Privacy Policy
This notice is provided pursuant to Regulation (EU) 2016/679 (GDPR) and applicable Italian data protection law. It describes how GVM processes the personal data of users who visit this website and use the services offered by GVM.
1. Data Controller
- Company name: GVM — Gabriella Vittoria Monti
- VAT number: 04601780960
- Registered office: Via Maestri d’Acqua 36, 90100 Palermo (PA), Italy
- Email: montigabriellavittoria@gmail.com
- Alternative email: g.monti@yahoo.it
- Telephone: +39 339 498 2946
2. Personal data collected
- Identification data (first name, last name);
- Contact data (email address, telephone number);
- Information relating to personalised requests for itineraries and experiences;
- Browsing data (IP addresses, system logs, technical information collected automatically by the server);
- Any further data voluntarily provided through the contact form or direct communications.
3. Purposes of processing
- Handling information requests;
- Designing tailor-made itineraries and personalised experiences;
- Administrative and organisational management of the services offered;
- Compliance with legal, accounting and tax obligations;
- Sending communications about the services offered, subject to consent where required;
- Protection of the Controller’s rights.
4. Legal basis
- Performance of pre-contractual and contractual measures at the data subject’s request (Art. 6(1)(b) GDPR);
- Compliance with legal obligations (Art. 6(1)(c));
- Consent of the data subject, where required (Art. 6(1)(a));
- Legitimate interest of the Controller for organisational and security purposes (Art. 6(1)(f)).
5. Contact form
Data sent through the contact form (name, surname, email, optional telephone, subject and message) is transmitted by email to the Controller and used solely to reply to your request. A technical record of the request is kept on the hosting server for security and proof of consent for a maximum of 12 months, after which it is automatically deleted.
6. Methods of processing
Personal data is processed using electronic and paper-based tools, with appropriate technical and organisational measures to ensure security, integrity and confidentiality, preventing unauthorised access, disclosure, modification or destruction.
7. Retention
Personal data is kept only for as long as strictly necessary to fulfil the purposes for which it was collected and, in any case, in accordance with the time limits established by law.
8. Recipients
- Tax, legal or administrative advisers;
- Technical and IT service providers, including the website hosting provider;
- Partners and collaborators involved in organising the requested experiences and itineraries;
- Competent authorities where required by law.
Data is not disseminated.
9. Transfers outside the EU
Should it be necessary to transfer data to third countries, the Controller will ensure that the transfer complies with the GDPR, through appropriate safeguards such as the Standard Contractual Clauses.
10. Your rights
You may exercise at any time the rights set out in Articles 15–22 GDPR: access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection, and withdrawal of consent without affecting the lawfulness of processing carried out before withdrawal. Requests can be sent to the email addresses above.
11. Cookies
Information about cookies is available in the Cookie Policy.
12. Provision of data
Providing data is optional; however, failure to provide the data required may make it impossible to reply to requests or deliver the services requested.
13. Complaints
You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) if you believe that the processing of your data infringes applicable law.
Last updated: 25 September 2026