Lake Como Tourism — Boat Charters & Experiences

Italiano

Return to Lake Como Tourism

Privacy Policy

Last updated: 9 September 2026

This policy explains how Lake Como Tourism S.r.l. collects and uses personal data through this website, and what rights you have over that data. It is written under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

1. Who is responsible for your data

The data controller is Lake Como Tourism S.r.l., with registered office at Piazza del Popolo 1, 22100 Como (CO), Italy, VAT number 04213480132.

You can reach us at info@lakecomotourismsrl.com, or by telephone and WhatsApp at +39 320 246 9283. For any question about this policy or about your data, write to info@lakecomotourismsrl.com with "Privacy" in the subject line.

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR.

2. What data we collect

We collect three kinds of data, and no more than we need for each.

3. Why we use it, and on what legal basis

4. Is providing your data mandatory

No field on this site is compulsory in the abstract: you decide whether to write to us. But if you do not give us at least a name, a way of reaching you and an idea of what you are looking for, we cannot answer or prepare a quotation. The data needed for invoicing, once a booking is confirmed, is required by law.

5. Who else sees your data

We do not sell personal data, and we do not share it for anyone else's marketing. Your data may be handled by:

6. Transfers outside the European Union

Booking data is stored inside the European Union: the database behind our booking platform sits on Amazon Web Services in Stockholm, Sweden.

Some of our providers process data in the United States, so the processing may involve a transfer there:

These providers are certified under the EU-US Data Privacy Framework, which is the mechanism their transfers rely on first; where it does not apply, the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision 2021/914) take over, as set out in the data processing agreement we hold with each of them. Where any other provider processes data outside the European Economic Area, we require the same safeguards: an adequacy decision, Standard Contractual Clauses, or another instrument permitted by Chapter V GDPR. You may ask us for a copy of the safeguards in place.

7. How long we keep it

8. Your rights

Under Articles 15 to 22 GDPR you have the right to ask us for access to your personal data, for its correction or erasure, for the restriction of its processing, and to object to processing based on our legitimate interest. Where processing is based on consent or on a contract and is carried out by automated means, you also have the right to receive your data in a portable format, and to withdraw consent at any time without affecting what was done before.

To exercise any of these rights, write to info@lakecomotourismsrl.com. We answer within one month, which may be extended by two further months for complex requests, as Article 12(3) GDPR allows.

If you believe your data has been handled unlawfully, you may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — garante@gpdp.it — www.garanteprivacy.it), or with the authority of the country where you live.

9. Cookies

On arrival this site sets no cookies at all, and loads neither analytics nor advertising. A bar in the corner lets you refuse; reading on allows them. Whatever you choose, you can change it at the foot of every page. Every cookie the site can set is listed, with its purpose and duration, in our Cookie Policy.

10. Children

This site is not addressed to children, and we do not knowingly collect data about them. Children are of course welcome aboard: where a booking concerns a family, the data of any minor is given to us by the adult who makes the booking, and we use it only to prepare the experience safely.

11. Security

The site is served over an encrypted connection (HTTPS). Our hosting provider holds ISO 27001 certification and a SOC 2 Type II attestation, and encrypts data at rest with AES-256 and in transit with TLS 1.2 or higher. Access to the mailboxes and to the booking system is limited to the people in the company who need it, and protected by individual credentials. No system is ever perfectly secure, but we take measures appropriate to the risk, as Article 32 GDPR requires.

12. Changes to this policy

We may update this policy when the site or the way we work changes. The date at the top always shows the current version, and a substantial change will be signalled on this page.

Lake Como Tourism

BOAT CHARTERS & EXPERIENCES

0%