WEBSITE AND JOB APPLICANTS
Privacy information for users of onebelvedere.com, provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).
Last updated: 18 August 2026
The Data Controller of personal data is ONE BELVEDERE SARL, VAT No. 04398131005 / Tax Code 00310770524, with registered office at Loc. Casanova dei Carfini, Castellina in Chianti (SI) 53011 and operational headquarters at Loc. Belvedere, 1 — 53036 Poggibonsi (SI), represented by its legal representative Natacha Le Cardiet Fazal Karim.
The Data Controller may be contacted by e-mail at [email protected], by certified e-mail (PEC) at [email protected], by telephone at +39 0577 1607365, or by ordinary mail at the registered office address indicated above.
Through the website https://onebelvedere.com, the Data Controller may process the following categories of personal data:
Personal data collected through or in connection with the website are processed for the following purposes:
Browsing data, security information and strictly necessary technologies are processed in order to provide, maintain and secure the website, prevent abuse, diagnose technical issues and protect the website and its users.
The legal basis is the legitimate interest of the Data Controller in providing and securing the service pursuant to Article 6(1)(f) GDPR. Data are retained for the technically necessary period and, where applicable, for the retention periods required by law.
Data submitted through contact forms, e-mail or other communication channels are processed in order to respond to requests for information, quotations, availability, services or other enquiries.
The legal basis is the performance of pre-contractual measures taken at the request of the data subject and/or the legitimate interest of the Data Controller in responding to the request, pursuant to Article 6(1)(b) and Article 6(1)(f) GDPR. Data are retained for the time necessary to manage the request and any subsequent relationship.
Data relating to accommodation, experiences and other hospitality services may be processed in order to respond to booking requests, manage reservations, provide the requested services and comply with related administrative, accounting and legal obligations.
The legal basis is the performance of a contract or pre-contractual measures pursuant to Article 6(1)(b) GDPR and, where applicable, compliance with legal obligations pursuant to Article 6(1)(c) GDPR.
Certain reservations may be completed through external booking platforms or booking engines accessed from links on the One Belvedere Tuscany website. Where the user proceeds to an external booking service, personal data may be processed directly by the relevant provider in accordance with its own privacy information and contractual arrangements.
Where payment, deposit or pre-authorisation is required in connection with a reservation, the relevant payment data may be processed by the booking platform or payment service provider involved in that reservation, where applicable.
One Belvedere Tuscany previously operated direct online purchasing functionality through this website. Direct e-commerce is no longer available through onebelvedere.com.
Information relating to historical orders and transactions may nevertheless continue to be retained where necessary for invoicing, accounting, tax, legal and record-keeping obligations.
The legal basis is the performance of the original contract pursuant to Article 6(1)(b) GDPR and compliance with legal obligations pursuant to Article 6(1)(c) GDPR. Accounting and tax records may be retained for 10 years pursuant to Articles 2214 and 2220 of the Italian Civil Code and applicable tax legislation.
Where users subscribe to the newsletter or other promotional communications, their contact data may be used to send news, stories, updates, invitations, offers or other communications relating to One Belvedere Tuscany and its activities.
The legal basis is the consent of the data subject pursuant to Article 6(1)(a) GDPR. Data are processed until consent is withdrawn. Users may withdraw their consent at any time, including by using the unsubscribe link provided in communications.
Subject to the user’s consent, analytics technologies may be used to understand how visitors interact with the website, including information such as visited pages, approximate traffic sources, device or browser information and interactions with website content.
The legal basis is consent pursuant to Article 6(1)(a) GDPR. Analytics technologies remain disabled where the relevant consent has not been provided. Further details, including cookie categories and durations, are provided in the Cookie Policy.
Subject to consent, the website may use advertising or conversion-measurement technologies and may load third-party content or services that can place or access non-essential cookies.
Such technologies are activated only where the user has provided the relevant consent through the website’s cookie preference system. The legal basis is consent pursuant to Article 6(1)(a) GDPR.
The website uses CookieYes as its consent management platform to provide users with granular control over non-essential cookies and similar technologies.
On their first visit, users may accept all cookies, reject non-essential cookies, or customise their preferences by category. Non-essential analytics, advertising and other consent-based technologies are intended to remain inactive unless the corresponding consent has been provided.
Users may change or withdraw their cookie preferences at any time through the Cookie Preferences control available on the website.
Detailed information about the cookies and technologies currently detected on the website, their purposes and durations is available in the Cookie Policy.
In order to operate the website, understand its use, communicate with users and provide access to hospitality services, One Belvedere Tuscany may rely on third-party service providers.
Depending on the user’s interaction with the website and consent preferences, these may include the following categories of services:
Third-party providers may act, depending on the specific service and processing activity, as processors appointed pursuant to Article 28 GDPR or as independent data controllers.
Where a user leaves the One Belvedere Tuscany website and accesses an external platform, that platform’s own privacy and cookie information will apply.
Applications received through the website, contact forms or the Data Controller’s e-mail addresses are processed exclusively for the purpose of evaluating candidates and managing recruitment and selection activities.
The legal basis is the performance of pre-contractual measures taken at the request of the data subject pursuant to Article 6(1)(b) GDPR and, in relation to spontaneous applications not connected to a specific vacancy, the legitimate interest of the Data Controller in evaluating the profiles received pursuant to Article 6(1)(f) GDPR.
Job application data are retained for 6 months from receipt of the application.
Providing the information required to assess the application is necessary in order to participate in the recruitment process. Failure to provide the necessary information may make it impossible to evaluate the application.
Applicants are requested not to include in their CV or application special categories of personal data within the meaning of Article 9 GDPR, such as information concerning health, religious beliefs or trade union membership, where such information is not relevant to the professional assessment.
Where such information is nevertheless provided voluntarily, it will be processed only where strictly necessary and within the limits permitted by applicable law.
Recruitment data are processed by persons authorised to process personal data and responsible for management and human resources activities. Such data are not disclosed to third parties or disseminated, except where required by law.
Personal data are processed using IT and telematic tools according to methods strictly related to the purposes described above and in accordance with the principles of lawfulness, fairness, transparency, purpose limitation and data minimisation.
The Data Controller adopts appropriate technical and organisational measures intended to protect personal data against unauthorised access, alteration, disclosure, loss or unlawful processing.
Such measures may include network and infrastructure protection, security monitoring, antivirus protection, personal access credentials, controlled administrative access, backups and a cookie consent system providing granular control over non-essential technologies.
The transmission of certain browsing data is inherent in the use of Internet communication protocols.
Where data are requested in order to respond to an enquiry, manage a booking or reservation, provide a service or perform a contract, the provision of data marked as mandatory is necessary. Failure to provide such information may prevent the Data Controller from responding to the request, completing the reservation or providing the requested service.
Providing data for newsletters, promotional communications and non-essential cookies is optional and based on consent, which may be freely withdrawn at any time.
Personal data may be disclosed, exclusively where necessary for the purposes described in this Privacy Policy, to:
Personal data are not subject to general public dissemination.
One Belvedere Tuscany primarily processes personal data within the European Economic Area.
Some third-party services used in connection with the website — particularly analytics, technology, communications, social media or external platform providers — may involve the processing or transfer of personal data in countries outside the European Economic Area.
Where such transfers occur, they are carried out in accordance with Articles 44 et seq. GDPR and, where applicable, on the basis of an adequacy decision of the European Commission, Standard Contractual Clauses, or other safeguards recognised under applicable data protection law.
Personal data are retained only for as long as necessary to fulfil the purpose for which they were collected and to comply with applicable legal obligations.
Pursuant to Regulation (EU) 2016/679 and applicable national legislation, data subjects may exercise the following rights, in accordance with the conditions and limits established by law:
To exercise these rights or request clarification concerning the processing of personal data, users may contact the Data Controller using the contact details provided above or contact the data protection consultant where applicable.
The Data Controller reserves the right to amend or update this Privacy Policy, including as a result of changes to applicable legislation, website functionality, service providers, technologies or services offered through the website.
Updated versions will be published on this page together with the relevant date of revision.