Privacy Policy
Last updated: August 2026. This document has been drawn up pursuant to EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. Draft to be legally validated before publication.
1. Data Controller
The Controller of your personal data is B&B Peonia Sun Light (VAT no. [P.IVA da inserire]), with registered office at Località Peonia Rosa, Sant'Antioco (SU), Sardegna, Italia.
For any request concerning your data you may write to: peoniasunlight@gmail.com
2. Types of data collected
Through this website we process the following categories of data:
- Data provided voluntarily through the website forms (booking request or contact message): first name, surname, email, telephone, town and country of origin, dates of the stay, number of guests and any information you decide to share with us in your message.
- Browsing data: automatically collected by the IT systems (e.g. IP addresses, browser type, pages visited, date and time), necessary for the operation and security of the website.
- Cookies and similar technologies: as described in the Cookie Policy.
- Conversations with the virtual assistant (chatbot): any content you type into the artificial-intelligence-based assistant, processed in order to provide you with answers.
- Contacts via WhatsApp: if you write to us via WhatsApp, we process your number and messages in order to respond to your requests.
3. Purposes and legal bases
- Managing booking and contact requests and providing you with the requested services (availability check, confirmation of the stay) — legal basis: performance of pre-contractual and contractual measures at your request (Art. 6.1.b GDPR).
- Providing and securing the website, preventing abuse and fraudulent use — legitimate interest of the Controller (Art. 6.1.f GDPR).
- Complying with legal obligations (accounting, tax) — Art. 6.1.c GDPR.
- Statistical and marketing cookies and the sending of any promotional communications — on the basis of your consent (Art. 6.1.a GDPR), freely revocable at any time.
4. Methods of processing
Data are processed using IT and electronic tools, with security measures adequate to ensure their confidentiality, integrity and availability and to prevent unauthorised access. Processing is carried out by the Controller and by specifically instructed authorised persons/processors.
5. Recipients and external processors
Data may be processed, on our behalf and in the capacity of Data Processors (Art. 28 GDPR) or independent controllers, by the following parties:
- Hosting provider: Hetzner Online GmbH (Germania/Finlandia, UE), for the delivery and technical storage of the website data.
- Email provider for receiving and sending emails.
- Statistical and advertising service providers (e.g. Google, Meta Platforms Ireland Ltd.), only subject to your consent to the relevant cookies.
- Artificial intelligence providers for the virtual assistant (by way of example: OpenAI, Google, Anthropic, OpenRouter, DeepSeek), which process the messages sent to the chat.
- WhatsApp messaging service (Meta) and its technical integration provider, if you contact us through that channel.
The updated list of data processors is available on request by writing to the Controller.
6. Transfer of data outside the EU
Some providers (e.g. AI, statistical or advertising services) may process data outside the European Economic Area. In such cases the transfer takes place in compliance with Art. 44 et seq. GDPR, with appropriate safeguards such as the Standard Contractual Clauses approved by the European Commission or adequacy decisions.
7. Retention period
- Contact/request data: for the time necessary to handle your request and, in the event of a relationship, for its duration and the subsequent statutory terms (generally up to 10 years for accounting/tax obligations).
- Browsing data and logs: for the technically necessary time, save for security needs or legal obligations.
- Cookie consent register: 6 months.
- Cookies: according to the durations indicated in the Cookie Policy.
8. Rights of the data subject
You may exercise at any time the rights provided for by Art. 15-22 GDPR: access, rectification, erasure, restriction, portability, objection and withdrawal of consent (without prejudice to the lawfulness of processing based on the consent given before its withdrawal). To exercise them, write to peoniasunlight@gmail.com.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it).
9. Cookies
This website uses technical cookies and, subject to consent, statistical and marketing cookies. For the details and to manage your preferences, please refer to the Cookie Policy.
10. Artificial intelligence (transparency — EU Regulation 2024/1689 “AI Act”)
The website may make available a conversational assistant (chatbot) based on artificial intelligence. We inform you, clearly and transparently, that you are interacting with an AI system and not with a natural person. Automatically generated content may contain inaccuracies and does not entail automated decisions producing legal effects concerning you. The possibility of contacting a human operator directly is always guaranteed.
11. Changes to this privacy notice
The Controller reserves the right to update this privacy notice. Changes will be published on this page with an indication of the update date.