Privacy Policy
Last updated: 5 September 2026
This Privacy Policy explains how Lake Como Explorer S.r.l. processes personal information when you visit or use Love You Italy, including its website, accounts, saved tours, enquiries, newsletters and, when enabled, booking-related services. It is intended to provide a clear global baseline; additional rights or duties may apply under the law of your location.
1. Who is responsible for your data
Data controller: Lake Como Explorer S.r.l., Via Alessandro Volta 81, 22100 Como (CO), Italy. VAT / P.IVA 04088110137.
Email: info@loveyouitaly.com
Certified email (PEC): lakecomoexplorer@legalmail.it
Telephone: +39 366 453 2841
2. Information we process
Depending on how you use the service, we may process:
- Account data: name, email address, account identifiers, authentication records, language and communication preferences.
- Travel and service data: destinations, saved tours, requested dates, guest numbers, accessibility or service needs you choose to provide, enquiries, messages, meeting-point information and related customer-service correspondence.
- Transaction data: booking reference, status, amount, invoice and legally required accounting information if paid booking becomes available. Payment providers process payment-card data under their own notices; we do not intend to store complete card numbers.
- Newsletter data: email address, subscription status, consent record and unsubscribe history.
- Technical, security and consent data: IP address, browser and device information, timestamps, requested URLs, diagnostic and security events, approximate country or region, cookie preferences, consent ID and policy version.
- Optional analytics and marketing data: online identifiers and interaction data collected by Google Tag/Analytics, Microsoft Clarity, Meta Pixel or similar services only when those services are enabled and the required consent or opt-out rules permit them.
Please do not send health, passport, payment-card or other sensitive information unless it is genuinely necessary for a service you request and a secure collection method has been provided.
3. Where the information comes from
We receive information directly from you, from your browser or device when you use the service, from security and hosting infrastructure, and from booking, payment, communications or analytics providers when those services are enabled. We may also receive information from a person arranging travel for you; that person should have authority to provide it.
4. Why we use information and our legal bases
- To provide requested services and take pre-contract steps: accounts, enquiries, saved tours, itinerary communication, booking administration and customer support.
- To comply with law: tax, accounting, consumer-protection, fraud-prevention, legal-claim and regulatory obligations.
- For legitimate interests: operating, securing, diagnosing and improving the service; preventing misuse; maintaining business records; and responding to communications, where those interests are not overridden by your rights.
- With consent: newsletters, non-essential cookies, session-replay or analytics tools, personalised advertising and similar optional processing. You may withdraw consent at any time without affecting earlier lawful processing.
- To protect vital interests or establish, exercise or defend legal claims: only where the circumstances require it.
Where local law uses a different legal framework, we process information only when a permitted ground applies, including consent, necessity to provide the requested service, legal obligation or another authorised purpose.
5. Cookies, pixels, tags and similar technologies
Strictly necessary technologies support security, consent choices, accounts and core site functions. Preference technologies may remember settings or enable optional content such as maps or booking widgets. Analytics and marketing technologies—including Google tags, Microsoft Clarity and Meta Pixel—are not permitted before the required choice in opt-in regions. The current categories, providers and retention periods are explained in our Cookie Policy.
Your consent reference, when available:
6. Who may receive information
We disclose only what is reasonably necessary to:
- hosting, infrastructure, security, cache, email and technical-support providers;
- travel operators, guides, attractions, transport providers or booking platforms such as Bókun when needed to answer or fulfil your request;
- payment and fraud-prevention providers if online payment is enabled;
- analytics, session-replay and advertising providers only when configured and legally permitted by your choices;
- professional advisers, insurers, auditors, courts, regulators and public authorities where required or appropriate; and
- a successor in a merger, restructuring or transfer, subject to appropriate confidentiality and transparency safeguards.
Service providers are expected to act under appropriate contractual, confidentiality and security duties. We do not sell personal information for money. If an advertising disclosure is treated as “sale”, “sharing” or targeted advertising under applicable US law, you may opt out through the cookie settings or a recognised Global Privacy Control signal.
7. International transfers
Some providers may process information outside Italy or your country. Where transfer restrictions apply, we use an available lawful mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or another recognised safeguard, and assess supplementary protections where required. You may contact us for information about the safeguard relevant to your data.
8. How long we keep information
We retain information only for as long as needed for the purpose, security, dispute resolution and legal obligations. Our general guide is:
- account information: while the account is active and for a reasonable period afterwards, unless earlier deletion is requested or law requires retention;
- ordinary enquiries and customer-service correspondence: normally up to 12 months after the last substantive contact;
- newsletter records: until unsubscribe, plus a minimal suppression record needed to honour the request and demonstrate compliance;
- consent records: normally 12 months; the browser choice currently expires after 180 days unless renewed or withdrawn earlier;
- routine security logs: normally up to 90 days, but longer where needed to investigate an incident or legal claim;
- booking, contractual, invoice and tax records: for the period required by applicable accounting, tax and civil law, which may be up to 10 years in Italy.
Backups may retain protected copies for a limited rotation period. Data may be anonymised instead of deleted where it can no longer identify a person.
9. Your privacy rights
Subject to applicable law and exceptions, you may ask us to access, correct, update, delete, restrict or receive a portable copy of your personal information; object to processing based on legitimate interests or direct marketing; withdraw consent; and complain to a supervisory authority. We may need to verify your identity and authority before completing a request.
European Economic Area and United Kingdom: the GDPR/UK GDPR rights above apply, including the right to lodge a complaint. In Italy, the supervisory authority is the Garante per la protezione dei dati personali.
Switzerland: you may request information about processing and, where applicable, correction, deletion or restriction under the Federal Act on Data Protection.
Brazil: where the LGPD applies, you may request confirmation, access, correction, anonymisation, blocking or deletion, portability, information about disclosures, review of certain automated decisions and withdrawal of consent, subject to law.
California and other applicable US states: you may have rights to know/access, correct, delete and obtain a portable copy, and to opt out of sale, sharing, targeted advertising or certain profiling. You may also have a right to appeal a denied request and not be discriminated against for exercising a right. We honour applicable Global Privacy Control signals. We do not currently use or disclose sensitive personal information to infer characteristics about you.
Canada: you may request access and correction, challenge compliance and withdraw consent subject to legal or contractual limits and reasonable notice.
Australia and other locations: you may have rights to access or correct information and complain to the relevant privacy regulator. We will honour any additional mandatory local right that applies to our processing.
To exercise a right, email info@loveyouitaly.com with “Privacy request” in the subject. You may use an authorised agent where local law permits. We will respond within the applicable legal deadline and explain any lawful limitation or appeal route.
10. Automated decisions
We do not make decisions producing legal or similarly significant effects about visitors solely by automated means. If this changes, we will provide the required information and safeguards before the processing begins.
11. Children
The service is not directed to children under 16 and we do not knowingly collect their personal information through accounts or marketing. A parent, guardian or responsible adult should arrange travel for a minor. Contact us if you believe a child has provided information without appropriate authorisation.
12. Security and data incidents
We use proportionate technical and organisational measures designed to protect information, including access controls, transport encryption, updates, logging, backups and service-provider review. No system is completely secure. Where required, we will notify the competent authority and affected individuals of a qualifying personal-data breach.
13. Changes to this policy
We may update this policy when services, providers or laws change. The date above identifies the current version. If a change materially affects processing based on consent, we will request a new choice where required.
14. Contact and complaints
Questions and complaints may be sent to info@loveyouitaly.com or to the postal address in section 1. You may also contact the privacy or consumer authority in your country. We encourage you to contact us first so we can investigate promptly.