking cookies.
1. Data controller
The data controller is Fabio's Guesthouse, with address at Viale Francesco Redi, Firenze (FI).
For any question about the processing of your data you can write to [email address to be added].
This notice applies to all accommodation managed by the data controller, in particular Fabio's Guesthouse (Viale Francesco Redi, Firenze) and Casa Pasquini (Via Pasquini 2, Firenze), and to bookings made through the Smoobu system from any of the data controller's websites.
2. What data we process
Guest data (booking and stay)
- Identification and contact data: first name, surname, email, telephone, address, number of guests and dates of stay.
- Identity document data of all guests (type, number, date and place of birth, nationality), collected before arrival because it is required by law, since check-in is self-service.
- Payment data: card payment is handled by the payment service provider. We do not see or store the full card number.
- Communications: the messages you send us by email, telephone or WhatsApp before, during and after your stay.
Website visitor data
- Technical browsing data: IP address, browser and device type, pages visited, recorded in the hosting service's logs for security reasons.
- Cookies: described in the Cookie policy. Statistical cookies, if enabled, are used only with your consent.
3. Why we process it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Managing the enquiry, booking, payment and stay; sending you confirmations and arrival information. | Performance of a contract (Art. 6(1)(b) GDPR). |
| Reporting guests' personal details to the police authorities (Questura) through the Alloggiati Web portal (Art. 109 of the Italian Public Security Act, TULPS). | Legal obligation (Art. 6(1)(c) GDPR). |
| Calculating and paying the tourist tax to the City of Florence; transmitting the statistical data required by the Tuscany Region and ISTAT. | Legal obligation (Art. 6(1)(c) GDPR). |
| Tax and accounting obligations; retention of receipts. | Legal obligation (Art. 6(1)(c) GDPR). |
| Replying to questions and requests for information. | Pre-contractual measures at your request (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)). |
| Website security and prevention of abuse. | Legitimate interest (Art. 6(1)(f) GDPR). |
| Anonymous statistics on the use of the site. | Consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time from the cookie preferences. |
Providing the data needed for booking and guest registration is mandatory: without it we cannot confirm your stay.
4. Who can access the data
The data is processed by the data controller and by suppliers acting as data processors, appointed pursuant to Art. 28 GDPR:
- Smoobu GmbH (Berlin, Germany), the booking management system and booking engine used on this site. Smoobu privacy policy.
- Stripe Payments Europe Ltd. (Dublin, Ireland), card payment service. Stripe privacy policy.
- The website hosting provider, , for storing the pages and technical logs.
- The data controller's accountant, for tax obligations.
- Any booking portals (for example Booking.com or Airbnb), if you booked through them: in that case they are independent data controllers.
Data is disclosed to public authorities when the law requires it: the police authorities (Questura, via Alloggiati Web), the City of Florence, the Tuscany Region and the Italian Revenue Agency (Agenzia delle Entrate).
5. Transfers outside the European Union
The suppliers listed store data in the European Union. If a supplier transfers data outside the EU (for example to the United States), the transfer takes place on the basis of European Commission adequacy decisions or standard contractual clauses, as stated in their respective privacy policies.
6. How long we keep it
- Booking data and communications: for the duration of the relationship and for the following 10 years, in line with civil and tax law obligations.
- Identity document data sent to the police authorities (Questura): the transmission receipt is kept for 5 years, as required by public security legislation.
- Website technical logs: no more than 12 months, unless needed for security reasons.
- Cookie consent: 12 months, after which you are asked again.
7. Your rights
At any time you can request access to your data, rectification, erasure, restriction of processing and portability, and object to processing based on legitimate interest (Arts. 15-22 GDPR). You can withdraw the consent you have given, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise your rights write to [email address to be added]. We reply within 30 days.
If you believe the processing infringes the law, you can lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma.
8. Security
The site is served over an encrypted connection (HTTPS). Booking data is stored in Smoobu's systems, protected by authentication and encryption. Access to the data is limited to the data controller and authorised persons.
9. Minors
Bookings can only be made by adults aged 18 or over. The data of minors staying at the property is collected solely to meet guest registration obligations.
10. Changes
This notice may be updated. The version in force is always the one published on this page, with the date of the last update shown at the top.