Skip to main content

Privacy Policy

In this page we describe the management methods of the website with reference to the processing of personal data of users who consult it.

Information pursuant to Art. 13 of EU Regulation 2016/679 (GDPR) regarding the protection of personal data

Data Controller

Data Controller: Experior Travel di Gianmaria Viero (hereinafter "Experiortravel")
Data Protection Officer / Processor: Gianmaria Viero
Contact Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
Address: Via Quattro Novembre 8 - 35123 Padova
Telephone: +39 334 21.85.125

Following the regulations dictated by EU Regulation 2016/679 "European General Data Protection Regulation" (hereinafter "GDPR"), Experiortravel, in its capacity as "Data Controller", informs that such processing of personal data will be guaranteed in compliance with the principles of lawfulness, fairness, transparency, necessity, and minimization, thereby protecting the confidentiality and rights of the data subjects.

Data Collected

- Contact Email or WhatsApp Link

In the event that the user utilizes the email address present on the website or the WhatsApp link to send communications and/or requests, the user's email address, mobile phone number, and any data contained therein will be processed exclusively for the purpose of responding to the same and will not be transferred, communicated, or disclosed to third parties in any way.

- Statistical Analysis

Data collected in aggregate form in accordance with the methods and reasons described below.

- Log Files

Data collected in accordance with the methods and reasons described below.

Statistical Analysis

For statistical purposes to measure the "traffic" of this website and to preserve visitor privacy, we collect statistical data in aggregate form using the Umami platform, which declares itself fully compliant with:

  • GDPR (General Data Protection Regulation)
  • CCPA (California Consumer Privacy Act)

Umami allows for the collection of necessary data while respecting user privacy. All data is anonymized, and personal data is never collected.
Umami does not use cookies and does not track users across different websites. All collected data is unique to each installation; therefore, even if Umami were installed on multiple websites, it is impossible to share data between sites to track users. The servers are located within the EU.

Further information can be viewed here:
https://umami.is/features (Privacy section)
https://umami.is/blog/why-privacy-matters

Purposes of Processing — Why Data is Processed

Received data will be processed for the purpose of:

A) responding to any requests and/or communications;
B) concluding contracts for services offered by the Data Controller (for example, assistance or consulting activities);
C) complying with obligations provided for by law, community regulations, or an order from an Authority;
D) fulfilling pre-contractual, contractual, accounting, and tax obligations should the need arise;
E) exercising the rights of the Data Controller (for example, the right of defense in legal proceedings).

Log files are collected and stored for security purposes (Art. 6, paragraph 1, point f and Recitals 47-49-50 of the GDPR), see the following section.

Log Files and Legitimate Interest

In some cases, processing is based on legitimizing grounds other than consent that override the rights of the data subject.
In this context, the collection and short-term retention of log files are considered. As referenced in this privacy policy, these are understood to be chronological and sequential records of accesses to the server hosting this website.

These files are highly important for the security of the website and server, the safeguarding and protection of data, defense against cyber threats (viruses, malware, etc.), and the detection of hardware or software anomalies, and are therefore essential for service continuity.
These specific files contain information that could identify the user (e.g., IP address), but their use is exclusively limited to the purposes and legitimate interests listed below:

  • protecting the website, server, and network from activities harmful to their integrity or to the safety of others (e.g., Denial of Service or DOS, DDOS attacks);
  • protecting and safeguarding data integrity (Data Protection);
  • preventing fraud and/or detecting suspicious or harmful activities (e.g., Spam);
  • investigating violations or reporting illegal conduct.

How Data is Collected

  • data provided by the user is collected exclusively through their free request or communication received via the email or WhatsApp link present on the website;
  • statistical data is collected anonymously during website navigation;
  • log files are collected automatically by the server on which the website is hosted.

Who Data is Shared With

  • personal data collected for the purposes indicated above under points A and B will not be subject to communication/disclosure;
  • data collected for the purposes under points C, D, and E may be shared with parties appointed to fulfill the respective obligations (tax studios or consultants, legal counsel, etc.).

A complete list may be requested from the Data Controller at any time.

Where Data is Stored

  • data provided by the user is stored on servers managed by Ergonet S.r.l. (P.IVA 01871500565, REA VT-135151), headquartered at Via Papa Giovanni XXI, 27 – 01100 Viterbo (VT), Italy, which provides domain registration and hosting services for this website. Ergonet S.r.l. exclusively uses data centres located in Italy and within the European Union for the provision of its services, the storage of personal data, and for backup and disaster recovery systems, in full compliance with GDPR requirements;
  • backup copies may be stored for redundancy and security reasons in other locations or online storage systems (Cloud storage) within the EU;
  • log files are stored on the server hosting the website and within its backup copies.

Ergonet privacy policy: https://contratti.ergonet.it/informativa_privacy.pdf

How Long Data is Stored

  • data collected for Contractual Purposes is stored for the entire duration of the contract and for the subsequent 10 years following its conclusion, except in cases where subsequent retention is required for any litigation, requests by competent authorities, or pursuant to applicable current regulations;
  • data collected for Legal Purposes is stored for a period equal to the duration prescribed by law for each type of data;
  • data collected for Marketing Purposes is stored for a period equal to the duration of the relationship, as well as for the 24 months following its conclusion;
  • log files collected in the manner and for the purposes indicated above are stored on the server hosting the website and periodically deleted by automated procedures every 30 days.

How Data is Kept Secure

For the management of data and log files, specific and appropriate organizational and technical-informatic security measures have been adopted as prescribed by Articles 24 et seq. of the GDPR, aimed at ensuring secure access and protecting information from risks of loss or destruction, including accidental loss.
These measures include, by way of example but not limitation, operating system updates, the adoption of complex passwords and their periodic renewal, the adoption of updated antivirus software, the use of firewalls, specific policies for the custody of backup copies and for the restoration of data and system availability, and any other software or hardware tool necessary for the purpose.
In adopting these measures, Experiortravel may make use of external services chosen independently on the basis of high standards of quality and reliability.

Data Verification and the Right to be Forgotten

At any time, the user, as the data subject, may send a request aimed at verifying the personal data provided, as well as exercising all rights provided for by current regulations (with particular reference to the right of access, rectification, erasure, restriction, and blocking of processing) to the email address: This email address is being protected from spambots. You need JavaScript enabled to view it.. If deemed necessary, the user may lodge a complaint with the Data Protection Authority (Garante della Privacy).
It is also specified that it will not be possible to erase data in cases where a law or regulation mandates its retention, and that if technical or computer problems related to integrity (e.g., of databases) should arise following erasure, the data will be anonymized in such a way as to effectively render it unavailable to the Data Controller.

Use of Cookies

Users visiting the website will have minimal amounts of information placed into the devices in use in small text files called "Cookies," saved by the web browser used for navigation. All information on cookie management is further described on the dedicated page: Cookie Policy.

Links to External Sites

The validity of this privacy policy does not extend to any other external websites consulted by the user via links present on this website. Navigation on such sites is done by free choice of the user, and Experiortravel is in no way responsible with respect to obligations incumbent upon other owners/operators of said websites/portals regarding the content of these sites, the adoption of adequate protection measures for personal data provided therein, or regarding the management of Cookies.

Last updated: May 2026