Atmosphere Logo
  • HOME
  • Rooms & Suites
  • PROPERTY
LogoAtmosphere Borgo Monchiero
  • DESTINATION
  • GET IN TOUCH
  • OFFERS
Subscribe to our newsletter
logo
Terms of UsePrivacy PolicyContactSitemap
+39 0173 78031
[email protected]
Select Language
© Atmosphere Hotels & Resorts 2026. All Rights Reserved.Powered by Digitech.
Atmosphere Core
Borgo Monchiero By Atmosphere

Privacy Policy

  1. Home
  2. Privacy Policy

PRIVACY NOTICE

 

 Enventi S.r.l. firmly believes that transparency is the foundation of its relationship with its customers and users (hereinafter the “Users” or “Data Subjects”). For this reason, it wishes to ensure the utmost clarity regarding the processing of Users’ personal data when browsing the website accessible at https://borgomonchiero-atmosphere.com/ (hereinafter the “Website”) and during their stay at Borgo Monchiero (hereinafter the “Property”).

This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter the “GDPR”) and is addressed to all Website Users.

1.    Data Controller, Processors and Authorized Persons

The data controller is Enventi S.r.l., with registered office at Via Alessandro Manzoni 40, 20121 Milan, represented by its pro tempore legal representative, domiciled at the company’s registered office (hereinafter the “Controller” or “Enventi”).

You may contact the Controller at the following contact details:

-      by email: [email protected];

-      by post: Via Alessandro Manzoni 40, 20121 Milan.

The Controller may appoint other data processors, as well as persons authorized to carry out processing operations, respectively pursuant to Articles 28 and 29 of the GDPR. A complete and up-to-date list of such subjects is available by contacting the Controller using the contact details above.

2.    Categories of data processed, purposes, legal basis and nature of data provision

2.1      Data collected through the Website

2.1.1       Browsing data

The IT systems and software procedures used to operate this Website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.

This category of data includes IP addresses or domain names of the computers used by users connecting to the Website, the URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server’s response (successful, error, etc.), and other parameters relating to the user’s operating system and IT environment.

Browsing data are processed for the following purpose:

·      to verify the proper functioning of the Website and the services offered.

Browsing data may also be used to ascertain criminal offences by the Judicial Authority.

The legal basis for the processing is the Controller’s legitimate interest in the proper functioning of the Website.

Provision of browsing data is necessary in order to access the Website.

2.1.2       Cookies

The Website uses cookies, as further specified in the Cookie Policy.

2.1.3       Requests for information

The optional, explicit and voluntary sending of messages to the addresses indicated on this Website entails the subsequent acquisition of the sender’s contact details (name and surname, email and/or telephone number), necessary in order to respond to requests, as well as any other personal data included in the communication.

Data voluntarily provided by the User are processed for the following purpose:

·      to allow the performance of operations strictly connected with and instrumental to the management of Users’ requests, such as – by way of example only – replying to questions received via contact forms, handling CVs (curriculum vitae) for recruitment purposes, and other relevant information sent by the user.

The legal basis for the processing is the performance of pre-contractual measures taken at the request of the data subject.

Provision of data is necessary to enable the Controller to respond to the User’s requests.

2.1.4       Data provided by the user at the time of booking

When making a booking through the Website, the Controller processes your common personal data such as, by way of example: name and surname, contact details (email and/or telephone number), postal address, billing address, tax code / VAT number, data relating to payment / billing instruments, booking information, etc.

Such data are processed for the following purposes:

·      management of the contractual relationship, i.e. to allow the proper performance of the contractual obligations undertaken by the Controller towards Users and customers and vice versa (including, for example, sending account notices and booking confirmations), the management of consequent accounting and tax obligations, as well as compliance with obligations laid down by laws, regulations and EU legislation, or by provisions issued by authorities legally empowered to do so and by supervisory and control bodies;

·      purposes necessary to establish, exercise or defend a right in court or whenever judicial authorities exercise their judicial functions.

The legal bases for the processing are the performance of a contract to which the data subject is party or the implementation of pre-contractual measures taken at their request, as well as compliance with legal obligations to which the Controller is subject. Provision of data is necessary for the proper management of the contractual relationship.

2.2      Data collected at the Property

2.2.1       Management of the stay

During the stay at the Property, the Controller may collect and process additional personal data of the Data Subject, including minors’ data, in addition to those provided at the booking stage, in order to properly manage the hospitality contractual relationship and comply with obligations under applicable law.

In particular, the following may be processed:

·      personal and identification data (e.g. identity document), necessary for check-in/check-out operations and for compliance with public security regulations;

·      contact details (e.g. telephone, email) used for communications relating to the stay;

·      information relating to the stay (dates, number of guests, accommodation preferences, requested services);

·      tax and payment data, for billing and administrative/accounting purposes;

·      any information voluntarily provided by the guest during the stay (e.g. special requests, reports, preferences), within the limits of what is necessary for the provision of the requested services;

·      in relation to specific services requested by the guest during the stay and to the extent necessary for their proper provision, special categories of personal data may also be processed, such as health data (e.g. food intolerances).

Such data are processed for the following purposes and on the following legal bases:

·      performance of the stay contract, including the management of services requested by the guest;

·      compliance with legal obligations to which the Controller is subject (e.g. public security, tax and administrative obligations);

·      for special categories of data, the consent collected at the Property.

Provision of data is necessary for the enjoyment of the stay – except for the processing of special categories of data, for which provision is optional – and any refusal to provide such information may make it impossible to provide, in whole or in part, the requested services.

2.2.2       Video surveillance at the Property

The Property is equipped with video surveillance systems installed exclusively for purposes of personal safety, protection of assets and prevention of unlawful conduct, in compliance with applicable law.

The processing of personal data through video surveillance systems is based on the Controller’s legitimate interest and is limited to duly signposted areas.

A specific and complete notice on the processing of personal data through video surveillance is made available at the Property by means of dedicated signage and at the reception desk.

 

2.3      Additional processing activities

2.3.1       Marketing activities

The data (name, surname and email address) collected when subscribing to the newsletter service, when requesting information via the contact form and when making a booking, will be processed for:

·      with regard to prospective customers, information activities by Enventi concerning its products and/or services, as well as promotional, commercial and marketing activities;

·      with regard to customers, (i) information activities by Enventi concerning its products and/or services, as well as promotional, commercial and marketing activities; (ii) carrying out market research or other sample surveys; (iii) measuring customer satisfaction;

·      transfer of data to the Property manager called Atmosphere Core for information activities by the latter regarding its own products and/or services, as well as promotional, commercial and marketing activities.

For each of the above purposes, the legal basis for the processing is the data subject’s specific consent.

Provision of data is optional.

3.    Processing methods and retention periods

Data will be processed manually and/or electronically, in compliance with the principles of lawfulness, fairness, transparency and data minimization, and retained for the time necessary to pursue the purposes indicated above and, thereafter, for the period required by applicable law.

In particular:

·      data collected via contact forms not followed by a booking will be retained for 6 months from receipt of the request;

·      data collected for administrative and accounting purposes will be retained for 10 years from the termination of the contractual relationship;

·      data collected for marketing purposes by the Controller or by third parties will be retained for 24 months from receipt of the relevant consent.

The Controller has adopted specific security measures to prevent data loss, unlawful or improper use and unauthorized access.

4.    Disclosure of data and transfer outside the European Union

4.1      Property manager

The management of this Website and the operational activities of the Property will also be carried out with the support of the manager/brand Atmosphere Core, which acts, depending on the specific activities, on behalf of the Controller and in accordance with its instructions as a processor appointed pursuant to Article 28 GDPR, or as an independent controller for separate and additional marketing processing activities, as specified in this notice under paragraph 2.3.1.

Where such activities involve the transfer of personal data to countries outside the European Economic Area that do not benefit from an adequacy decision pursuant to Article 45 GDPR, in particular to the Republic of Maldives, where the manager/brand Atmosphere Core is established, the transfer shall take place in compliance with Articles 44 et seq. GDPR, on the basis of the Standard Contractual Clauses adopted by the European Commission pursuant to Article 46 GDPR:

·      between Enventi as controller and Atmosphere Core as processor, with reference to the Website and stay management activities carried out on behalf of the Controller;

·      between Enventi and Atmosphere Core as independent controllers, with reference to any marketing activities carried out by Atmosphere Core for its own purposes.

This is without prejudice to the specific notices provided by the manager/brand for any additional processing carried out in its capacity as independent controller (e.g. loyalty programmes, promotional communications or brand initiatives), where applicable.

4.2      Guest service providers

In order to allow guests to use the services requested during their stay, guests’ personal data may be disclosed to external providers delivering services within or in connection with the Property, such as, by way of example, concierge services, wellness and fitness services (spa), leisure or sports activities, childcare services, equipment rental services, transport or accompaniment services, and other services requested by the guest.

As a rule, such parties act as independent controllers, processing personal data for their own purposes related to the provision of the services directly requested by the guest.

4.3      Additional recipients

In order to comply with specific legal obligations or for reasons strictly functional to the performance of the contract and the relationship with the Company, your Data may also be disclosed or transferred to the following recipients: external legal, tax and business advisors, banking institutions, judicial authorities, public bodies and institutions, as well as other third parties where this is strictly necessary for the proper management of the contractual relationship.

5.    Third-party advertisers and links to other websites

The Website may include advertising messages from parties other than the Controller (hereinafter, the “Third Parties”) and links to other websites and/or applications. By accessing such websites and/or applications, Third Parties may collect information about you when you interact with their content, advertising and services under the conditions and terms described in their respective websites/applications.

6.    Data subjects’ rights

As provided for by Article 13 GDPR, the User may at any time:

a)    ask the Controller for access to, rectification or erasure of personal data, or restriction of processing of personal data concerning them;

b)    object to the processing of personal data;

c)    exercise the right to data portability;

d)    withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;

e)    lodge a complaint with a supervisory authority.

The rights described above under letters a), b), c) and d) may be exercised by sending an informal request to the Controller at the following addresses:

-      by email: [email protected];

-      by post: Via Alessandro Manzoni 40, 20121 Milan.

7.    Amendments

The Controller reserves the right to amend this Privacy Notice at any time, including as a result of changes to the applicable legislation, by updating this page. Users are therefore required to check the Privacy Notice periodically in order to become aware of any updates.


This notice Rev.00 was issued on 15 August 2026 and is effective from 15 August 2026