Grand Hotel Vesuvio

Mobile Application Privacy Policy

Last updated: 6 August 2026

Leggi questa pagina in italiano

This policy describes how personal data is processed through the Grand Hotel Vesuvio mobile application (the “App”), available for iOS and Android devices, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).

1. Data Controller

Hotel Vesuvio Sorrento
Via Nastro Verde 7
80067 Sorrento (NA) — Italy
VAT no. 01246491219
Phone: +39 081 878 26 45
Email: info@vesuviosorrento.com

To exercise your rights or for any request concerning the processing of personal data, please write to the email address above.

2. Personal data processed

2.1 Data provided by the user

Account registration. First name, last name, email address, password (stored in encrypted form), telephone number, mobile number, nationality, date of birth.

Pre-check-in and stay registration. First name, last name, place and date of birth, residence, country, sex, type of identity document, document number, place of issue, expiry date, photographic image of the identity document.

Services requested during the stay. Booking requests, fault reports, requests for additional supplies, restaurant reservations, room service orders, stay voucher association and consultation of current charges.

2.2 Data collected automatically

Technical and usage data. Device model and operating system, App version, device identifier for push notifications (Firebase Cloud Messaging token), IP address, diagnostic data and crash reports.

Usage statistics. App sections opened, services and areas viewed, application errors. This data is collected in aggregated and anonymous form: it is not linked to the user's identity or account.

2.3 Children

The App is not intended for minors and the Controller does not knowingly collect personal data of minors. Account registration and use of the services are reserved for adults.

Should the Controller become aware of having processed a minor's data in the absence of the legal requirements, it will delete such data without undue delay. Holders of parental responsibility may report such circumstances by writing to the address indicated in section 1.

3. Purposes and legal bases of processing

PurposeLegal basis
Creation and management of the user accountPerformance of a contract (Art. 6.1.b GDPR)
Provision of the hotel services requested through the App (pre-check-in, reservations, assistance requests, consultation of charges)Performance of a contract (Art. 6.1.b GDPR)
Compliance with the obligation to report guest particulars to the Public Security Authority (Art. 109 of the Italian Consolidated Law on Public Security) and with statistical reporting obligationsLegal obligation (Art. 6.1.c GDPR)
Sending service push notifications relating to the stayPerformance of a contract (Art. 6.1.b GDPR)
Sending promotional push notifications and commercial communicationsConsent (Art. 6.1.a GDPR), withdrawable at any time
Aggregated statistical analysis of App usage and error diagnostics, in order to ensure its operation and improve its functionalityLegitimate interest of the Controller (Art. 6.1.f GDPR)
Legal defence and establishment of liabilityLegitimate interest of the Controller (Art. 6.1.f GDPR)

Providing the data required for registration and for the delivery of services is optional, but refusal makes it impossible to use the relevant App features. Providing the data required to comply with public security obligations is mandatory by law.

4. Methods of processing

Data is processed using IT and electronic tools, applying technical and organisational measures appropriate to ensure its security and to prevent unauthorised access, loss or disclosure.

Communications between the App and the Controller's systems take place over an encrypted channel (HTTPS). Access credentials are stored on the user's device in an area protected by the operating system.

No automated decision-making or individual profiling is carried out.

5. Recipients of the data

Personal data may be disclosed to the following parties:

Data is not disseminated nor transferred to third parties for their own independent marketing purposes.

6. Place of processing and transfers outside the EU

Personal data is processed and stored on servers located within the European Union.

Certain technical services provided by Google and Amazon Web Services may involve the transfer of technical data to third countries, in particular the United States of America. Such transfers take place on the basis of the safeguards provided for in Chapter V of the GDPR, such as the Standard Contractual Clauses approved by the European Commission and, where applicable, the provider's certification under the EU-U.S. Data Privacy Framework.

7. Retention period

Category of dataRetention
Account dataFor the entire duration of the relationship, until the user requests deletion
Check-in data and identity document imagesTransferred to the Controller's management system and retained there for the period required by public security obligations and by applicable tax and civil law
Data relating to requests and services during the stayFor the duration of the stay and thereafter for the time necessary to handle any disputes
Aggregated statistical and diagnostic dataIn accordance with the retention periods of the Firebase services, in any case in a form not attributable to the user
Consents givenFor the entire period of their validity and thereafter as evidence of compliance

Once these periods have elapsed, data is deleted or irreversibly anonymised.

8. Rights of the data subject

Users have the right, at any time, to:

Requests should be addressed to info@vesuviosorrento.com. The Controller will respond without undue delay and in any case within one month of receipt.

9. Account deletion

Deletion of the account and associated data may be requested by completing the form available at the following address:

https://docs.google.com/forms/d/e/1FAIpQLScRs4jXD_Wos7Fagq-zY9_lueVHe4bYIP3K7HjHl0RiEjiw1w/viewform

The request results in the deletion of the account and the data associated with it, with the exception of data that the Controller is required to retain in order to comply with legal obligations, which remains stored only for the prescribed period and is not further used.

10. Permissions requested by the App

PermissionPurpose
CameraCapturing the photograph of the identity document for pre-check-in
Photo librarySelecting an image of the identity document already stored on the device
NotificationsReceiving communications relating to the stay and, subject to consent, promotional communications
Network accessCommunication with the Controller's systems

Each permission may be revoked at any time from the device settings; revocation may limit the functionality of the App.

11. Push notifications

The App sends two types of notification:

Consent to promotional notifications may be withdrawn at any time from the App settings or by disabling notifications in the device settings.

12. Changes to this policy

The Controller reserves the right to amend this policy in order to reflect subsequent regulatory changes or changes to the services offered. The updated version is published at this address together with the date of the latest update. In the event of substantial changes, users will be informed through the App.