Privacy and personal data

What we collect, why, for how long, and what you can ask us. Last updated: 24 August 2026.

In short

We collect your data only to handle your booking: name, contact details, stay dates and payment. We do not profile you, we use no tracking cookies, and we never pass your data to anyone for commercial purposes.

To take payments, send emails and store bookings we rely on specialised providers, each named below. Your card details never pass through our systems.

Who processes your data

The data controller is Paola Saitta, Via Damiano Rosso 13, 98039 Taormina (ME), Italy. For any request concerning your data, write to Booking@casaawayataormina.it.

What we collect and why

When you send a booking request we collect your name to register the booking, your email address to send confirmations, reminders and arrival instructions, your phone number to reach you if needed, your country if you provide it, the number of guests and children to calculate the price and the city tax, the dates of your stay and any special requests you write.

Legal basis: performance of a contract or pre-contractual steps at your request (Art. 6.1.b GDPR).

When you pay

Payment is handled by Stripe. Your card details — number, expiry, security code — are entered in a form provided by Stripe and travel from your browser to their servers: they never pass through our systems and we neither see nor store them. For each payment we keep only a technical reference, the amount and the date.

Legal basis: performance of the contract and, for accounting records, legal obligation (Art. 6.1.b and 6.1.c GDPR).

When you visit the site

This site uses no profiling cookies, has no traffic analytics and does not follow you across other sites. The only thing stored in your browser is the language you chose. Servers automatically log technical connection data (IP address, date and time, page requested) for security and to prevent abuse.

Legal basis: legitimate interest in the security of the site (Art. 6.1.f GDPR).

On arrival

At check-in, as required by Italian public security law, the person welcoming you records the details of each guest’s identity document and submits them to the Alloggiati Web portal of the Italian State Police. This is done in person: the website neither requests nor stores copies of documents.

Legal basis: legal obligation (Art. 6.1.c GDPR, Art. 109 TULPS).

Who we share your data with

To run the booking we rely on the providers listed below. Each processes data on our behalf, under a contract limiting use to service purposes only.

  • Stripe Payments Europe, Ltd. — payment data, name, email, phone. Ireland, with transfers to the United States.
  • Resend (Plus Five Five, Inc.) — name, email and the content of messages sent. United States.
  • Neon Inc. — booking records: name, email, phone, country, notes, dates and amounts. Servers in Germany; company based in the United States.
  • Vercel Inc. — page delivery and technical connection data. United States, with delivery in Europe.
  • Aruba S.p.A. — email and domain registration. Italy.

We also share data required by law with public security authorities and, for the city tax, with the Municipality of Taormina. We do not sell, rent or pass your data to third parties for marketing.

Transfers outside the European Union

Some of the providers listed are based in the United States, so your data may be processed outside the European Economic Area. These transfers rely on the Standard Contractual Clauses approved by the European Commission and, for participating providers, on the EU-U.S. Data Privacy Framework. You may request a copy by writing to the address above.

How long we keep your data

  • Requests not completed, declined or expired: 24 months, then automatic deletion.
  • Confirmed bookings: 10 years from the end of the stay, under civil and tax law.
  • Accounting records and payment data: 10 years, by legal obligation.
  • Log of messages sent: 24 months.
  • Technical connection data: per the provider’s policy, normally no more than 12 months.
  • Identity document details: not kept by us — submitted to the authorities and not archived.

Your rights

At any time you may ask us to access the data concerning you and receive a copy, correct inaccurate data, erase your data where no legal obligation requires us to keep it, restrict or object to processing, and receive your data in a machine-readable format to transfer it elsewhere.

To exercise these rights write to Booking@casaawayataormina.it: we will reply within one month. If you believe the processing breaches the law you may contact the Italian Garante per la protezione dei dati personali or the supervisory authority of your country of residence.

Some data is necessary to book: if you choose not to provide it we cannot proceed with the request, but no other consequence follows.

Security

The site uses an encrypted connection on every page. Access to the booking records is restricted to the owner, protected by temporary links sent to authorised addresses, with no stored passwords. Card data is not in our possession: it is held by Stripe, certified to PCI-DSS Level 1.

Changes to this notice

If we change how we process data we will update this page and the date at the top. Bookings already under way remain governed by the notice in force when the request was made.

Casa Awaya Taormina Whole house · up to 7 guests · from 3 nights
Check the dates