Privacy Policy

Last updated: September 2026.

Information provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)

This notice describes how personal data of users visiting the website www.ricasolitravel.com, interacting with its services and booking travel services under the Ricasoli Travel brand are processed.

Ricasoli Group S.r.l. is a single company operating on the market through several brands, each specialised by sector and none of which has separate legal personality: Ricasoli Travel (travel and mobility services), Ricasoli Realty (real estate services) and Ricasoli Stays (short lets and property management). Any reference to a brand in this document is to be understood as a reference to Ricasoli Group S.r.l.

1. Data controller

The controller of personal data is:

  • Controller: Ricasoli Group S.r.l.
  • Registered office: Via Senato 29, 20121 Milan (MI), Italy
  • Tax code, VAT number and registration number with the Companies Register of Milano Monza Brianza Lodi: 08638750961
  • R.E.A. (Economic and Administrative Index): MI - 2038959
  • Share capital: EUR 10,000.00 fully paid up
  • Certified e-mail (PEC): ricasoliconsulting@legalmail.it
  • E-mail: booking-eu@ricasolitravel.com
  • Telephone: +39 328 743 4871
  • Brands and divisions of the company: Ricasoli Travel, Ricasoli Realty, Ricasoli Stays.

The Controller has not appointed a Data Protection Officer, the conditions set out in Article 37 GDPR not being met. Any request concerning the processing of personal data may be sent to the e-mail address indicated above.

2. Single controller and use of data across the brands

The websites www.ricasoligroup.com, www.ricasolitravel.com, www.ricasolirealty.com and www.ricasolistays.com all belong to a single data controller, Ricasoli Group S.r.l., which operates through the Ricasoli Travel, Ricasoli Realty and Ricasoli Stays brands. Those brands are not separate companies but operating divisions of the same company.

Accordingly, the use of personal data across the different divisions does not constitute disclosure to third parties, but processing internal to the same controller, and in any event takes place solely within the limits of the purposes and legal bases set out in this notice. In particular, data collected through one website is not used to send promotional communications concerning the services of another division without the specific consent of the data subject.

3. Categories of data processed

The Controller processes the following categories of personal data:

  • contact and identification data — first name, surname, e-mail address, telephone number and any other information voluntarily provided through the contact or enquiry forms on the website;
  • data relating to enquiries and bookings — itinerary, dates, number and names of passengers, services requested, travel preferences and any information necessary to provide the service;
  • travel document data — identity card or passport details, nationality, date of birth and, where required by the country of destination or by the carrier, data relating to visas and health certificates, necessary for ticket issuance and for compliance with reporting obligations towards border authorities;
  • data relating to the traveller’s particular needs — where voluntarily communicated, data concerning assistance, mobility, medical or dietary needs, which may constitute special categories of data within the meaning of Article 9 GDPR;
  • payment and billing data — billing details and transaction data necessary to process payments. Full card details are entered directly with the payment service provider and are not stored by the Controller;
  • images and content relating to reviews and testimonials — the name and, where shown, the image of clients who have published a review on public platforms or who have authorised its publication on the website;
  • browsing data — data collected automatically while browsing (for example IP address, browser and device type, pages visited, date and time of access), as described in the Cookie Policy;
  • data collected through cookies and similar technologies — as described in the Cookie Policy published on the website.

4. Data of passengers other than the person making the booking and source of the data (Article 14 GDPR)

Where a booking concerns more than one passenger, their personal data are provided to the Controller by the person making the booking, who declares that they are authorised to provide them and undertakes to bring the content of this notice to the attention of the data subjects.

In such cases the source of the data is the person making the booking; the categories of data are those set out in paragraph 3 and the processing takes place for the performance of the travel contract and for the related legal obligations. The Controller provides this notice to data subjects other than the person making the booking, where they have not already received it, within one month of collection of the data or at the time of the first communication, pursuant to Article 14(3) GDPR.

Data relating to minors travelling with their family are processed solely for ticket issuance, for booking the services and for compliance with the requirements of carriers and authorities.

5. Purposes and legal bases of the processing

Personal data are processed for the purposes and on the legal bases set out below.

  • Responding to enquiries and quotations — following up on requests for information, quotations and contact sent through the website. Legal basis: performance of pre-contractual measures taken at the data subject’s request and the Controller’s legitimate interest in replying (Article 6(1)(b) and (f) GDPR).
  • Provision of services and management of bookings — processing bookings, issuing air tickets, making reservations with carriers, hotels, aircraft operators and other suppliers, and providing customer assistance. Legal basis: performance of a contract (Article 6(1)(b) GDPR); for passengers other than the person making the booking, legitimate interest in the performance of the travel contract (Article 6(1)(f) GDPR).
  • Traveller’s particular needs — acting upon requests for special assistance or concerning mobility, medical or dietary needs communicated by the traveller, including their transmission to the carriers and suppliers concerned. Legal basis: the data subject’s explicit consent (Article 9(2)(a) GDPR), which may be withdrawn at any time; failing that, the Controller is unable to guarantee the service requested.
  • Border control and aviation security requirements — transmitting to carriers and, through them or directly, to the competent authorities of the countries of departure, transit and destination, advance passenger information and booking record data, where required by applicable law. Legal basis: legal obligation and, for obligations imposed by non-EU legal systems, performance of a contract and legitimate interest (Article 6(1)(c), (b) and (f) GDPR).
  • Payment management — processing payments and complying with accounting and tax obligations. Legal basis: performance of a contract and compliance with legal obligations (Article 6(1)(b) and (c) GDPR).
  • Publication of reviews and testimonials — publishing client reviews and feedback on the website. Legal basis: the Controller’s legitimate interest in promoting its business, where the review has already been made public by the data subject on third-party platforms and is reproduced with an indication of its source (Article 6(1)(f) GDPR), or the data subject’s consent where the testimonial is collected directly by the Controller (Article 6(1)(a) GDPR).
  • Marketing of similar services — sending communications concerning services similar to those already used by the client. Legal basis: the Controller’s legitimate interest under Article 130(4) of Italian Legislative Decree 196/2003, with the data subject’s right to object at the time of collection and in every communication; for other recipients, consent (Article 6(1)(a) GDPR).
  • Legal compliance — complying with obligations laid down by law, regulation or an order of the authorities. Legal basis: legal obligation (Article 6(1)(c) GDPR).
  • Legal claims — establishing, exercising or defending legal claims. Legal basis: the Controller’s legitimate interest (Article 6(1)(f) GDPR).

6. Nature of the provision of data and how consent is collected

Providing the data requested through the website forms is optional; failure to provide the data marked as mandatory, however, makes it impossible to follow up on the request or to provide the service. Providing travel document data is necessary for ticket issuance and for compliance with the requirements of carriers and authorities.

The forms on the website include a non-pre-ticked acknowledgement box confirming that the user has read this notice; ticking it is a condition for submitting the request. That box does not constitute consent to the processing: a privacy notice is an information document, and the processing operations connected with handling the request rely on the legal bases set out in the preceding paragraph.

Subscribing to the newsletter requires a separate consent box, likewise not pre-ticked and independent of the submission of the request: declining to subscribe in no way affects the possibility of contacting the Controller or using its services. Consent may be withdrawn at any time through the unsubscribe link included in every communication or by writing to the addresses set out in paragraph 1.

Choices concerning cookies and similar technologies are collected through the dedicated banner on first access and may be changed or withdrawn at any time through the Cookie preferences control in the website footer, as described in the Cookie Policy.

7. Recipients and processors

Personal data may be disclosed, for the purposes set out above, to the following parties, which process them as processors or as separate controllers:

  • providers of technical, hosting and content delivery services for the website (Vercel Inc. for hosting and page delivery);
  • providers of e-mail services and of contact form management services;
  • providers of website analytics services (Google Ireland Ltd., for Google Tag Manager and connected services), within the limits of the consent given through the cookie banner and as described in the Cookie Policy;
  • air carriers, aircraft operators, hotels, chauffeur services and other suppliers of the services booked, as separate controllers, to the extent necessary to provide the service requested;
  • global distribution systems and booking and ticketing platforms used to manage reservations and issue travel documents;
  • IATA and the operators of the settlement systems between agencies and carriers, to the extent necessary to manage the accreditation and the transactions;
  • border, public security and customs authorities of the countries of departure, transit and destination, in the cases provided for by applicable law;
  • payment service providers, which process card payments in compliance with the PCI-DSS standard;
  • consultants, professionals and service providers of the Controller (for example in accounting, tax and legal matters), to the extent necessary to carry out their respective engagements;
  • public and supervisory authorities, where required by law or by an order of the authorities.

Parties processing data on behalf of the Controller are appointed as processors under Article 28 GDPR. An up-to-date list of processors is available on request by writing to the addresses set out in paragraph 1. Personal data are not disseminated.

8. Transfers of data to third countries

Some of the providers listed in the preceding paragraph may process personal data outside the European Economic Area. In that case, the transfer takes place solely subject to appropriate safeguards under Articles 44 et seq. GDPR, such as an adequacy decision of the European Commission (including the decision concerning the EU-U.S. Data Privacy Framework, for US providers certified thereunder) or the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional measures. A copy of the safeguards adopted may be requested at the addresses set out in paragraph 1.

In the travel sector, transfers of data to third countries are not a marginal possibility but an ordinary condition for performing the service: booking with a carrier, hotel or operator located outside the European Economic Area, as well as complying with reporting obligations towards the border authorities of the country of destination, necessarily entails transmitting the traveller’s data to parties established in those countries.

In the absence of an adequacy decision or other appropriate safeguards, such transfers are made on the basis of the derogation provided for by Article 49(1)(b) GDPR, being necessary for the performance of a contract concluded with the data subject or for the implementation of pre-contractual measures taken at the data subject’s request or, for passengers other than the person making the booking, on the basis of the derogation under point (c) of that paragraph.

9. Retention period

Personal data are retained for no longer than is necessary to achieve the purposes for which they were collected and, in particular:

  • contact data and quotations not followed by a booking are retained for a maximum of 24 months from the last contact;
  • data relating to bookings and services provided are retained for ten years from the end of the trip, in view of the ordinary limitation periods and of accounting obligations;
  • travel document data are retained for as long as necessary for ticket issuance and for compliance with obligations towards carriers and authorities; any copies of documents are deleted once those requirements have been fulfilled, unless a different legal obligation applies;
  • data relating to the traveller’s particular needs are deleted at the end of the trip, unless the data subject requests that they be retained for future trips;
  • payment and billing data are retained for the period required by applicable tax and accounting legislation (as a general rule, ten years);
  • data necessary to establish, exercise or defend legal claims are retained for as long as necessary for that purpose.

10. No automated decision-making

The Controller does not carry out automated decision-making, including profiling, producing legal effects concerning the data subject or similarly significantly affecting them within the meaning of Article 22 GDPR. Should the Controller intend to introduce such processing in the future, it will give prior notice by updating this notice, setting out the logic involved as well as the significance and the envisaged consequences for the data subject.

11. Data relating to minors

Minors may not make bookings independently through the website. Data of minors are processed only where communicated by the holder of parental responsibility in the context of a booking concerning them, to the extent necessary to issue travel documents and provide the services booked.

12. Security of processing

The Controller implements appropriate technical and organisational measures under Article 32 GDPR to protect personal data against unauthorised destruction, loss, alteration, disclosure or access, including encryption of communications through the HTTPS protocol, restriction of access to authorised personnel instructed under Article 29 GDPR, and the appointment of providers as processors under Article 28 GDPR.

13. Rights of the data subject

Data subjects have the right to obtain from the Controller, in the cases provided for by Articles 15 et seq. GDPR: access to their personal data; rectification of inaccurate data; erasure of data (right to be forgotten); restriction of processing; data portability; and objection to processing based on legitimate interest. Data subjects have in any event the right to object at any time, without giving reasons, to the processing of their data for direct marketing purposes. Where processing is based on consent, data subjects have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.

These rights may be exercised by writing to the addresses set out in paragraph 1. The Controller replies without undue delay and in any event within one month of the request, extendable by two months where the request is particularly complex. Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the Member State of their habitual residence or place of work.

14. Language of this notice

The website is also published in languages other than Italian. This notice is drafted in Italian and is made available, for transparency purposes under Article 12 GDPR, also in the other languages in which the website is available. In the event of any discrepancy between versions, the Italian version prevails.

15. Amendments to this notice

The Controller reserves the right to amend or update this notice at any time, giving notice by publication on the website. The version in force is the one published on this page on the date of consultation; the date of the last update is shown at the top of the document.