Skip to content
Legal Information

Privacy Policy

Paestum Holidays Legal Information

Last updated: 1 August 2026

This policy explains what personal data we collect through this website, why we collect it, how long we keep it, and the rights you have over it. It is provided under Article 13 of the EU General Data Protection Regulation (GDPR, Regulation 2016/679).

1. Who we are

The data controller is:

  • Paestum Holidays by Leonardo D’Onofrio
  • Via Cesare Pavese 27, Capaccio Paestum, 84047 (SA), Italy
  • VAT / P.IVA: 03498150659 — REA: SA-301486
  • Campania Region Authorisation no. 687
  • Email: travel@paestumholidays.com
  • Phone / WhatsApp: +39 389 586 8476

For anything concerning this policy or your personal data, write to travel@paestumholidays.com. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR.

2. What we collect, why, and on what legal basis

We only collect data you actively give us, plus the minimum technical data needed to run the site securely. We do not buy personal data, we do not build advertising profiles, and we do not carry out automated decision-making or profiling.

Enquiry form

  • Data: your name, email address, number of travellers, area of interest, how you heard about us, and the content of your message.
  • Purpose: to answer your enquiry and prepare a travel proposal.
  • Legal basis: steps taken at your request before entering into a contract — Article 6(1)(b) GDPR.
  • Retention: 24 months from our last contact with you, then deleted.

Bookings

  • Data: name, contact details, booking details and payment data, collected through our booking platform Regiondo.
  • Purpose: to take, confirm and manage your booking.
  • Legal basis: performance of a contract — Article 6(1)(b) GDPR.
  • Retention: for the duration of the contract; accounting records are kept for 10 years as Italian law requires.

Accounting and invoicing

  • Data: billing details and transaction records.
  • Purpose: statutory bookkeeping and tax obligations.
  • Legal basis: compliance with a legal obligation — Article 6(1)(c) GDPR.
  • Retention: 10 years (Article 2220 of the Italian Civil Code).

Server logs

  • Data: IP address, date and time, page requested, browser type.
  • Purpose: site security, prevention of abuse, and diagnosing faults.
  • Legal basis: our legitimate interest in keeping the site available and secure — Article 6(1)(f) GDPR.
  • Retention: logs are generated and rotated by our hosting provider, Aruba S.p.A. We keep them only for as long as they are needed to investigate a security incident or fault, after which they are overwritten. We do not use server logs for any analytics purpose.

Analytics

  • Data: pseudonymised usage data collected by Google Analytics 4 (Measurement ID G-VXFXX5Z4V6).
  • Purpose: to understand which pages are useful and improve the site.
  • Legal basis: your consent — Article 6(1)(a) GDPR. Nothing is collected unless you accept.
  • Retention: Google retains the analytics data associated with your visit for up to 14 months. The cookies Google places can last up to 2 years — the individual cookie lifetimes are listed in our Cookie Policy. You may withdraw consent at any time, which stops any further collection.

Consent record

  • Data: a first-party cookie named pst_consent storing your cookie choice.
  • Purpose: to honour your decision and to be able to demonstrate it was given.
  • Legal basis: compliance with a legal obligation — Article 6(1)(c) GDPR — together with our legitimate interest in being able to prove which choice you made, under Article 6(1)(f).
  • Retention: 180 days.

When you contact us, providing your data is voluntary — but without the fields marked as required on the enquiry form we cannot reply to you or prepare a proposal. For bookings the data is required in order to enter into the contract, and for invoicing it is required by law: without it we cannot confirm a booking or issue a valid invoice.

3. Cookies and tracking

On most pages this website sets no cookies and loads no third-party scripts before you give consent. The exception is our tour and package pages, described in the third bullet below — please read it, because it applies before you make any cookie choice.

  • Strictly necessary: the pst_consent cookie records your cookie choice for 180 days. It requires no consent, because it exists solely to respect your decision.
  • Analytics (optional, off by default): Google Analytics 4 loads only if you press “Accept”. We use Google Consent Mode v2, with consent for analytics storage set to denied until you opt in.
  • Booking widget (tour and package pages only): individual tour and package pages embed the booking box of our booking provider Regiondo, so that live availability and prices can be shown. It loads as part of the page, before you make any cookie choice, and it in turn loads scripts from Regiondo’s payment provider Stripe. As a result: Regiondo and Stripe receive technical data such as your IP address, browser type and the address of the page; a cart-id value is stored in your browser’s local storage to remember your booking selection; and Stripe sets the cookies __stripe_mid (about 1 year) and __stripe_sid (about 30 minutes) to detect and prevent payment fraud. These are used for the booking and payment function only — not for advertising, profiling or analytics. Pages without a booking box load nothing from Regiondo or Stripe.
  • We use no advertising, profiling or social-media tracking cookies. Links to Instagram and WhatsApp are ordinary links, not embedded trackers or social plugins.
  • Web fonts are served from our own server, so no data is sent to third-party font providers when you load a page.

You can change or withdraw your choice at any time using the “Cookie preferences” link in the footer. Further detail is in our Cookie Policy.

4. Who receives your data

We do not sell or rent personal data. We share it only with providers who help us operate, each bound by a data processing agreement under Article 28 GDPR:

  • Aruba S.p.A. — web hosting and email (Italy / EU)
  • Regiondo GmbH — booking and payment platform (Germany / EU)
  • Stripe — payment processing and payment-fraud prevention, used by Regiondo (EU, with transfers to the USA)
  • Google Ireland Ltd. — analytics, only with your consent (EU, with transfers to the USA)
  • Our accountant and tax advisers — statutory bookkeeping (Italy)
  • Our insurers, where a claim requires it (Europ Assistance)

Public authorities may receive data where the law requires it.

5. Transfers outside the EU

Our hosting, email and booking systems are located in the European Union.

One transfer outside the EU concerns Google Analytics, and only if you consent to analytics cookies. Transfers by Google LLC are covered by the EU–US Data Privacy Framework and by the European Commission’s Standard Contractual Clauses. If you do not consent, no data is sent to Google.

In addition, the booking box on our tour and package pages contacts Stripe, the payment provider used by Regiondo, which operates partly outside the EU. Where Stripe transfers data to the United States it relies on the European Commission’s Standard Contractual Clauses. Details are in Stripe’s privacy policy.

You may obtain a copy of the safeguards we rely on for these transfers by writing to travel@paestumholidays.com.

6. Your rights

Under Articles 15 to 22 GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you;
  • Rectification — have inaccurate or incomplete data corrected;
  • Erasure (“right to be forgotten”) — have your data deleted, where no legal obligation requires us to keep it;
  • Restriction — ask us to limit how we use your data in the cases set out in Article 18, for example while the accuracy of the data is being checked, or as an alternative to erasure;
  • Data portability — receive the data you gave us in a structured, commonly used, machine-readable format;
  • Object — object at any time to processing based on our legitimate interest;
  • Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • Not be subject to automated decision-making — we carry out no profiling or automated decisions.

To exercise any of these rights, email travel@paestumholidays.com. We respond within one month, extendable by a further two months for complex requests, in which case we will tell you why.

Right to complain: if you believe your data has been handled unlawfully, you may lodge a complaint with the Italian supervisory authority — Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it — or with the authority in your country of residence.

7. Security

We protect your data with HTTPS/TLS encryption across the whole site, strict security headers, two-factor authentication on administrator accounts, restricted server access and regular software updates. No system is perfectly secure, but we take these measures seriously and review them regularly.

8. Children

This website is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.

9. Changes to this policy

If we change the way we handle personal data we will update this page and revise the “last updated” date above. Changes that materially affect your rights will be signalled clearly on the site.