Privacy Policy
Last updated: October 2026
This Privacy Policy explains how personal data are collected and processed through the website www.cookingclasssantulivieri.it, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Italian data protection legislation.
1. Data Controller
The Data Controller is:
AZ. AGR. S.ULIVIERI DI GANOZZI ALESSANDRO
VAT No. IT01545940528
Via Podere Sant’Ulivieri, 144
53034 Colle di Val d’Elsa (SI), Italy
Email: info@santulivieri.it
2. Personal Data We Process
Depending on how you use the website, we may process the following categories of personal data:
-
name and surname;
-
email address;
-
telephone number;
-
booking date and time;
-
number of participants;
-
information relating to adults and children included in the booking;
-
dates requested for cooking classes, accommodation or multi-day experiences;
-
booking status;
-
information voluntarily entered in booking forms, contact forms or messages;
-
information concerning dietary requirements, food allergies or intolerances, where voluntarily provided;
-
technical information relating to access to and use of the website;
-
referring website, referral source or campaign information;
-
information necessary to manage a payment card guarantee;
-
communications exchanged in connection with a booking or enquiry.
3. Booking Management and Provision of Services
Personal data are processed in order to:
-
receive and manage booking requests;
-
confirm, modify or cancel reservations;
-
communicate with customers regarding their booking;
-
organise and provide cooking classes;
-
organise accommodation or multi-day experiences where booked;
-
manage transfers or other ancillary services requested by the customer;
-
respond to customer requests relating to the experience;
-
manage administrative matters connected with the booking.
The legal basis for this processing is the performance of a contract or the taking of steps at the customer’s request prior to entering into a contract, pursuant to Article 6(1)(b) GDPR.
4. Online Booking System – Amelia
The website uses Amelia as its online booking management system.
When a booking is made, information entered by the customer is stored in the website’s WordPress database.
This may include:
-
name and surname;
-
email address;
-
telephone number;
-
selected experience;
-
selected date and time;
-
number of participants;
-
booking status;
-
additional information voluntarily provided by the customer.
These data are processed for the purpose of managing the reservation and providing the requested service.
5. Contact Forms and Enquiries
The website may also collect personal data through contact forms used for information and availability requests.
If you contact Sant’Ulivieri through the website, by email or through a contact form, the information provided will be processed in order to respond to your request.
Where the request relates to a possible booking or service, the legal basis is Article 6(1)(b) GDPR.
For other general enquiries, processing may be based on the legitimate interest of the Data Controller in responding to communications received, pursuant to Article 6(1)(f) GDPR.
6. Dietary Requirements, Allergies and Intolerances
Customers may voluntarily provide information regarding allergies, food intolerances or other dietary requirements where relevant to a cooking class, meal or multi-day experience.
Such information may constitute special categories of personal data within the meaning of Article 9 GDPR.
These data are processed only where necessary to organise and provide the requested service safely and appropriately.
Customers are requested to provide only information that is relevant and necessary for this purpose.
Such information will not be used for marketing or unrelated purposes.
7. Payment Card Guarantee – Stripe
Certain bookings may require customers to provide a valid payment card as a guarantee.
Payment card information is processed securely through Stripe.
Full payment card details are not stored in the website’s WordPress database.
The website may retain technical identifiers and information necessary to associate the payment method processed by Stripe with the relevant booking and to manage the booking guarantee.
Where the card is requested solely as a booking guarantee, no immediate payment is made unless otherwise expressly stated during the booking process.
The card may be charged only in accordance with the booking, cancellation and no-show conditions communicated to the customer.
Stripe processes personal data in accordance with its own privacy and data-protection terms and may act, depending on the processing activity, as a data processor or independent data controller.
8. Accommodation and Multi-Day Experiences
The website also offers multi-day cooking experiences that may include accommodation, meals, tours and other activities.
Where such services are requested, personal data may be processed to:
-
manage accommodation arrangements;
-
coordinate check-in and check-out;
-
organise included activities;
-
arrange meals;
-
organise transfers or transport where requested;
-
communicate practical information necessary for the stay or experience.
The legal basis is Article 6(1)(b) GDPR.
9. Booking Source and Referral Tracking
The website records information relating to how a customer reached the website or booking page.
This information may include:
-
referring website;
-
referral domain;
-
campaign parameters, including UTM parameters;
-
booking source;
-
referral type;
-
date on which referral information was acquired.
This information may be associated with the relevant booking.
It is used for internal administrative, statistical and commercial purposes, including:
-
identifying the source of a booking;
-
measuring the effectiveness of promotional or referral channels;
-
identifying, where applicable, a commercial partner associated with a booking;
-
determining commissions or commercial attribution relating to a booking.
Where technically possible, booking-source information may be transmitted through the booking flow without the use of persistent cookies.
Where the user has given the relevant cookie consent, the website may also use a first-party attribution cookie to remember the booking source across future visits.
This information is not used for behavioural advertising or cross-site profiling and is not used for automated decision-making producing legal or similarly significant effects on customers.
10. Website Analytics – SlimStat
The website uses SlimStat Analytics to obtain statistical information regarding use of the website.
SlimStat is configured in a privacy-oriented manner.
In particular:
-
IP addresses are masked;
-
browser fingerprinting is disabled;
-
SlimStat does not set its own tracking cookie;
-
statistical data are stored locally in the website’s WordPress database;
-
analytics data are retained for a maximum of 420 days;
-
archived records are not retained after the applicable retention period;
-
geographic information is limited to country-level data.
SlimStat may process information such as:
-
page views;
-
referring websites;
-
browser information;
-
device information;
-
operating system;
-
country of origin;
-
technical navigation information.
These data are used to understand how the website is used, identify technical issues, evaluate traffic sources and improve the website and its services.
11. Hosting – Aruba
The website and its database are hosted through services provided by Aruba S.p.A.
As a consequence, personal and technical data processed through the website may be stored and processed on the hosting infrastructure used to operate the website.
Aruba may process data where necessary for:
-
website hosting;
-
database hosting;
-
security;
-
backups;
-
maintenance;
-
technical operation of the website.
Where required by applicable data-protection law, Aruba and other providers processing personal data on behalf of the Data Controller act as data processors pursuant to Article 28 GDPR.
12. Email Communications
The website uses SMTP-based email services to send communications connected with:
-
booking confirmations;
-
booking modifications;
-
cancellations;
-
customer enquiries;
-
availability requests;
-
booking reminders;
-
other service-related communications.
The main email address used by the Data Controller is:
Email communications may therefore also involve the technical infrastructure of the relevant email service provider.
13. Technical and Security Data
Technical information may be processed where necessary for:
-
ensuring the correct functioning of the website;
-
preventing misuse, fraud or unauthorised access;
-
diagnosing technical problems;
-
maintaining website and booking-system security;
-
protecting the website, database and users.
The legal basis for this processing is the legitimate interest of the Data Controller in maintaining a secure and functional website, pursuant to Article 6(1)(f) GDPR.
14. Legal, Accounting and Administrative Obligations
Personal data may be processed where necessary to comply with applicable:
-
tax obligations;
-
accounting obligations;
-
administrative requirements;
-
legal obligations;
-
requests from competent public authorities.
The legal basis is Article 6(1)(c) GDPR.
15. Provision of Personal Data
The provision of data marked as mandatory during the booking or contact process is necessary to manage the request or reservation.
Failure to provide required information may make it impossible to process the request or provide the requested service.
The provision of optional information is voluntary.
16. Recipients of Personal Data
Personal data may be accessed or processed, where necessary, by:
-
persons authorised by the Data Controller;
-
Aruba S.p.A. and other hosting providers;
-
website developers and technical maintenance providers;
-
booking-management software providers;
-
Stripe and other payment-service providers;
-
email and communication providers;
-
providers involved in accommodation, transport or activities included in a booked experience, where necessary;
-
accountants, tax advisers and other professional advisers;
-
public authorities or other entities where disclosure is required by law.
Access is limited to what is necessary for the performance of the relevant functions.
Where required, service providers acting on behalf of the Data Controller are appointed as data processors pursuant to Article 28 GDPR.
Personal data are not sold to third parties.
17. International Data Transfers
Some service providers used in connection with the website, payment processing, email communications or other technical services may process personal data outside the European Economic Area.
Where personal data are transferred outside the European Economic Area, such transfers are carried out in accordance with Chapter V GDPR.
Where applicable, this may include reliance on:
-
an adequacy decision adopted by the European Commission;
-
Standard Contractual Clauses;
-
other safeguards recognised under applicable data-protection law.
18. Data Retention
Personal data are retained only for as long as necessary for the purposes for which they were collected and for any additional period required by applicable law.
In particular:
-
booking data are retained for the period necessary to manage the booking and subsequent administrative, accounting or legal requirements;
-
information relating to accommodation or multi-day experiences is retained for the period necessary to manage the stay and related obligations;
-
accounting and tax documentation is retained for the periods required by Italian law;
-
contact requests that do not result in a booking are retained only for the period reasonably necessary to respond to the request;
-
SlimStat analytics data are retained for a maximum of 420 days;
-
referral and booking-source information may be retained together with the relevant booking where necessary for administrative, statistical or commercial-attribution purposes;
-
security and technical logs are retained for the period reasonably necessary for security and technical-management purposes.
Data may be retained for a longer period where necessary for the establishment, exercise or defence of legal claims.
19. Cookies and Similar Technologies
The website uses cookies and similar technologies for technical, booking-related, statistical and other purposes.
The website may use first-party storage mechanisms to remember information relating to the origin of a booking or referral source.
SlimStat Analytics is configured not to set its own tracking cookie.
Technical cookies and technologies necessary for the operation of the website or for providing a service requested by the user may be used without prior consent where permitted by applicable law.
Where consent is required for a particular cookie or tracking technology, it will be used only after the user has provided the required consent.
Further information about the cookies and similar technologies used by the website, including their purposes and duration, is available in the website’s Cookie Policy.
20. Embedded Content and Maps
The website may display embedded content from third-party providers, including maps, review widgets or other external content.
Third-party content may involve the processing of technical information or the use of cookies or similar technologies.
Where consent is required for such technologies, the relevant embedded content should only be activated after the user has provided the appropriate consent.
21. Automated Decision-Making and Profiling
The website does not carry out automated decision-making producing legal effects or similarly significant effects on users within the meaning of Article 22 GDPR.
The website does not use personal data to create behavioural profiles for automated decision-making of this kind.
22. Rights of Data Subjects
Under Articles 15 to 22 GDPR, depending on the circumstances, you may have the right to:
-
obtain confirmation as to whether your personal data are being processed;
-
obtain access to your personal data;
-
request rectification of inaccurate or incomplete data;
-
request erasure of personal data;
-
request restriction of processing;
-
object to processing based on legitimate interests;
-
receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
-
withdraw consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Requests regarding personal data may be sent to:
The Data Controller may request information necessary to verify the identity of the person making the request where appropriate.
23. Right to Lodge a Complaint
If you believe that your personal data have been processed in breach of applicable data-protection legislation, you have the right to lodge a complaint with the competent supervisory authority.
In Italy, the competent authority is:
Garante per la Protezione dei Dati Personali
You may also contact the Data Controller directly before submitting a complaint in order to request clarification or resolution of the issue.
24. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time to reflect:
-
changes to the website;
-
changes to booking or payment systems;
-
changes to accommodation or services offered;
-
changes to service providers;
-
changes to data-processing activities;
-
changes to applicable legislation or regulatory guidance.
The latest version will always be published on this page together with the date of the most recent update.