Italiano
Return to Lake Como Tourism
Privacy Policy
Last updated: 9 September 2026
This policy explains how Lake Como Tourism S.r.l. collects and uses personal data through this website, and what rights you have over that data. It is written under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
1. Who is responsible for your data
The data controller is Lake Como Tourism S.r.l., with registered office at Piazza del Popolo 1, 22100 Como (CO), Italy, VAT number 04213480132.
You can reach us at info@lakecomotourismsrl.com, or by telephone and WhatsApp at +39 320 246 9283. For any question about this policy or about your data, write to info@lakecomotourismsrl.com with "Privacy" in the subject line.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR.
2. What data we collect
We collect three kinds of data, and no more than we need for each.
- Data you give us. When you use the contact form, write to one of our addresses, call or message us on WhatsApp, we receive what you choose to send: your name and surname, e-mail address, telephone number, the tour you are interested in, the number of guests, a date and time, and anything you write in the message. The contact form on this site does not send anything by itself — it opens your own mail programme with the message ready, and it is you who send it to us.
- Booking data. Bookings are not taken on this website. They are handled on lakecomotourismsrl.com by Calerio, our own booking platform, which collects what is needed to confirm a booking — name, contact details, the experience, the date and the number of guests — and stores it in a database hosted in the European Union (Supabase, on Amazon Web Services in Stockholm, Sweden). Payments are processed by Stripe: card details are entered on Stripe's systems and we never see the full card number.
- Technical data. This site is served by Netlify, whose systems record the requests they receive: IP address, date and time, the page requested, the browser and operating system you use, and the page you came from. These logs exist to keep the site running and secure.
- Analytics and advertising data, only with your consent. If you allow cookies, Google Analytics 4 tells us how many people visit and which pages they read, and the Google Ads tag tells us which advertisements led to an enquiry. Both see a randomly generated identifier, the pages you open, your approximate location derived from a shortened IP address, and your device and browser. Until you allow it, neither is loaded at all, and nothing about your visit is measured. The detail — every cookie, its purpose and its duration — is in our Cookie Policy.
3. Why we use it, and on what legal basis
- To answer you and prepare a private charter — the enquiry you send us, used to reply, to propose an itinerary and a price, and to agree the details. Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
- To run the experience you booked — organising the boat, the skipper, the timing and any restaurant or supplier involved. Legal basis: performance of the contract (Article 6(1)(b)).
- To meet our legal obligations — invoicing, accounting, tax and, where applicable, maritime and safety requirements. Legal basis: legal obligation (Article 6(1)(c)).
- To keep the site available and secure — server logs, protection against abuse and attacks. Legal basis: our legitimate interest in the security of our systems (Article 6(1)(f)).
- To understand how the site is used and how our advertising performs — Google Analytics and the Google Ads tag, but only from the moment you allow them. Legal basis: your consent, which you can withdraw at any time from the foot of any page, without affecting what was done before (Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code).
- We do not send commercial messages. There is no newsletter, so your address is never used for mailings. Our advertising is bought from Google and shown on Google's own surfaces; we never write to you unless you wrote to us first.
4. Is providing your data mandatory
No field on this site is compulsory in the abstract: you decide whether to write to us. But if you do not give us at least a name, a way of reaching you and an idea of what you are looking for, we cannot answer or prepare a quotation. The data needed for invoicing, once a booking is confirmed, is required by law.
5. Who else sees your data
We do not sell personal data, and we do not share it for anyone else's marketing. Your data may be handled by:
- Netlify (Netlify, Inc.), which hosts this website and our booking platform, as a data processor under a signed data processing agreement;
- Supabase (Supabase, Inc.), which provides the database behind the booking platform, hosted on Amazon Web Services in Stockholm, Sweden (region eu-north-1), as a data processor under a signed data processing agreement;
- Stripe (Stripe Payments Europe, Limited, Dublin), which processes the payment on our behalf and is, at the same time, an independent controller for fraud prevention and for the anti-money-laundering and identification duties the law places on it, under its own privacy policy;
- our e-mail provider, which delivers and stores the messages you send us;
- the skippers, and — when we book a table on your behalf — the restaurant, along with transfer services and other suppliers where your experience includes them. They receive only what they need to serve you on the day: normally a name, the number of guests and a time;
- Google (Google Ireland Limited), through Analytics and the advertising tag, but only if you allow cookies: Google acts as our processor for Analytics and as an independent controller for its advertising services, under its own policy;
- our accountant and our professional advisers, for invoicing and legal obligations;
- public authorities, where the law requires it.
6. Transfers outside the European Union
Booking data is stored inside the European Union: the database behind our booking platform sits on Amazon Web Services in Stockholm, Sweden.
Some of our providers process data in the United States, so the processing may involve a transfer there:
- Netlify, Inc., which hosts the site and receives the technical data described above;
- Supabase, Inc., which provides the database — the data itself stays in Sweden, but the company may access it for support;
- Google Ireland Limited and Google LLC, because this site loads its typefaces from Google Fonts: when a page loads, your IP address is communicated to Google's servers.
- Stripe, LLC, in the United States: our contract for payments is with Stripe Payments Europe, Limited in Dublin, and it transfers payment data to its American parent to provide the service.
These providers are certified under the EU-US Data Privacy Framework, which is the mechanism their transfers rely on first; where it does not apply, the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision 2021/914) take over, as set out in the data processing agreement we hold with each of them. Where any other provider processes data outside the European Economic Area, we require the same safeguards: an adequacy decision, Standard Contractual Clauses, or another instrument permitted by Chapter V GDPR. You may ask us for a copy of the safeguards in place.
7. How long we keep it
- Enquiries that do not become a booking: up to 24 months from the last contact, so that we can pick up a conversation you left open.
- Bookings and the data around them: for the duration of the relationship and then 10 years, the period Italian law requires for accounting records (Article 2220 of the Civil Code).
- Invoicing and tax data: 10 years.
- Server logs: the period set by Netlify, ordinarily not more than 12 months.
- Analytics data, if you allow it: 14 months, the longest Google Analytics 4 keeps event-level data.
- Advertising data, if you allow it: the periods set out in the Cookie Policy, at most 13 months.
8. Your rights
Under Articles 15 to 22 GDPR you have the right to ask us for access to your personal data, for its correction or erasure, for the restriction of its processing, and to object to processing based on our legitimate interest. Where processing is based on consent or on a contract and is carried out by automated means, you also have the right to receive your data in a portable format, and to withdraw consent at any time without affecting what was done before.
To exercise any of these rights, write to info@lakecomotourismsrl.com. We answer within one month, which may be extended by two further months for complex requests, as Article 12(3) GDPR allows.
If you believe your data has been handled unlawfully, you may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — garante@gpdp.it — www.garanteprivacy.it), or with the authority of the country where you live.
9. Cookies
On arrival this site sets no cookies at all, and loads neither analytics nor advertising. A bar in the corner lets you refuse; reading on allows them. Whatever you choose, you can change it at the foot of every page. Every cookie the site can set is listed, with its purpose and duration, in our Cookie Policy.
10. Children
This site is not addressed to children, and we do not knowingly collect data about them. Children are of course welcome aboard: where a booking concerns a family, the data of any minor is given to us by the adult who makes the booking, and we use it only to prepare the experience safely.
11. Security
The site is served over an encrypted connection (HTTPS). Our hosting provider holds ISO 27001 certification and a SOC 2 Type II attestation, and encrypts data at rest with AES-256 and in transit with TLS 1.2 or higher. Access to the mailboxes and to the booking system is limited to the people in the company who need it, and protected by individual credentials. No system is ever perfectly secure, but we take measures appropriate to the risk, as Article 32 GDPR requires.
12. Changes to this policy
We may update this policy when the site or the way we work changes. The date at the top always shows the current version, and a substantial change will be signalled on this page.