INFORMATION NOTICE ON THE PROCESSING OF PERSONAL DATA

(Privacy Policy ai sensi del Regolamento UE 2016/679 – GDPR e del D.Lgs. 196/2003)

Ultimo aggiornamento: Maggio 2026

This information describes the ways in which Levante Outdoor Paradise, as Data Controller, collects, uses, stores and protects the personal data of users who visit the site https://levanteoutdoor.it (hereinafter, the "Site") or who interact with it through the contact forms, registering an account, booking experiences and itineraries, subscribing to the newsletter, and the other channels made available.

This document is drawn up pursuant to articles 13 and 14 of Regulation (EU) 2016/679 (hereinafter, “GDPR”), of Legislative Decree no. 30 June 2003. 196 as amended by Legislative Decree 101/2018 (“Privacy Code”) and in compliance with the provisions of the Guarantor for the Protection of Personal Data.

The objective is to guarantee maximum transparency regarding the processing of personal data and the methods with which the rights of the interested party are protected.

1. Data Controller

The Data Controller of personal data collected through the Site is:

Levante Outdoor Paradise

Sede operativa: Piazza della Croce 2, 16039 Riva Trigoso, Sestri Levante (GE), Italia

Forma giuridica e ragione sociale completa: [DA COMPILARE]

Tax code / VAT number: [TO BE COMPLETED]

Iscrizione Registro Imprese / REA: [DA COMPILARE]

Email: info@levanteoutdoor.it

Phone: +39 333 161 9238

Website: https://levanteoutdoor.it

For any request relating to the processing of personal data, the interested party can contact the Data Controller by writing to the email address indicated or using the contact form on the Site.

2. Data Protection Officer

Taking into account the nature, scope and purpose of the processing carried out, the type of data collected and the organization of the Data Controller, there is currently no obligation to appoint a Data Protection Officer (DPO) pursuant to art. 37 GDPR. If the Data Controller appoints a DPO, the relevant contact details will be promptly published in this information notice.

For all requests relating to data processing, the interested party can contact the Data Controller directly at the contact details indicated in paragraph 1.

3. Categories of Personal Data Processed

The Data Controller processes the following categories of personal data.

3.1 Data provided voluntarily by the user via contact form

These are the data that the user communicates directly by filling out the contact form on the Site or by writing to the Owner's email address. This data includes name, email address, subject and content of the message, any further information that the user spontaneously decides to communicate in order to receive a response to their request.

3.2 Data provided for registering a user account

To access the reserved functions of the Site ("My account", "My reservations" area), the user is invited to register by providing name, surname, email address, password (stored in encrypted form and never accessible in plain text to the Owner), any additional profile data (telephone number, profile image, activity preferences) that the user decides to enhance.

Any access via third-party authentication services (Single Sign-On with Google, Facebook, Apple, or other providers) involves the transmission of essential profile data (name, surname, email address, account identifier) ​​to the Data Controller in accordance with the policies of the provider chosen by the user.

3.3 Data provided for booking experiences and itineraries

For booking guided experiences, self-guided itineraries and other services offered through the Site, the data necessary to identify the participant and correctly provide the service is collected: name, surname, email address, telephone number, date of birth where requested, number and names of companions, date and time slot of the booking, chosen activity, any preferences and special needs, payment data (managed via an external payment processor, see paragraph 8).

Due to the sporting and outdoor nature of some activities (kayaking, snorkelling, trekking, mountain biking, climbing) the Owner may require the user, when booking or during reception at the meeting point, to sign a release including a declaration of physical suitability and absence of medical contraindications to carrying out the activity. This release may involve the collection of data relating to health pursuant to art. 9 GDPR; in this case the processing is carried out exclusively on the basis of the explicit consent of the interested party and for the sole purposes of protecting the physical safety of the participant and of the people involved in the activity.

3.4 Data relating to newsletter subscription

If the user subscribes to the newsletter, the email address and, optionally, the name and communication preferences are collected. Subscription always requires the free, specific, informed and unequivocal consent of the interested party, expressed according to the double opt-in method.

3.5 Data collected automatically during navigation

The computer systems and software procedures used to operate the Site acquire, during their normal operation, some data whose transmission is implicit in the use of Internet communication protocols. Among these: IP address of the device used by the user; browser type, language and version; operating system and device type (desktop, mobile, tablet); URL of the requested pages, date, time and duration of the visit; URL of origin (referrer) and navigation path within the Site; HTTP status codes, response file size and other technical transmission parameters.

These data are used for the sole purpose of obtaining anonymous statistical information on the use of the Site and to check its correct functioning, and could be used to ascertain responsibility in the event of hypothetical computer crimes against the Site or third parties.

3.6 Data collected through cookies and similar technologies

The Site uses technical cookies and, with the consent of the interested party, third-party analytical and profiling cookies. For any detailed information, please refer to the Cookie Policy published on the Site.

4. Purposes of Processing and Legal Basis

The personal data collected are processed for the following purposes, each based on a specific legal basis.

a) Management of contact requests

Purpose: to respond to requests received via contact form, email, telephone or social channels, provide the information requested by the user and organize any subsequent appointments.

Legal basis: art. 6, par. 1, letter. b) GDPR – execution of pre-contractual measures adopted at the request of the interested party.

b) Registration and management of the user account

Purpose: to allow user registration, management of personal profile, access to the reserved area and booking history, authentication and access security.

Legal basis: art. 6, par. 1, letter. b) GDPR – execution of the registration contract of which the interested party is a party.

c) Gestione delle prenotazioni e dei servizi richiesti

Purpose: receive, process and execute reservations for experiences, itineraries and ancillary services (transfers, equipment); coordinate the provision of the activity with the guides and operators in charge; manage any changes, rescheduling or cancellations; provide the user with confirmations, reminders and operational information connected to the service.

Legal basis: art. 6, par. 1, letter. b) GDPR – execution of the service contract.

d) Management of payments and accounting obligations

Purpose: process booking payments, issue receipts, invoices and tax documents, manage any refunds and disputes.

Legal basis: art. 6, par. 1, letter. b) GDPR (execution of the contract) and art. 6, par. 1, letter. c) GDPR (fulfillment of legal obligations in tax, accounting and anti-money laundering matters).

e) Protection of the physical safety of the participant

Purpose: collection and management of any health or physical fitness data connected to participation in sporting and outdoor activities (kayaking, snorkeling, trekking, mountain biking, climbing and similar), for the sole purpose of guaranteeing the safety of the interested party and other participants.

Legal basis: art. 9, par. 2, letter. a) GDPR – explicit consent of the interested party; in case of emergency, art. 9, par. 2, letter. c) GDPR – protection of vital interests.

f) Sending newsletters and promotional communications

Purpose: to send the user who has requested newsletters, promotions, news on experiences and itineraries, editorial content, invitations to events.

Legal basis: art. 6, par. 1, letter. a) GDPR – express and specific consent of the interested party, revocable at any time via the unsubscribe link present in each communication or by writing to the Data Controller.

g) Soft spam (marketing su servizi analoghi acquistati)

Purpose: if the user has already used a similar experience or service, sending promotional communications relating to services similar to those purchased, subject to the right of opposition which can be exercised at any time (so-called "soft spam").

Legal basis: art. 130, paragraph 4, Privacy Code and legitimate interest of the Data Controller pursuant to art. 6, par. 1, letter. f) GDPR.

h) Anonymous measurement and analysis of the use of the Site

Purpose: to analyze user behavior in aggregate and, where possible, anonymized form to improve content, usability and browsing experience.

Legal basis: art. 6, par. 1, letter. a) GDPR – consent of the interested party expressed through the cookie banner. Consent can be revoked at any time through the "Manage consent" tool on the Site.

i) Compliance with legal obligations

Purpose: to comply with obligations established by applicable legislation, including tax, accounting, anti-money laundering and security provisions, as well as respond to requests from the competent authorities.

Legal basis: art. 6, par. 1, letter. c) GDPR – fulfillment of a legal obligation to which the Data Controller is subject.

j) Protection of the rights of the Owner

Purpose: to ascertain, exercise or defend a right in court, manage disputes and prevent abuse in the use of the Site or the services booked.

Legal basis: art. 6, par. 1, letter. f) GDPR – legitimate interest of the Data Controller.

5. Nature of the Provision of Data

The provision of the data requested for account registration, for booking experiences and for contractual and legal obligations is mandatory: any refusal makes it impossible to proceed with the registration, booking or provision of the requested service.

The provision of data for direct marketing purposes (newsletters, promotional communications) and for statistical and profiling purposes via cookies is always optional: any failure to consent does not affect the possibility of using the Site and the services offered.

6. Methods of Treatment

Personal data are processed in a lawful, correct and transparent manner, with IT and telematic tools and, to a residual extent, with paper tools (for example for the signing of releases during the reception phase at the meeting point), adopting technical and organizational security measures suitable to guarantee a level of security appropriate to the risk (art. 32 GDPR).

The processing is carried out exclusively by authorized personnel (collaborators, guides, operators, partners) who are appropriately trained and bound by confidentiality obligations. The systems adopt encryption in transit protocols (HTTPS/TLS), backup procedures, irreversible password hashing and access policies based on the principle of least privilege.

No processing is carried out based on automated decision-making processes, including profiling, which produce significant legal effects on the interested party pursuant to art. 22 GDPR.

7. Recipients of the Data and Third Parties

Personal data may be communicated to the following categories of recipients, based on the purposes indicated above.

  • Guides and operators of the collective that provides the experiences:limited to the strictly necessary data (name, contact, number of participants, any needs) and only for the period necessary for the preparation and provision of the booked activity.
  • Entities carrying out activities instrumental to the operation of the Site:hosting service provider, technical maintainer, cookie consent management platform provider, booking and account management platform provider.
  • Payment processors:third parties who independently manage the processing of payment data (credit cards, direct debits, electronic wallets), as independent Data Controllers with respect to this processing segment.
  • Fornitori di servizi di analisi statistica e marketing digitale:subject to the user's consent, subjects who provide tools for measuring traffic, analyzing browsing behavior, email marketing, digital advertising (for example, the services described in paragraph 8 below).
  • Professional consultants of the Owner:commercialista, consulente del lavoro, consulente legale, vincolati al segreto professionale.
  • Compagnie assicurative:where necessary for the management of any claims or insurance coverage related to outdoor activities.
  • Public and supervisory authorities:Guarantor for the Protection of Personal Data, Judicial Authority, Financial Police, Revenue Agency, health and public security authorities, where required in compliance with legal obligations or binding provisions.

Third parties who process personal data on behalf of the Data Controller are appointed Data Controllers pursuant to art. 28 GDPR through a specific contractual document (DPA – Data Processing Agreement). The data is in no case disclosed or transferred to third parties for independent marketing purposes by the latter.

8. Third Party Services Used or Potentially Used on the Site

The third-party services that can be integrated into the Site are listed below. The activation of these services and the related data processing take place, for the services that require it, exclusively with the consent of the interested party expressed through the cookie banner. For the technical characteristics of the individual cookies and the data processed, please refer to the Cookie Policy.

8.1 Hosting e infrastruttura tecnica

The Site is hosted by a hosting service provider that processes navigation data (system logs, IP addresses, HTTP requests) for the sole purpose of technical provision of the service and IT security.

Legal basis: art. 6, par. 1, letter. f) GDPR – legitimate interest of the Owner in the provision and security of the Site.

Storage: the technical logs are kept for the strictly necessary period, normally not exceeding twelve months, unless necessary for judicial verification.

8.2 WordPress, Elementor and site management plugins

The Site is created via the WordPress platform and the Elementor page builder, which can install technical session cookies necessary for the operation of the pages. The Site also uses third-party plugins to manage the booking features, reserved area, interactive map, photo galleries, security and performance optimization. These plugins process the data strictly necessary for the functioning of the related functions.

8.3 Google reCAPTCHA

The Site uses Google reCAPTCHA v3, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin, Ireland), in order to protect the forms (contact form, registration, booking) from automated submissions and fraudulent activities. The service analyzes user behavior on the Site and collects technical and interaction information (IP address, mouse movements, device data, Google cookies) to assign a risk score.

Legal basis: art. 6, par. 1, letter. f) GDPR – legitimate interest in the security of the Site and the prevention of fraud.

Privacy Policy: https://policies.google.com/privacy

Terms of Service: https://policies.google.com/terms

8.4 Google Maps

The Site uses Google Maps, provided by Google Ireland Limited, for the display of static or interactive maps (for example: location of the office, itinerary maps, points of interest). The integration of Google Maps involves the transmission of the user's IP address to Google servers, which can install technical and profiling cookies.

Legal basis: art. 6, par. 1, letter. a) GDPR – consent of the interested party (for interactive maps and non-strictly necessary cookies).

Privacy Policy: https://policies.google.com/privacy

8.5 Google Fonts

The Site uses typographic families provided by Google Fonts (Google Ireland Limited). Depending on the integration method adopted, loading fonts may involve the transmission of the user's IP address to the provider's servers. Where technically possible, the Owner adopts local font hosting solutions or configurations that minimize data transmission.

Legal basis: art. 6, par. 1, letter. f) GDPR – legitimate interest in the correct display of the Site.

Privacy Policy: https://policies.google.com/privacy

8.6 Google Analytics / Google Analytics 4

If activated, the Site uses Google Analytics, a statistical analysis service provided by Google Ireland Limited. The service collects information in aggregate form on user browsing (pages visited, duration of visit, type of device, traffic source). The Data Controller adopts measures to anonymize the IP address and deactivate the sharing of data with other Google services.

Legal basis: art. 6, par. 1, letter. a) GDPR – consent of the interested party expressed through cookie banners.

Storage: up to 26 months (default) or as configured by the Owner.

Privacy Policy: https://policies.google.com/privacy

Opt-out: https://tools.google.com/dlpage/gaoptout

8.7 Google Ads e Conversion Tracking

If activated, the Site may use Google Ads tools (Google Ireland Limited) for conversion tracking (bookings, registrations, newsletter subscriptions) and for advertising remarketing. These tools allow you to measure the effectiveness of promotional campaigns and show relevant ads to users on partner sites in the Google advertising network.

Legal basis: art. 6, par. 1, letter. a) GDPR – consent of the interested party.

8.8 Meta Pixel (Facebook / Instagram) e collegamenti social

The Site presents links to the Owner's social profiles on Instagram (@levanteoutdoorparadise) and Facebook (facebook.com/levanteoutdoor). Simply viewing the link does not involve data processing. If the Meta Pixel, provided by Meta Platforms Ireland Limited (4 Grand Canal Square, Dublin, Ireland), is activated, the service will allow you to measure the effectiveness of advertising campaigns on the social networks Facebook and Instagram, build personalized audiences and track conversions.

Legal basis: art. 6, par. 1, letter. a) GDPR – consent of the interested party.

Privacy Policy Meta: https://www.facebook.com/privacy/policy

8.9 Strumenti di analisi comportamentale (Hotjar / Microsoft Clarity)

If activated, the Site can use behavioral analysis tools such as Hotjar (Hotjar Ltd, Malta) or Microsoft Clarity (Microsoft Ireland Operations Limited, Dublin, Ireland), which allow browsing sessions, heat maps and interaction paths to be recorded in an anonymized form, with automatic masking of sensitive fields.

Legal basis: art. 6, par. 1, letter. a) GDPR – consent of the interested party.

8.10 Transactional Email and Newsletter Services

To send transactional emails (registration confirmations, booking confirmations and reminders, payment receipts, service communications) and newsletters, the Owner may use external professional platforms (for example: Mailchimp – Intuit Inc.; Brevo – Sendinblue SAS; MailerLite – MailerLite Limited; SendGrid – Twilio Inc.; Amazon SES – Amazon Web Services). These suppliers operate as Data Controllers.

Legal basis for transactional emails: art. 6, par. 1, letter. b) GDPR (execution of the contract).

Legal basis for the newsletter: art. 6, par. 1, letter. a) GDPR – consent of the interested party, always revocable.

8.11 Payment processors

Payments made on the Site are managed through external payment processors that operate as independent data controllers relating to payment methods. The Data Controller does not store at any time the complete data of the credit cards or payment instruments used. By way of example, providers that may be used include Stripe (Stripe Payments Europe Ltd, Dublin, Ireland), PayPal (PayPal Europe S.à r.l. et Cie, S.C.A., Luxembourg), Nexi (Nexi Payments S.p.A., Milan, Italy), SumUp (SumUp Limited, Dublin, Ireland).

Legal basis: art. 6, par. 1, letter. b) GDPR – execution of the contract and art. 6, par. 1, letter. c) GDPR – legal obligations regarding electronic payments, anti-money laundering and anti-fraud.

Privacy Policy Stripe: https://stripe.com/privacy

Privacy Policy PayPal: https://www.paypal.com/it/legalhub/privacy-full

8.12 Experience booking systems (booking engines)

To manage experience and itinerary bookings, the Site can integrate professional booking engine systems (for example: Bokun – Bokun ehf., TripAdvisor group; Regiondo – Regiondo GmbH; FareHarbor – FareHarbor Holdings Inc.; Bookly or Amelia – WordPress booking plugin). These suppliers process the participants' data on behalf of the Data Controller as Data Controllers.

Legal basis: art. 6, par. 1, letter. b) GDPR – execution of the booking contract.

8.13 Cookie banner and Consent Management Platform

The Site uses a consent management platform (Consent Management Platform) which stores the choices expressed by the user regarding cookies and tracking technologies. The platform collects data relating to consent (date, time, category of cookies consented) for the sole purpose of documenting compliance with GDPR obligations.

Legal basis: art. 6, par. 1, letter. c) GDPR – legal obligation to document consent (art. 7 GDPR).

Conservation: 12 months from the date of expression of consent.

8.14 Embed video e contenuti esterni (YouTube, Vimeo)

If the Site incorporates videos or multimedia content from external platforms (YouTube – Google Ireland Limited; Vimeo – Vimeo LLC), these platforms may install their own cookies and collect interaction data. Where technically possible, the Data Controller adopts privacy-friendly methods ("no-cookies").

Legal basis: art. 6, par. 1, letter. a) GDPR – consent of the interested party.

9. Transfer of Data to Third Countries

Some of the service providers indicated in paragraph 8 (in particular Google, Meta, Microsoft, Stripe, PayPal and other international operators) may involve the transfer of personal data to non-EU countries. These transfers take place in compliance with articles 44 et seq. of the GDPR and in particular towards the United States of America on the basis of the Adequacy Decision of the European Commission of 10 July 2023 (EU-U.S. Data Privacy Framework) for certified suppliers; where an adequacy decision is not made, on the basis of the Standard Contractual Clauses approved by the European Commission with Implementing Decision (EU) 2021/914; with the adoption, where applicable, of additional security measures (end-to-end encryption, pseudonymisation, access controls).

The user can request a copy of the guarantees adopted from the Data Controller by writing to the email address indicated in paragraph 1.

10. Data Retention Period

Personal data are kept for the time strictly necessary to achieve the purposes for which they were collected, according to the following criteria.

  • Contact details and content of information requests:up to 24 months from the last contact, unless the user's interest or the establishment of a contractual relationship require longer storage.
  • User account data:for the entire duration of registration for the service and up to 24 months from any cancellation request, without prejudice to legal retention obligations.
  • Data relating to reservations and service contracts:10 anni dalla cessazione del rapporto, ai sensi dell’art. 2220 c.c. e della normativa fiscale e antiriciclaggio applicabile.
  • Data relating to releases and declarations of physical fitness:for the entire duration necessary to provide the activity and for the time necessary to manage any disputes or claims, normally no more than 10 years.
  • Newsletter and direct marketing data:until the interested party revokes consent; in case of unsubscription, retention of a minimum data (email + revocation date) for 24 months for the sole purpose of documenting the ceased membership.
  • Log tecnici di sistema:no longer than 12 months, unless necessary to ascertain computer crimes.
  • Analytics data and profiling cookies:according to the duration indicated in the Cookie Policy, in any case no longer than 26 months.
  • Cookie consent data:12 mesi dalla data di espressione.

Upon expiry of the retention period, the data will be irreversibly deleted or anonymized.

11. Rights of the interested party

As an interested party, the user has the right to exercise the rights provided for in articles 15-22 of the GDPR at any time, and in particular:

  • Diritto di accesso (art. 15):obtain confirmation of the existence of data processing concerning him and access such data and the information required by law.
  • Diritto di rettifica (art. 16):obtain the correction of inaccurate data or the integration of incomplete data.
  • Diritto alla cancellazione (art. 17):obtain the deletion of data in the cases provided for (withdrawal of consent, data no longer necessary, legitimate opposition, etc.), except in cases of mandatory conservation by law.
  • Diritto di limitazione (art. 18):obtain the limitation of processing in the cases provided for by law.
  • Right to portability (art. 20):receive the data concerning him in a structured, commonly used and machine-readable format and transmit them to another owner.
  • Diritto di opposizione (art. 21):object at any time to data processing based on the legitimate interest of the Owner, including direct marketing communications.
  • Diritto di non essere sottoposto a decisioni automatizzate (art. 22):not be subjected to decisions based solely on automated processing that produce significant legal effects.
  • Right to withdraw consent (art. 7, par. 3):revoke the consent given at any time, without prejudice to the lawfulness of the processing based on the consent before the revocation.

To exercise their rights, the interested party can send a written request to the email address info@levanteoutdoor.it, clearly indicating the rights they intend to exercise and providing the information necessary to verify their identity. The Data Controller will respond within 30 days of receiving the request, unless there are justified extensions pursuant to art. 12, par. 3 GDPR.

The exercise of rights is free, except for manifestly unfounded or excessive requests (in particular due to their repetitive nature) for which the Owner may charge a reasonable fee or refuse the request.

12. Right to lodge a complaint with the Supervisory Authority

If you believe that the processing of your personal data is in violation of the GDPR or applicable national legislation, the interested party has the right to lodge a complaint with the competent Supervisory Authority:

Guarantor for the Protection of Personal Data

Piazza Venezia n. 11 – 00187 Roma

Centralino: +39 06 696771

Email: garante@gpdp.it

PEC: protocollo@pec.gpdp.it

Website: www.garanteprivacy.it

The right to appeal to the judicial authorities remains unaffected.

13. Security Measures

The Data Controller adopts adequate technical and organizational measures to guarantee a level of security suitable for the risk, in compliance with the art. 32 GDPR. Among the measures adopted include: HTTPS/TLS encrypted connection throughout the site; periodic updating of the software and components of the Site; periodic backups and disaster recovery procedures; access controls based on the principle of least privilege; strong authentication for administrative accounts; irreversible hashing of passwords with secure cryptographic algorithms; periodic training of people authorized to process; verification and selection of suppliers who guarantee adequate security measures.

In the event of a violation of personal data (data breach) likely to present a risk for the rights and freedoms of natural persons, the Data Controller will provide the notifications required by the articles. 33 and 34 GDPR, informing the Guarantor Authority within 72 hours of becoming aware of the event and, where necessary, the interested parties directly involved.

14. Minors

Registration on the Site and booking experiences are reserved for adults. The participation of minors in outdoor activities is permitted only under the responsibility of the person holding parental responsibility or of their guardian, who must provide consent to the processing of the minor's data and sign the release within the terms established by the organization. The Data Controller does not knowingly collect data from children under 14 years of age without the consent of their parent or guardian.

If it is found that data of a minor under 14 years of age have been communicated without the consent of those exercising parental responsibility, such data will be promptly deleted.

15. Links to Third Party Sites

The Site may contain links to websites managed by third parties (for example: Instagram, Facebook, Google Maps, partner sites and affiliated operators). The Owner is not responsible for the contents, privacy policies or data processing practices of these sites, to which the respective information applies.

16. Changes to this Policy

The Owner reserves the right to update this Privacy Policy at any time, notifying users via publication on the Site. The date of the last update is indicated at the bottom of the title of the document. The user is invited to periodically consult this information to be informed of any changes.

Changes take effect on the date of publication. Continued use of the Site following the publication of the changes constitutes acceptance of the same. For changes that substantially affect the purposes or methods of processing, the Data Controller will specifically inform registered users and request, where necessary, a new consent.

17. Contatti

For any clarification or request relating to this information or the processing of personal data, you can contact the Data Controller at the following addresses:

Levante Outdoor Paradise

Sede: Piazza della Croce 2, 16039 Riva Trigoso, Sestri Levante (GE), Italia

Email: info@levanteoutdoor.it

Phone: +39 333 161 9238

Website: https://levanteoutdoor.it

* * *

Document drawn up in compliance with Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.