Data protection
Privacy Policy
Last updated: 24.06.2026
This policy describes how La Scogliera S.r.l. processes the personal data of users who visit this website and use our services (sunbed booking, contact, table reservations), pursuant to Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended ("Privacy Code").
1. Data Controller
The Data Controller is La Scogliera S.r.l., registered office at Viale Ungheria 16, 80059 Torre del Greco (NA), Italy, VAT no. 11027741211.
- Operating site (beach club): Via Alcide de Gasperi 127, Torre del Greco (NA), Italy.
- Email: info@lascoglieratorredelgreco.it
- SDI code: 5RUO82D.
No Data Protection Officer (DPO) has been appointed, as it is not mandatory for our activity. For any request regarding personal data you may write to the email address above.
2. Data we process
We only process the data necessary to provide the requested services. Depending on the interaction, we may process:
- Sunbed booking data: first and last name, email address, phone number (optional), date and selected spots, booking code.
- Payment data: payments are handled by our provider Stripe through a secure checkout page. We do not process or store full card details: we only receive the transaction outcome and a session identifier.
- Table reservation data: name, surname, phone and notes, collected when you book a table (including by phone) and entered by our staff.
- Browsing and technical data: IP address, browser and device type, pages visited, collected automatically by hosting and security systems and — subject to consent — by analytics tools.
- Contact data: the information you provide when you email or call us.
We do not collect special categories of data (art. 9 GDPR) and we do not carry out profiling or automated decision-making.
3. Purposes and legal bases
We process data for the following purposes and legal bases:
| Purpose | Data | Legal basis |
|---|---|---|
| Manage sunbed and table bookings and deliver the service | Identity, contact, booking | Performance of a contract (art. 6.1.b) |
| Process online payments | Transaction outcome, session id | Performance of a contract (art. 6.1.b) |
| Send confirmation and service emails | Name, email, booking details | Performance of a contract (art. 6.1.b) |
| Comply with tax and accounting obligations | Booking and billing data | Legal obligation (art. 6.1.c) |
| Ensure security, abuse prevention and error diagnostics | Technical data, IP, logs | Legitimate interest (art. 6.1.f) |
| Measure site usage (statistics) | Browsing data (Google Analytics) | Consent (art. 6.1.a) |
| Show the interactive map (Google Maps) | IP, technical data | Consent (art. 6.1.a) |
5. Processors and recipients
To deliver our services we rely on providers that process data on our behalf, appointed as Data Processors (art. 28 GDPR) or independent controllers where applicable:
| Provider | Service | Location / data |
|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing | Ireland / EU (US group) |
| Supabase Inc. | Database, authentication, storage | EU (European infrastructure) |
| Resend (Plticon, Inc.) | Transactional email delivery | EU (eu-west-1 region) |
| Cloudflare, Inc. | Hosting, CDN, security (Turnstile), media storage | USA / global network |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | EU (European ingest) |
| Google Ireland Ltd. | Statistics (Analytics) and maps (Maps) | Ireland / EU (US group) |
| Indian Type Foundry (Fontshare) | Web font delivery | India |
Data may also be disclosed to consultants, professionals and authorities where required by law.
6. Transfers outside the EU
Some providers (notably Cloudflare and Google) belong to US-based groups and may transfer data outside the European Economic Area. Such transfers comply with the GDPR, based on appropriate safeguards such as the EU-US Data Privacy Framework and/or the Standard Contractual Clauses approved by the European Commission.
7. Retention periods
- Booking and billing data: 10 years, for tax and civil-law obligations (art. 2220 of the Italian Civil Code).
- Payment data: retained by Stripe according to its own policies.
- Error and diagnostic logs (Sentry): up to 90 days.
- Browsing statistics (Google Analytics): up to 14 months.
- Cookie preferences: up to 6 months, after which consent is requested again.
After these periods the data is deleted or anonymised, unless needed to establish or defend a legal claim.
8. Your rights
As a data subject you may exercise the rights set out in articles 15-22 of the GDPR at any time:
- access to your data and a copy of it;
- rectification of inaccurate or incomplete data;
- erasure ("right to be forgotten");
- restriction of processing;
- data portability;
- objection to processing based on legitimate interest;
- withdrawal of consent at any time, without affecting the lawfulness of prior processing.
To exercise your rights write to info@lascoglieratorredelgreco.it. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
9. Data security
We adopt appropriate technical and organisational measures to protect data: encrypted connections (HTTPS), access control, anti-bot systems (Cloudflare Turnstile) on forms, and infrastructure managed by certified providers.
10. Minors
The services are not directed to children under 14. We do not knowingly collect data from minors without the consent of those holding parental responsibility.
11. Changes to this policy
We may update this policy to reflect changes in legislation or in the services offered. The current version is always published on this page, with the date of the latest update.
