Privacy Policy
pursuant to the Regulation (UE) 2016/679 (GDPR)
Last updated: 26 June 2026
This information describes the methods of processing the personal data of users who consult and use the website www.moonresortspa.com, in compliance with the Regulation (UE) 2016/679 (“GDPR”), del D.Lgs. 196/2003, as amended by the D.Lgs. 101/2018, as well as applicable national and European legislation..
Use of the Site involves the processing of personal data in the manner and for the purposes indicated in this policy.
Art. 1 – Data controller
The Data Controller is:
ROMA RESORT S.R.L.
Registered office
Via G. Amendola, 46 00195 Roma
VAT number 12585841005
E-mail:
info@moonresortspa.com
For any requests regarding the processing of personal data, you can contact the Data Controller at the email address indicated above.
Art. 2 – Types of data processed
While browsing and using the Site, the following categories of personal data may be collected.
Browsing data
The computer systems automatically acquire some technical information necessary for the functioning of the Site, such as:
- IP address;
- browser used;
- operating system;
- date and time of the visit;
- pages visited;
- referring URL;
- time spent on the site;
- device information.
This data is used exclusively to ensure the correct functioning of the site, for statistical purposes and for security reasons.
Data provided voluntarily by the user
The user may voluntarily provide:
- first and last name;
- email address;
- phone number;
- content of messages sent;
- any requests relating to the stay;
- data required to request availability or booking.
Data collected during bookings
Reservations are managed through the system Booking Engine 5stelle*.
During this process, additional data necessary to manage the stay, conclude the contract, and comply with legal requirements for accommodation facilities may be collected.
For more information on the processing carried out directly by the booking platform, users are also invited to consult the relevant privacy policy of the service provider.
Art. 3 – Purpose of the processing
Personal data are processed for the following purposes.
- a) Management of information requests
Respond to requests sent via:
- contact form;
- email;
- phone.
Legal basis: art. 6, par.1, lett. b) GDPR.
- b) Booking Management
Allow:
- check room availability;
- send quotes;
- manage reservations;
- manage stays;
- provide customer support.
Legal basis: performance of the contract and pre-contractual measures.
- c) Regulatory compliance
Comply with the obligations set forth in the regulations::
- tax;
- administrative;
- accounting;
- public safety;
- regarding accommodation facilities.
Legal basis: legal obligation.
- d) Site security
Ensure the IT security of the Site, prevent unauthorized access, fraudulent activity, and illicit use.
Legal basis: legitimate interest of the Data Controller..
- e) Statistical analysis
The Site uses Google Analytics 4 to analyze traffic in aggregate form and improve the services offered.
Analytical cookies are installed exclusively with the user’s consent, where required by applicable law.
- f) Marketing and advertising
With the user’s prior consent, tools such as:
- Google Ads;
- Google Remarketing;
- Meta Pixel (Facebook e Instagram).
The information collected may be used exclusively for:
- conversion analysis;
- advertising campaign measurement;
- ad personalization;
- remarketing activities.
Consent may be revoked at any time..
Art. 4 – Nature of the transfer
Providing data is optional.
However, failure to provide the data requested in the contact or booking forms may make it impossible to follow up on the user’s request.
Art. 5 – Treatment methods
The data is processed electronically and, where necessary, on paper.
The Data Controller adopts appropriate technical and organizational measures to ensure:
- confidentiality;
- integrity;
- availability;
- data security.
Art. 6 – Data recipients
The data may be communicated to parties operating on behalf of the Data Controller, including:
- hosting providers;
- companies responsible for maintaining the WordPress website;
- companies that manage the Booking Engine 5stelle*;
- tax and accounting consultants;
- IT consultants;
- assigned professionals;
- cloud service providers;
- Google LLC;
- Meta Platforms Ireland Ltd.;
- competent authorities where required by law.
These entities act, where applicable, as Data Processors pursuant to Art. 28 GDPR..
Art. 7 – Transfer of data outside the EU
The use of some technological services (for example, Google and Meta) may involve the transfer of personal data to countries located outside the European Economic Area..
Such transfers occur exclusively in compliance with Articles 44 et seq. of the GDPR and through the adoption of the guarantees provided by European legislation, including the Standard Contractual Clauses (SCC).
Art. 8 – Data Retention
The data will be retained for the time strictly necessary to achieve the purposes for which they were collected.
In particular:
Typology | Retention period |
Information requests | up to 12 months |
Requests for quotes | up to 24 months |
Reservations | in accordance with civil, tax, and administrative obligations |
Marketing | until consent is revoked |
Cookie | in accordance with the Cookie Policy |
Art. 9 – Rights of the data subject
The data subject may exercise the rights provided for in articles 15–22 of the GDPR at any time.
In particular, they have the right to:
- obtain confirmation of the existence of the data;
- access personal data;
- request their rectification;
- obtain their erasure;
- request the restriction of processing;
- object to the processing;
- request data portability;
- withdraw consent previously given;
- lodge a complaint with the Data Protection Authority.
Requests may be sent to the following address:
Art. 10 – Cookie
The Site uses technical cookies necessary for proper functioning.
With the user’s consent, the following may also be installed:
- analytical cookies;
- profiling cookies;
- marketing cookies;
- third-party cookies.
For further information, you can consult the Cookie Policy.
Art. 11 – Links to external sites
The Site may contain links to third-party websites.
The Data Controller is not responsible for the data processing practices of such sites, which operate as independent data controllers.
Users are therefore advised to consult the respective privacy policies.
Art. 12 – Updates
This Privacy Policy may be modified at any time to comply with new regulations or changes to the services offered.
Changes will be published on this page, indicating the date of the last update.