Transparency
Privacy Policy
Last updated: August 2026
1. Data Controller
The data controller (within the meaning of art. 4, no. 7 GDPR) is:
Cooperiamo Insieme Cooperativa Sociale
VAT No. / Tax Code: 02812020598
Registered office: Province of Latina, Lazio, Italy
Email: gsuite@cooperiamoinsieme.it
Data Protection Officer (DPO) and contact point
The Cooperative does not fall under any of the mandatory DPO designation cases provided by art. 37 GDPR and art. 38 of D.Lgs. 101/2018, not being a public authority or body (art. 37, par. 1, lett. a GDPR), not carrying out core activities requiring regular and systematic large-scale monitoring of data subjects (lett. b), nor processing on a large scale special categories of data under art. 9 GDPR or data relating to criminal convictions under art. 10 GDPR (lett. c).
Despite the absence of an obligation, the Cooperative has designated an internal data protection contact point performing the functions of art. 39 GDPR — information and advice, compliance monitoring, cooperation with the Data Protection Authority and contact point for data subjects. For any matter relating to the processing of your personal data — including the exercise of rights (art. 15-22 GDPR), withdrawal of consent (art. 7 GDPR) and information requests (art. 13-14 GDPR) — you can contact:
Data protection contact point
Cooperiamo Insieme Cooperativa Sociale
Email: gsuite@cooperiamoinsieme.it
Subject: "Data protection request — GDPR"
Legal references: Regulation (EU) 2016/679, art. 37 (DPO designation criteria), art. 38 (DPO position), art. 39 (DPO tasks); D.Lgs. of 30 June 2022, no. 101, art. 38 (adaptation of the national privacy code to the GDPR).
2. Categories of Personal Data Processed
We collect the following categories of personal data (art. 13, par. 1, lett. b GDPR):
- Identification data: first and last name of the booking party and participants
- Contact data: email address and phone number
- Booking data: chosen itinerary, guide, date, time slot, formula (private/group), number of participants
- Transaction data: amount paid, payment method (managed by Stripe)
- Usage data: IP address, browser type, referring page, date and time of visit (for security and aggregate statistics)
- User-generated content: published reviews and comments
3. Purposes and Legal Basis of Processing
Personal data is processed for the following purposes, each associated with its legal basis (art. 6 GDPR):
a) Performance of the booking contract
Art. 6 par. 1 lett. b- Receipt, confirmation and organisation of guided tour bookings
- Management of guide availability and time slots
- Synchronisation of bookings on Google Calendar for logistical organisation
- Fulfilment of contractual obligations towards the user
b) Compliance with legal obligations
Art. 6 par. 1 lett. c- Issuing receipts and invoices
- Compliance with accounting and tax obligations under current law
- Retention of tax documents within legal time limits
c) Data subject's consent
Art. 6 par. 1 lett. a- Publication of reviews and user-generated content
- Possible sending of service communications not strictly necessary for contract performance
Consent is given by ticking the acceptance box and may be withdrawn at any time.
d) Legitimate interest
Art. 6 par. 1 lett. f- Sending operational notifications to the manager for new bookings received
- Communications regarding booking status (confirmation, changes, cancellation)
- Fraud prevention and service security protection
- Improving service quality through aggregate analysis
4. Nature of Data Provision
Providing identification, contact and booking data is necessary and mandatory for the conclusion and performance of the booking contract: refusal to provide it makes it impossible to deliver the service.
Providing data for publishing reviews is optional and based on consent; refusal does not prejudice the ability to make bookings.
5. Recipients of Data
Your personal data may be communicated to the following recipients (art. 13, par. 1, lett. e GDPR), as processors (art. 28 GDPR) or autonomous controllers:
Processors
- Base44 Inc. — hosting infrastructure, database and application platform provider. Stores bookings, reviews and user profiles on its servers. Base44 privacy policy
- Stripe, Inc. — payment service provider. Processes transaction data necessary for online payments. Full card details are not stored on our system. Stripe privacy policy
Autonomous controllers
- Google LLC — Google Workspace services (Calendar for appointment management, Gmail for service notifications). Processes data as an autonomous controller. Google privacy policy
Other recipients
- Partner tourist guides — receive the data necessary to deliver the booked service (booking party name, contact details, visit details)
- Public authorities — where required by law (e.g. for tax compliance or upon request of the judicial authority)
The complete list of processors can be requested by contacting the controller.
6. Retention Period
Personal data is retained for the time strictly necessary to achieve the purposes indicated (art. 13, par. 2, lett. a GDPR):
| Data category | Retention period |
|---|---|
| Booking and contact data | 10 years from the service date (for tax and accounting obligations) |
| Transaction and payment data | 10 years (tax obligations; card data managed by Stripe) |
| Reviews and user content | Until deletion requested |
| Usage data (logs, IP) | 12 months from last visit |
| User account | Until account deletion requested |
After the retention period, data is deleted or anonymised, subject to further retention obligations under current law.
7. International Data Transfers
Some of the providers listed above (Base44 Inc., Stripe Inc., Google LLC) may transfer personal data outside the European Economic Area (EEA). Such transfers take place on the basis of European Commission adequacy decisions or, in their absence, appropriate safeguards under art. 46 GDPR (standard contractual clauses, certifications).
You may request a copy of the appropriate safeguards by contacting the controller at the email address indicated.
8. Data Subject Rights
As a data subject, you have the following rights (art. 15-22 GDPR):
Right of access (art. 15)
Obtain confirmation of processing and a copy of your personal data.
Right to rectification (art. 16)
Request the correction of inaccurate data or completion of incomplete data.
Right to erasure (art. 17)
Request the erasure of your data ("right to be forgotten"), subject to legal limits.
Right to restriction (art. 18)
Request the restriction of processing in specific cases provided by law.
Right to portability (art. 20)
Receive your data in a structured format and transmit it to another controller.
Right to object (art. 21)
Object to processing based on legitimate interest or reasons relating to your situation.
Withdrawal of consent (art. 7, par. 3)
Withdraw consent given at any time, without affecting the lawfulness of processing already carried out.
Complaint to the Authority (art. 77)
Lodge a complaint with the Data Protection Authority
How to exercise your rights
You can exercise each of the rights listed above through the following channels. The controller responds without undue delay and in any case within 30 days of receiving the request (art. 12, par. 3 GDPR), extendable by a further two months in case of complexity.
Online form — fill in the form below. The request is sent automatically to the data protection contact point. Also available in your account area.
Self-service in your account area — for portability (art. 20) you can download your data in JSON format; for erasure (art. 17) you can delete your account directly, with immediate effect.
Direct email — write to gsuite@cooperiamoinsieme.it with subject "Data protection request — GDPR".
For access and rectification requests, identity verification will be required. Manifestly unfounded or excessive requests may be refused or subject to a charge (art. 12, par. 5 GDPR).
Exercise your rights
Fill in the form: your request will be sent directly to the data protection contact point. Log in to speed up your request or write to gsuite@cooperiamoinsieme.it
9. Artificial Intelligence Systems
This website uses AI-based systems to support booking management and review moderation, in compliance with the EU AI Act. The data entered may be automatically analysed for service quality purposes.
The use of such systems does not involve automated decisions with legal or significant effects on the user, within the meaning of art. 22 GDPR. You have the right not to be subject to a decision based solely on automated processing.
10. Data Security
The controller implements adequate technical and organisational measures to ensure a level of security appropriate to the risk, in compliance with art. 32 GDPR. These measures include:
Encryption
Data in transit encrypted via TLS/HTTPS. Database and storage encrypted at rest at infrastructure level.
Pseudonymisation
Use of internal identifiers (user_id) instead of direct data in logs and operational tables.
Backup and recovery
Periodic automated backups and recovery procedures to ensure availability and resilience.
Access control
Row-Level Security on every entity: each user accesses only their own data. Mandatory authentication and differentiated roles.
Periodic testing
Periodic verification of the effectiveness of security measures through internal audits and continuous access monitoring.
External processors
Contracts with processors (Base44, Stripe, Google) that guarantee adequate security measures.
In the event of a personal data breach posing a risk to the rights and freedoms of data subjects, the controller notifies the competent supervisory authority within 72 hours (art. 33 GDPR) and, if necessary, communicates the means of protection to data subjects (art. 34 GDPR).
11. Cookie Policy
This section provides detailed information on the cookies and similar technologies used on the site, in compliance with art. 13 GDPR and the ePrivacy Directive (Directive 2002/58/EC).
10.1 What cookies are
Cookies are small text files that visited websites send to the user's device, where they are stored to be transmitted back to the same sites on subsequent visits. They are used for authentication, session tracking and storing preferences.
10.2 Categories of cookies used
The site uses the following types of cookies:
Necessary technical cookies
Always activeArt. 122 par. 1 Privacy CodeUsed for the correct functioning of the site. Do not require prior consent.
| Cookie | Purpose | Duration |
|---|---|---|
cookie_consent | Stores the user's choice on the cookie banner | 6 months |
session_token | Authentication and maintenance of the user session | Session (deleted on browser close) |
csrf_token | Protection against cross-site request forgery attacks | Session |
First-party analytics cookies
Consent requiredArt. 6 par. 1 lett. aUsed to collect aggregate statistics on site usage. Activated only after consent.
| Cookie | Purpose | Duration |
|---|---|---|
site_visit | Aggregate tracking of page visits | 12 months |
Third-party cookies
Consent requiredArt. 6 par. 1 lett. aCookies installed by external providers. Activated only after explicit consent.
- Google LLC — Google Analytics (usage statistics), Google Maps (interactive maps). Google cookie policy
10.3 Cookies not used
The site does not use profiling cookies to send targeted advertising messages, nor social media cookies for advertising tracking.
10.4 Legal basis
- Technical cookies: do not require consent (art. 122, par. 1 of the Privacy Code; art. 5, par. 3 ePrivacy Directive)
- Analytics and third-party cookies: installed only with the user's freely given, specific and informed consent (art. 6, par. 1, lett. a GDPR; art. 122, par. 2 of the Privacy Code)
10.5 How to withdraw consent
You may withdraw your consent to non-technical cookies at any time. Withdrawal does not affect the lawfulness of processing already carried out (art. 7, par. 3 GDPR).
Option 1 — Cookie banner
Click the cookie banner icon at the bottom of the page to reopen preferences and change or revoke previously given consent.
Option 2 — Browser settings
You can manage or disable cookies directly from your browser settings:
Disabling technical cookies may compromise the functioning of the site (e.g. access to the account area).
Option 3 — Contact the controller
Send a request to gsuite@cooperiamoinsieme.it to ask for the deletion of cookies associated with your session.
10.6 Duration and retention
Cookies have variable durations as indicated in the table in section 10.2. Session cookies are deleted when the browser is closed. Persistent cookies remain until the indicated expiry or until deleted by the user.
12. Changes to this Policy
The controller reserves the right to update or amend this policy to adapt it to any new regulations or changes in the services offered. Changes take effect from the date of publication on this page. We invite you to check this page periodically.
13. Contacts
To exercise your rights, withdraw consent or for any questions about the processing of your personal data, contact the controller:
Cooperiamo Insieme Cooperativa Sociale
VAT No. / Tax Code: 02812020598
Email: gsuite@cooperiamoinsieme.it