Who processes your data
Hidden Sicily is run by two parties who are joint controllers under Article 26 of Regulation (EU) 2016/679:
- Network and software consulting di Lauria Marco — Via Antonio Scavo 56, 90146 Palermo, Italy, VAT 05338360828. Looks after the website, the contact form, email and the security of the infrastructure.
- Kalesa Viaggi di Glorioso Gianluca & C. S.N.C. — Via Sardegna 72, 90144 Palermo, Italy, VAT 03843580824. Receives the enquiry, prepares the quotation and organises the travel services as technical organiser.
For any question about this notice, or to exercise your rights, write to [email protected]: your request counts towards both controllers, who coordinate with each other to answer you.
What we collect
From the contact form we collect your name, email address and message, which are required, and then company, telephone, source market, type of request, travel period, number of participants and indicative budget, which are optional. We ask only for what we need in order to understand the enquiry and reply to it.
We do not ask for special category data — health, beliefs, memberships — and we ask you not to include any in your message.
The form stores nothing on the website: enquiries are sent by email to our mailbox. If sending fails, what you typed stays for ten minutes in a temporary area of the server, only so the form can be filled back in for you, and is then discarded.
From the server, as on any website, IP addresses and technical connection details are recorded in the logs and in the security systems.
We do not track your browsing and we build no advertising profiles. If you accept statistics cookies, Google Analytics collects in aggregate form the pages viewed, the country you are in and the kind of device you use; without your consent it is not loaded at all.
Why we process the data, and on what basis
- Answering your enquiry and preparing a proposal — Art. 6(1)(b): steps taken at your request before entering into a contract. Without name, email and message we cannot reply.
- Organising the services if the proposal is accepted — Art. 6(1)(b): performance of the contract.
- Protecting the site from automated submissions and abuse — Art. 6(1)(f): our legitimate interest in keeping the infrastructure secure and working.
- Counting visits to the site — Art. 6(1)(a): your consent, which you can withdraw at any time from Cookie preferences at the bottom of every page.
- Keeping accounting and tax records — Art. 6(1)(c): legal obligation.
Who we share the data with
- Travel suppliers needed to build and then deliver the programme: accommodation, guides, transport companies, restaurants and local partners. We pass on only what the individual booking requires.
- Aruba S.p.A., which hosts the server, and Affiance Group, which runs the mail service the enquiries travel on.
- Cloudflare, Inc., which sits in front of the site as a delivery network and security filter and processes IP addresses for that purpose.
- Defiant, Inc., for the Wordfence security system installed on the site.
- Google Ireland Limited, for Google Analytics — but only if you have accepted statistics cookies.
- Accountants and lawyers, and public authorities where the law requires it.
These parties act as processors, or as controllers in their own right for their own part. We do not sell or pass on your data to anyone for commercial purposes.
Where the data is, and how long we keep it
The server is in Italy, with Aruba S.p.A. in the province of Bergamo, and the mail runs on European infrastructure. Cloudflare may process data outside the European Union: in that case protection rests on the standard contractual clauses approved by the European Commission. The same holds for Google, which with your consent may process the statistics data in the United States as well: that transfer is covered by the EU-US Data Privacy Framework adequacy decision as well as by standard contractual clauses.
- Enquiries that do not become an accepted quotation: 24 months from the last contact.
- Concluded contracts and the related tax documents: 10 years, as the law requires.
- Server logs and security data: a few months, for as long as is technically necessary.
- Statistics data, if you accepted it: no more than 14 months.
Your rights
At any time you may ask us to give you access to your data, correct it, delete it, restrict its use, hand it to you in a machine-readable format, or object to processing based on legitimate interest. Write to [email protected]: we answer within one month.
If you believe the processing breaches the Regulation you may contact the Italian supervisory authority, Garante per la protezione dei dati personali (garanteprivacy.it), or the authority of the country where you live.
Cookies
This site uses no profiling cookies. The only cookies that may appear are those of Google Analytics, and only if you accept them. The details are in the Cookie policy.
Updates
Last updated: 25 September 2026. If the way we handle data changes, we will update this page and the date above.