Vers. n. 2 - 2026-10-02
PRIVACY POLICY
Privacy notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 – GDPR
Last updated: 2 October 2026
This Privacy Policy describes how the personal data of users who visit and use the website www.continentalbrescia.com is collected, used and protected.
The protection of users' personal data is an important aspect of the management of this website. Personal data is processed in compliance with Regulation (EU) 2016/679 (“GDPR”), Italian Legislative Decree No. 196/2003, as subsequently amended and supplemented, and any other applicable provisions concerning the protection of personal data.
1. Data Controller
The Data Controller responsible for the personal data collected through the website is:
Quality Hotel Continental Brescia
Via Martiri della Libertà 267
25030 Roncadelle (BS) – Italy
Telephone: +39 030 2582721
Email: info@continentalbrescia.com
For any request concerning this Privacy Policy or the processing of personal data, users may contact the Data Controller using the contact details provided above.
2. Types of Data Processed
Different categories of personal data may be processed while browsing the website or using the services available on it.
Browsing Data
The IT systems and software procedures used to operate the website may automatically collect certain information relating to browsing activity.
This information may include:
- IP address;
- browser type;
- type of device used;
- operating system;
- date and time of access;
- pages visited;
- referring URL;
- technical information relating to browsing activity.
This data is mainly used to ensure the proper functioning of the website, maintain its security, obtain aggregate statistical information regarding the use of the services and identify any anomalies or attempted unlawful use.
Data Voluntarily Provided by the User
Users may voluntarily provide personal data through the forms available on the website or by contacting the hotel directly.
By way of example, the following data may be collected:
- first and last name;
- email address;
- telephone number;
- information contained in messages sent by the user;
- data relating to accommodation or availability requests;
- information relating to requests for meeting rooms, events or other services offered by the hotel.
Users are advised not to enter personal information in the free-text fields of forms unless such information is necessary for the request being made.
3. Purposes and Legal Bases of Processing
Personal data collected through the website may be processed for the following purposes.
Managing Contact and Information Requests
Data provided by users may be used to respond to requests submitted through forms available on the website, by email or through other contact channels.
Legal basis: taking steps at the request of the data subject prior to entering into a contract and, depending on the nature of the request, the legitimate interest of the Data Controller in responding to communications received.
Availability Requests and Reservations
When users request information concerning rooms, stays, meetings or other services, their data may be processed to prepare an offer, check availability, manage the request and subsequently perform the contractual relationship.
Legal basis: taking steps at the request of the data subject prior to entering into a contract and/or performance of a contract to which the data subject is party.
Administrative, Accounting and Tax Obligations
Where a contractual relationship is established, certain data may be processed in order to comply with administrative, accounting, tax and regulatory obligations required by law.
Legal basis: compliance with legal obligations to which the Data Controller is subject.
Website Security
Technical and browsing data may be processed to prevent fraud, unauthorised access, cyberattacks and other activities that may potentially harm the website or its users.
Legal basis: the legitimate interest of the Data Controller in ensuring the security of its IT systems and digital services.
Statistics and Website Improvement
Subject to the user's consent, where required by applicable law, statistical or analytical tools may be used to understand how the website is used and to improve its content, performance and usability.
Legal basis: the consent of the data subject, where required.
Information concerning the tools actually used and the related cookies is available in the website's Cookie Policy.
Marketing Communications
If newsletter services or other forms of promotional communication are available on the website, personal data may be used to send commercial communications exclusively in the cases and according to the procedures permitted by applicable law.
Where required, such communications will be sent on the basis of the data subject's consent, which may be withdrawn at any time.
4. Nature of the Provision of Data
The provision of data marked as mandatory in the forms available on the website is necessary to enable the Data Controller to respond to the user's request.
Failure to provide such data may make it impossible to provide the requested service or information.
The provision of data for additional and optional purposes, where applicable, is voluntary and does not affect the use of other website features.
5. Methods of Processing
Personal data is processed using IT, electronic and, where appropriate, paper-based tools, adopting technical and organisational measures appropriate to the nature of the data processed and the risks associated with the processing.
Processing is carried out in accordance with the principles of:
- lawfulness;
- fairness;
- transparency;
- data minimisation;
- purpose limitation;
- accuracy;
- storage limitation;
- integrity and confidentiality.
Access to personal data is permitted only to individuals who need such access in connection with their duties or assignments.
6. Recipients of Personal Data
Personal data may be disclosed, to the extent strictly necessary for the purposes described in this Privacy Policy, to parties providing services to the Data Controller.
These may include, by way of example:
- hosting and IT infrastructure providers;
- website support and maintenance providers;
- technology service providers;
- hotel booking system providers;
- administrative, tax, legal or technical consultants;
- communication and marketing service providers, where applicable;
- parties responsible for the management and security of IT systems.
Depending on the circumstances, these parties may act as independent data controllers or as Data Processors pursuant to Article 28 of the GDPR.
Personal data may also be disclosed to public authorities or other parties where required by law or by an order issued by a competent authority.
Personal data will not be disseminated, except where expressly required by law.
7. Transfers of Personal Data Outside the EU
Certain technology services that may be used by the website could involve the processing or transfer of personal data to countries located outside the European Economic Area.
Where this occurs, the Data Controller ensures that the transfer is carried out in compliance with the conditions set out in Articles 44 et seq. of the GDPR, for example on the basis of:
- adequacy decisions adopted by the European Commission;
- standard contractual clauses approved by the European Commission;
- other instruments or safeguards provided for under applicable law.
Further information may be requested from the Data Controller using the contact details provided in this Privacy Policy.
8. Data Retention Period
Personal data is retained for no longer than is necessary to achieve the purposes for which it was collected.
In particular:
- data relating to contact requests is retained for the time necessary to manage the request and any subsequent relationship;
- data relating to contractual relationships is retained for the period necessary to perform the contract and subsequently for the period required by applicable administrative, tax and civil law obligations;
- data used for marketing activities is processed until consent is withdrawn or the right to object is exercised, subject to any further legal retention obligations;
- technical and security data is retained for the period necessary to manage system security and prevent unlawful use.
Once the purposes of the processing have ceased, personal data is deleted or anonymised, unless further retention is required by law.
9. Cookies and Similar Technologies
The website may use technical cookies and, subject to consent where required, cookies or similar technologies for statistical, analytical purposes or in connection with third-party services.
Users can manage their preferences through the consent management system available on the website.
Complete information regarding:
- the categories of cookies used;
- the providers involved;
- their purposes;
- cookie duration;
- how to change or withdraw consent
is available in the website's Cookie Policy.
10. Third-Party Links and Services
The website may contain links to websites, platforms or services managed by third parties, such as booking services, maps, social media platforms, tourism portals or other external services.
When users access these services, they leave www.continentalbrescia.com, and the processing of their personal data will be governed by the privacy policies provided by the respective service providers.
The Data Controller is not responsible for the manner in which external websites or services process users' personal data.
11. Rights of the Data Subject
With regard to their personal data, data subjects may exercise, where the relevant conditions are met, the rights provided for under Articles 15 et seq. of the GDPR.
In particular, data subjects may request:
- access to their personal data;
- rectification of inaccurate data or completion of incomplete data;
- erasure of personal data in the cases provided for by law;
- restriction of processing;
- objection to processing, where applicable;
- data portability, in the cases provided for by law;
- withdrawal of previously given consent, without affecting the lawfulness of processing carried out before such withdrawal.
Data subjects also have the right, in the circumstances provided for by law, not to be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them.
Requests may be sent to:
The Data Controller will process the request within the time limits established by applicable law.
12. Right to Lodge a Complaint
If a data subject believes that the processing of their personal data is being carried out in breach of applicable data protection legislation, they have the right to lodge a complaint with the:
Italian Data Protection Authority (Garante per la protezione dei dati personali)
or with the competent supervisory authority of the European Union Member State in which they habitually reside, work or in which the alleged infringement occurred.
This is without prejudice to the data subject's right to seek judicial remedies before the competent courts.
13. Data Security
The Data Controller adopts appropriate technical and organisational measures to protect personal data against risks including:
- loss;
- destruction;
- alteration;
- unauthorised disclosure;
- accidental or unlawful access.
Security measures are reviewed and updated where necessary, taking into account technological developments, the nature of the data processed and the risks associated with the processing.
14. Children's Data
The services available on the website are not specifically intended for the collection of personal data relating to children.
Where personal data relating to children is provided in connection with a booking or accommodation request, such data will be processed solely to the extent necessary to manage the requested service and in accordance with applicable law.
15. Changes to this Privacy Policy
The Data Controller reserves the right to amend or update this Privacy Policy, including as a result of legislative, regulatory, technological or organisational changes.
The updated version will be published on this page together with the relevant date of the latest update.
Users are therefore advised to periodically review this section of the website.
Last updated: 2 October 2026
Data Controller
Quality Hotel Continental Brescia
Via Martiri della Libertà 267
25030 Roncadelle (BS) – Italy
Tel. +39 030 2582721
Email: info@continentalbrescia.com