LEGAL

Privacy Policy

We believe discretion is part of good hospitality. This policy explains, plainly, what personal data we handle when you contact us through this website, why, and the rights you have over it.

Last updated: 6 October 2026

This Privacy Policy explains how SAVORING EXPERIENCES S.R.L. ("Savoring Experiences", "we", "us" or "our") collects and uses the personal data of people who visit the website savoringexperiences.com (the "Website"), contact us, request a quote or book our travel services and experiences. It is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and with Legislative Decree no. 196/2003 as amended by Legislative Decree no. 101/2018 (the Italian Personal Data Protection Code, the "Privacy Code").

Contents

  1. Data controller
  2. Website management and hosting
  3. Personal data we process
  4. Purposes, legal bases and retention periods
  5. Children and data about other people
  6. Protection of our forms: Cloudflare Turnstile
  7. Cookies and similar technologies
  8. Is providing your data mandatory?
  9. How we process and protect your data
  10. Who we share your data with
  11. Transfers outside the European Economic Area
  12. Your rights
  13. Automated decision-making
  14. Links to other websites and social networks
  15. Changes to this Privacy Policy

1. Data controller

The data controller is:

Savoring Experiences is an online Tour Experiences Operator with its registered office in the Municipality of Venice, operating under a certified notice of commencement of activity (SCIA) filed with the Veneto Region, Protocol no. 499440 of 7 September 2026.

For any question about this Privacy Policy or about the processing of your personal data, you can contact us at info@savoringexperiences.com.

2. Website management and hosting

The Website is hosted by Aruba S.p.A., Via San Clemente 53, 24036 Ponte San Pietro (BG), Italy, on servers located in the European Union.

The domain name and the hosting service are registered in the name of Queenlike Concierge S.r.l., Largo Valtournanche 13, Rome, Italy (VAT number IT17613391006), which manages the Website's content and multimedia materials on our behalf. Where these activities involve access to personal data (for example, data stored on the server or in the Website's administration area), Queenlike Concierge S.r.l. acts as a data processor appointed by us under Article 28 GDPR, and Aruba S.p.A. acts as a sub-processor solely for the purpose of providing the hosting service. Both may process personal data only on documented instructions and for the purposes described in this Privacy Policy.

3. Personal data we process

3.1 Browsing data

The computer systems and software that operate the Website automatically acquire, during their normal operation, some data whose transmission is implicit in the use of internet communication protocols. This includes IP addresses, browser type and version, operating system, the addresses (URLs) of the resources requested, the date and time of the request, the method used to submit it, the size of the response, the response code returned by the server and the referring page. This data is not collected in order to identify you, but it could allow identification if combined with other data, for example in the event of an investigation into a cybercrime.

3.2 Data you provide when you contact us

When you fill in a form on the Website, write to us by email or contact us by phone or through a messaging app (for example WhatsApp), we process the data you choose to share with us, such as your first name and surname, email address, telephone number, country, preferred language, the experience or service you are interested in, travel dates, the number and age range of participants, your preferences and any other information you include in your message. If you contact us through a messaging app, the provider of that app also processes your data as an independent controller under its own privacy policy.

3.3 Data needed to book and provide our services

If you book a travel service or an experience with us, we may also process: the names of all participants; date of birth or age, where the service requires it (for example, for activities involving the tasting of alcoholic beverages, which are reserved for adults, or to apply reduced rates for children); identity document details, only where required by a supplier or by law (for example, for some accommodation or transport services); arrival and departure details, accommodation address and meeting or pick-up points; billing details (name or company name, address, tax code or VAT number); payment information; and the communications relating to your booking.

When you pay by card or through other online payment services, your payment details are entered directly into the secure systems of the bank or payment service provider. We do not have access to your full card details: we only receive confirmation of the payment and limited information such as the amount, date, payment method and transaction reference.

3.4 Special requirements

If you choose to tell us about food allergies or intolerances, dietary requirements, health conditions or accessibility needs, we may process data that the GDPR classifies as "special categories of personal data" (Article 9 GDPR): data concerning health and, in some cases, data that may reveal religious beliefs (for example, a request for kosher or halal meals). Section 4.3 explains how we handle this data.

3.5 Data we receive from third parties

In some cases we receive your data from other people or organisations, for example from the person who makes a booking for you (such as a family member, a friend, your employer or an event organiser), or from travel agencies, tour operators, online booking platforms, hotels and concierge services that book our services on your behalf. In these cases we receive only the data needed to organise and provide the service, typically your name, contact details, booking details and any special requirements.

4. Purposes, legal bases and retention periods

We process your personal data only for the purposes listed below. For each purpose we indicate the legal basis and how long we keep the data. At the end of the retention period, the data is deleted or irreversibly anonymised.

4.1 Replying to your requests and preparing quotes

We use the data you send us to answer your questions, give you information about our experiences and prepare quotes and tailor-made proposals.

  • Legal basis: the performance of pre-contractual measures taken at your request (Art. 6(1)(b) GDPR); for general enquiries not related to a possible booking, our legitimate interest in replying to the messages we receive (Art. 6(1)(f) GDPR).
  • Retention: for the time needed to handle your request. If no booking follows, we keep the correspondence for up to 12 months from our last contact, so that we can deal with any follow-up, and then delete it.

4.2 Booking, organising and providing our services

We use your data and the data of the other participants to manage your booking, organise the services included (such as tastings, guided visits, transfers, accommodation, restaurant reservations and other activities), communicate with the suppliers involved, send you confirmations and practical information, manage payments, changes, cancellations and refunds, and assist you before and during your experience or trip.

  • Legal basis: the performance of the contract concluded with you or in favour of the participants (Art. 6(1)(b) GDPR) and, where applicable, compliance with the obligations of travel organisers and retailers under the Italian Tourism Code (Legislative Decree no. 79/2011), such as the obligation to assist travellers in difficulty (Art. 6(1)(c) GDPR).
  • Retention: for the duration of the contractual relationship and, after it has ended, for 10 years, corresponding to the ordinary limitation period under Italian law (Art. 2946 of the Italian Civil Code).

4.3 Special requirements: allergies, dietary needs, health and accessibility

If you tell us about food allergies or intolerances, dietary requirements, health conditions or accessibility needs, we use this information only to adapt the service to your needs and to ensure your safety, and we share it only with the suppliers who need it to provide the service (for example the restaurant, chef, producer or guide). We collect only the information that is strictly necessary and we do not use it for any other purpose.

  • Legal basis: your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw at any time; in an emergency, where you are unable to give consent, the protection of your vital interests (Art. 9(2)(c) GDPR).
  • Retention: until the end of the service; the information is then deleted within 90 days, unless it is needed to establish, exercise or defend legal claims.

If you prefer not to share this information, or if you withdraw your consent, we will not be able to adapt the service to your special requirements.

4.4 Compliance with legal obligations

We process your data to comply with the obligations laid down by law, including tax and accounting obligations, the issuing of invoices (also electronically, through the Italian Exchange System, SDI), obligations under tourism legislation and requests from public and judicial authorities.

  • Legal basis: compliance with a legal obligation to which we are subject (Art. 6(1)(c) GDPR).
  • Retention: for the period required by law; in particular, accounting records and invoices are kept for 10 years (Art. 2220 of the Italian Civil Code).

4.5 Website operation and security

We process browsing data and the signals collected by Cloudflare Turnstile (see section 6) to make the Website available, keep it secure, protect our forms from spam and automated abuse, and identify and prevent malicious activity.

  • Legal basis: our legitimate interest in ensuring the security and correct functioning of the Website (Art. 6(1)(f) GDPR).
  • Retention: browsing data is kept only for the time strictly necessary for these purposes, according to the log retention settings of our hosting provider, and is then deleted, unless it is needed to investigate a security incident or is requested by the judicial authority.

4.6 Establishing, exercising or defending legal claims

Where necessary, we may process your data to establish, exercise or defend our rights, including in court or out-of-court proceedings.

  • Legal basis: our legitimate interest in protecting our rights (Art. 6(1)(f) GDPR) and, for special categories of data, Art. 9(2)(f) GDPR.
  • Retention: for the duration of the dispute and until the time limits for appeals have expired.

4.7 Newsletters and promotional communications

If you subscribe to our newsletter or otherwise give us your specific consent, we will send you news, offers and invitations relating to our experiences by email. If you have already booked with us, we may also send you emails about experiences similar to the ones you purchased, using the email address you provided at the time of booking. You can object to these emails at any time, free of charge, using the unsubscribe link included in every email or by writing to us.

  • Legal basis: your consent (Art. 6(1)(a) GDPR and Art. 130 of the Privacy Code), which you can withdraw at any time; for emails to existing customers about similar services, our legitimate interest in promoting our services (Art. 6(1)(f) GDPR and Art. 130(4) of the Privacy Code).
  • Retention: until you unsubscribe, withdraw your consent or object.

4.8 Photos and videos during our experiences

We will not publish photos or videos in which you are recognisable on the Website, on our social media channels or in our promotional materials without your prior consent. If we would like to use such images, we will ask you first.

  • Legal basis: your consent (Art. 6(1)(a) GDPR), in compliance with Italian rules on the protection of personal image (Art. 10 of the Italian Civil Code and Articles 96 and 97 of Law no. 633/1941).
  • Retention: until you withdraw your consent, after which we will remove the images from the channels under our control within a reasonable time.

4.9 Job applications

If you send us your CV, we use it only to assess your application.

  • Legal basis: pre-contractual measures taken at your request (Art. 6(1)(b) GDPR and Art. 111-bis of the Privacy Code).
  • Retention: up to 12 months from receipt, unless you ask us to delete it earlier.

5. Children and data about other people

Children. The Website is not directed at children under the age of 14, and we do not knowingly collect personal data directly from them online. Data about minors taking part in our experiences (for example name, age and dietary needs) is provided by, and processed with the agreement of, a parent or other person with parental responsibility.

Other participants. If you give us data about other people, for example your travel companions, you confirm that you are entitled to do so and that you have made them aware of this Privacy Policy. Please share information about another adult's health or other special categories of data only with that person's explicit consent; where appropriate, we may ask them to confirm it directly.

6. Protection of our forms: Cloudflare Turnstile

To protect the forms on the Website from spam, bots and other automated abuse, we use Cloudflare Turnstile, a security service provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States ("Cloudflare").

Turnstile is configured in invisible mode: no box, puzzle or widget is displayed and you do not need to do anything. The check runs automatically in the background on the pages that contain our forms, and its result is verified by our server when you submit a form.

To distinguish people from bots, Turnstile processes a limited set of technical signals from your browser and connection, such as your IP address, TLS fingerprint, User-Agent header and the site key and origin of the page you are visiting. According to Cloudflare, these signals are used solely to detect and block bots, not to identify, profile or target individuals. We do not store these signals ourselves: we only receive the outcome of the check.

  • Roles: when it performs bot detection for our Website, Cloudflare acts as our data processor. Cloudflare also uses the signals as an independent data controller to improve Turnstile's bot-detection capabilities, on the basis of its own legitimate interest.
  • Legal basis: our legitimate interest in protecting the Website and our forms from spam and fraudulent use (Art. 6(1)(f) GDPR). Because the signals are strictly necessary to provide the forms you choose to use in a secure way, this processing does not require your consent.
  • Transfers and retention: Cloudflare may process the signals in the United States and in other countries where it operates. Cloudflare is certified under the EU-U.S. Data Privacy Framework and also relies on the European Commission's Standard Contractual Clauses (see section 11). Cloudflare retains the signals in accordance with its own policies.

For more information, please read Cloudflare's Turnstile Privacy Addendum and the Cloudflare Privacy Policy. You can contact Cloudflare's Data Protection Officer at dpo@cloudflare.com. If you are unable to submit a form, for example because of your browser settings or an outdated browser, you can always contact us directly at info@savoringexperiences.com.

7. Cookies and similar technologies

The Website uses technical cookies that are necessary for it to work and, only with your consent where required by law, other cookies and similar technologies. Full information, including the list of cookies used, their purposes and duration, and how to give, refuse or withdraw your consent at any time, is available in our Cookie Policy.

8. Is providing your data mandatory?

Browsing data is acquired automatically when you use the Website. Data marked as mandatory in our forms, and the data needed to manage a booking, are necessary to reply to your request or to provide the service: without them we cannot handle your request or complete your booking. All other data is optional. Information about allergies, health or other special requirements is also optional, but if you do not provide it we cannot adapt the service to your needs. Giving your consent to marketing communications is entirely optional and has no effect on your requests or bookings.

9. How we process and protect your data

Your data is processed with electronic and, where necessary, paper-based tools, by our staff and collaborators who have been authorised and instructed to do so and who are bound by confidentiality (Art. 29 GDPR and Art. 2-quaterdecies of the Privacy Code). We adopt appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration and destruction, including encrypted connections, access controls and backups. We do not use the data you provide in forms or bookings for profiling.

10. Who we share your data with

We share your data only to the extent necessary for the purposes described above, with the following categories of recipients:

  • Suppliers of the services included in your booking, such as accommodation providers, transport and transfer companies, guides, restaurants, wineries, producers and other experience providers, who process the data as independent controllers in order to provide their services.
  • Other travel operators, such as travel agencies, tour operators and booking platforms involved in your booking, as independent controllers.
  • Insurance companies, where you purchase a travel insurance policy through us, or for the management of claims under our liability insurance and the insolvency protection required by law.
  • Banks and payment service providers, for the management of payments and refunds, as independent controllers.
  • Service providers acting as our data processors, including Queenlike Concierge S.r.l. (Website management), Aruba S.p.A. (hosting), Cloudflare, Inc. (protection of our forms) and the providers of the email, cloud storage, booking management and accounting services we use.
  • Professional advisers, such as accountants, tax advisers and lawyers, who are bound by professional secrecy.
  • Public and judicial authorities, where required by law.

Your data is not disseminated and is never sold. An up-to-date list of our data processors is available on request.

11. Transfers outside the European Economic Area

We process your data mainly within the European Economic Area (EEA). Some service providers, such as Cloudflare, Inc., may process data in the United States or in other countries outside the EEA. In these cases, transfers take place on the basis of an adequacy decision of the European Commission, such as the EU-U.S. Data Privacy Framework for certified companies, or of the Standard Contractual Clauses adopted by the European Commission (Art. 46 GDPR). If your booking includes services provided in a country outside the EEA, we transfer to the suppliers concerned only the data necessary to perform the contract (Art. 49(1)(b) and (c) GDPR). You can obtain information about the safeguards adopted by writing to us.

12. Your rights

Under Articles 15 to 22 GDPR, you have the right to:

  • access your personal data and receive a copy of it;
  • have inaccurate data corrected and incomplete data completed;
  • have your data erased, where the conditions laid down by law are met;
  • obtain the restriction of processing;
  • receive the data you provided to us in a structured, commonly used and machine-readable format and have it transmitted to another controller (data portability), where processing is based on your consent or on a contract and is carried out by automated means;
  • withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Right to object. You have the right to object at any time, on grounds relating to your particular situation, to the processing of your data based on our legitimate interest. You can also object at any time, without having to give reasons, to the use of your data for direct marketing purposes, including by using the unsubscribe link included in each email.

To exercise your rights, write to info@savoringexperiences.com or, from a certified email address, to savoringexperiences@pec.it. We will reply without undue delay and in any case within one month of receiving your request. This period may be extended by two further months where necessary, taking into account the complexity and number of requests; in that case we will let you know within the first month. Exercising your rights is free of charge. We may ask you for information to verify your identity.

Right to lodge a complaint. If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy; www.garanteprivacy.it; email: protocollo@gpdp.it; certified email: protocollo@pec.gpdp.it) or with the supervisory authority of the EU Member State where you habitually reside or work or where the alleged infringement took place. You also have the right to take legal action before the competent courts.

13. Automated decision-making

We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. The automatic check carried out by Cloudflare Turnstile only verifies that a form is being used by a person rather than a bot; if you cannot submit a form, you can always contact us by email.

The Website may contain links to third-party websites and to our pages on social networks. We are not responsible for the content or the privacy practices of these websites and services: when you visit them or interact with our pages, your data is processed by their operators in accordance with their own privacy policies. Where we manage pages on social networks, we may act as joint controllers with the platform provider for certain processing, such as page statistics, in accordance with the terms published by the provider.

15. Changes to this Privacy Policy

We may update this Privacy Policy, for example to reflect changes in the law or in our services. The current version is always available on this page, with the date of the latest update shown at the top. This version replaces all previous versions published on the Website. Where changes are significant, we will inform you by appropriate means.