Privacy Policy

Data controller: Semprox Lab di Moscioni Jacopo

Data we collect

Contact and booking forms collect the information you provide: name, email, phone number, property, dates, guest count and notes. To manage an offer we also record its reference, status, amount, accepted terms and timestamps. Strictly necessary security data includes a pseudonymous identifier derived from the IP address and used for abuse rate limiting. The hosting infrastructure may also record the IP address, user agent, requested URL and time in technical access and security logs.

Purpose of processing

We process data to answer requests, check availability, prepare and administer an offer, receive payment, fulfil the stay and applicable accounting or legal duties, secure the site and prevent abuse. When analytics or advertising is enabled with consent, the relevant providers may process online identifiers and technical data under the applied settings and their own notices.

Legal bases

  • Pre-contract and contract: requests, offers, bookings, payments and stays.
  • Legal obligation: applicable tax, accounting and guest-registration duties.
  • Legitimate interest: site security and abuse prevention.
  • Consent: analytics and advertising cookies (when enabled).

Cookies and consent

We use necessary technical storage. Your banner choice is stored locally in the browser; analytics and advertising scripts are enabled only for the categories you authorise. You can change preferences at any time.

Platform calendars

We consult iCalendar feeds exported by connected booking platforms to check dates. Feeds are cached temporarily in a private server directory. The calendar exported by WellStay contains only busy intervals, opaque identifiers and the generic label “WellStay reservation”; it does not contain guest names, email addresses or phone numbers.

Payments

When enabled, checkout is handled by the relevant provider: Stripe for cards, Satispay for Satispay, and BTCPay Server for on-chain or Lightning Bitcoin. We send only necessary data such as the amount, currency, booking reference and, where required, email. WellStay does not receive or store complete card numbers, Satispay credentials, wallet seed phrases or Bitcoin private keys.

Data recipients

Necessary data may be processed by hosting and email providers, the selected payment providers and, for busy intervals only, connected booking platforms. For chess tournament enquiries, contact details are shared with partner accommodation providers only when the user selects the specific authorisation in the form.

Other third-party services

When enabled with the required consent, we use measurement and advertising services including Google Analytics and Google AdSense. Website fonts are hosted directly by WellStay and do not require connections to external font services. Google Maps is loaded only after an explicit user action. External providers may act as processors or independent controllers under their terms and apply safeguards to transfers outside the European Economic Area.

Data retention

Unconfirmed requests are retained as needed to handle the enquiry, prevent abuse and address disputes. For requests that are received, rejected or expired and have no payment record, the technical process currently applies a 180-day window from the last update; pending requests for future stays are kept at least until the requested period has passed. Confirmed bookings and any records linked to a payment are retained separately for applicable administrative, tax and legal periods. If an email cannot be delivered immediately, it remains in a private outbox for automatic retries for up to 7 days; permanently failed messages are retained for troubleshooting for no more than 30 days and then deleted. Database backups remain in a private area and are removed according to the configured technical rotation; any copy transferred off the server must be encrypted. Cookie and analytics retention follows the Cookie Policy and provider settings.

User rights (EU residents)

European residents have the right to:

  • Be informed about data processing
  • Access their personal data
  • Request correction or deletion
  • Restrict or object to processing
  • Data portability
  • Object to automated decision-making

Data security

Reasonable safeguards include HTTPS, authenticated administration, request tokens stored only as hashes, verified payment notifications and a database outside the public web directory. No Internet transmission can be guaranteed as absolutely secure.

Third-party links

The website disclaims responsibility for the privacy practices of external websites and encourages users to review their policies independently.

Contact

For privacy requests: j.moscioni@semproxlab.it