Last updated: September 2026.
Information provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
This notice describes how personal data of users visiting the website www.ricasolitravel.com, interacting with its services and booking travel services under the Ricasoli Travel brand are processed.
Ricasoli Group S.r.l. is a single company operating on the market through several brands, each specialised by sector and none of which has separate legal personality: Ricasoli Travel (travel and mobility services), Ricasoli Realty (real estate services) and Ricasoli Stays (short lets and property management). Any reference to a brand in this document is to be understood as a reference to Ricasoli Group S.r.l.
The controller of personal data is:
The Controller has not appointed a Data Protection Officer, the conditions set out in Article 37 GDPR not being met. Any request concerning the processing of personal data may be sent to the e-mail address indicated above.
The websites www.ricasoligroup.com, www.ricasolitravel.com, www.ricasolirealty.com and www.ricasolistays.com all belong to a single data controller, Ricasoli Group S.r.l., which operates through the Ricasoli Travel, Ricasoli Realty and Ricasoli Stays brands. Those brands are not separate companies but operating divisions of the same company.
Accordingly, the use of personal data across the different divisions does not constitute disclosure to third parties, but processing internal to the same controller, and in any event takes place solely within the limits of the purposes and legal bases set out in this notice. In particular, data collected through one website is not used to send promotional communications concerning the services of another division without the specific consent of the data subject.
The Controller processes the following categories of personal data:
Where a booking concerns more than one passenger, their personal data are provided to the Controller by the person making the booking, who declares that they are authorised to provide them and undertakes to bring the content of this notice to the attention of the data subjects.
In such cases the source of the data is the person making the booking; the categories of data are those set out in paragraph 3 and the processing takes place for the performance of the travel contract and for the related legal obligations. The Controller provides this notice to data subjects other than the person making the booking, where they have not already received it, within one month of collection of the data or at the time of the first communication, pursuant to Article 14(3) GDPR.
Data relating to minors travelling with their family are processed solely for ticket issuance, for booking the services and for compliance with the requirements of carriers and authorities.
Personal data are processed for the purposes and on the legal bases set out below.
Providing the data requested through the website forms is optional; failure to provide the data marked as mandatory, however, makes it impossible to follow up on the request or to provide the service. Providing travel document data is necessary for ticket issuance and for compliance with the requirements of carriers and authorities.
The forms on the website include a non-pre-ticked acknowledgement box confirming that the user has read this notice; ticking it is a condition for submitting the request. That box does not constitute consent to the processing: a privacy notice is an information document, and the processing operations connected with handling the request rely on the legal bases set out in the preceding paragraph.
Subscribing to the newsletter requires a separate consent box, likewise not pre-ticked and independent of the submission of the request: declining to subscribe in no way affects the possibility of contacting the Controller or using its services. Consent may be withdrawn at any time through the unsubscribe link included in every communication or by writing to the addresses set out in paragraph 1.
Choices concerning cookies and similar technologies are collected through the dedicated banner on first access and may be changed or withdrawn at any time through the Cookie preferences control in the website footer, as described in the Cookie Policy.
Personal data may be disclosed, for the purposes set out above, to the following parties, which process them as processors or as separate controllers:
Parties processing data on behalf of the Controller are appointed as processors under Article 28 GDPR. An up-to-date list of processors is available on request by writing to the addresses set out in paragraph 1. Personal data are not disseminated.
Some of the providers listed in the preceding paragraph may process personal data outside the European Economic Area. In that case, the transfer takes place solely subject to appropriate safeguards under Articles 44 et seq. GDPR, such as an adequacy decision of the European Commission (including the decision concerning the EU-U.S. Data Privacy Framework, for US providers certified thereunder) or the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional measures. A copy of the safeguards adopted may be requested at the addresses set out in paragraph 1.
In the travel sector, transfers of data to third countries are not a marginal possibility but an ordinary condition for performing the service: booking with a carrier, hotel or operator located outside the European Economic Area, as well as complying with reporting obligations towards the border authorities of the country of destination, necessarily entails transmitting the traveller’s data to parties established in those countries.
In the absence of an adequacy decision or other appropriate safeguards, such transfers are made on the basis of the derogation provided for by Article 49(1)(b) GDPR, being necessary for the performance of a contract concluded with the data subject or for the implementation of pre-contractual measures taken at the data subject’s request or, for passengers other than the person making the booking, on the basis of the derogation under point (c) of that paragraph.
Personal data are retained for no longer than is necessary to achieve the purposes for which they were collected and, in particular:
The Controller does not carry out automated decision-making, including profiling, producing legal effects concerning the data subject or similarly significantly affecting them within the meaning of Article 22 GDPR. Should the Controller intend to introduce such processing in the future, it will give prior notice by updating this notice, setting out the logic involved as well as the significance and the envisaged consequences for the data subject.
Minors may not make bookings independently through the website. Data of minors are processed only where communicated by the holder of parental responsibility in the context of a booking concerning them, to the extent necessary to issue travel documents and provide the services booked.
The Controller implements appropriate technical and organisational measures under Article 32 GDPR to protect personal data against unauthorised destruction, loss, alteration, disclosure or access, including encryption of communications through the HTTPS protocol, restriction of access to authorised personnel instructed under Article 29 GDPR, and the appointment of providers as processors under Article 28 GDPR.
Data subjects have the right to obtain from the Controller, in the cases provided for by Articles 15 et seq. GDPR: access to their personal data; rectification of inaccurate data; erasure of data (right to be forgotten); restriction of processing; data portability; and objection to processing based on legitimate interest. Data subjects have in any event the right to object at any time, without giving reasons, to the processing of their data for direct marketing purposes. Where processing is based on consent, data subjects have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
These rights may be exercised by writing to the addresses set out in paragraph 1. The Controller replies without undue delay and in any event within one month of the request, extendable by two months where the request is particularly complex. Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the Member State of their habitual residence or place of work.
The website is also published in languages other than Italian. This notice is drafted in Italian and is made available, for transparency purposes under Article 12 GDPR, also in the other languages in which the website is available. In the event of any discrepancy between versions, the Italian version prevails.
The Controller reserves the right to amend or update this notice at any time, giving notice by publication on the website. The version in force is the one published on this page on the date of consultation; the date of the last update is shown at the top of the document.