Privacy notice on the processing of guests’ personal data

Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 («GDPR»)
Version: 2026-07-21 · Last updated: 21 July 2026

This notice describes solely how Creti Room GuestHouse (website cretiroom.it) processes the personal data of guests in relation to booking, self check-in, identity verification, communications to the authorities, access to the digital guide and, where requested, invoicing. It is not a general privacy notice for the entire website (for cookies, see the Cookie Policy).

1. Data controller

The data controller is:

No Data Protection Officer (DPO) has been appointed. For any privacy request it is sufficient to contact the Controller at the address indicated above.

2. Categories of data subjects and data

Data subjects: guests (and, where applicable, accompanying persons) who complete check-in or use the digital services linked to the stay.

2.1 Identity and contact data

2.2 Identity document

2.3 Biometric and identity verification data

Where identity verification is enabled (facial recognition and/or fallback video):

These are data belonging to special categories under Article 9 GDPR (biometric data processed to uniquely identify a natural person), processed only with the data subject’s explicit consent, where required by the check-in flow.

2.4 Geolocation data

On-site access mode is always required: the device location (approximate GPS coordinates) is verified solely to confirm that the guest is near the property before enabling unlock / delivery of access instructions. Location is not used for continuous tracking.

2.5 Communication and operational traceability data

2.6 Billing data (only if requested)

If an invoice is issued, the necessary tax data may be processed (billing name, tax code / VAT number, address, SDI code or PEC). The system may generate a FatturaPA XML file that the host uploads manually to the chosen transmission channel (e.g. Aruba portal). Aruba is not used in production as an automatic integration.

3. Purposes and legal bases

Purpose Legal basis
Guest registration, stay management, delivery of access instructions / digital guide, assistance Performance of a contract / pre-contractual measures (Art. 6(1)(b) GDPR)
Communication of data to the competent authorities (e.g. Police Headquarters – guest registration forms; regional obligations such as Ross1000 / tourist tax, where applicable) Legal obligation (Art. 6(1)(c) GDPR)
Documentary and tax retention linked to the stay / any invoice Legal obligation and/or legitimate interest in proper administrative management (Art. 6(1)(c) and (f))
Verification of the guest’s identity via automatic face recognition and/or review video Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), collected before biometric processing
Verification of on-site presence via geolocation (always required) Performance of a contract and/or legitimate interest in preventing unauthorised access (Art. 6(1)(b) and (f)); where required, consent
Service security, prevention of abuse of identity checks, technical logs Legitimate interest of the Controller (Art. 6(1)(f) GDPR)

Refusal to provide data required for legal obligations may prevent check-in. Refusal of biometric consent, where verification is required for digital access, may prevent completion of that access mode; in such a case the Controller may indicate managerial alternatives.

4. How we use data in the check-in journey

  1. The guest completes the self check-in form and uploads images of the document.
  2. Identity and document data are used to register the stay and, when due, for mandatory communications to the authorities.
  3. If identity verification is enabled: with explicit consent, the face captured in real time (liveness check) is compared with the document photo via Amazon Rekognition services. In case of repeated negative outcomes, a short video may be requested for manual review.
  4. «On-site» mode is always required: the device location is checked against the property address before enabling access instructions.
  5. After the required checks, the digital guide and useful entry information (e.g. keybox code) may be sent to the guest (via email and/or a web page protected by a link), according to the host’s settings.

5. Recipients and processors

Data may be disclosed or made accessible, within the limits of the purposes indicated above, to:

Data are not sold to third parties nor used for advertising profiling of guests.

6. Transfers outside the EU

The AWS services used for this processing are configured on regions in the European Union (Rekognition: eu-west-1; S3 storage: eu-central-1). Should transfers to third countries occur due to the provider’s technical needs, they will take place only with appropriate safeguards under the GDPR (e.g. standard contractual clauses / Amazon DPA).

7. Retention periods (criteria adopted)

We retain data only for as long as necessary for the stated purposes and legal obligations. In particular, identity document files and verification images/videos (including biometric material) are not retained on the system or on Amazon S3 beyond the time strictly necessary: they are deleted immediately after the data have been communicated to the competent authorities. Only the textual/identity data necessary for legal compliance remain for the periods indicated below.

Operational criteria adopted:

Category Retention
Guest identity data, textual document data (type/number), stay history, authority communication logs For the duration required by public security / hospitality obligations and in any event no longer than 5 years from checkout, unless different legal terms apply
Identity document files and images (front/back and uploaded attachments) Deleted immediately after communication to the competent authorities
Biometric data, liveness frames, fallback videos and related verification images Deleted immediately after communication to the competent authorities
Geolocation data from on-site verification Not retained as a tracking history; used for the check outcome at the time of the request
Technical logs / verification attempts (anti-abuse) Up to 12 months
Proof of consent (privacy / biometric) and accepted notice version For the entire duration of the related processing and for the time needed to demonstrate compliance (as a rule aligned with identity data retention)
Billing data / XML According to applicable civil and tax terms (as a rule up to 10 years)

Once the periods have expired, data are deleted or anonymised, unless a further retention obligation applies.

8. Processing methods and security measures

Data are processed with IT tools and organisational procedures appropriate to the risk, including:

9. Data subject rights

The guest may exercise, within the limits of the law, the rights of:

To exercise your rights: info@cretiroom.it or vincenzo.pistoia94@gmail.com. Some erasure requests may be limited if data must still be retained for legal obligations (e.g. guest registration communications already made or still to be made).

10. Minors

The check-in service is intended for adult guests or for those exercising parental / legal responsibility for entering the data of any accompanying minors, within the limits permitted by law.

11. Updates

This notice may be updated for organisational or regulatory reasons. The current version is indicated at the top of the page and referenced when accepting check-in (version field: 2026-07-21).

12. Contacts

For questions about the processing of guests’ data:
Vincenzo Pistoia
Email: info@cretiroom.it or vincenzo.pistoia94@gmail.com
Web: cretiroom.it