Privacy Policy
Published on 15/06/2026
Anett Hotel, with registered office in Jaufenstraße 24, Ratschings (BZ) - 39040, Tax ID IT02731040214, (hereinafter "Data Controller" or "Controller") is constantly committed to protecting the online privacy of natural persons during the browsing and enjoyment of services on the website https://www.anett-hotel.com (hereinafter "Portal" or "Website").
This document describes all aspects related to the processing of Personal Data of users (hereinafter "Data Subjects") carried out through the Website, in compliance with the provisions of Art. 13 of Regulation (EU) no. 2016/679 (hereinafter "Regulation"). According to the rules of the Regulation, the processing carried out by the Controller through the Website shall be based on the principles of lawfulness, fairness, transparency, purpose limitation and storage limitation, data minimization, accuracy, integrity and confidentiality.
1. Data Controller
The Data Controller for the processing carried out through the Portal is Anett Hotel as defined above and can be contacted through the methods indicated in the "Contacts" section (see Art. 10).
2. Categories of Personal Data Processed
Navigation/usage data:
Information collected during the user's visit to the Website (e.g., IP address, URI notation addresses, browsing history, information related to interactions with the site, information related to the user's computing environment, browser type and language, operating system, location, date and time of the request). These are pieces of information that are not collected to be associated with identified data subjects, but which by their very nature could, through processing and association with data held by third parties, allow users to be identified;
Data voluntarily communicated by the user:
Personal information voluntarily released by the user through special forms on the Website (e.g., subscription/registration, contact, comments, reviews, posts, etc.). This information may include, by way of example: identifying data (name, surname, Tax ID, username, user ID, password, place and date of birth, etc.), personal image, contact and location data (residential/domicile address, email address, telephone number and postal address, etc.);
Commercial data:
Information necessary for the performance of economic and tax obligations related to the provision of Website services (e.g., payment information, Tax ID, purchase history, product or service usage information, credit and billing information, support requests, etc.);
Sensitive data:
So-called "special categories of personal data" as provided for in Art. 9 of the Regulation, namely personal information capable of revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data intended to uniquely identify a natural person, data concerning health or sex life or sexual orientation of the person.
Location or position data (or mobility):
Information indicating the geographic position (latitude, longitude, altitude, direction of travel, time of position recording) of a user's terminal equipment (e.g., smartphone, pc) of the Website service.
3. Processing Purposes
The Controller uses Personal Data collected through this Website for the following purposes:
Contract execution:
Processing of personal data in order to execute contracts of which the user is a party (e.g., service provision contracts, product sales, registrations, subscriptions, participation in interactive services and similar). This purpose concerns the processing of data necessary to maintain the contractual relationship with the user, provide the services offered by the Website and fulfill the obligations arising from it;
Compliance with legal obligations:
Processing of personal data for compliance with legal obligations to which the Controller is subject (e.g., tax obligations, workplace safety regulations, document retention regulations, anti-money laundering regulations, civil liability, data protection regulations, etc.);
Fulfillment of legal obligations:
Processing of personal data where this is necessary to fulfill the legal obligations mentioned above;
Security and fraud protection:
Processing of personal data in order to protect the security of data, information systems and the technological platform of the Controller, as well as to prevent, detect and combat fraudulent activities, abuse, cyber attacks and all other illegal activities;
Contact with the data subject:
Processing of personal data in order to contact the user through various communication channels (e.g., email, telephone, SMS, WhatsApp) for various purposes such as: request for feedback, customer satisfaction surveys, service communications, account updates, technical assistance, etc.;
4. Legal Basis of Processing
The processing of Personal Data is lawful by virtue of the following legal bases, as provided for in Art. 6 of the Regulation:
Contract execution:
Art. 6(1)(b) of the Regulation – The data are necessary to execute a contract to which the data subject is a party;
Compliance with legal obligations:
Art. 6(1)(c) of the Regulation – Processing is necessary to comply with a legal obligation to which the Controller is subject;
Legitimate interests:
Art. 6(1)(f) of the Regulation – Processing is necessary for the pursuit of legitimate interests of the Controller;
Protection of vital interests:
Art. 6(1)(d) of the Regulation – Processing is necessary to protect the vital interests of the data subject or of another natural person;
Performance of tasks in the public interest:
Art. 6(1)(e) of the Regulation – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
Consent:
Art. 6(1)(a) of the Regulation – The data subject has given consent to the processing of their personal data;
5. Processing Methods
Processing is carried out through manual and/or automatic methods, including through the use of information and computer technologies (e.g., CRM, management software and mailing list services), subject to the application of appropriate technical and organizational security measures to ensure the security, integrity and confidentiality of Personal Data, so as to minimize the risks of destruction, loss, unauthorized access, modification and unauthorized disclosure, in accordance with Articles 6 and 32 of the GDPR.
6. Transfer of Personal Data outside the EU/EEA
The Controller does not intend to transfer Personal Data outside the European Economic Area. However, should it become necessary to meet organizational/production needs (by way of non-exhaustive example, by using providers and/or cloud services that require the transfer of data abroad), adequate safeguards will be identified for the transfer of Personal Data to a Third Country, which depending on the circumstances may include: verification of the existence of adequacy decisions of the European Commission, execution of standard contractual clauses and/or binding corporate rules, verification of the adoption of any supplementary measures in implementation of Recommendation 01/2020 EDPB.
7. Data Retention Periods
The Controller retains Personal Data only for the periods of time necessary to pursue the purposes indicated in this document, or for the timeframes provided for by specific regulations.
After the expiration of such retention periods, Personal Data will be deleted or made anonymous, if not retained for further purposes based on appropriate legal grounds.
8. Recipients
Personal Data collected by the Data Controller may be communicated or made accessible, for the execution of the purposes indicated above, to the following categories of subjects:
After the expiration of such retention periods, Personal Data will be deleted or made anonymous, if not retained for further purposes based on appropriate legal grounds.
9. Rights of the Data Subject
At any time, the Data Subject may access the information concerning them and request its rectification, deletion, restriction of processing, and portability. They may also object, in whole or in part, to the processing and have the right not to be subject to automated decision-making concerning natural persons, including profiling.
To exercise the rights referred to in Articles 15-22 of the GDPR, the Data Subject may contact the Data Controller in the manner indicated in the "Contacts" section (see art. 10). The Data Controller must respond to the request within 1 month, or communicate any delay in response in the case of numerous and/or complex requests (the extension cannot exceed 2 months in any case). In any case, the Data Subject always has the right to lodge a complaint with the competent Supervisory Authority (Data Protection Authority), pursuant to Article 77 of the Regulation, if they believe that the processing of their Personal Data is contrary to the applicable regulations.
Contacts
For further information about the processing of Personal Data carried out in execution of the contract, or to submit a request to exercise rights, it is possible to contact the Controller at the email address: info@anett-hotel.com
AI Kosmo
Privacy Information Clause
[X]. Processing of personal data through the KOSMO virtual assistant
An interactive virtual assistant chatbot is active on our website to assist you during navigation, provide information about our services, and answer your questions. This service is developed by AI KOSMO S.r.l., which acts as Data Processor pursuant to Article 28 of the GDPR, on the basis of a specific agreement governing its tasks and responsibilities. The Data Controller of the data you provide through the Chatbot remains anett-hotel.com
The Chatbot uses Large Language Model (LLM) artificial intelligence systems to understand your requests and provide relevant responses.
a. Categories of data processed
The processing concerns the following personal data:
b. Purposes and legal basis of the processing
Your personal data are processed for the following purposes:
The provision of data for purpose no. 1 is optional but necessary in order to use the Chatbot service. For purpose no. 2, you may object at any time, without prejudice to your ability to continue using the chat service.
c. Processing methods and security measures
The processing is carried out using IT and telematic tools. In accordance with the principles of data protection by design and by default (Article 25 GDPR), appropriate technical and organisational measures are adopted to ensure a level of security appropriate to the risk, including pseudonymisation or anonymisation of data where possible, especially for the purposes of training the algorithms.
d. Data retention period
Your personal data will be retained in accordance with the principle of storage limitation:
e. Data disclosure and transfers
The data collected through the Chatbot are processed by our provider AI KOSMO, appointed as Data Processor. AI KOSMO may use sub-processors (e.g. cloud service providers) for the provision of the service, in compliance with the obligations set out in Article 28 of the GDPR. The use of such services may involve the transfer of your personal data outside the European Economic Area (EEA). Such transfers will take place only where appropriate safeguards are in place, such as adequacy decisions of the European Commission or the execution of Standard Contractual Clauses.
f. Use of artificial intelligence systems
The Chatbot service makes use of artificial intelligence technologies, in particular LLMs. In line with the transparency principles set out in the European AI Act, the GDPR, and national Law No. 132/2025, we wish to provide you with the following information:
g. Data Subject rights in relation to the use of AI
In addition to the general rights provided for by the GDPR (access, erasure, restriction, portability, objection), we remind you that, in relation to the use of artificial intelligence systems, you are guaranteed specific rights, in line with the guidance of supervisory authorities:
To exercise your rights, you may contact anett-hotel.com using the contact details provided in this privacy notice.