Privacy notice on the processing of guests’ personal data
This notice describes solely how Creti Room GuestHouse (website cretiroom.it) processes the personal data of guests in relation to booking, self check-in, identity verification, communications to the authorities, access to the digital guide and, where requested, invoicing. It is not a general privacy notice for the entire website (for cookies, see the Cookie Policy).
1. Data controller
The data controller is:
- Vincenzo Pistoia (natural person who owns the Creti Room GuestHouse property)
- VAT number: 04353620711
- Registered office / address: Via Donato Creti 49, Bologna, 40128
- Email: info@cretiroom.it or vincenzo.pistoia94@gmail.com
No Data Protection Officer (DPO) has been appointed. For any privacy request it is sufficient to contact the Controller at the address indicated above.
2. Categories of data subjects and data
Data subjects: guests (and, where applicable, accompanying persons) who complete check-in or use the digital services linked to the stay.
2.1 Identity and contact data
- first name, last name, date and place of birth, nationality, sex;
- tax code (if required);
- residence / domicile address;
- email, phone number;
- preferred communication language;
- check-in and check-out dates, assigned room, booking references.
2.2 Identity document
- type, number, country of issue, expiry date of the document;
- images of the document (front/back or relevant pages) uploaded during check-in.
2.3 Biometric and identity verification data
Where identity verification is enabled (facial recognition and/or fallback video):
- images / frames of the face captured during the «liveness» check (real person);
- automatic comparison between the live face and the photo on the document;
- verification outcome (e.g. passed, failed, video fallback);
- any short video recorded by the guest as an alternative to automatic verification, for manual review by the host;
- technical metadata (date/time, session identifier, number of attempts).
These are data belonging to special categories under Article 9 GDPR (biometric data processed to uniquely identify a natural person), processed only with the data subject’s explicit consent, where required by the check-in flow.
2.4 Geolocation data
On-site access mode is always required: the device location (approximate GPS coordinates) is verified solely to confirm that the guest is near the property before enabling unlock / delivery of access instructions. Location is not used for continuous tracking.
2.5 Communication and operational traceability data
- acceptance of the privacy notice and, where applicable, of biometric consent (date/time and text version);
- email sending logs (e.g. access guide / instructions);
- status of mandatory communications to the authorities (e.g. guest registration / Ross1000);
- internal operational notes strictly necessary for managing the stay.
2.6 Billing data (only if requested)
If an invoice is issued, the necessary tax data may be processed (billing name, tax code / VAT number, address, SDI code or PEC). The system may generate a FatturaPA XML file that the host uploads manually to the chosen transmission channel (e.g. Aruba portal). Aruba is not used in production as an automatic integration.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Guest registration, stay management, delivery of access instructions / digital guide, assistance | Performance of a contract / pre-contractual measures (Art. 6(1)(b) GDPR) |
| Communication of data to the competent authorities (e.g. Police Headquarters – guest registration forms; regional obligations such as Ross1000 / tourist tax, where applicable) | Legal obligation (Art. 6(1)(c) GDPR) |
| Documentary and tax retention linked to the stay / any invoice | Legal obligation and/or legitimate interest in proper administrative management (Art. 6(1)(c) and (f)) |
| Verification of the guest’s identity via automatic face recognition and/or review video | Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), collected before biometric processing |
| Verification of on-site presence via geolocation (always required) | Performance of a contract and/or legitimate interest in preventing unauthorised access (Art. 6(1)(b) and (f)); where required, consent |
| Service security, prevention of abuse of identity checks, technical logs | Legitimate interest of the Controller (Art. 6(1)(f) GDPR) |
Refusal to provide data required for legal obligations may prevent check-in. Refusal of biometric consent, where verification is required for digital access, may prevent completion of that access mode; in such a case the Controller may indicate managerial alternatives.
4. How we use data in the check-in journey
- The guest completes the self check-in form and uploads images of the document.
- Identity and document data are used to register the stay and, when due, for mandatory communications to the authorities.
- If identity verification is enabled: with explicit consent, the face captured in real time (liveness check) is compared with the document photo via Amazon Rekognition services. In case of repeated negative outcomes, a short video may be requested for manual review.
- «On-site» mode is always required: the device location is checked against the property address before enabling access instructions.
- After the required checks, the digital guide and useful entry information (e.g. keybox code) may be sent to the guest (via email and/or a web page protected by a link), according to the host’s settings.
5. Recipients and processors
Data may be disclosed or made accessible, within the limits of the purposes indicated above, to:
- Public authorities (e.g. Police Headquarters / Portale Alloggiati Web; regional systems such as Ross1000), for legal obligations;
-
Amazon Web Services EMEA (and Amazon group companies necessary for delivery), for:
- Amazon Rekognition (Face Liveness / face comparison) — typical region:
eu-west-1; - Amazon S3 for temporary technical processing of documents, frames and/or verification videos (with no retention beyond the time strictly necessary for verification and communication to the authorities) — typical region:
eu-central-1;
- Amazon Rekognition (Face Liveness / face comparison) — typical region:
- Hosting / email provider used to run the website and send service emails;
- Electronic invoicing intermediary (e.g. Aruba), only if and when the host manually uploads the invoice XML to the relevant portal;
- Any consultants (legal, tax, technical) bound by confidentiality, only if necessary.
Data are not sold to third parties nor used for advertising profiling of guests.
6. Transfers outside the EU
The AWS services used for this processing are configured on regions in the European Union (Rekognition: eu-west-1; S3 storage: eu-central-1). Should transfers to third countries occur due to the provider’s technical needs, they will take place only with appropriate safeguards under the GDPR (e.g. standard contractual clauses / Amazon DPA).
7. Retention periods (criteria adopted)
We retain data only for as long as necessary for the stated purposes and legal obligations. In particular, identity document files and verification images/videos (including biometric material) are not retained on the system or on Amazon S3 beyond the time strictly necessary: they are deleted immediately after the data have been communicated to the competent authorities. Only the textual/identity data necessary for legal compliance remain for the periods indicated below.
Operational criteria adopted:
| Category | Retention |
|---|---|
| Guest identity data, textual document data (type/number), stay history, authority communication logs | For the duration required by public security / hospitality obligations and in any event no longer than 5 years from checkout, unless different legal terms apply |
| Identity document files and images (front/back and uploaded attachments) | Deleted immediately after communication to the competent authorities |
| Biometric data, liveness frames, fallback videos and related verification images | Deleted immediately after communication to the competent authorities |
| Geolocation data from on-site verification | Not retained as a tracking history; used for the check outcome at the time of the request |
| Technical logs / verification attempts (anti-abuse) | Up to 12 months |
| Proof of consent (privacy / biometric) and accepted notice version | For the entire duration of the related processing and for the time needed to demonstrate compliance (as a rule aligned with identity data retention) |
| Billing data / XML | According to applicable civil and tax terms (as a rule up to 10 years) |
Once the periods have expired, data are deleted or anonymised, unless a further retention obligation applies.
8. Processing methods and security measures
Data are processed with IT tools and organisational procedures appropriate to the risk, including:
- access to the management area reserved to authorised staff;
- temporary technical processing of sensitive files on protected storage and/or S3 buckets, with immediate deletion after communication to the authorities;
- transmission over protected channels (HTTPS);
- recording of date/time and version of the accepted notice / consents;
- minimisation: only data necessary for check-in and legal obligations are collected.
9. Data subject rights
The guest may exercise, within the limits of the law, the rights of:
- access, rectification, erasure, restriction, portability;
- objection to processing based on legitimate interest;
- withdrawal of consent (for processing based on consent, including biometric consent), without affecting the lawfulness of prior processing;
- complaint to the Italian Data Protection Authority (www.garanteprivacy.it).
To exercise your rights: info@cretiroom.it or vincenzo.pistoia94@gmail.com. Some erasure requests may be limited if data must still be retained for legal obligations (e.g. guest registration communications already made or still to be made).
10. Minors
The check-in service is intended for adult guests or for those exercising parental / legal responsibility for entering the data of any accompanying minors, within the limits permitted by law.
11. Updates
This notice may be updated for organisational or regulatory reasons. The current version is indicated at the top of the page and referenced when accepting check-in (version field: 2026-07-21).
12. Contacts
For questions about the processing of guests’ data:
Vincenzo Pistoia
Email: info@cretiroom.it
or vincenzo.pistoia94@gmail.com
Web: cretiroom.it