Last updated: 23 September 2026
Privacy Policy
This policy describes how the personal data of users who visit fenixhotel.it and who use its contact form are processed, in accordance with Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (“Privacy Code”).
1. Data controller
The data controller is FENIX — Società a responsabilità limitata, registered office at Viale Gorizia 7, 00198 Rome (RM), Italy — VAT no. 00879321008, tax code 00396860587, REA RM-223484.
For any request concerning the processing of your personal data:
- Email: info@fenixhotel.it
- Certified email (PEC): fenixhotel@pec.it
- Telephone: +39 06 854 0741
The controller has not appointed a Data Protection Officer (DPO).
2. Types of data collected
- Data provided voluntarily by the user through the contact form: first and last name, email address, telephone number (if given), arrival and departure dates, number of guests and the content of the message.
- Browsing data collected automatically by the hosting infrastructure (IP address, browser type, pages visited, date and time of access), used in aggregate form for security purposes.
- Technical cookies, described in detail in the Cookie Policy.
3. Purposes and legal basis of the processing
- Replying to enquiries and booking requests sent through the contact form: legal basis is the performance of pre-contractual measures requested by the data subject (Art. 6.1.b GDPR).
- Security and prevention of abuse (anti-spam filters on the form, protection of the infrastructure): legitimate interest of the controller (Art. 6.1.f GDPR).
The website currently carries out no profiling, analytics or marketing activity: no measurement or advertising tools are installed.
4. How data are processed and how long they are kept
Data are processed using electronic tools and appropriate technical and organisational security measures designed to prevent unauthorised access, loss or destruction of data.
- Enquiries sent through the contact form: for as long as needed to handle the request and any resulting booking, and in any case no longer than 24 months from the last contact.
- Browsing data and technical logs: only for as long as strictly necessary for security.
Data relating to a stay actually booked are kept for the periods required by law for tax records and for the reporting obligations towards the public security authorities.
5. Recipients of the data
Personal data may be disclosed, strictly as necessary for the purposes described above, to parties acting as data processors or independent controllers, including:
- Cloudflare, Inc., which delivers the website and protects its infrastructure.
- The hosting provider that runs the content management system and the sending of the emails generated by the contact form.
- Microsoft Ireland Operations Ltd. (Microsoft 365), which runs the hotel mailboxes that receive the enquiries.
- Google Ireland Ltd., limited to the map on the Location page, which is loaded only after an explicit click by the user.
- Consultants, professionals and suppliers assisting the controller, as well as public authorities where required by law.
Data are never disclosed or sold to third parties for their own commercial purposes. Bookings made through the “Book now” button take place on the booking engine provider's own website, which is subject to its own privacy policy.
6. Transfers outside the EU
Some of the providers listed in section 5 (for example Cloudflare, Microsoft, Google) may process data outside the European Economic Area. In such cases the transfer takes place on the basis of appropriate safeguards provided for by the GDPR, such as the European Commission's Standard Contractual Clauses.
7. Is providing data mandatory?
Providing the data requested in the form is optional but necessary in order to send the enquiry: without them, we cannot follow up on requests for information or bookings.
8. Your rights
You may exercise at any time, by contacting the controller using the details in section 1, the rights set out in Articles 15–22 GDPR, including:
- access to your personal data;
- rectification or erasure;
- restriction of processing;
- objection to processing;
- data portability;
- withdrawal of consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) if you believe that the processing of your data infringes the applicable law.
9. Children
The website is not directed at children under 16 and the controller does not knowingly collect personal data of children without the consent of the holder of parental responsibility.
10. Changes to this policy
The controller may amend or update this policy, including in response to changes in the law. Any changes will be published on this page, together with the date of the latest update.
11. Cookies
For detailed information on the cookies used by this website, their purposes and how to manage them, please see the Cookie Policy.