How we handle personal data

Last updated: 29 July 2026 · version 2026-07-29.1

This notice explains which personal data Ospitia collects, why, who it is shared with, how long it is kept and what rights you have. It is written to be understood, not merely to be compliant. Questions: privacy@ospitia.it. This English version is a courtesy translation: in case of conflict, the Italian text prevails.

1. Who processes your data

Ospitia is operated by Elite Properties SRL, based in Genova, Italia ("we", "the provider"). For anything concerning data protection, write to privacy@ospitia.it.

We are not currently required to appoint a Data Protection Officer under Art. 37 GDPR. If and when the scale of processing makes it mandatory, the contact details will be published here.

2. Two different roles, explained

How we process data depends on whose data it is. There are two situations and they must not be conflated, because they decide who answers to the supervisory authority.

  • Your account data. For data about you as a customer (name, email, billing details, settings, product usage) we are the controller: we decide the purposes and the means, within the limits described here.
  • Your guests' data. For data about the people staying in your apartments (identity documents, check-in details, messages, payments) you are the controller and we act as processor under Art. 28 GDPR: we process that data only to run the service for you, and only on your documented instructions.

The processor relationship is governed by the [Data Processing Agreement](/dpa) required by Art. 28 GDPR, accepted together with the terms of service before the account is activated. It covers instructions, confidentiality, security measures, sub-processors, assistance with data subject rights, breach notification, and deletion or return of data at the end of the relationship.

3. What we collect

  • Registration and account data: name, email, password (stored only in an irreversible hashed form), organisation, role, preferences.
  • Billing and subscription data: company name, VAT number, address, subscription status. Full card details never reach our systems; the payment provider handles them directly.
  • Operational data you enter: apartments, reservations, costs, cleaning shifts, inventory, tax documents.
  • Guest data (as processor): reservation details, contact details, identity documents uploaded at online check-in, data required by law, guest conversations, door-opening events if you use connected locks.
  • Usage and diagnostic data: technical logs, errors, response times and operating metrics, used to keep the service stable and secure.
  • Access and audit records: who did what and when on sensitive operations, so that incidents can be reconstructed.
Biometric data: online check-in only, and only with your consent. If the property enables identity verification, your selfie is compared with the photo on your ID document by an artificial-intelligence system to confirm you are the same person. This is biometric data (GDPR art. 9): we ask you first, with a separate explicit consent, and if you prefer not to give it a human performs the check instead, with no disadvantage to you. We run no video surveillance, we do not use guest data for advertising profiling and we sell it to no one.

4. Why we process it (legal bases)

ProcessingLegal basisNote
Providing the service you signed up forPerformance of a contract (Art. 6.1.b)Without this data the service cannot work
Invoicing and accountingLegal obligation (Art. 6.1.c)Ten-year retention under Italian tax law
Security, abuse prevention, diagnosticsLegitimate interest (Art. 6.1.f)Balanced so as not to override your rights
Service communications (notices, incidents)Performance of a contract (Art. 6.1.b)These are not marketing messages
Optional commercial communicationsConsent (Art. 6.1.a)Withdrawable at any time, with no consequences
Guest dataController's instructions (Art. 28)The legal basis towards the guest is yours to identify

5. Use of artificial intelligence

The product includes AI-assisted features: draft replies to guests, pricing suggestions, assisted reading of documents uploaded at check-in. You should know exactly how they behave.

  • Guest replies are drafts. By default no message is sent automatically: a person reviews and approves it. Automatic sending exists as a feature, but you must switch it on deliberately and it remains your responsibility.
  • No automated decisions with legal effect. The AI does not set final prices, does not accept or refuse bookings and produces no significant effect on individuals on its own within the meaning of Art. 22 GDPR.
  • Your data does not train the providers' models. AI providers process content only to generate the individual response, under agreements that exclude training on customer data.
  • Internal service improvement. We may use conversations in aggregated or anonymised form to measure and improve answer quality. If an improvement required identifiable data, we would ask you first.
  • Transparency towards guests. You must not present fully AI-generated interactions as human: transparency is an obligation under the EU AI Act.
  • Who answers for what. Under the EU AI Act we are the provider of the AI system and answer for the provider's obligations; you are the deployer and answer for how you use it towards your guests. No contractual clause shifts onto you the obligations the law places on us, or the other way round.

For the AI features applied to check-in documents we have carried out a Data Protection Impact Assessment (DPIA, Art. 35 GDPR), available to customers on request.

6. Who we share data with (sub-processors)

We do not sell data and do not pass it to third parties for marketing. We rely on selected technology providers that process data only on our behalf, under contracts imposing the same safeguards we owe you. This is the complete, current list:

ProviderServiceData location
SupabaseDatabase and storageFrankfurt (EU)
VercelWebsite and function hostingFrankfurt (EU)
Cloudflare R2Temporary photo and video storageEU edge
StripePayments and subscriptionsIreland (EU)
Beds24Channel manager (OTA synchronisation)Germany (EU)
ChannexSecondary channel manager / failoverUnited Kingdom
TwilioSMS and messaging deliveryIreland (EU)
OpenAPIElectronic invoice transmission to the Italian SDIItaly (EU)
GoogleStorage on the customer's own Drive, if enabledEU / United States
AnthropicAI assistant for guest replies and, where enabled, identity verification (selfie/document match)United States
OpenAIAI assistant (fallback)United States
We notify you at least 30 days before adding or replacing a sub-processor that handles personal data, so that you can object. If you object and no alternative is available, you may terminate without penalty.

7. Disclosures to authorities

Some data leaves the service because the law requires it. There are three distinct cases and it is worth keeping them apart.

  • Filings we transmit on your behalf: public security reports to the police, regional and national statistics, tourist tax to the municipality, electronic invoices to the Italian SDI. Here you are the controller and we are the instrument: the allocation of responsibility is in the compliance liability statement.
  • Tax reporting about you as our customer (DAC7): see the paragraph below.
  • Requests addressed to us by judicial or police authorities: we require a formal act, check that it is lawful and limited, hand over only what is requested and inform you, unless the law forbids it.

DAC7 — when it will apply. EU Directive 2021/514 (Italian Legislative Decree 32/2023) requires platform operators that facilitate payments while retaining a fee to report annually to the Italian Revenue Agency the details of sellers exceeding 30 transactions or 2,000 euro in a year.

Today this obligation does not apply to us, because we retain no fee on collections from your guests: the money goes straight to your account through the payment provider. If we ever introduce a fee, we will tell you at least 30 days in advance and from then on we will have to collect and report your tax code or VAT number, residence or registered office, IBAN and amounts earned, keeping them for 5 years. You will receive a copy of what we report about you.

8. Where data is stored

Core data (database, documents, photos and videos) is stored inside the European Union. Some AI providers are based in the United States: those transfers rely on the Standard Contractual Clauses approved by the European Commission, together with a transfer impact assessment and supplementary measures (encryption in transit, minimisation of what is sent, no long-term retention on the provider's side).

9. How long we keep it

DataRetentionThen
Account dataFor the duration of the contractDeleted or anonymised within 90 days of closure
Tax and accounting documents10 yearsStatutory, cannot be shortened
Photos of guest identity documents30 days after check-out (default)Automatically deleted from our storage
Guest identity detailsAs long as needed for the stay and legal filingsDeleted according to the settings you choose
Alloggiati Web / ISTAT submissions30-90 days for technical supportOnly metadata remains; multi-year archiving is yours
Cleaning videos30 days in our temporary bufferRetained on your own storage (e.g. your Drive)
Diagnostic logs3 days when successful, 7 days for errorsAutomatically deleted
Aggregated operating metrics90 daysAutomatically deleted
Audit records of sensitive operations5 years, immutableAutomatically deleted
One point deserves attention. Some rules require *you*, as the accommodation operator, to keep records for longer than we do (five years for public security filings, ten years for invoices). The service gives you export and automatic archiving to your own storage, but the obligation to keep them is yours: if you do not archive, that data no longer exists once our window closes. See the compliance liability statement.

10. Your rights

You have the right to access your data, have it corrected, request its erasure, restrict or object to processing, and receive it in a machine-readable format to take it elsewhere (Arts. 15-22 GDPR). Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing already carried out.

Exercise these rights from your account settings or by writing to privacy@ospitia.it. We reply within 30 days, extendable by a further 60 for complex requests, with notice to you. There is no charge, save for manifestly unfounded or repetitive requests.

If the request concerns a guest's data, you are the controller: pass it to us as your processor and we will assist technically, but the answer to the data subject is yours to give.

If you believe the processing infringes the law you may lodge a complaint with the Italian Garante per la protezione dei dati personali (www.garanteprivacy.it) or with the supervisory authority of your country of residence, and seek a judicial remedy.

11. Information for guests

If you are a guest who arrived here from an online check-in: your data is processed by the property hosting you, which is the controller. We provide the software and process the data only on its behalf.

  • Identity details and the document are needed for the mandatory report to the Italian public security authority (Art. 109 TULPS) and for local statistical and tax filings.
  • The photo of the document is kept for a short period (30 days after check-out by default) and then deleted automatically.
  • If the apartment uses a connected lock, door openings are logged for security: date, time and device — no images.
  • Conversations with the property may be processed by an AI assistant to prepare replies; the final reply is reviewed by a person unless the property has chosen otherwise.
  • To exercise your rights, contact the property hosting you; if you get no reply you may also write to us and we will act as technical intermediary.

12. Security

We protect data with encryption in transit and at rest, role-based access control, isolation between organisations, immutable audit records on sensitive operations, and automatic deletion once a retention window closes. No system is invulnerable, but we treat security as part of the product, not as an add-on.

13. Data breaches

If a personal data breach affects you as a customer, we inform you without undue delay and in any case within 72 hours of becoming aware of it, with what we know: what happened, which data is involved, what we are doing and what you should do. Where the breach concerns your guests' data, notifying the authority is your duty as controller: we provide everything you need to do so in time.

14. Minors

The service is aimed at professionals and is not intended for minors. Data concerning underage guests may appear in mandatory filings: it is processed solely for that purpose and under the responsibility of the property, which collects it from the accompanying adult.

15. Changes to this notice

We may update this notice. The date at the top shows the last revision. For material changes we notify you before they take effect and, where they affect your rights, we ask you to acknowledge them at your next sign-in.

Privacy contact: privacy@ospitia.it.