Rome Private Experience

Privacy Policy

This notice explains how personal data are collected and processed when you visit this website or contact us regarding private tours, corporate programmes or bespoke experiences in Rome.

Transparency and Data Protection

Your privacy is treated with care and discretion.

Personal data are processed only where necessary, lawfully and transparently, in accordance with Regulation (EU) 2016/679 and applicable Italian data-protection legislation.

Last updated: 30 August 2026
Data Controller

Who is responsible for your data

Data Controller: Daniele Avanzato

VAT number: 13646351000

Registered address: Via della Giuliana 43, 00195 Rome, Italy

Email: info@romeprivateexperience.com

Website: www.romeprivateexperience.com

01 — Scope of this Notice

When this Privacy Policy applies

This Privacy Policy applies to personal data processed through www.romeprivateexperience.com, including data submitted through contact forms, data sent by email and limited technical data generated when the website is visited.

It does not apply to third-party websites that may be linked from this website. Those websites operate under their own privacy terms.

02 — Personal Data Collected

What information we may process

Information provided voluntarily

When you contact us through WPForms, email, telephone or WhatsApp, we may receive:

  • name and surname;
  • email address;
  • telephone or WhatsApp number;
  • company or organisation name;
  • travel or event dates;
  • number and profile of participants;
  • preferred language;
  • interests, accessibility requirements and organisational needs;
  • the content of your message and subsequent correspondence.

Technical and browsing data

The website infrastructure may automatically process technical information such as IP address, browser type, operating system, requested pages, date and time of access, response codes and security logs. Such data are normally generated by web servers and are used to operate, protect and troubleshoot the website.

Special-category data

Please do not send health or other sensitive information unless it is genuinely necessary to organise an accessible and safe experience. Where voluntarily provided, such information will be used only for the specific request and handled with additional care.

03 — Purposes and Legal Bases

Why we use personal data

PurposeLegal basis
Responding to enquiries, checking availability and preparing personalised proposals. Steps taken at the request of the data subject before entering into a contract, Article 6(1)(b) GDPR.
Managing bookings, agreed services, communications and operational arrangements. Performance of a contract, Article 6(1)(b) GDPR.
Issuing invoices, retaining accounting records and complying with tax, legal or regulatory obligations. Compliance with a legal obligation, Article 6(1)(c) GDPR.
Protecting the website, preventing abuse, defending legal claims and maintaining service security. Legitimate interests of the Controller, Article 6(1)(f) GDPR, balanced against the rights and freedoms of users.
Processing voluntarily supplied health or accessibility information where necessary to arrange an appropriate service. Explicit consent where required, Article 6(1)(a) and Article 9(2)(a) GDPR, or another applicable legal condition.

Sending a contact form or requesting a proposal does not by itself create a binding contract. A booking becomes effective only after the relevant commercial terms have been expressly confirmed.

04 — Mandatory and Optional Data

What happens if data are not provided

Fields marked as required are necessary to assess and answer the request. Without them, it may not be possible to respond, prepare a proposal or organise the requested service.

Additional information is optional and should be provided only when relevant to the enquiry.

05 — Methods of Processing

How personal data are handled

Data may be processed electronically and, where necessary, in paper form. Appropriate organisational and technical measures are used to reduce the risks of unauthorised access, accidental loss, improper disclosure, alteration or unlawful use.

Access is limited to the Controller and to persons or service providers who need the information for the purposes described in this notice.

06 — Recipients and Service Providers

Who may receive personal data

Data are not sold. They may be disclosed, only where necessary, to:

  • hosting, email, website-maintenance and security providers;
  • providers involved in operating the contact form;
  • guides, venue managers, transport coordinators, ticketing providers or other suppliers needed to prepare or deliver the requested experience;
  • accountants, legal advisers and professional consultants;
  • public authorities or other entities where disclosure is required by law or necessary to protect legal rights.

Where required, external providers act as processors under Article 28 GDPR or as independent controllers for their own activities. Only the data reasonably necessary for the relevant task are shared.

07 — International Transfers

Processing outside the European Economic Area

The Controller seeks to use providers located in the European Economic Area. If a provider processes data in a country outside the EEA, the transfer will take place only where permitted by Chapter V GDPR, for example on the basis of an adequacy decision, Standard Contractual Clauses or another lawful safeguard.

08 — Retention Periods

How long personal data are kept

  • Unconverted enquiries: normally up to 12 months from the last meaningful communication, unless a longer period is justified by an ongoing request or legal need.
  • Pre-contractual and booking correspondence: for the time needed to manage the request and, where a service is confirmed, for the duration of the contractual relationship.
  • Invoices and accounting records: for the period required by Italian tax and civil-law obligations, normally 10 years.
  • Security and server logs: for the period necessary to ensure website security, investigate incidents and comply with legal requests, normally for a limited period unless an incident requires longer retention.
  • Special-category or accessibility information: only for as long as necessary to organise and deliver the relevant service, unless further retention is required by law.

Data may be retained for a longer period where necessary to establish, exercise or defend legal claims.

09 — Cookies and Similar Technologies

Technical operation of the website

The website may use cookies or similar technologies that are strictly necessary for security, session management, form functionality and basic operation. Strictly necessary technical cookies do not normally require consent, but they are described transparently in the Cookie Policy.

The website uses a cookie consent management system that allows visitors to accept, reject or manage non-essential cookies where applicable. Non-essential technologies requiring consent are not intended to be activated before the visitor has made the relevant choice. Visitors can review or change their preferences at any time through the cookie settings available on the website.

At the date shown above, the Controller does not intentionally use Meta Pixel, newsletter tracking, embedded Google Maps or embedded YouTube videos.

Detailed and up-to-date information about cookies and similar technologies used or detected on this website, their purposes and applicable consent choices is provided in the Cookie Policy.

10 — WPForms and Contact Requests

Information submitted through forms

Contact forms are used solely to receive and manage enquiries. Information entered in the form is transmitted to the Controller and may also be processed by the website hosting, email or form infrastructure necessary to deliver the message.

Before submitting the form, users are required to acknowledge that they have read this Privacy Policy. This acknowledgement confirms that the privacy information has been made available; it does not constitute consent to processing where another legal basis applies.

Users should provide only information relevant to the request and should not include unnecessary confidential or sensitive data.

11 — Security

Measures used to protect information

The Controller adopts measures appropriate to the nature of the data and the risks involved, including access controls, software updates, secure credentials, encrypted connections where available, backups and limited disclosure to authorised recipients.

No method of transmission or storage can be guaranteed to be completely risk-free. Users are therefore encouraged not to send unnecessary sensitive information through ordinary email or forms.

12 — Your Rights

Rights under the GDPR

Subject to the conditions set out in the GDPR, you may request:

  • confirmation as to whether your personal data are processed;
  • access to your personal data and related information;
  • correction of inaccurate or incomplete data;
  • erasure of personal data where the legal conditions apply;
  • restriction of processing;
  • data portability where applicable;
  • objection to processing based on legitimate interests;
  • withdrawal of consent at any time, without affecting earlier lawful processing;
  • information about safeguards used for applicable international transfers.

Requests may be sent to info@romeprivateexperience.com. The Controller may request reasonable information to verify the identity of the person making the request.

13 — Automated Decision-Making

No automated decisions or profiling

Personal data submitted through this website are not used for automated decision-making that produces legal or similarly significant effects, and are not intentionally used for behavioural profiling.

14 — Minors

Information concerning children

This website is intended for adults arranging travel or corporate services. Any information concerning minors should be supplied only by a parent, guardian or authorised adult and only where necessary for the organisation of the requested service.

15 — Complaints

Right to contact the supervisory authority

If you believe that your personal data have been processed unlawfully, you may lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali, without prejudice to any other administrative or judicial remedy.

16 — Changes to this Policy

Updates and revisions

This Privacy Policy may be updated to reflect changes to the website, services, suppliers or applicable law. The latest version will always be published on this page with the revision date shown above.

Questions About Your Personal Data?

For access, correction, deletion, restriction, objection or any other privacy-related request, contact the Data Controller.

Contact the Data Controller