Website: www.suitesdelborgo.com
Property: Suites del Borgo
Data Controller: Anglo Language Mediterranean Academy Società Benefit S.r.l.
Last updated: March 10, 2026
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”),
and Legislative Decree No. 196/2003 as amended by Legislative Decree No. 101/2018, Anglo Language Mediterranean Academy
Società Benefit S.r.l. (the “Data Controller”), in its capacity as Data Controller, provides the following information
regarding the processing of personal data of users visiting www.suitesdelborgo.com and guests staying at Suites del Borgo.
| Company name | Anglo Language Mediterranean Academy Società Benefit S.r.l. |
|---|---|
| Registered office | Via Ghana, 4 – 07026 Olbia (SS), Italy |
| Tax Code / VAT No. | 02953150907 |
| sales@suitesdelborgo.com | |
| Certified email (PEC) | alma.benefit@pec.it |
| Website | www.suitesdelborgo.com |
For any request concerning this Policy or to exercise your rights under Articles 15–22 GDPR, please contact
sales@suitesdelborgo.com or
alma.benefit@pec.it.
During their normal operation, the computer systems and software procedures used to run this website acquire certain
personal data whose transmission is implicit in the use of Internet communication protocols. This category includes,
for example, IP addresses, domain names of the computers used by visitors, request time, HTTP method, and parameters
relating to the user’s operating system and IT environment. These data are used solely to obtain anonymous statistical
information on website usage and to check that the website functions properly, and are deleted immediately after processing.
The optional, explicit and voluntary sending of emails to the addresses indicated on this website, or the completion
of contact forms, entails the acquisition of the sender’s email address and any other personal data included in the message,
for the purpose of responding to requests.
For the management of bookings and guest stays, through the Slope S.r.l. management system, we collect the following categories of data:
We may process health-related data, particularly information concerning allergies or food intolerances, exclusively when
voluntarily provided by the guest in order to ensure their safety while using the property’s restaurant, bar, and breakfast services.
Such data are processed pursuant to Article 9(2)(a) GDPR (explicit consent of the data subject) and, where applicable,
Article 9(2)(h) GDPR. These data are handled only by authorised staff and deleted at the end of the guest’s stay,
unless otherwise requested by the guest.
The property is equipped with a video surveillance system in common areas (entrance, reception, corridors, swimming pool,
and outdoor areas) for the purpose of protecting people and safeguarding company assets. Processing is carried out in
accordance with the guidelines issued by the Italian Data Protection Authority on video surveillance. Appropriate notices
pursuant to Article 13 GDPR are displayed in the monitored areas.
This website and the services offered are not intended for children under the age of 16. In the case of family bookings
involving minors, processing takes place exclusively with the consent of a parent or legal guardian, pursuant to Article 8 GDPR
and applicable Italian law.
| Purpose | Legal Basis | GDPR Article |
|---|---|---|
| Technical management of the website, IT security, and detection of malfunctions | Legitimate interest of the Data Controller | Art. 6(1)(f) |
| Replying to contact requests and information requests | Performance of pre-contractual measures at the request of the data subject | Art. 6(1)(b) |
| Management of bookings and guest stays (through Slope) | Performance of a contract with the data subject | Art. 6(1)(b) |
| Access to property services (swimming pool, bar, restaurant) | Performance of a contract with the data subject | Art. 6(1)(b) |
| Communication of guest data to the police authority (Alloggiati Web) | Legal obligation | Art. 6(1)(c) |
| Management of tourist tax and fiscal/accounting obligations | Legal obligation | Art. 6(1)(c) |
| Video surveillance for the protection of people and property | Legitimate interest of the Data Controller | Art. 6(1)(f) |
| Processing of health-related data (allergies/intolerances) | Explicit consent of the data subject | Art. 9(2)(a) |
| Marketing, newsletters, and promotional communications | Freely given, specific, and revocable consent | Art. 6(1)(a) |
| Aggregated website usage statistics (Google Analytics) | User consent via cookie banner | Art. 6(1)(a) |
The Data Controller does not carry out automated decision-making processes or profiling activities within the meaning of Article 22 GDPR.
Consent given for marketing purposes may be withdrawn at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
Personal data are processed using automated and/or manual means for the time strictly necessary to achieve the purposes for which they were collected.
The Data Controller adopts appropriate technical and organisational measures pursuant to Article 32 GDPR to prevent data loss, unlawful or unauthorised use,
and unauthorised access.
Processing is carried out by authorised personnel and, where applicable, by data processors appointed pursuant to Article 28 GDPR.
| Category of Data | Retention Period |
|---|---|
| Browsing data | No longer than 7 days, unless required for the investigation of cybercrime. |
| Contact data (requests via email/form) | 12 months from the response to the last communication. |
| Booking and stay data | 3 years from the date of check-out, unless litigation is pending. |
| Fiscal and contractual data | 10 years, pursuant to applicable civil and tax law. |
| Public security data (Alloggiati Web) | According to the time limits established by applicable law and police authority instructions (normally 5 years). |
| Health-related data (allergies/intolerances) | Deleted at the end of the stay, unless the guest expressly consents to retention for future stays. |
| Video surveillance recordings | No longer than 48 hours from recording, unless required for judicial protection or by law enforcement authorities. |
| Marketing data (newsletter) | Until consent is withdrawn, and in any case no longer than 24 months from the user’s last interaction. |
Personal data may be processed by employees and collaborators of the Data Controller who have been duly authorised to do so.
Personal data may be disclosed to the following data processors, with whom the Data Controller has entered into appropriate agreements pursuant to Article 28 GDPR:
Data may be disclosed to public authorities in fulfilment of legal obligations, including:
The use of Google Analytics (provider: Google LLC, United States) may involve the transfer of personal data to the United States.
Such transfer takes place on the basis of the adequacy decision adopted under the EU-US Data Privacy Framework.
Except as indicated above, personal data will not be transferred to non-EU countries lacking an adequacy decision by the European Commission.
Pursuant to Articles 15–22 GDPR, data subjects may exercise the following rights:
| Right | Description | GDPR Article |
|---|---|---|
| Access | Obtain confirmation as to whether personal data are being processed and receive a copy of such data | Art. 15 |
| Rectification | Request correction of inaccurate or incomplete data | Art. 16 |
| Erasure | Request deletion of personal data where applicable | Art. 17 |
| Restriction | Request restriction of processing in certain cases | Art. 18 |
| Portability | Receive personal data in a structured format, where applicable | Art. 20 |
| Objection | Object to processing based on legitimate interest | Art. 21 |
| Withdraw consent | Withdraw consent at any time | Art. 7(3) |
| Lodge a complaint | File a complaint with the competent data protection authority | Art. 77 |
To exercise these rights, data subjects may contact the Data Controller at:
The Data Controller will respond within 30 days of receipt of the request, extendable by a further 60 days in cases of particular complexity.
The Data Controller may request proof of identity before processing the request.
The Data Controller adopts appropriate technical and organisational measures to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR, including:
In the event of a personal data breach involving a risk to the rights and freedoms of natural persons, the Data Controller will notify the competent authority within 72 hours where required by Article 33 GDPR,
and will communicate the breach to affected individuals where the risk is high, pursuant to Article 34 GDPR.
Cookies are small text files that websites send to the user’s browser, where they are stored and then transmitted back to the same websites during subsequent visits.
Cookies allow the website to remember the user’s actions and preferences, such as login details, language, or other display settings.
In accordance with applicable cookie guidelines, this website uses the following categories of cookies:
These cookies are necessary for browsing and for the proper functioning of the website, including the management of the online booking process through the Slope booking engine.
Without these cookies, some website functions may not be available.
This website uses Google Analytics (provider: Google LLC) to collect aggregated information on website usage. Google Analytics is configured with IP anonymisation.
As these are third-party analytics cookies, prior user consent is required through the cookie banner.
Users may grant or refuse consent at any time through their browser settings or through the cookie management panel available on the website.
Please note: scrolling the page or continuing navigation does not constitute valid consent to analytics cookies.
Consent must be explicit, free, and specific through interaction with the cookie banner.
This website does not currently use proprietary profiling cookies. Should such cookies be introduced in the future,
this Policy will be updated and prior user consent will be required.
The website uses third-party services that may install their own cookies:
| Cookie Name | Provider | Type | Duration | Purpose |
|---|---|---|---|---|
| _ga | Google Analytics | Analytics (third party)* | 13 months | Distinguishes users for aggregated statistics. |
| _ga_* | Google Analytics | Analytics (third party)* | 13 months | Anonymised counting of page views. |
| slope_session | Slope (Suites del Borgo) | Technical (first party) | Session | Necessary for cart and booking process functionality. |
| cookie_consent | suitesdelborgo.com | Technical (first party) | 6 months | Stores cookie consent preferences. |
| CookieConsent | Cookiebot / Usercentrics | Technical (third party) | 12 months | Manages and stores the user’s consent status. |
* Google Analytics cookies are installed only upon prior user consent.
Upon first access to the website, users are shown an information banner (managed through Cookiebot) allowing them to:
Consent may be withdrawn or updated at any time through the cookie management panel accessible from the website footer.
The Data Controller stores evidence of the consents collected through Cookiebot in compliance with the accountability principle under Article 5(2) GDPR.
Users may manage cookie preferences directly through their browser settings. Please note that disabling technical cookies may affect the correct operation of the website and booking process.
The Data Controller reserves the right to update, amend, or supplement this Policy at any time, particularly following changes in applicable laws or the introduction of new services.
Updated versions will be published on this page together with the relevant revision date.
Where substantial changes affect data subjects’ rights, the Data Controller will provide appropriate notice on the website or, where possible, by email with reasonable advance notice before such changes take effect.
For any information, request, or complaint relating to this Privacy & Cookie Policy, you may contact the Data Controller at:
Data subjects also have the right to lodge a complaint with the competent data protection authority.