Skip to content

Privacy notice

Last updated: 17 September 2026

This page explains which personal data we collect when you use the Travelplannings website, why we process it, who we share it with and what your rights are, under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003.

1. Data controller

The controller is Simon Software & Services di Paolo Bolla, VAT no. 07360800960, which operates the Travelplannings brand.

For any question about your data or to exercise your rights, write to info@travelplannings.it.

2. Data we collect

  • Browsing the site: the server receives technical data with each request (IP address, browser, page visited), needed to display pages and protect them from abuse.
  • Quote request: first and last name, email, phone (optional), travel dates, number of adults, children (2-12), infants (0-2) and rooms, chosen experiences, services, partners and events, and any notes you write.
  • Protection against automated submissions: an encrypted fingerprint of your IP address (never the address itself), used to limit the number of requests.
  • Customer area: sign-in email, one-time codes sent by email and technical session data.
  • Communication with your consultant: messages exchanged by email or on the customer portal.

For children and infants we only collect the number, never names or other data. Requests must be sent by an adult.

Please do not include health data or other special categories of data in your notes. If the trip requires them (for example accessibility or dietary needs), we will use them only to organise it.

3. Why we process data and on what legal basis

PurposeLegal basis
Preparing and sending your quote, replying to you, showing the status of your requestPre-contractual steps at your request (Art. 6(1)(b) GDPR)
Organising and managing the trip if you confirm the quotePerformance of a contract (Art. 6(1)(b))
Running the customer area and email code sign-inProvision of the service you requested (Art. 6(1)(b))
Protecting the site from abuse and automated submissionsLegitimate interest in service security (Art. 6(1)(f))
Meeting accounting, tax and other legal obligationsLegal obligation (Art. 6(1)(c))

Name and email are required: without them we cannot prepare a quote or reply to you. Phone is optional. We do not use your data for newsletters or advertising and we do not make automated decisions about you.

4. Who receives the data

Data is processed by the controller and its authorised staff. To run the service we rely on providers acting as processors (Art. 28 GDPR), bound by contract:

  • Supabase Inc. — database and customer area authentication; data is stored on servers in the European Union (Frankfurt, Germany).
  • Atlassian (Jira Service Management) — case management and the customer portal where you receive your consultant's messages.
  • Amazon Web Services — website hosting and service emails.

Local partners (accommodation, transport, guides, event organisers) receive only the data needed to check availability or book the services you chose, and only when necessary.

Some providers are based in the United States or may process data outside the European Economic Area. In those cases transfers rely on the EU-US Data Privacy Framework or on the standard contractual clauses approved by the European Commission (Arts. 45-46 GDPR).

Data is never sold or made public.

5. How long we keep data

  • Quote requests not followed by a contract: up to 24 months after the last contact, then deleted or anonymised.
  • Data related to a confirmed trip: 10 years, as required by Italian civil and tax law.
  • Personal link to the status page: active until 6 months after the end of the trip.
  • IP address fingerprint: kept with the request, used only to limit submissions.
  • Customer area sign-in codes: valid for a few minutes.

7. Your rights

At any time you can ask the controller:

  • to access your data and receive a copy (Art. 15);
  • to correct or complete it (Art. 16);
  • to erase it when it is no longer needed or there is no obligation to keep it (Art. 17);
  • to restrict its processing (Art. 18);
  • to receive it in a machine-readable format (Art. 20);
  • to object to processing based on legitimate interest (Art. 21).

Write to info@travelplannings.it: we reply within one month. If you believe the processing breaches the law, you can lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the authority of your country.

8. Changes to this notice

We may update this page when our services or the law change. The date of the last update is shown at the top; the version accepted with each quote request is recorded.