Privacy Policy
pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”)
Dear Guest,
this Privacy Policy describes how Albergo Italia srl, with registered office at Viale Italia, 7 – 33054 Lignano Sabbiadoro (UD), Italy, processes the personal data of users who visit this website, send information requests, make bookings or use the services offered by the hotel.
This Privacy Policy applies exclusively to this website and does not apply to any other websites that users may access through links available on our pages.
1. Data Controller
The Data Controller is:
Albergo Italia srl
Viale Italia, 7
33054 Lignano Sabbiadoro (UD) – Italy
Email: info@hotelitaliapalace.it
For any request relating to the processing of personal data, the Data Controller may be contacted at the email address indicated above.
2. Categories of personal data processed
The Company may process the following categories of personal data.
a) Data voluntarily provided by the user
This includes data provided by the user through contact forms, information requests, quotation requests, online bookings, newsletter subscriptions or other communications sent to the hotel.
By way of example, such data may include:
- first name and surname;
- email address;
- telephone number;
- residence or postal address, where necessary;
- information relating to the request submitted;
- data relating to the booking or stay;
- any preferences communicated by the guest;
- data necessary for the management of hotel services and administrative, accounting or tax-related activities.
b) Data relating to bookings and stays
In the event of availability requests, bookings or stays at the hotel, the data necessary for managing the contractual relationship and the requested services may be processed, including through online booking systems and hotel management software.
The website uses, among others, systems connected to Vertical Booking for the management of online bookings and Ericsoft Suite 5° for internal hotel management.
c) Browsing data
The IT systems and software procedures used to operate the website may acquire, during their normal operation, certain technical data whose transmission is implicit in the use of Internet communication protocols.
This may include, for example:
- IP address;
- type of browser used;
- operating system;
- type of device;
- pages visited;
- date and time of access;
- time spent on pages;
- technical data relating to browsing and the proper functioning of the website.
Such data is used to allow the proper functioning of the website, obtain aggregated statistical information, improve online services and ensure the security of the systems.
d) Cookies and tracking technologies
The website may use technical cookies and, where consent is required, analytical cookies, profiling cookies and other tracking technologies.
In particular, the website may use services such as:
- Google Analytics, for statistical analysis of website usage;
- Meta Pixel / Facebook Pixel, for measurement, remarketing and advertising campaigns;
- Google Maps, to display maps and geographical information;
- YouTube, to display videos embedded on the website;
- other technical or third-party services required for the operation of online services.
For further information on the cookies used, their purposes, retention periods and consent management methods, users are invited to consult the website’s Cookie Policy.
3. Purposes and legal bases of processing
Personal data may be processed for the following purposes.
a) Responding to information or contact requests
Data sent through contact forms, email, telephone or other channels is processed in order to respond to the user’s requests.
Legal basis: performance of pre-contractual measures requested by the data subject.
b) Managing availability requests, bookings and stays
Data may be processed to manage availability requests, bookings, stays, hotel services, operational communications with guests, check-in, check-out and any requested additional services.
Legal basis: performance of a contract or pre-contractual measures.
c) Compliance with legal obligations
Data may be processed in order to comply with civil, tax, accounting, administrative, public security or other applicable legal obligations.
Legal basis: compliance with a legal obligation.
d) Managing payments, invoicing and administrative activities
Data may be processed for the management of payments, invoices, receipts, accounting records, relations with banks, payment service providers, consultants and competent authorities.
Legal basis: performance of a contract and compliance with legal obligations.
e) Sending newsletters and promotional communications
With the user’s specific consent, data may be used to send newsletters, offers, commercial communications and promotional messages relating to the hotel’s services.
For newsletter management, the Company may use external platforms, including MailUp.
Legal basis: consent of the data subject.
The user may withdraw consent at any time by using the unsubscribe link included in the communications received or by contacting the Data Controller at the email address indicated in this Privacy Policy.
f) Statistical analysis and website improvement
Browsing data and data collected through analytical tools may be used to analyse website usage, improve content, optimise online services and understand the effectiveness of communication campaigns.
Legal basis: user consent, where required by applicable law, or the legitimate interest of the Data Controller in permitted cases.
g) Marketing, remarketing and advertising campaign measurement
With the user’s consent, data collected through tracking technologies such as Meta Pixel / Facebook Pixel and similar services may be used to measure the effectiveness of advertising campaigns, display personalised promotional content and carry out remarketing activities.
Legal basis: consent of the data subject.
h) Display of external content
The website may integrate third-party services, such as Google Maps and videos embedded through YouTube. These services may process the user’s personal data, such as IP address, browsing data or information relating to the device used.
Legal basis: user consent, where required, or technical necessity to provide the service requested by the user.
i) Website security and prevention of misuse
Technical browsing data may be processed to ensure website security, prevent unauthorised access, fraud, misuse, harmful activities or malfunctions.
Legal basis: legitimate interest of the Data Controller.
4. Processing methods
Personal data is processed using manual, IT and telematic tools, according to methods strictly related to the purposes indicated above.
The Company adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, disclosure, alteration or misuse.
5. Provision of data
The provision of personal data is optional. However, failure to provide the necessary data may make it impossible to:
- respond to an information request;
- manage an availability request;
- make or confirm a booking;
- provide the requested services;
- comply with contractual or legal obligations.
The provision of data for marketing, newsletter, profiling or remarketing purposes is always optional and subject to the consent of the data subject.
6. Persons and entities that may access the data
Personal data may be processed by internal staff authorised and properly instructed by the Data Controller.
Data may also be communicated, within the limits necessary for the purposes indicated above, to external parties such as, by way of example:
- IT and hosting service providers;
- web agencies and technical consultants;
- online booking system providers, including Vertical Booking;
- hotel management software providers, including Ericsoft Suite 5°;
- newsletter and promotional communication service providers, including MailUp;
- analytics, marketing and tracking service providers, including Google and Meta;
- administrative, tax, accounting and legal consultants;
- banks and payment service providers;
- public authorities, bodies or administrations, where required by law.
Such parties may act, depending on the case, as independent data controllers or as data processors appointed pursuant to Article 28 of the GDPR.
Personal data will not be disseminated.
7. Transfer of data outside the European Union
Personal data is mainly processed within the European Union.
However, the use of certain technical, statistical, advertising, newsletter, video, map, online booking or other third-party services may involve the transfer of personal data to countries outside the European Union or access to such data by entities located in third countries.
In such cases, the transfer will take place in compliance with the safeguards provided for by the GDPR, such as adequacy decisions, standard contractual clauses, supplementary measures or other legal instruments provided for by applicable legislation.
8. Data retention periods
Personal data will be retained for the time necessary to achieve the purposes for which it was collected and, subsequently, for any period required by law.
In particular:
- data relating to information requests will be retained for the time necessary to handle the request and for any subsequent organisational or legal needs;
- data relating to bookings, stays and contractual relationships will be retained for the time necessary to provide the service and for the additional periods required by tax, accounting, administrative or legal obligations;
- data processed for newsletter or marketing purposes will be retained until consent is withdrawn or a deletion request is made by the data subject;
- data collected through cookies and tracking technologies will be retained according to the periods indicated in the Cookie Policy and in the settings of the individual services used;
- data necessary to protect the rights of the Data Controller may be retained for the duration of the applicable limitation periods.
9. Cookies and consent management
The website uses a consent management system that allows users to accept, reject or customise the use of non-technical cookies and tracking technologies.
Users may change their cookie preferences at any time through the consent management panel available on the website.
Technical cookies are necessary for the proper functioning of the website and do not require the user’s consent. Non-anonymised analytical cookies, profiling cookies, remarketing technologies and similar tools are used only with prior consent, where required by applicable law.
For further details, please refer to the website’s Cookie Policy.
10. Rights of the data subject
The data subject may exercise, in the cases provided for by the GDPR, the following rights:
- right of access to personal data;
- right to rectification of inaccurate data;
- right to erasure;
- right to restriction of processing;
- right to object to processing;
- right to data portability;
- right to withdraw consent, where processing is based on consent.
The withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.
To exercise their rights, the data subject may contact the Data Controller at the following email address:
11. Complaint to the Supervisory Authority
The data subject has the right to lodge a complaint with the competent Supervisory Authority if they believe that the processing of their personal data violates applicable data protection legislation.
For Italy, the competent Supervisory Authority is:
Garante per la protezione dei dati personali
Piazza Venezia, 11
00187 Rome – Italy
12. Changes to this Privacy Policy
This Privacy Policy may be updated over time, including as a result of legal, technical or organisational changes or the introduction of new digital services and tools.
Users are therefore invited to consult this page periodically.
Last updated: 10 May 2026



Follow us
OUR SOCIAL
Follow us on social media to keep up to date on the latest news, discounts and events.