INTEGRATED PRIVACY, COOKIE, AND DATA GOVERNANCE POLICY
Last Revised: June 2026
1. Fundamental Principles and Corporate Commitment
At Hotel Belair, identified by the National Identification Code (CIN) IT063080A1IKZVFQ69, the protection of personal data is integrated into the very fabric of our luxury hospitality. We recognize that our guests entrust us not only with their physical comfort but also with their most sensitive personal information. This policy serves as a formal declaration of our commitment to the principles of lawfulness, fairness, and transparency. In accordance with Article 5 of the GDPR, we ensure that all data processing is limited to what is necessary for the specified purposes and that every technical and organizational measure is taken to prevent unauthorized access or data breaches. This document provides a global view of our data lifecycle, covering every digital interaction on belair.it and every physical touchpoint within our Sorrento cliffside establishment.
2. Legal Identification of the Data Controller
The Data Controller responsible for your information is Hotel Belair S.r.l., a legal entity incorporated under Italian law, with its primary operational headquarters at Via del Capo 29, 80067 Sorrento (NA), Italy. The Hotel operates under the unique National Identification Code IT063080A1IKZVFQ69, which ensures our compliance with national tourism and security regulations. As the Controller, we define the “why” and “how” of your data processing. To ensure the highest level of oversight, we have established a dedicated Data Protection Office. For any formal inquiries regarding this policy or the management of your personal information, you may contact our Privacy Liaison via registered electronic mail (PEC) or via standard email at info@belair.it. We maintain a rigorous internal registry of processing activities to ensure that every byte of data we handle is accounted for and legally justified.
3. Comprehensive Legal Bases for Processing
The processing of personal data at Hotel Belair is never arbitrary; it is strictly anchored in the legal grounds established by Article 6 of the GDPR. First and foremost, we process data based on Contractual Necessity. When you book a room or a suite overlooking the Bay of Naples, we must process your identity and financial data to fulfill our promise of accommodation. Secondly, a significant portion of our processing is mandated by Legal Obligations. As a registered hospitality provider (CIN IT063080A1IKZVFQ69), we are legally required by the Italian “Testo Unico delle Leggi di Pubblica Sicurezza” to communicate guest details to the State Police via the “Alloggiati Web” portal.
Furthermore, we rely on Legitimate Interest for activities such as ensuring the security of our premises through CCTV, preventing fraud, and conducting internal analyses to improve our 5-star services. In these cases, we perform a “balancing test” to ensure our interests do not override your fundamental rights and freedoms. Finally, for activities such as sending promotional newsletters or using non-essential tracking cookies, we rely exclusively on your Explicit Consent. You possess the absolute right to withdraw this consent at any time, through a simple “unsubscribe” link or by contacting our privacy office, without affecting the legality of the processing performed prior to the withdrawal.
4. Detailed Taxonomy of Collected Data
The data we collect is categorized to ensure granular control and protection. Navigation Data is collected automatically by the servers hosting belair.it; this includes IP addresses, timestamps, and browser strings, which are necessary for the technical delivery of the website. Personal Identification Data includes your name, date of birth, nationality, and passport details, which are essential for the “Alloggiati” registration. Contact Data includes your email and phone number, used for booking confirmations and concierge communication.
We also manage Financial and Transactional Data, including credit card tokens and billing addresses, processed through PCI-DSS compliant gateways to ensure your financial safety. In the context of luxury hospitality, we may process Special Categories of Data (sensitive data) as defined in Article 9 of the GDPR. This occurs only when you voluntarily provide information regarding health-related needs, such as mobility requirements or severe food allergies, to ensure your safety during your stay. We also collect Multimedia Data, including images captured by our security cameras in public areas (clearly marked with signage) and, with your specific permission, photographs or reviews you may share on our social media channels or feedback platforms.
5. Advanced Cookie Management and Tracking Technologies
The domain belair.it employs a sophisticated cookie architecture to balance website performance with user privacy, fully compliant with the “Guidelines on cookies and other tracking tools” issued by the Italian Data Protection Authority. Technical Cookies are strictly necessary for the operation of the site, enabling functions like the booking engine and language selection; these do not require consent as they are essential for the service you requested.
Analytical Cookies are used to collect aggregated, non-identifiable data about how visitors navigate our site. We use these insights to optimize our content, for instance, ensuring that information about our Calypso Restaurant or Oblivion Roof Bar is easily accessible. If these cookies are managed by third parties (like Google Analytics), we implement IP masking to further protect your anonymity. Profiling and Marketing Cookies are the most intrusive category and are only activated if you click “Accept All” on our consent banner. These allow us to understand your preferences and show you tailored offers for Hotel Belair across the web. You can manage, block, or delete cookies at any time through your browser settings or our dedicated cookie preference center. We maintain a “Consent Log” to prove that your choices are respected in real-time.
6. Data Retention and Deletion Protocols
Hotel Belair adheres to the “Data Minimization” and “Storage Limitation” principles. Your data is not kept for a moment longer than necessary. Booking and Fiscal Records are retained for a period of ten years, as required by Italian civil and tax codes (Art. 2220 of the Civil Code). Police Registration Data is deleted from our local systems shortly after transmission to the authorities, in accordance with public security regulations.
For Marketing Data, we maintain a retention period of 24 months from the date of consent or your last active interaction with our brand. After this period, the data is either permanently purged from our databases or irreversibly anonymized for statistical research. CCTV Footage is typically overwritten within 24 to 72 hours, unless a security incident requires a longer retention for legal evidence. Our deletion protocols are automated where possible, ensuring that “expired” data does not remain a liability for the guest or the Hotel.
7. Global Data Transfers and Third-Party Disclosure
In the course of providing premium hospitality, Hotel Belair may share your data with a curated list of Authorized Data Processors. These include our IT maintenance providers, the software company managing our Property Management System (PMS), and specialized marketing agencies. Each provider is bound by a “Data Processing Agreement” (DPA) under Article 28 of the GDPR, which dictates exactly how they must handle your information.
Your data is primarily stored on secure servers located within the European Union. Should any service provider require the transfer of data to a “Third Country” (such as the United States), we ensure that such transfers are protected by Standard Contractual Clauses (SCCs) or occur within countries deemed “adequate” by the European Commission. We never sell your personal data to brokers or third-party advertisers. Disclosure to public authorities occurs only when mandated by law or to protect the vital interests of the guest or another individual.
8. The “Bill of Rights” for Our Guests
As a data subject under the GDPR, you hold a suite of powerful rights which Hotel Belair is committed to honoring. You have the Right to Access your data, receiving a clear report on what we hold. You have the Right to Rectification, allowing you to update your contact details or passport information. The Right to Erasure (the “Right to be Forgotten”) allows you to request the deletion of your data when the legal basis for holding it has expired.
You also possess the Right to Restrict Processing, the Right to Data Portability (receiving your data in a structured, machine-readable format), and the Right to Object to any processing based on legitimate interest. To exercise these rights, simply email info@belair.it. We provide these services free of charge, unless requests are manifestly unfounded or excessive. If you feel your rights have been infringed, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
9. Technical Security and Organizational Safeguards
To protect the integrity of the data associated with CIN IT063080A1IKZVFQ69, we have implemented “Privacy by Design and by Default.” Our website uses HTTPS encryption (TLS 1.3) to secure all communications. Internally, we utilize multi-factor authentication for staff access to guest databases. Our physical premises are secured, and access to the server room is restricted to senior IT personnel. We conduct regular “Penetration Testing” to identify digital vulnerabilities and maintain a “Data Breach Response Plan” to notify the authorities and affected individuals within 72 hours should a significant risk arise.
10. Final Provisions and Policy Evolution
This Integrated Policy represents the entirety of our data governance framework as of March 2026. As the hospitality industry and digital regulations evolve, so too will this document. We reserve the right to modify these terms to ensure continued compliance with EU standards. Significant changes will be communicated via our website or email. By continuing to use our services and the belair.it platform, you acknowledge the terms of this policy and our commitment to your privacy.
11. Granular Data Processing Operations and Workflow
The lifecycle of data at Hotel Belair is governed by a strict “Data Flow Protocol.” When a user initiates a query on belair.it, the system captures metadata necessary to maintain the session’s integrity. If the user proceeds to a booking, the “Transaction Phase” begins. During this phase, the Data Controller collects not only primary identifiers but also secondary metadata, such as the source of the booking (e.g., direct web, OTA, or corporate travel agent). This information is vital for the Statistical and Revenue Management purpose, allowing the Hotel to optimize its Mediterranean hospitality offerings. Under GDPR Article 6(1)(f), this constitutes a legitimate interest in understanding market trends without compromising individual guest identities through anonymization techniques applied post-checkout.
Upon physical arrival at the Sorrento premises, the “Check-in Phase” triggers the collection of “Alloggiati” data. This process is a non-negotiable legal requirement under Italian Decree (DM 7 gennaio 2013). We utilize secure scanners to digitize identity documents; the resulting digital files are encrypted and transmitted via a secure tunnel to the State Police. Once the “transmission successful” receipt is generated, the digital copies of the documents are purged from our temporary local buffer unless the guest has provided explicit, separate consent for the Hotel to retain a copy for “Fast Check-in” during future visits. This dual-layer consent mechanism ensures that legal compliance does not infringe upon the guest’s right to data minimization.
12. Advanced Cookie Governance and Digital Fingerprinting
Beyond standard HTTP cookies, belair.it may utilize “Local Storage” and “Session Storage” objects to improve the performance of our high-resolution image galleries and interactive maps. These technologies are governed by the same ePrivacy standards as cookies. Our Cookie Management System (CMS) categorizes these trackers into four distinct silos. Essential Trackers manage load balancing and CSRF (Cross-Site Request Forgery) protection, ensuring that your interaction with our booking engine is secure from malicious third-party interference.
Functional Trackers remember your language preference (e.g., Italian, English, or German) and your preferred currency. Performance Trackers utilize heat-mapping tools to identify which sections of our site, such as the “Yacht Excursion” page or the “Wellness & Fitness” gallery, are most engaging to our audience. Finally, Targeting Trackers enable the “Retargeting” function. If you view a specific suite on our site but do not complete the booking, these cookies allow us to show you a reminder of that suite on social media platforms. We strictly adhere to the “Opt-in” principle; no targeting trackers are deployed on your device until you have made an affirmative action on our consent banner.
13. Data Protection Impact Assessments (DPIA)
In compliance with Article 35 of the GDPR, Hotel Belair conducts regular Data Protection Impact Assessments for processing operations that are likely to result in a high risk to the rights and freedoms of natural persons. This specifically applies to our integrated CCTV system and any large-scale profiling of guest preferences. The DPIA process involves a systematic description of the processing, an assessment of the necessity and proportionality, and an evaluation of the risks.
Where risks are identified, for example, the potential for unauthorized access to the video surveillance feed, we implement “Mitigation Controls,” such as end-to-end encryption for the video stream and two-factor authentication for security personnel. The results of these assessments are kept in our internal compliance archive and are available for review by the Italian Data Protection Authority (Garante) upon formal request. This proactive stance ensures that “Privacy by Design” is not just a slogan but a documented technical reality at our Sorrento location.
14. Liability, Indemnification, and Data Breach Protocol
Hotel Belair S.r.l. maintains a comprehensive Cyber Liability Insurance policy to protect the interests of our guests in the unlikely event of a sophisticated cyber-attack. However, the Data Controller shall not be held liable for data breaches resulting from the guest’s own negligence, such as the loss of booking credentials or the use of insecure public Wi-Fi networks outside the Hotel’s controlled infrastructure.
In the event of a “Personal Data Breach” (as defined in Art. 4(12) of the GDPR), we follow a rigid 72-Hour Response Protocol. This includes: (I) Identification and containment of the breach; (II) Assessment of the risk to data subjects; (III) Notification to the Garante per la protezione dei dati personali; and (IV) Direct communication to the affected guests if the breach is likely to result in a high risk to their rights (e.g., identity theft or financial loss). Our notification will include a clear description of the nature of the breach, the name of our Data Protection Liaison, and the measures being taken to mitigate the effects.
15. Social Media Integration and Third-Party API Governance
The website belair.it utilizes Application Programming Interfaces (APIs) from platforms like Instagram, Facebook, and TripAdvisor to display real-time guest reviews and social media feeds. When you interact with these elements, your browser may establish a direct connection with the servers of these third-party providers. This interaction is governed by the privacy policies of those respective companies.
We also use “Social Plugins” (like the ‘Share’ button). To protect your privacy, we implement a “Two-Click Solution” or a technical “Wrapper” that prevents these plugins from sending data to social networks until you actually click them. We advise all guests to manage their privacy settings on social media platforms independently. Hotel Belair is not responsible for the data processing practices of these external entities, though we select partners who demonstrate a baseline commitment to EU data protection standards.
16. Processing of Employee and Candidate Data
While this policy focuses on customers, Hotel Belair also applies rigorous standards to the processing of Professional Data. Individuals submitting their CVs via the “Career” section of our site are informed that their data will be processed solely for recruitment purposes. We do not retain CVs for more than 12 months after the recruitment process has concluded, unless the candidate provides explicit consent for their profile to be kept in our “Talent Pool” for future openings. Employee data is managed under a separate Internal Privacy Manual which covers payroll, social security contributions, and occupational health data in strict accordance with Italian labor laws.
17. Governance of “Special Categories” (Sensitive Data)
The processing of sensitive data (e.g., health data or religious affiliations reflected in dietary needs) requires an even higher threshold of protection under Article 9 of the GDPR. Hotel Belair processes this information only when it is “manifestly made public” by the data subject or when it is necessary to protect the “vital interests” of the guest. For example, if a guest suffers a medical emergency on-site, we may share relevant health information with emergency medical services. In all other scenarios, such as documenting a gluten-free requirement for the Calypso Restaurant, the data is tagged with “High-Level Confidentiality” and is accessible only to the relevant kitchen staff.
18. Accessibility and Language of the Policy
This Privacy Policy is provided in English and Italian to accommodate our international clientele. In the event of any discrepancy between the linguistic versions, the Italian version (as the language of the jurisdiction of the Data Controller) shall prevail. We are committed to making this policy accessible to individuals with disabilities; if you require this document in an alternative format (such as large print or audio), please contact our concierge team.
19. Strategic SEO Metadata for Privacy Transparency
To ensure that guests can easily find our privacy commitments, this document is indexed with relevant metadata including “GDPR Sorrento Hotel,” “Hotel Belair Privacy Policy,” and “CIN IT063080A1IKZVFQ69 Data Protection.” We believe that transparency in data management is a competitive advantage in the luxury travel sector, and we encourage our guests to read this policy in its entirety.
20. Formal Execution and Jurisdiction
This policy is governed by and construed in accordance with the laws of Italy and the European Union. Any disputes arising from the interpretation or application of this policy that cannot be resolved through mediation shall be subject to the exclusive jurisdiction of the Court of Torre Annunziata (Naples).
By engaging with the services of Hotel Belair, either digitally or in person, you confirm that you have been provided with this information and understand the methods by which your personal data is handled to ensure your safety and the excellence of your stay in Sorrento.
21. Annex A: Mandatory Data Processing Agreement (DPA) for Vendors
Under Article 28 of the GDPR, Hotel Belair must ensure that any third party (e.g., booking engines, Wi-Fi providers, or marketing agencies) handling guest data is legally bound by a DPA. The following clauses are integrated into every service contract:
- Scope of Processing: The Processor (the vendor) shall process personal data only on documented instructions from Hotel Belair, including transfers of personal data to a third country.
- Confidentiality: The Processor ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security Measures: The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including pseudonymization and encryption of personal data (Art. 32).
- Sub-processing: The Processor shall not engage another processor without prior specific or general written authorization of Hotel Belair.
- Data Subject Rights: The Processor shall assist the Controller by appropriate technical and organizational measures for the fulfillment of the Controller’s obligation to respond to requests for exercising the data subject’s rights.
- Audit Rights: The Processor shall make available to Hotel Belair all information necessary to demonstrate compliance with the obligations laid down in Article 28 and allow for and contribute to audits, including inspections.
22. Annex B: Standardized Cookie Consent & Management Protocol
To comply with the Garante della Privacy guidelines (June 2021), the website belair.it implements a “Granular Consent” interface. This prevents “Dark Patterns” and ensures user autonomy.
I. The First-Layer Banner (The Pop-up)
Upon the first landing, the user is presented with a clear banner stating:
“Hotel Belair uses cookies to enhance your experience. We use technical cookies for site functionality and, with your consent, analytical and profiling cookies to provide tailored offers. You can ‘Accept All’, ‘Reject All’ (leaving only technical cookies active), or ‘Manage Preferences’. Closing this banner by clicking the ‘X’ will result in default settings where only technical cookies are used.”
II. The Second-Layer (Cookie Settings Menu)
Users can toggle the following categories:
- Necessary (Always Active): Security, Load Balancing, and Booking Engine integrity.
- Preferences (Optional): Language settings, Currency display, “Remember Me” for returning guests.
- Statistics (Optional): Google Analytics 4 (with IP Anonymization), Heat-maps for page optimization.
- Marketing (Optional): Facebook Pixel, Google Ads remarketing, and Instagram API tracking.
23. Annex C: Data Subject Request (DSR) Procedure
To facilitate the “Right to Access” and “Right to Erasure,” Hotel Belair provides a standardized workflow for guests.
- Submission: Requests must be sent to info@belair.it or via the contact form on belair.it.
- Verification: To prevent “Identity Theft via Privacy Request,” the Hotel requires a copy of a valid ID or a verification email from the address used during the original booking.
- Timeline: We acknowledge receipt within 72 hours and provide a full response (including data logs in JSON or CSV format for portability) within 30 days.
- Exceptions: We will decline erasure requests for data that must be kept for legal/fiscal reasons (e.g., invoices required by Italian tax law for 10 years).
24. Annex D: Physical Data Security & CIN Compliance
As a holder of CIN IT063080A1IKZVFQ69, the Hotel adheres to the “National Database of Accommodation Facilities” (BDSR) security standards.
- Access Control: Physical guest registers and paper backup forms are stored in a fireproof safe in the administrative office, accessible only by the General Manager and the Front Office Manager.
- Wi-Fi Security: The guest Wi-Fi network is logically separated from the Hotel’s internal administrative network (VLAN tagging). Guest browsing logs are not monitored, though session metadata is retained for 6 months as per Italian anti-terrorism legislation.
- Device Management: Staff tablets used for poolside ordering or housekeeping updates are encrypted and can be remotely wiped if lost or stolen.