Privacy Policy — Personal Data Notice
Website: mt-etnaexcursions.com · Last updated: 13 July 2026
This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and of Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, to anyone visiting mt-etnaexcursions.com and using its services (contact forms, booking form, online payment). It applies to this website only and not to other websites that may be reached through links.
1. Data Controller
Dream Island S.R.L.
Via Francesco Messina, 45/B — 95015 Linguaglossa (CT), Italy
VAT no. (P.IVA): 06159470878
Email: info@mt-etnaexcursions.com · Phone: (+39) 348 1574899
2. Data processed, purposes and legal bases
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Browsing data (IP addresses, technical logs, data implicit in Internet protocols) | Operation and security of the website, aggregate statistics, abuse prevention | Legitimate interest (Art. 6(1)(f) GDPR) | Strictly necessary technical time (logs: max 12 months) |
| Contact details provided voluntarily (email, forms, WhatsApp) | Replying to your requests | Pre-contractual measures (Art. 6(1)(b)) | Time needed to handle the request |
| Booking data (first name, last name, email, phone, language, pick-up point, group composition, any notes) | Managing the booking, providing the service, service communications (confirmation, reminders, changes) | Performance of the contract (Art. 6(1)(b)); legal accounting and tax obligations (Art. 6(1)(c)) | 10 years from the booking (civil and tax law obligations) |
| Any health information you spontaneously enter in the notes field (e.g. allergies, intolerances, pregnancy, reduced mobility) | Providing the service safely and adapting it to your needs | Explicit consent expressed by voluntarily entering the information (Art. 9(2)(a)) | Until the service is provided, then kept only within the archived booking |
| Payment data | Collection of deposits and payments, refunds | Performance of the contract (Art. 6(1)(b)) | Card data is processed exclusively by Stripe: it never passes through or gets stored on our servers; we only keep the transaction identifiers |
| Partial completion of the booking form (date, no. of people and, if filled in, name, email, phone) | Contacting you to help complete the request, if you do not submit the form | Consent given via the cookie/privacy banner (Art. 6(1)(a)) | Maximum 14 days, in encrypted form; without consent this data is not saved |
| Marketing data (cookies and advertising identifiers) | Conversion measurement, traffic analysis, personalised ads (remarketing) | Consent (Art. 6(1)(a)) — see the Cookie Policy | Durations listed in the Cookie Policy |
3. Processing methods
Data is processed with IT tools, applying organisational and technical measures suitable to protect it (encrypted HTTPS connections, access control, backups). No data is disseminated, and no automated decision-making producing legal effects on the data subject takes place.
4. Recipients of the data
For the purposes listed above only, data may be shared with:
- Stripe Payments Europe Ltd / Stripe Inc. — online payment processing (independent controller for card data);
- Google Ireland Ltd / Google LLC — Google Analytics 4, Google Ads, Google Tag Manager, reCAPTCHA (subject to consent, where required);
- hosting, infrastructure and email providers acting as data processors (Art. 28 GDPR);
- administrative and tax consultants, for legal compliance;
- guides and operational staff, limited to the data needed to provide the service (name, group, pick-up point, phone number, operational notes).
Data is never sold or transferred to third parties for marketing purposes of parties other than the Controller.
5. Transfers outside the EU
The use of Google and Stripe services may involve data transfers to the United States. Such transfers take place on the basis of the EU-U.S. adequacy decision (EU-U.S. Data Privacy Framework) and/or the Standard Contractual Clauses approved by the European Commission, with supplementary measures where necessary.
6. Cookies
For the full list of cookies used, their durations and how to manage your preferences, please see the Cookie Policy. Statistics and marketing tools (Google Analytics 4, Google Ads, Google Tag Manager) are activated only with your prior consent given through the banner.
7. Rights of data subjects
Under Articles 15–22 GDPR you have the right to obtain: access to your data and information about its processing; rectification of inaccurate data; erasure ("right to be forgotten"); restriction of processing; data portability; objection to processing based on legitimate interest or carried out for marketing purposes. You may also withdraw any consent given at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Requests should be sent to info@mt-etnaexcursions.com. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
8. Nature of data provision
Providing the data marked as required in the booking form is necessary to conclude the contract: without it, the booking cannot be completed. Providing data for marketing and statistics purposes is always optional.
9. Minors
The booking services of this website are intended for adults. Data of any minors taking part in the excursions is provided by the responsible adult who makes the booking.
10. Changes to this notice
This notice may be updated: the "last updated" date at the top of the page prevails. Previous versions are available on request.
Contacts
Dream Island SRL
Via Francesco Messina, 45, B - 95015 Linguaglossa (CT)
VAT no. (P.IVA): 06159470878
Email: info@mt-etnaexcursions.com
Phone: +39 348 1574899