Grand Hotel Menaggio
Privacy
PRIVACY POLICY – WEBSITE
Information notice pursuant to and for the purposes of Article 13 of Regulation (EU) 2016/679 (GDPR)
WHY THIS INFORMATION?
Pursuant to Regulation (EU) 2016/679 (hereinafter the “GDPR”), this page describes the methods used to process personal data. This information notice is provided pursuant to Article 13 of the GDPR. It does not apply to third-party websites that may be accessed through links available on this website, for which no responsibility is assumed.
Personal data that may be processed
- Personal data: any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity (Recitals 26, 27 and 30 GDPR).
- Data relating to contracting parties/users.
- Browsing data: the IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category includes IP addresses or domain names of computers and devices used by users, URI/URL addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server response (successful, error, etc.), and other parameters relating to the user’s operating system and IT environment.
- Data provided voluntarily: the optional, explicit and voluntary sending of messages to the contact addresses indicated on this website and/or the completion of data collection forms results in the acquisition of the sender’s address, which is necessary to reply to requests, as well as any other personal data entered.
Information on the processing of personal data through Social Media platforms
With regard to personal data processing carried out by the operators of the Social Media platforms used by the Controller, reference should be made to the information provided by those operators in their respective privacy policies. The Controller processes personal data provided by users through dedicated Social Media pages in order to manage interactions with users, such as comments and public posts, in compliance with applicable legislation.
Specific information notices
Specific information notices may be available on pages of the Website relating to particular services or processing activities involving the data provided.
COOKIES AND OTHER TRACKING SYSTEMS: WHAT ARE THEY AND WHAT ARE THEY USED FOR?
For information on cookies and other tracking systems, please refer to the Cookie Policy available in the website footer.
1. WHO IS THE DATA CONTROLLER AND HOW CAN YOU CONTACT IT?
The Data Controller is Hotel Menaggio S.r.l., with registered office at Via Ariberto no. 22, Cantù (CO), represented by its legal representative pro tempore. The Controller may be contacted for any information by telephone at +39 0344 30640 or by email at privacy@grandhotelmenaggio.it.
2. PURPOSES OF PROCESSING, DATA RETENTION PERIOD AND NATURE OF THE PROVISION OF DATA
PURPOSES OF PROCESSING
Browsing this website. Data necessary for the use of web services are also processed in order to:
- obtain statistical information on the use of services, such as the most visited pages, the number of visitors by time slot or day, and geographical areas of origin;
- verify the correct operation of the services provided.
Use of cookies and similar technologies. Please refer to the Cookie Policy in the website footer.
LEGAL BASIS
Processing is necessary for the purposes of the legitimate interests pursued by the Controller or by third parties, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data, taking into account the data subject’s reasonable expectations and the activities strictly necessary for the operation of and browsing on the website (Article 6(1)(f) and Recital 47 GDPR). Data subjects may request information on the balancing test carried out.
For non-technical cookies and similar technologies that are not strictly necessary, processing is based on consent to the processing of personal data (Article 6(1)(a) and Recitals 42 and 43 GDPR). Consent is given through the website banner and Cookie Policy.
DATA RETENTION PERIOD
Browsing data are retained for the duration of the browsing session.
Please refer to the Cookie Policy in the website footer for information on cookies.
NATURE OF THE PROVISION OF DATA
The provision of data is necessary in order to browse the website.
Please refer to the Cookie Policy in the website footer for information on cookies.
In addition to browsing-related purposes, personal data will be processed for the following purposes:
A) MANAGEMENT OF YOUR REQUESTS and requests submitted by other data subjects pursuant to Articles 15 et seq. GDPR (data subject rights).
LEGAL BASIS
Processing is necessary for compliance with a legal obligation to which the Controller is subject (Recital 45 and Article 6(1)(c) GDPR).
DATA RETENTION PERIOD
Five years from closure of the request, unless legal disputes arise.
NATURE OF THE PROVISION OF DATA
The provision of personal data is mandatory, as it is essential for compliance with legal obligations.
PURPOSES OF PROCESSING
B) Administrative and accounting activities connected with the booking of accommodation and/or additional services offered by the Hotel; protection of resulting receivables; management of civil liability and third-party insurance policies. For this purpose, the Controller may process special categories of data voluntarily provided by the data subject, such as health information relating to disability or coeliac disease.
LEGAL BASIS
Performance of pre-contractual measures taken at the request of the data subject or performance of a contract (Article 6(1)(b) GDPR). Consent for any special categories of personal data processed (Article 6(1)(a) and Article 9(2)(a) GDPR).
DATA RETENTION PERIOD
Ten years.
NATURE OF THE PROVISION OF DATA
The provision of personal data is necessary in order to make a booking at our establishment. Failure to provide the data will make it impossible to complete the booking.
3. TO WHOM WILL PERSONAL DATA BE DISCLOSED? RECIPIENTS OF THE DATA
Personal data will be disclosed to parties that process them as independent Data Controllers or as Data Processors pursuant to Article 28 GDPR, and will be processed by natural persons pursuant to Article 29 GDPR acting under the authority of the Controller and Processors on the basis of specific instructions concerning the purposes and methods of processing. Data will be disclosed to recipients belonging to the following categories:
- parties established in Italy that provide services relating to the website and communication networks, including email, hosting and website management;
- parties established in Italy with which the Controller has entered into agreements and, where required, subject to prior consent;
- competent authorities for compliance with legal obligations and/or provisions issued by public bodies, upon request.
The list of Data Processors appointed pursuant to Article 28 GDPR is available by writing to privacy@grandhotelmenaggio.it or using the other contact details indicated above.
4. WILL THE DATA BE TRANSFERRED TO COUNTRIES OUTSIDE THE EEA?
Personal data will not be transferred to countries outside the European Economic Area. In particular, data relating to website hosting, management, development and maintenance services will be stored in Italy. All third parties to whom data may be disclosed are established in Italy.
5. IS THERE ANY AUTOMATED PROCESSING?
Personal data will be processed using traditional manual, electronic and automated methods. No fully automated decision-making processes are carried out.
6. WHAT ARE YOUR RIGHTS AND HOW CAN YOU EXERCISE THEM?
You may exercise the rights provided for in Articles 15 et seq. of Regulation (EU) 2016/679 by contacting the Data Controller at privacy@grandhotelmenaggio.it. At any time, you may request access to your personal data, rectification, erasure and restriction of processing. Where applicable, you also have the right to data portability, in which case the Controller will provide the personal data concerning you in a structured, commonly used and machine-readable format. Without prejudice to any other administrative or judicial remedy, if you consider that the processing of personal data relating to you infringes Regulation (EU) 2016/679, you have the right to lodge a complaint with the Italian Data Protection Authority: https://www.garanteprivacy.it/.
7. CHANGES TO THIS INFORMATION NOTICE
The Controller may change, amend, add to or remove any part of this Privacy Policy. To make it easier to identify any changes, the notice will indicate the date on which it was last updated.
Last updated: 31 July 2025

