Privacy Policy

Version 1.0 — In force from 26/04/2026

PREAMBLE

This Privacy Policy (hereinafter the «Privacy Policy» or the «Policy») describes transparently the ways in which Horizon Servizi Integrati S.r.l.s. (hereinafter «Stravagando» or the «Platform»), data controller and operator of the digital platform Stravagando accessible at the main address stravagando.com and related subdomains, on the mobile app for iOS and Android (hereinafter the «App») and on the connected support, marketing and communication channels, collects, uses, retains, communicates and transfers the personal data of Data Subjects, in compliance with:

  • (a) Regulation (EU) 2016/679 of the European Parliament and of the Council, on the protection of natural persons with regard to the processing of personal data (hereinafter the «GDPR»);

  • (b) Italian Legislative Decree no. 196 of 30 June 2003 («Privacy Code»), as amended by Italian Legislative Decree no. 101 of 10 August 2018;

  • (c) the Guidelines of the Italian Data Protection Authority (hereinafter the «Garante») and the decisions of the European Data Protection Board (EDPB);

  • (d) Directive 2002/58/EC (ePrivacy Directive) as amended, for the aspects relating to direct marketing and Tracking Tools;

  • (e) for the processing of data presenting tax-related profiles or attributable to payment processing, the applicable sectoral regulations including Italian Legislative Decree no. 32 of 1 March 2023 (DAC7), Italian Legislative Decree no. 231 of 21 November 2007 (anti-money laundering), Italian Presidential Decree 600/1973 (assessment of income taxes) and Italian Presidential Decree 633/1972 (VAT);

  • (f) Regulation (EU) 2022/2065 (Digital Services Act, «DSA») and Regulation (EU) 2019/1150 (Platform-to-Business, «P2B») for the aspects of transparency in digital services and in relations with business users;

  • (g) Regulation (EU) 2024/1689 (Artificial Intelligence Act, «AI Act») for the aspects of transparency of the artificial intelligence systems employed for the automated moderation of User-generated content and for the calculation of the Trust Score;

  • (h) Directive (EU) 2022/2555 (NIS2), for the aspects of information security.

This Privacy Policy constitutes the general information notice pursuant to Articles 13 and 14 GDPR and is integrated, for specific aspects, by the Cookie Policy of the Platform — to which reference is made for the detail of the Tracking Tools — by the General Terms and Conditions of Use (with particular reference to Sections 5, 6, 7, 8, 8-bis, 9, 11, 12, 12-bis, 16 and 16.1), by the Terms and Conditions of Sale for the aspects relating to the marketplace of paid Experiences, by the Host Terms, by the Referral Program Terms, by the Technical Specifications of the Service for the operational parameters of the processing, as well as by the specific privacy notices that may be provided at the time of collection of personal data for further purposes (e.g. participation in contests, surveys, pilot programs, beta access).

In the event of discrepancy between this Privacy Policy and other specific privacy notices provided to the Data Subject for individual processing operations, the provisions of the most recent specific notice prevail for the specific processing concerned; the provisions of this Policy remain in force for everything not specifically governed.

ART. 1 — DEFINITIONS

For the purposes of this Privacy Policy, the following terms have the meaning set out below. The definitions are supplemented by those provided in the General Terms and Conditions, in the Terms and Conditions of Sale, in the Host Terms, in the Referral Program Terms and in the Cookie Policy of the Platform.

1.1 «Personal Data»: any information relating to an identified or identifiable natural person, pursuant to Article 4(1)(1) GDPR. It includes, by way of example: first name, surname, address, date of birth, tax code, VAT number, email address, telephone number, IP address, unique identifiers, transaction data, communication contents, geographic coordinates, UGC.

1.2 «Processing»: any operation or set of operations, performed with or without the aid of automated processes, applied to Personal Data, pursuant to Article 4(1)(2) GDPR. It includes collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, communication by transmission, dissemination, comparison, interconnection, restriction, erasure and destruction.

1.3 «Data Controller» or «Controller»: the natural or legal person who, individually or jointly with others, determines the purposes and means of the processing of Personal Data, pursuant to Article 4(1)(7) GDPR. For the processing operations described in this Policy, the Controller is Horizon Servizi Integrati S.r.l.s. unless otherwise indicated.

1.4 «Data Processor» or «Processor»: the natural or legal person who processes Personal Data on behalf of the Controller pursuant to Article 28 GDPR, on the basis of a contract or other binding legal act.

1.5 «Data Subject»: the identified or identifiable natural person to whom the Personal Data relate. For the purposes of this Policy, the Data Subject typically corresponds to the User of the Platform in one of the capacities defined below.

1.6 «User»: any party who accesses or uses the Platform. The User may hold one or more of the following capacities, also cumulatively in the same period, pursuant to Section 3-bis of the General Terms and Conditions:

  • (a) Unregistered Visitor — anyone who accesses the Platform without having registered, including the recipients of the pre-registration assistance service («Guest Help», see Section 17-ter of the General Terms and Conditions);

  • (b) Social User — natural person registered on the Platform for the non-transactional functionalities (Profile, Social/Community, Gamification, exploration of the Places catalogue, publication of UGC), pursuant to the General Terms and Conditions. It constitutes the base regime applicable to every registered User;

  • (c) Customer or Guest — the User who, in addition to the capacity of Social User, searches, books or enjoys the paid Experiences offered through the integrated marketplace, pursuant to the Terms and Conditions of Sale;

  • (d) Host — the User, natural person or legal entity, who publishes and offers paid Experiences on the integrated marketplace, pursuant to the Host Terms;

  • (e) Referrer — the User who joins the Referral Program by promoting the Platform and receiving the benefits thereof, pursuant to the Referral Program Terms.

The assumption of a special capacity (Customer, Host, Referrer) does not entail the loss of the base capacity of Social User, but entails the cumulative application of the processing operations envisaged for the further purposes. This Policy describes the processing operations applicable to each capacity in the dedicated sections.

1.7 «Experience»: the paid experiential activity offered by the Host to Customers through the integrated marketplace of the Platform, according to the definitions of the Terms and Conditions of Sale.

1.8 «Place» or «POI» (Point of Interest): individual locality or geographic entity catalogued in the Places catalogue of the Platform (internal technical designation: Atlas), identified by geographic coordinates, descriptive attributes (name, category, address) and thematic categorisation. Places may comprise villages, trails, castles, restaurants, natural monuments and other points of interest, which may bear UGC such as check-ins, reviews and posts published on the Place Wall.

1.9 «Check-in»: the geolocated registration carried out by the User in the vicinity of a Place present in the catalogue, validated server-side by calculating the distance from the coordinates of the POI. The check-in constitutes the main method of accruing XP in the Gamification system and may be associated with a UGC Tag pursuant to definition 1.13 below.

1.10 «User-Generated Content» or «UGC»: any content published by the User on the Platform, comprising, by way of example, photographs, scored reviews, narrative posts published on the Wall of a Place, proposals for new Places, suggestions for editing existing Places, comments, personal lists (Notebooks), tags, likes, check-ins and direct messages exchanged through the integrated messaging system.

1.11 «Wall»: the interface for displaying UGC on the Platform, declined in two forms:

  • (a) Personal Wall (route /{locale}/feed) — the personalised aggregate of Content relevant to the User, including Content that mentions them via UGC Tag;

  • (b) Place Wall — the public space associated with each POI in which Users may publish narrative posts and other Content contextual to the Place.

1.12 «Gamification System»: the playful system of the Platform comprising XP (experience points), Levels, Achievements, Streaks (consecutive series of activity), Level Perks (advantages associated with reaching Levels) and Year Review (periodic reporting of activity). The elements of the Gamification System have an exclusively symbolic and playful nature and do not constitute virtual currency nor an asset convertible into money, pursuant to Section 9.1 of the General Terms and Conditions.

1.13 «UGC Tag»: the association, within Content published by a User, of the reference to another registered User. The UGC Tag is applicable within the limits and according to the rules of Section 8-bis of the General Terms and Conditions and, for the specific case of companion tagging in check-ins, of Section 8.

1.14 «Trust Score»: the numerical technical indicator (between 0 and 100) calculated automatically on the basis of the technical consistency of a User's check-ins, described in Section 11 of the General Terms and Conditions. The Trust Score affects the attribution of XP for check-ins, the automatic approval of reviews and access to reserved functionalities.

1.15 «Automated Moderation»: the processing of preventive analysis of UGC carried out by means of third-party artificial intelligence systems, comprising, in particular, a language model for text classification and an image analysis service, described in Section 12 of the General Terms and Conditions and in compliance with Regulation (EU) 2024/1689 (AI Act).

1.16 «Special Categories of Personal Data» or «Sensitive Data»: the Personal Data referred to in Article 9(1) GDPR — namely those revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, sex life or sexual orientation. The Platform does not normally require the provision of Sensitive Data from Users; if a User voluntarily provides Sensitive Data (e.g. by mentioning in communications with the Host a health condition relevant to the enjoyment of the Experience, or by publishing UGC that reveals them), their processing takes place on the basis of explicit consent pursuant to Article 9(2)(a) GDPR or, where applicable, on the basis of Article 9(2)(f) GDPR (establishment or defence of a legal claim).

1.17 «Criminal Data»: the Personal Data relating to criminal convictions and offences or related security measures pursuant to Article 10 GDPR. The Platform may process such data exclusively in the cases provided for by law, in particular in implementation of anti-money laundering, anti-fraud and international sanctions measures.

1.18 «Tracking Tools»: cookies and other analogous technologies for tracking the User, as defined in the Cookie Policy of the Platform, to which full reference is made.

1.19 «Stripe Connect»: the payment infrastructure provided by Stripe Payments Europe Ltd, used by the Platform for collecting Customers' payments, executing transfers to Hosts and Cashouts to Referrers.

1.20 «KYC» (Know Your Customer): the set of procedures for verifying the identity of Users, conducted directly by Stravagando by means of manual collection and verification of the documents uploaded by the User, for the purposes of security, anti-fraud, anti-money laundering and compliance with tax regulations.

1.21 «DAC7»: Directive (EU) 2021/514, transposed in Italy by Italian Legislative Decree no. 32 of 1 March 2023, which requires operators of digital platforms to collect, verify and communicate to the Italian Revenue Agency the data relating to the parties carrying out «Relevant Activities» through the Platform.

1.22 «UIF»: the Financial Intelligence Unit established at the Bank of Italy pursuant to Article 6 of Italian Legislative Decree 231/2007, recipient of suspicious transaction reports for anti-money laundering purposes.

1.23 «Garante»: the Italian Data Protection Authority, the Italian supervisory authority pursuant to the GDPR, with registered office in Rome, Piazza Venezia no. 11.

1.24 «EEA»: the European Economic Area, comprising the Member States of the European Union, Iceland, Liechtenstein and Norway.

1.25 «Extra-EEA Transfer»: the transfer of Personal Data to recipients established in countries that are not part of the European Economic Area, subject to the safeguards of Chapter V GDPR.

1.26 «Data Breach»: the breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed, pursuant to Article 4(1)(12) GDPR.

1.27 «DSA»: Regulation (EU) 2022/2065 (Digital Services Act), which governs digital services in the European single market.

1.28 «AI Act»: Regulation (EU) 2024/1689, which establishes harmonised rules on artificial intelligence.

1.29 «P2B»: Regulation (EU) 2019/1150 (Platform-to-Business Regulation), which promotes fairness and transparency for business users of online intermediation services.

1.30 «Legal Hold»: the extension, by way of derogation from the ordinary retention periods, of the retention of specific Personal Data or Content for reasons of law, of defence in legal proceedings, of compliance with mandatory obligations or of investigation by competent Authorities, pursuant to Article 9-bis of this Policy and Section 16.1 of the General Terms and Conditions.

1.31 «DPO» (Data Protection Officer): the party tasked with monitoring compliance with the GDPR pursuant to Articles 37-39 GDPR. The DPO, where appointed, is contactable at the address support@stravagando.com.

ART. 2 — DATA CONTROLLER AND DPO

2.A — Data Controller

2.1 Identification. The Controller of the processing of the Personal Data collected through the Platform is:

Horizon Servizi Integrati S.r.l.s. Registered office: Viale Giovanni Bovio, 103/1 65124 Pescara (PE), Italy Tax Code / VAT No.: 02445190685 General assistance email: support@stravagando.com Email for data protection requests: support@stravagando.com Certified email (PEC): horizonserviziintegrati@pec.it

2.2 Commercial identity. The Platform is commercially known under the trademark «Stravagando» and its graphic variations, the exclusive property of Horizon Servizi Integrati S.r.l.s.

2.B — Data Protection Officer (DPO)

2.3 DPO. Where appointment is mandatory pursuant to Article 37 GDPR or where Horizon Servizi Integrati S.r.l.s. provides for it on a voluntary basis, the Data Protection Officer (DPO) is contactable at the address:

support@stravagando.com (with subject: «DPO»)

Horizon Servizi Integrati S.r.l.s. reserves the right to establish in the future a dedicated email address, which will be communicated to Data Subjects by means of an update to this Policy pursuant to Art. 13. Requests addressed to the DPO are handled according to the principle of confidentiality under Article 38(5) GDPR.

2.C — EU Representative (for extra-EEA parties)

2.4 EU Representative. For Data Subjects resident in the European Economic Area, Horizon Servizi Integrati S.r.l.s. is itself established in the European Union (Italy) and therefore does not require the appointment of an EU Representative pursuant to Article 27 GDPR.

2.D — Joint Controllers and Autonomous Controllers

2.5 Joint Controllers. For some specific processing operations, Horizon Servizi Integrati S.r.l.s. may act as a Joint Controller together with other Controllers, pursuant to Article 26 GDPR. In such cases, the specific configuration of the respective obligations is the subject of a formal arrangement between the Joint Controllers, the essence of which is made available to Data Subjects upon request at support@stravagando.com. Typical configurations of Joint Controllership include — by way of example — the use of Meta Business Tools (Facebook Pixel, Custom Audiences) for joint marketing purposes between Horizon Servizi Integrati S.r.l.s. and Meta Platforms Ireland Limited.

2.6 Autonomous Controllers. Numerous Third Parties that receive Personal Data in the context of the Platform act as autonomous Controllers for the purposes they determine, in particular: (a) Stripe Payments Europe Ltd, for payments and financial services; (b) the national and foreign judicial, tax, administrative and supervisory Authorities; (c) the banking institutions for the execution of payments; (d) Hosts and Customers for the communication and execution of the booked Experiences, each within the limits of their role; (e) the other Users of the social community for the enjoyment of the UGC published with public visibility or extended to the mutual-follow network. This Policy describes the processing carried out by Horizon Servizi Integrati S.r.l.s. as Controller; for the processing carried out by the Third Parties as autonomous Controllers, reference is made to their respective privacy notices.

ART. 3 — CATEGORIES OF PERSONAL DATA PROCESSED

Horizon Servizi Integrati S.r.l.s. processes various categories of Personal Data depending on the relationship with the Data Subject and the functionalities of the Platform used. The categories listed below are detailed by User-type (Visitor, Social User, Customer, Host, Referrer); the processing of each category takes place for the purposes and on the legal bases described in Art. 4 below.

3.A — Registration and Profile data

3.1 Unregistered Visitors. For Unregistered Visitors, Horizon Servizi Integrati S.r.l.s. does not collect registration data. The Usage Data described in paragraph 3.K below are collected automatically. Where the Visitor contacts pre-registration assistance («Guest Help» pursuant to Section 17-ter of the General Terms and Conditions), the email address provided, the content of the request and the metadata of the temporary access token issued by the system are collected.

3.2 Social Users and registered Customers. For Users registered for the non-transactional functionalities (social, gamification, exploration, UGC) — which constitute the base regime applicable to every User — and for Customers who access the integrated marketplace, the following are collected, at the stage of account creation and subsequent updating:

  • (a) minimum identifying data: first name, surname;

  • (b) contact data: email address (verified by means of a confirmation message with verification link, according to the methods described in Section 4.1 of the General Terms and Conditions), mobile telephone number, optional, where provided by the User for specific functionalities (not subject to verification via SMS), postal address where provided for Experiences booked on the marketplace;

  • (c) access credentials: password (stored in hashed form with secure cryptographic algorithms such as bcrypt or Argon2; in no case stored in clear text), any two-factor authentication (2FA) tokens based on TOTP and recovery codes, any unique identifiers received from federated authentication providers (SSO Google, Meta/Facebook);

  • (d) date of birth, where the Platform provides for its collection in implementation of age verification obligations pursuant to Article 28 DSA or for the purposes of participation in Experiences with age restrictions; failing that, the User confirms at the registration stage that they possess the minimum access age provided for by Section 3 of the General Terms and Conditions (14 years for residents in Italy, in application of Article 8 GDPR and Article 2-quinquies of the Italian Privacy Code);

  • (e) preferences: interface language, currency, preferred destination cities, categories of Experiences of interest, marketing preferences, accessibility, time zone;

  • (f) public Profile data: username (automatically generated by the system at the registration stage on the basis of the data provided, as provided in Section 4 of the General Terms and Conditions; subsequent modification will possibly be made available as a functionality under development, see Section 29 of the General Terms and Conditions), profile image (optional), short bio (optional);

  • (g) Profile visibility and privacy settings, autonomously managed by the Data Subject from the account privacy page (route account.privacy), as provided by Section 5 of the General Terms and Conditions. The settings — independent of one another — comprise in particular:

    • (i) Profile visibility (profile_visibility, default: public);

    • (ii) indexing of the Profile in external search engines (allow_search_indexing, default: enabled; operates jointly with the public Profile and the reaching of a minimum activity threshold);

    • (iii) visibility in public leaderboards (show_in_leaderboards, default: enabled);

    • (iv) consent to being tagged in content (default: enabled).
      The public default settings referred to in points (i) and (ii) serve the social discovery and territory exploration purposes inherent to the Platform; pursuant to Art. 25 GDPR, they are disclosed to the data subject at the time of registration/onboarding and may be changed to a more restrictive setting (opt-out) at any time from the account privacy page. The more restrictive default settings for minor Users set out in Art. 12.5 remain unaffected.

  • (h) IP address and browser user-agent, retained in sessions and in the main events (by way of example: login, check-in) for the purposes of security, audit and detection of abuse, pursuant to Section 4.4 of the General Terms and Conditions.

3.3 Hosts. For Hosts registered on the integrated marketplace the following are collected, in addition to the data referred to in paragraph 3.2 where applicable:

  • (a) extended identifying and tax data: first name and surname or company name, business name, registered office, Business Register registration number, tax code, VAT number with indication of the tax regime adopted (ordinary, simplified, flat-rate, special regime for agritourism or B&B), any REA code, indication of consumer or business status;

  • (b) beneficial owner data pursuant to Italian Legislative Decree 231/2007 for legal entities;

  • (c) legal representative data: first name, surname, tax code, position, valid identity document;

  • (d) banking data: IBAN for payments, account holder name, BIC/SWIFT for extra-SEPA IBANs, any documents of account ownership;

  • (e) insurance data: professional liability or third-party liability policy (insurer name, number, ceiling, expiry date);

  • (f) compliance data: self-certified declarations pursuant to Italian Presidential Decree 445/2000, certificates of sanitary/safety compliance where required for the category of Experience, any National Identification Code (CIN) for tourist accommodation pursuant to Italian Law 191/2023;

  • (g) activity data: types of Experiences offered, operational locations, availability calendars, textual and visual descriptions of the offer;

  • (h) Experience data (limited to the part relating to the Host): description, price, duration, capacity, location, photographic/video material, reviews received.

3.4 Referrers. For Referrers registered with the Referral Program the following are collected, in addition to the data referred to in paragraph 3.2 where applicable:

  • (a) extended identifying and tax data: as for Hosts, distinguishing the occasional regime (natural person without VAT number) from the professional regime (natural person with VAT number or legal entity);

  • (b) banking data: IBAN for Cashouts, BIC/SWIFT;

  • (c) promotional channel data: identification of the promotional channels used (website, social media, blog, newsletter, podcast), main URLs, indicative audience, description of promotion activity;

  • (d) Referral Code and Referral Link assigned to the Referrer;

  • (e) Referral performance data: number of Referred parties, number of Qualifying Actions, Rewards accrued, Cashouts made.

3.B — Transaction and payment data

3.5 Transaction data. For each transactional operation carried out on the integrated marketplace of the Platform the following are collected:

  • (a) unique transaction identifier;

  • (b) amount, currency, date and time;

  • (c) identifier of the booked Experience, with detail of unit price, participants, options purchased;

  • (d) Host data receiving the payment;

  • (e) Referrer data possibly attributed to the conversion (for the purposes of the 90-day last-click Attribution Cookie, according to the rules of the Referral Program Terms);

  • (f) transaction status: pending, succeeded, failed, refunded, disputed/chargeback;

  • (g) any refunds, chargebacks, escrow holds.

3.6 Payment data (handled by Stripe). The data instrumental to payment — card number, expiry, CVV, 3D Secure authentication, data of the device used for the payment — are collected and processed exclusively by Stripe Payments Europe Ltd as autonomous Controller. Horizon Servizi Integrati S.r.l.s. does not have access to the complete payment card data; it receives from Stripe exclusively:

  • (a) a tokenised identifier of the payment method (e.g. last 4 digits, card brand, expiry);

  • (b) the transaction status;

  • (c) any error codes or reasons for refusal.

3.7 Stripe Radar risk score. For each transaction, Stripe Radar processes a pseudonymised anti-fraud risk score which is shared with Horizon Servizi Integrati S.r.l.s. for the purposes of authorisation decisions. The score comprises elements of device fingerprinting, behavioural and chronological, according to Stripe Radar's policies.

3.C — Identity and KYC data

3.8 Identity documents. For Customers who so request in specific cases (e.g. Experiences with age restrictions or specific regulatory requirements) and — systematically — for Hosts and Referrers, the following are collected by means of manual upload of the documents to private storage and verification carried out by the authorised staff of Horizon Servizi Integrati S.r.l.s.:

  • (a) valid identity document (identity card, passport, driving licence): front/back image, document number, issuing authority, date of issue and expiry;

  • (b) proof of residence for legal entities only or for enhanced KYC requests (utility bill, recent bank statement);

  • (c) company registration extract or equivalent document for legal entities.

Identity verification does not make use of biometric techniques, facial recognition, selfies or liveness detection: it consists of the manual comparison, by authorised staff, between the uploaded documents and the data provided by the User. The documents are stored on restricted-access storage according to the periods referred to in Art. 9.

3.D — Tax, anti-money laundering and DAC7 data

3.9 Tax data. For Hosts and Referrers the tax data necessary to fulfil regulatory obligations are collected:

  • (a) tax code (Italian) or TIN (for foreign residents) for each State of tax residence;

  • (b) VAT number, VAT regime, VIES number for non-Italian EU parties;

  • (c) foreign tax residence certificate for the application of double taxation conventions;

  • (d) tax calculations and certifications processed by the system: withholding taxes, VAT, Italian Single Certifications (Certificazioni Uniche).

3.10 DAC7 data. Horizon Servizi Integrati S.r.l.s. collects and verifies the information required by Directive (EU) 2021/514 (DAC7) and by Italian Legislative Decree 32/2023 for non-excluded Sellers:

  • (a) for natural persons: name, main address, date and place of birth, tax code/TIN for each State of tax residence, VAT number, financial account identifier (IBAN);

  • (b) for legal entities: name, registered office, tax code/TIN for each State of tax residence, VAT number, Business Register number, beneficial owner, financial account identifier.

3.11 DAC7 audit log. To ensure the documentary compliance required by Italian Legislative Decree 32/2023, Horizon Servizi Integrati S.r.l.s. maintains an audit log recording the verifications carried out, the discrepancies detected, the corrections made and the automatic data exchanges with the Italian Revenue Agency, retained for 10 years.

3.12 Anti-money laundering data. For the anti-money laundering purposes referred to in Italian Legislative Decree 231/2007 and in Regulation (EU) 2024/1624, where applicable, data are collected relating to:

  • (a) origin of funds;

  • (b) purpose of the economic relationship;

  • (c) ownership structure of legal entities and identification of the beneficial owner;

  • (d) exposure to political risk (Politically Exposed Persons — PEP), where such measures are applicable and in the course of adoption;

  • (e) presence in international sanctions lists (UN, EU, OFAC, HMT), where such measures are applicable and in the course of adoption.

3.E — Geolocation data

3.13 Approximate geolocation. Approximate geolocation data (at city or region level) derived from the User's IP address are collected automatically, for the purposes of content personalisation, fraud prevention and anti-money laundering.

3.14 Precise geolocation. Precise geolocation data (GPS) are collected only upon explicit consent of the User, in particular:

  • (a) when the User activates the «Find Experiences near me» function in the App or on the web;

  • (b) when the User performs a geolocated check-in at a Place (see Art. 3.E-bis);

  • (c) when the User grants system geolocation to the App.

Precise geolocation can be deactivated at any time from the device settings. Consent can be withdrawn without prejudice to the lawfulness of the processing based on consent before withdrawal.

3.E-bis — Geolocated Check-in data

3.15 Check-in. Upon the check-in carried out by the User in the vicinity of a Place, the following are collected:

  • (a) GPS geographic coordinates (latitude, longitude, any altitude) acquired from the User's device, with the precision allowed by the device's operating system;

  • (b) timestamp of the check-in;

  • (c) identifier of the Place (POI) to which the check-in is associated;

  • (d) distance calculated from the POI for validation purposes (Haversine geodesic formula);

  • (e) visibility level chosen by the User for the individual check-in (Only me / Friends / Everyone), pursuant to Section 7.1 of the General Terms and Conditions;

  • (f) any associated UGC Tag (see Art. 3.K);

  • (g) technical indicators useful for calculating the Trust Score (see Art. 3.H).

3.16 Rounding and technical pseudonymisation. The transmitted GPS coordinates are rounded in the system logs in order to limit the level of tracking, according to the precision indicated in the Technical Specifications of the Service. Such operation constitutes technical pseudonymisation pursuant to Article 4(1)(5) GDPR, and not definitive anonymisation, since the attributability of the datum to the Data Subject remains possible by combination with other account information.

3.17 Anti-spoofing. For the purposes of verifying the authenticity of the check-in and preventing position simulation by means of GPS spoofing or analogous techniques, behavioural and pattern indicators may be processed (by way of example: speed of movement between geographically distant consecutive check-ins, congruence with accelerometer data where available) which feed into the calculation of the Trust Score (see Art. 3.H and Art. 11).

3.F — Communication and support data

3.18 Communications with customer service. The contents of the communications between the User and the Stravagando customer service are collected, through:

  • (a) email to support@stravagando.com or to specific addresses (e.g. legal@, dmca@);

  • (b) internal ticketing system of the Platform;

  • (c) live chat (where activated by a third-party provider) — limited to the chat session;

  • (d) telephone communications — recorded only upon specific consent of the User, with prior notice;

  • (e) any communications via certified email (PEC);

  • (f) Guest Help conversations for Unregistered Visitors, managed via a temporary access token issued to the email address provided, pursuant to Section 17-ter of the General Terms and Conditions.

3.19 Direct messaging between Users. The contents of the communications exchanged through the integrated messaging system of the Platform are collected, retained and — where necessary for the purposes of security, anti-fraud, dispute management and DSA compliance — analysed in automated form, in particular:

  • (a) Host-Customer communications in relation to a booking on the marketplace;

  • (b) pre-purchase information requests from potential Customers to Hosts;

  • (c) direct messages between registered Users within the social community, where such functionality is made available by the Platform.

Communications made outside the integrated messaging system (e.g. WhatsApp, direct email) are not collected nor retained by Horizon Servizi Integrati S.r.l.s. and fall outside the security and dispute management protections offered by the Platform; Users are encouraged to use exclusively the integrated messaging system.

3.20 Reviews and feedback. The contents of the reviews and feedback released by Users on the Experiences, on the Places of the catalogue, on the Hosts and — internally — on the Customers are collected. Published reviews are visible in the public profile of the Experience/Host/Place and, where indexable, indexed by search engines; the username of the reviewer is publicly visible, while the complete identifying data are not. In compliance with Directive (EU) 2019/2161 (Omnibus), Horizon Servizi Integrati S.r.l.s. adopts adequate measures to ascertain that the published reviews come from Users who have actually enjoyed the Experience or visited the Place, with related attestations in the profile of the Experience/Place.

3.G — UGC and community data

3.21 Content published by the User. All UGC published by the User on the Platform is collected and retained, according to the following main types:

  • (a) photographs uploaded as profile image, as accompaniment to UGC or to Experiences;

  • (b) narrative posts published on the Wall of a Place;

  • (c) comments on Content of other Users;

  • (d) likes and other reactions to Content of other Users;

  • (e) personal lists (Notebooks) with their inserted Places/Experiences;

  • (f) proposals for new Places for insertion in the catalogue;

  • (g) suggestions for editing existing Places.

3.22 Privacy-by-design processing of photographs (EXIF strip). To protect the privacy of Users, in implementation of Article 25 GDPR (data protection by design and by default), Horizon Servizi Integrati S.r.l.s. removes the EXIF metadata from the photographs uploaded by the User at the time of their server-side processing, by means of re-encoding of the image. In particular, the following are removed: geolocation data (GPS), model and serial number of the capturing device, original date and time, technical exposure parameters. Horizon Servizi Integrati S.r.l.s. does not retain copies of the removed EXIF metadata: the operation is irreversible. The Data Subject who wishes to preserve the metadata of their own photograph is invited to autonomously retain the original, as the version retained on the Platform will be devoid of it.

3.23 Social relationship data. Data relating to social relationships between Users on the Platform are collected, such as:

  • (a) follow relationships (who follows whom);

  • (b) mutual-follow (reciprocal follow relationships, relevant for the purposes of enabling the UGC Tag and certain visibility functionalities pursuant to Sections 7 and 8 of the General Terms and Conditions);

  • (c) blocks between Users and any reports.

3.H — Gamification System data and derived indicators

3.24 Gamification elements. The elements of the Gamification System associated with the User are collected and retained, as described in Section 9 of the General Terms and Conditions:

  • (a) XP (experience points) accrued and history of increments;

  • (b) Level reached and progression;

  • (c) Achievements unlocked, date and context of the unlock;

  • (d) Streaks active and history of consecutive series;

  • (e) Level Perks active, including any discount codes generated and beta access enabled;

  • (f) data processed for the periodic Year Review.

The elements of the Gamification System have an exclusively symbolic and playful nature and do not constitute virtual currency nor an asset convertible into money, pursuant to Section 9.1 of the General Terms and Conditions. Their processing does not constitute profiling pursuant to Article 4(1)(4) GDPR nor automated decision-making pursuant to Article 22 GDPR.

3.25 Trust Score and anti-fraud indicators. Indicators derived from the User's activity are processed and retained, in particular:

  • (a) Trust Score (numerical value 0-100) calculated automatically on the basis of the technical consistency of the User's check-ins, according to the criteria described in Section 11 of the General Terms and Conditions and detailed in the Technical Specifications of the Service;

  • (b) behavioural anti-fraud indicators (by way of example: check-in velocity, geographic congruence, UGC publication patterns, reports received);

  • (c) Host reliability indicators (booking acceptance rate, cancellation rate, average rating, percentage of complaints, quality of responses to communications);

  • (d) Referrer performance indicators (conversion rate, quality of Referred parties post-onboarding, refund/chargeback rate of the Referred parties' bookings);

  • (e) anti-fraud risk profile (synthesised from behavioural, technological and chronological indicators);

  • (f) aggregate non-identifying statistics.

The impact of some of these indicators on the usability of the Service is described in Art. 11 (Automated decision-making and profiling).

3.I — UGC Tags and Automated Moderation data

3.26 UGC Tags. For the UGC Tags applied by Users, pursuant to Section 8-bis of the General Terms and Conditions, the following are collected and retained:

  • (a) numerical identifier of the tagging User and numerical identifier of the tagged User;

  • (b) identifier of the Content to which the Tag is associated (check-in, post on the Wall of a Place);

  • (c) timestamp of creation of the Tag;

  • (d) timestamp of any removal of the Tag and numerical identifier of the User who carried out the removal (tagging or tagged party);

  • (e) anonymised history of the removal (timestamp and role of the author — tagging or tagged party — devoid of the personal identifier), retained for a maximum of 24 months for the purposes of moderation audit and abuse prevention.

UGC Tags are not used for profiling purposes nor for automated decisions pursuant to Article 22 GDPR. In particular, Tags applied to posts on the Wall do not contribute to the attribution of XP nor to the unlocking of Achievements, consistently with Section 8-bis.8 of the General Terms and Conditions. For Tags applied to check-ins within companion tagging, the rules of Section 8 of the General Terms and Conditions and of the related gamification recognitions apply, described in Art. 3.H.

3.27 Automated Moderation data. For each Automated Moderation decision taken by the third-party artificial intelligence systems employed by the Platform, the following metadata are collected and retained in a dedicated system table:

  • (a) identifier of the Content subject to analysis;

  • (b) decision taken (approval, refusal, flagging for manual review, downranking);

  • (c) reason code and risk category detected;

  • (d) model used and version, confidence threshold applied;

  • (e) confidence scores processed by the system;

  • (f) latency, cost and operational data of the call to the provider;

  • (g) outcome of any subsequent human review and identifier of the operator who carried out the re-examination.

Such metadata are used for the purposes of audit, improvement of the systems, management of any complaints and fulfilment of the transparency obligations provided for by the AI Act, by the DSA (in particular Article 17 — Statement of Reasons) and by Article 22 GDPR, according to the methods described in Art. 11.

3.J — Navigation data and Tracking Tools

3.28 Usage Data. The following are collected automatically, as described in detail in the Cookie Policy:

  • (a) IP address (anonymised, where configurable);

  • (b) device identifiers (device fingerprinting, user-agent, operating system, browser version);

  • (c) session data (duration, pages visited, navigation sequence, clickstream);

  • (d) mobile advertising identifiers (IDFA for iOS, Google Advertiser ID for Android), only upon consent;

  • (e) referrer URL and UTM parameters of origin;

  • (f) interactions with the Platform (buttons clicked, searches carried out, bookings started and abandoned, check-ins attempted and completed).

3.29 Data stored locally on the User's device. The Platform is also designed as an installable Progressive Web App (PWA) on the User's device and includes a Service Worker that uses the native browser APIs (Cache API, IndexedDB, localStorage) for the purposes of caching, storage of preferences, offline support and push notifications. Such storage takes place exclusively on the User's device, does not transfer data to Horizon Servizi Integrati S.r.l.s. directly and does not constitute processing of Personal Data by the Controller insofar as it remains confined to the local browser. The User may clear such memory at any time from the settings of their browser, as provided by Section 18.1 of the General Terms and Conditions.

3.30 Third-party Tracking Tools. Further data are collected through third-party Tracking Tools, exclusively within the limits of the consent given by the User. The tools actually employed are: Google (Google Analytics 4, Google Tag Manager, Firebase Analytics — Google LLC) and Meta (Meta Pixel, Meta Conversions API, App Events SDK — Meta Platforms Ireland Limited), as detailed in the Cookie Policy. Horizon Servizi Integrati S.r.l.s. adopts Google's Consent Mode v2 model for the granular management of consent and the retention of the history of choices in append-and-update mode.

3.K — Third-party data provided by the User

3.31 Data of other participants. When a Customer books an Experience for several participants, they may provide third-party data (first name, surname, possibly date of birth for Experiences with age restrictions). The User who provides third-party data:

  • (a) guarantees that they have obtained their consent, or have another legal basis for sharing;

  • (b) undertakes to provide the data subject with the summary privacy notice available in the «Book for others» section of the Platform, containing the essential information on the processing;

  • (c) holds Horizon Servizi Integrati S.r.l.s. harmless from claims by third parties arising from the lack of or inadequate information, pursuant to the indemnity clauses of the General Terms and Conditions.

Analogous responsibility falls on the User who publishes UGC containing third-party data (by way of example: photographs depicting identifiable persons beyond the User themselves). The User guarantees that they have obtained the necessary authorisations from the depicted or named parties, pursuant to Article 97 of Italian Law 633/1941 and Section 6.3 of the General Terms and Conditions.

ART. 4 — PURPOSES OF PROCESSING AND LEGAL BASES

The Personal Data collected are processed for the purposes described below, each with its own legal basis pursuant to Article 6 (and, where applicable, Article 9) GDPR. This section constitutes the summary information notice provided for by Article 13(1)(c) GDPR.

4.A — Contractual and Service delivery purposes

4.1 Performance of the contract. The Personal Data are processed for:

  • (a) creation and management of the User account, including the automatic generation of the username and any federated authentication (SSO);

  • (b) delivery of the non-transactional functionalities of the Platform (Profile, Social, Gamification, exploration of the Places catalogue, publication and enjoyment of UGC, participation in the community);

  • (c) delivery of the marketplace functionalities (search, booking, payment, enjoyment of the paid Experiences);

  • (d) management of bookings, payments, cancellations and refunds, including the execution of the applicable Cancellation Policies;

  • (e) calculation and payment of Host Rewards and Referrer Rewards, management of Cashouts via Stripe Connect;

  • (f) execution of geolocated check-ins and attribution of the related elements of the Gamification System (XP, Levels, Achievements, Streaks), including the possible attribution of UGC Tags within companion tagging;

  • (g) publication, visibility and moderation of UGC according to the visibility settings autonomously managed by the User and the rules applicable to the UGC Tag;

  • (h) management of messaging between Users (Host-Customer; community); management of Guest Help for Unregistered Visitors;

  • (i) delivery of the customer assistance service;

  • (j) administration of follow relationships, including the management of mutual-follow relationships relevant to the applicability of certain functionalities (UGC Tag, visibility of «Friends» level check-ins).

Legal basis: Article 6(1)(b) GDPR — performance of a contract to which the Data Subject is party (General Terms and Conditions, Terms and Conditions of Sale, Host Terms, Referral Program Terms) or performance of pre-contractual measures at the request of the Data Subject.

4.B — Regulatory compliance purposes

4.2 Legal obligations. The Personal Data are processed for:

  • (a) tax obligations: bookkeeping, electronic invoicing via the Italian Interchange System (SdI), Italian Single Certifications, withholding taxes, VAT returns;

  • (b) DAC7 obligations: collection, verification, retention and communication to the Italian Revenue Agency and — via automatic exchange — to foreign tax Authorities of the data of non-excluded Sellers (Hosts and Referrers);

  • (c) anti-money laundering obligations: customer due diligence, retention of the customer file, suspicious transaction reports to the UIF, taking into account the tipping-off prohibition under Article 39 of Italian Legislative Decree 231/2007 (prohibition on disclosing the report);

  • (d) compliance with international sanctions: screening against the UN, EU, OFAC, HMT sanctions lists, blocking of operations or relationships with sanctioned parties;

  • (e) DSA obligations: publication of the periodic Transparency Report, management of notice and action reports pursuant to Article 16 DSA, guarantee of the anonymity of the reporter unless requested by the competent Authority, retention of the log of moderation decisions and of the Statements of Reasons, management of Trusted Flaggers pursuant to Article 22 DSA, communications to the competent Authorities through the designated points of contact (Sections 12-bis.4 and 12-bis.5 of the General Terms and Conditions);

  • (f) AI Act obligations: transparency regarding the use of artificial intelligence systems for the Automated Moderation of Content, pursuant to Regulation (EU) 2024/1689, including the documentation of decisions and related metadata;

  • (g) P2B obligations: publication of the general conditions, management of internal complaints from business Users, designated external mediation;

  • (h) responses to requests from competent judicial, tax, administrative, supervisory or public security Authorities, Italian or foreign, within the limits provided for by applicable law (by way of example: production orders, evidentiary seizures, preservation orders pursuant to Article 254-bis of the Italian Code of Criminal Procedure, requests under the Budapest Convention on cybercrime).

Legal basis: Article 6(1)(c) GDPR — compliance with legal obligations.

4.C — Security, anti-fraud and rights protection purposes

4.3 Security, anti-fraud and Trust Score. The Personal Data are processed for:

  • (a) prevention and identification of unauthorised access, brute force, credential stuffing, account takeover, automated bots; management of re-authentication for sensitive operations pursuant to Section 4.2 of the General Terms and Conditions;

  • (b) prevention of payment fraud (Stripe Radar, device fingerprinting, velocity check);

  • (c) prevention of fraudulent practices in the Referral Program (Self-Referral, Cookie Stuffing, Click Fraud) and in the Gamification System (multiple accounts, suspicious reciprocal exchanges, simulation of activity);

  • (d) calculation of the Trust Score of Users on the basis of the technical consistency of check-ins, pursuant to Section 11 of the General Terms and Conditions and Articles 3.E-bis and 3.H of this Policy, with the procedural safeguards described in Art. 11.B;

  • (e) identification of GPS spoofing attempts and position simulation, for the purposes of protecting the integrity of the Places catalogue and of the Gamification System;

  • (f) protection of the assets of the Platform, of Hosts, of Customers, of Referrers and of other Users from fraud and abuse;

  • (g) protection of the IT security of the Platform pursuant to NIS2;

  • (h) investigative support to requests from judicial and public security Authorities;

  • (i) protection of the rights of Horizon Servizi Integrati S.r.l.s. in the event of judicial or extra-judicial disputes, including the retention of electronic evidentiary material.

Legal basis: Article 6(1)(f) GDPR — legitimate interest of Horizon Servizi Integrati S.r.l.s. in security, fraud prevention, protection of its own rights and the rights of Users, balanced against the fundamental rights and freedoms of the Data Subject. For the processing operations involving automated risk assessments, reference is made to Art. 11.

4.D — Automated Moderation of UGC purposes

4.4 Automated Moderation. The UGC published by the User is subjected, preventively, to automated analysis by means of third-party artificial intelligence systems, pursuant to Section 12 of the General Terms and Conditions, in particular:

  • (a) a language model for the textual classification of reviews, posts, comments and proposals;

  • (b) an image analysis service for the detection of adult, violent or offensive content in photographs.

The systems are integrated with a manual review fallback for borderline cases, the unavailability of the automated systems or Content pending upon exceeding the operational limits. The specific identity of the models employed, the confidence thresholds, the criteria for access to the fast-track for Users with a positive history and the operational spending limits are indicated in the Technical Specifications of the Service.

The Data Subject has the right to request human review of the moderation decision within 14 days of the notification, according to the methods described in Art. 11.C, consistently with Section 12.3 of the General Terms and Conditions. The review is carried out by qualified Stravagando personnel and is not conducted through the same automated system that issued the contested decision.

Legal basis:

  • Article 6(1)(b) GDPR — performance of the contract (moderation constitutes a condition for the publication of the Content on the Platform);

  • Article 6(1)(c) GDPR — compliance with legal obligations (DSA, AI Act);

  • Article 6(1)(f) GDPR — legitimate interest in maintaining the integrity and quality of the User community.

4.E — Service improvement purposes

4.5 Analytics and optimisation. The Personal Data are processed, in aggregate and anonymised form where possible, for:

  • (a) measurement of the performance of the Platform and of conversion rates;

  • (b) analysis of navigation behaviour to identify areas for improvement (in aggregate form or, where disaggregated, on the basis of consent pursuant to the Cookie Policy);

  • (c) A/B testing of interfaces and functionalities;

  • (d) processing of internal statistics on the User population;

  • (e) iterative improvement of the Automated Moderation systems and of the Trust Score calculation algorithms, on the basis of the decision metadata described in Art. 3.27 and of the outcome of any human reviews.

Legal basis:

  • for aggregate analytics comparable to technical ones (Provision of the Italian Garante of 10/06/2021, par. 4.2): Article 122 of the Italian Privacy Code + Article 6(1)(f) GDPR (legitimate interest in improving the Service);

  • for disaggregated analytics: Article 6(1)(a) GDPR — consent, according to the Cookie Policy.

4.F — Service communication purposes

4.6 Service communications. Communications are sent to the User in relation to the delivery of the Service and the performance of the contract, pursuant to Section 17 of the General Terms and Conditions, distinguished into three categories:

  • (a) essential categories (by way of example: changes to the Terms, account suspension, security alerts, marketplace receipts, legal communications, account deletion confirmation): not deactivable as they are necessary for the performance of the contract and the fulfilment of the Controller's obligations;

  • (b) service categories (by way of example: social, gamification, informational marketplace activity notifications): deactivable granularly from the account settings;

  • (c) marketing utility categories connected to the contractual relationship but of a promotional nature (by way of example: pre-Experience reminders for bookings made, invitations to review after the Experience): sending is subject to the opt-in consent of the User, granular for each category.

The channels used comprise email, web push notifications, mobile push notifications (for future native iOS/Android Apps) and in-app notifications.

Legal basis: Article 6(1)(b) GDPR (performance of the contract) for the essential and service categories; Article 6(1)(a) GDPR (consent) for the marketing utility categories.

4.G — Direct marketing and newsletter purposes

4.7 Direct marketing on analogous services (soft opt-in). For Users who have made at least one booking or created an account, direct marketing communications on services analogous to those booked or used may be sent (e.g. new Experiences in the same cities, new Hosts in the same category), via email and in-App notifications.

Legal basis: Article 6(1)(f) GDPR — legitimate interest in direct marketing on analogous services, pursuant to Recital 47 GDPR and Article 130(4) of the Italian Privacy Code. The Data Subject may object at any time by means of the opt-out link present in each communication, the account settings or the request to support@stravagando.com.

4.8 Newsletter and profiled direct marketing. For marketing communications addressed to Users — including those without an account — on the periodic newsletter and on general promotional initiatives, Horizon Servizi Integrati S.r.l.s. adopts the double opt-in model pursuant to Section 17-bis of the General Terms and Conditions. The newsletter is offered independently of account ownership; the legal basis is the explicit consent of the Data Subject.

The Data Subject may withdraw consent at any time and unsubscribe from the newsletter by means of:

  • (a) the unsubscribe link present at the foot of each marketing email;

  • (b) the one-click unsubscribe mechanism provided for by industry standards for deliverability (RFC 8058);

  • (c) the request sent to support@stravagando.com.

Following unsubscription, Horizon Servizi Integrati S.r.l.s. retains the unsubscription datum (email address in a form sufficient for unique identification and withdrawal metadata) as a suppression list in order to guarantee the Data Subject the respect over time of the choice to no longer be contacted. The legal basis of such retention is the legitimate interest in suppression pursuant to Article 6(1)(f) GDPR, as well as compliance with Article 7(3) GDPR (obligation to respect the withdrawal of consent). The Data Subject has the right to request the deletion also of the suppression record, noting the consequences (any future re-subscription will no longer be recognised as such by the system).

4.9 Profiled marketing and on non-analogous services. For direct marketing purposes:

  • (a) on non-analogous services (e.g. promotion of Third-Party services);

  • (b) profiled on the basis of disaggregated navigation behaviour;

  • (c) through Third-Party advertising channels (Meta);

  • (d) via telephone (where applicable);

the prior consent of the User is collected, by means of the Preferences Panel of the Cookie Policy, the account settings or a specific checkbox.

Legal basis: Article 6(1)(a) GDPR — consent, withdrawable at any time.

4.10 Exclusion of targeted advertising to minors. In compliance with Article 28 DSA, Horizon Servizi Integrati S.r.l.s. does not present targeted advertising based on profiling pursuant to Article 4(4) GDPR to Users for whom indicators of minor age subsist, according to the methods described in the Technical Specifications of the Service and consistently with Section 14-bis.3 of the General Terms and Conditions.

4.H — UGC Tag: differentiated legal basis

4.11 UGC Tag processing. The UGC Tag functionality, described in Section 8-bis of the General Terms and Conditions and in Art. 3.26 of this Policy, entails processing of Personal Data on a differentiated legal basis in relation to the role of the Data Subject:

  • (a) for the User recipient of the Tag (Tag «inbound»), the processing is based on the explicit consent of the Data Subject expressed by means of the «Allow others to tag me in content» setting, active by default and withdrawable at any time from the Profile settings, pursuant to Article 6(1)(a) GDPR;

  • (b) for the User author of the Tag (Tag «outbound»), the processing is based on the performance of the contract and in particular of the social functionalities of the Platform to which the User has adhered by means of the General Terms and Conditions, pursuant to Article 6(1)(b) GDPR;

  • (c) for the related notification and display functionalities, the processing is based on the performance of the contract pursuant to Article 6(1)(b) GDPR and on the notification preferences expressed by the Data Subject.

The withdrawal of such setting operates pro-future: subsequent Tag attempts by other Users are silently discarded by the system without notification to the protected recipient. Any Tags already applied before the withdrawal may be removed by the Data Subject through the Profile panel, with immediate and definitive effect, consistently with Section 8-bis.4 of the General Terms and Conditions.

4.I — Automated profiling purposes

4.12 Internal automated profiling. Horizon Servizi Integrati S.r.l.s. carries out automated profiling activities limited to:

  • (a) personalisation of the search results of the Experiences and of the Places suggested in the exploration of the catalogue;

  • (b) suggestions of Experiences and Places consistent with the User's interest profile;

  • (c) calculation of the rating of reliability of Host and Referrer;

  • (d) calculation of the anti-fraud risk score (described in Art. 11.A);

  • (e) calculation of the Trust Score (described in Art. 11.B).

The activities referred to in letters (a), (b) and (c) do not produce legal effects on the Data Subject nor significantly affect them. The activities referred to in letters (d) and (e) are potentially apt to produce significant effects and are dealt with separately in Art. 11.

Legal basis: Article 6(1)(b) and (f) GDPR — performance of the contract and legitimate interest in improving the Service, in the quality of the community and in anti-fraud.

4.J — Special categories of data and criminal data

4.13 Exceptional processing. When voluntarily provided by the User or necessary for specific purposes, Sensitive or Criminal Data may be processed exclusively on the basis of:

  • (a) explicit consent of the Data Subject, pursuant to Article 9(2)(a) GDPR;

  • (b) performance of employer obligations under Article 9(2)(b) GDPR, where applicable (e.g. for data of employees involved in the delivery of the Service);

  • (c) substantial public interest under Article 9(2)(g) GDPR, in implementation of anti-money laundering and financial crime prevention regulations;

  • (d) establishment, exercise or defence of a legal claim under Article 9(2)(f) GDPR;

  • (e) processing by public authorities under Article 10 GDPR, for criminal data, in implementation of regulatory obligations.

ART. 5 — METHODS OF COLLECTION OF PERSONAL DATA

5.A — Direct collection from the Data Subject

5.1 Registration and profile forms. The registration and profile Personal Data (paragraphs 3.2-3.4) are collected directly from the Data Subject through the registration and Profile update forms, in the web and App versions of the Platform. The provision of some data is necessary for the use of the Platform's services; in the event of failure to provide them, the use of the related functionality may be impossible or limited.

5.2 Publication of UGC. The UGC (paragraphs 3.21-3.23) are collected directly from the Data Subject at the time of their publication on the Platform. Photographs are subjected server-side to the EXIF metadata removal process described in paragraph 3.22.

5.3 Geolocated check-ins. The check-in data (paragraphs 3.15-3.17) are collected directly at the time of execution of the check-in by the Data Subject, subject to the granting of permission to access the device's GPS. The transmitted coordinates are rounded in the logs as provided in paragraph 3.16.

5.4 Communications with customer service and with other Users. The communication Personal Data (paragraphs 3.18-3.19) are collected directly from the Data Subject through the assistance and messaging channels of the Platform, including Guest Help for Unregistered Visitors.

5.5 Insertion of Experiences (Host). The data relating to the Experiences are inserted directly by the Host through the account management panel; the Host is exclusively responsible for the truthfulness and completeness of the data inserted, pursuant to the Host Terms.

5.6 Update of privacy settings. The Profile visibility and privacy settings (par. 3.2 letter g) are collected and updated directly by the Data Subject from the account.privacy page, with re-authentication required for sensitive operations pursuant to Section 4.2 of the General Terms and Conditions.

5.B — Collection from Third Parties

5.7 Single Sign-On (SSO). When the User chooses to register or authenticate by means of SSO from third-party providers (Google, Apple, Meta/Facebook), Horizon Servizi Integrati S.r.l.s. receives from the third-party provider, as autonomous Controller, exclusively the strictly necessary data (first name, surname, verified email address, any profile image, unique identifier with the provider), in compliance with the provider's policies.

5.8 Manual KYC verification. For KYC procedures, in particular of Hosts and Referrers, Horizon Servizi Integrati S.r.l.s. collects identity documents by means of direct upload by the Data Subject to private, restricted-access storage. The verification of authenticity and correspondence with the identifying data provided is carried out manually by the authorised staff of Horizon Servizi Integrati S.r.l.s. The procedure does not entail biometric processing, acquisition of selfies or video, nor liveness detection.

5.9 VIES verification and public registers. For the VAT numbers provided, Horizon Servizi Integrati S.r.l.s. carries out automatic verification through the European Commission's VIES system for non-Italian EU VAT numbers, and through the archive of the Italian Revenue Agency for Italian VAT numbers. For legal entities, the public Business Registers may be consulted for verification of correct incorporation and of the powers of representation.

5.10 International sanctions lists. Horizon Servizi Integrati S.r.l.s. carries out periodic screening against the UN, EU, OFAC and HMT sanctions lists, by means of specialised providers operating as Processors. The names and tax codes/TINs of Users are compared with the names on the lists; in the event of a potential match, manual verification is carried out to rule out false positives.

5.11 Anti-fraud providers. For anti-fraud purposes, Horizon Servizi Integrati S.r.l.s. may receive risk information from the Stripe Radar service.

5.12 Automated Moderation systems. The metadata of Automated Moderation decisions (Art. 3.27) are generated by the interactions of Horizon Servizi Integrati S.r.l.s. with the third-party artificial intelligence providers (language model for texts and image analysis service), which operate as Processors pursuant to Article 28 GDPR. The User's UGC is transmitted to such providers exclusively for the purposes of Automated Moderation and for the time strictly necessary for the analysis.

5.C — Automatic collection

5.13 Usage Data via Tracking Tools. The Usage Data (paragraphs 3.28-3.30) are collected automatically through Tracking Tools described in the Cookie Policy. Collection takes place on the basis of the preferences expressed by the Data Subject in the Preferences Panel, in compliance with the Provision of the Italian Garante of 10/06/2021 and the Consent Mode v2 model.

5.14 Security and auditing logs. The security logs of the systems (access, transactions, check-ins, errors, relevant events) are collected automatically and retained for the purposes of IT security, incident investigation and audit pursuant to Section 4.4 of the General Terms and Conditions.

5.15 Audit trail of UGC Tag removal. The removal of a UGC Tag by the tagged Data Subject or by the author of the Tag automatically generates an audit trace comprising timestamp and identifier of the author of the operation, pursuant to paragraph 3.26 letter (d), retained in anonymised form beyond 24 months for the sole purposes of moderation abuse prevention.

5.D — Collection from public sources

5.16 Public sources. Limited to anti-fraud and compliance purposes (e.g. enhanced KYC for Hosts with high expected volumes), Horizon Servizi Integrati S.r.l.s. may consult information from public sources, such as press publications, public registers, professional social networks within the limits permitted by the policies of such platforms. Such consultations are carried out in compliance with the principle of minimisation and for the sole purposes indicated above.

ART. 6 — METHODS OF PROCESSING AND SECURITY MEASURES

6.A — Methods of processing

6.1 Tools. The processing of Personal Data takes place both with automated tools (IT systems, automatic processes, artificial intelligence algorithms for Automated Moderation and Trust Score calculation) and, where necessary, manually (consultation, modification, management of Data Subjects' requests, dispute management, human review pursuant to Articles 11 and 12). The data are stored on IT systems accessible to the authorised personnel of Horizon Servizi Integrati S.r.l.s., to the Processors and — limited to what is strictly necessary — to the competent Authorities.

6.2 Persons authorised to process. The Personal Data are processed by personnel of Horizon Servizi Integrati S.r.l.s. formally authorised and trained on data protection matters pursuant to Article 29 GDPR and Article 2-quaterdecies of the Italian Privacy Code. Authorisations are granted according to the need-to-know principle (minimum access necessary for the task) and least-privilege, and are periodically reviewed.

6.3 Principles. The processing is carried out according to the principles of:

  • (a) lawfulness, fairness and transparency (Article 5(1)(a) GDPR);

  • (b) purpose limitation (Article 5(1)(b) GDPR) — the data collected for one purpose are not processed for incompatible purposes;

  • (c) minimisation (Article 5(1)(c) GDPR) — only the relevant, adequate data limited to what is necessary are collected;

  • (d) accuracy (Article 5(1)(d) GDPR) — the data are kept up to date and accurate;

  • (e) storage limitation (Article 5(1)(e) GDPR) — the data are retained for the time strictly necessary;

  • (f) integrity and confidentiality (Article 5(1)(f) GDPR) — the data are protected from unauthorised or unlawful processing, loss, destruction or accidental damage;

  • (g) accountability (Article 5(2) GDPR) — Horizon Servizi Integrati S.r.l.s. maintains documentation of the measures adopted and is able to demonstrate compliance.

6.B — Technical security measures

6.4 Technical measures. Horizon Servizi Integrati S.r.l.s. adopts technical security measures adequate to the risk of the processing pursuant to Article 32 GDPR, including:

  • (a) encryption of data in transit by means of TLS 1.2 or higher for all communications with the Platform;

  • (b) encryption of data at rest provided at storage level by the cloud provider (volume/disk encryption by means of industry-standard algorithms, typically AES-256); no application-level per-field encryption is promised;

  • (c) secure hashing of passwords by means of cryptographic algorithms (bcrypt, scrypt or Argon2) with a unique salt per password;

  • (d) two-factor authentication (2FA) based on a TOTP authenticator application and recovery codes, available for all accounts; mandatory for Hosts and Referrers with significant volumes and for Horizon Servizi Integrati S.r.l.s. personnel with access to critical systems, pursuant to Section 4.2 of the General Terms and Conditions;

  • (e) re-authentication for sensitive operations (modification of email, password, visibility settings, indexing, leaderboard, UGC Tag) even with an active session, as protection against account takeover attacks;

  • (f) segregation of the development, staging and production environments;

  • (g) firewall, intrusion detection and intrusion prevention at network boundaries;

  • (h) periodic vulnerability scans and annual penetration tests;

  • (i) backups that are encrypted and geographically distributed, with periodic verification of restoration;

  • (j) timely security updates (patch management) on operating systems, applications and libraries;

  • (k) pseudonymisation of analysis data where possible, including the rounding of the GPS coordinates of check-ins in the system logs (par. 3.16);

  • (l) irreversible removal of EXIF metadata from uploaded photographs, as a technical measure of privacy by design (par. 3.22);

  • (m) retention of IP address and user-agent in sessions and in the main events for audit purposes, according to the principle of minimisation.

6.C — Organisational security measures

6.5 Organisational measures. The following organisational measures are also adopted:

  • (a) documented and periodically updated security policies;

  • (b) training of personnel on data protection matters;

  • (c) classification of information by levels of sensitivity;

  • (d) data protection by design and by default integrated into new developments (Article 25 GDPR), with particular reference to the social and geolocation functionalities (restrictive default privacy settings, granular choice of visibility for each check-in, granular opt-outs);

  • (e) data protection impact assessment (DPIA) pursuant to Article 35 GDPR for high-risk processing, including those concerning AI Automated Moderation, Trust Score calculation and the processing of geolocated check-ins;

  • (f) record of processing activities pursuant to Article 30 GDPR;

  • (g) periodic internal and independent audits, also on the effectiveness of the Automated Moderation systems;

  • (h) security incident management procedure integrated with the Data Breach notification procedure.

6.D — Security pursuant to NIS2

6.6 NIS2 compliance. Limited to the requirements applicable to Horizon Servizi Integrati S.r.l.s. pursuant to Directive (EU) 2022/2555 (NIS2) as transposed in Italy, IT security measures proportionate to the level of identified risk are adopted, with particular reference to: cyber risk management, incident response, operational continuity, supply chain security, personnel training.

6.E — Data Breach

6.7 Procedure. In the event of a Data Breach with a risk to the rights and freedoms of Data Subjects, Horizon Servizi Integrati S.r.l.s. notifies the Italian Garante within 72 hours of becoming aware of the incident (Article 33 GDPR) and — when the risk is high — promptly communicates the event to the Data Subjects in the ways and with the contents provided for by Article 34 GDPR. Horizon Servizi Integrati S.r.l.s. maintains an internal register of all Data Breaches, regardless of their severity.

ART. 7 — RECIPIENTS OF PERSONAL DATA AND COMMUNICATION

The Personal Data may be communicated to the categories of recipients described below, each within the limits and for the purposes indicated below. The communication is governed by specific contractual agreements or, where required by law, takes place in fulfilment of regulatory obligations.

7.A — Data Processors

7.1 Processors. The following categories of parties operate as Data Processors pursuant to Article 28 GDPR, on the basis of contractual agreements (DPA — Data Processing Agreement) governing the nature, subject matter, duration, purposes of the processing, types of data, categories of data subjects, obligations and rights of the Controller:

  • (a) providers of cloud hosting and application infrastructure (Laravel Cloud and related underlying cloud computing providers) — hosting of the Platform's infrastructure and storage of the data;

  • (b) providers of security, edge and anti-bot protection services (Cloudflare, Inc., including the Cloudflare Turnstile CAPTCHA service for the prevention of automated access, which processes IP address, user-agent and verification token) — DDoS protection, Web Application Firewall, Content Delivery Network, edge caching;

  • (c) providers of transactional email and newsletter services (Mailgun as the main provider; alternatively or as fallback: Amazon SES, Postmark, Resend) — sending of transactional, service and marketing emails;

  • (d) providers of push notification services (Firebase Cloud Messaging of Google LLC for Android and web; Apple Push Notification service (APNs) of Apple for iOS; Web Push (VAPID) for browser notifications) — sending of push notifications and alerts;

  • (e) providers of analytics services (Google LLC for Google Analytics 4 and Firebase Analytics) — usage measurement and analytics, within the limits of the consent given and according to the Cookie Policy;

  • (f) provider of electronic invoice issuance and transmission (FattureInCloud — TeamSystem S.p.A., Italy/EU) — issuance of electronic invoices and transmission to the Interchange System (SdI); receives tax registry data, VAT number, recipient code, certified email (PEC) and amounts;

  • (g) provider of error monitoring and crash reporting (Sentry — Functional Software, Inc. / Sentry, EU — Germany) — monitoring of the stability of the Platform; receives a pseudonymous user identifier and technical breadcrumbs, with the collection of identifying personal data disabled by default;

  • (h) provider of route calculation (OpenRouteService — HeiGIT gGmbH, Germany/EU) — calculation of the routes and itineraries of the notebooks; receives geographic coordinates;

  • (i) documentary KYC service provider: documentary verification is carried out internally by the authorised staff of Horizon Servizi Integrati S.r.l.s.; no third-party biometric identity verification providers are employed;

  • (j) providers of artificial intelligence systems, in particular:

    • (j.1) Anthropic, PBC (USA) — language model employed for the textual classification of UGC in Automated Moderation and for the automatic translation of editorial content and of the Experiences; USA transfer with SCC (see Art. 8);

    • (j.2) Google LLC (Google Cloud Vision API, routed to the EU endpoint) — image analysis service for the detection of adult, violent or offensive content in photographs;

  • (k) law firms and consultants bound by professional secrecy, for legal, tax and compliance consultancy activities;

  • (l) auditing and certification firms, for legal obligations.

7.2 Updated list. The updated list of the Processors appointed by Horizon Servizi Integrati S.r.l.s., with indication of their location and of the transfer safeguards adopted, is available upon request of the Data Subject at support@stravagando.com.

7.B — Autonomous Controllers

7.3 Autonomous Controllers. The following categories of parties receive Personal Data as autonomous Controllers, pursuing purposes autonomously determined by them. Horizon Servizi Integrati S.r.l.s. is not responsible for the processing carried out by such parties, to whom reference is made for their respective privacy notices:

  • (a) Stripe Payments Europe Ltd — for payment, escrow, Connect, Radar anti-fraud services and tax reporting;

  • (b) banking institutions of the Controller and of the Users — for the execution of SEPA and SWIFT payments;

  • (c) advertising platforms and social networks (Meta Platforms Ireland Limited) — for marketing and profiling purposes, on the basis of the consent given by the User, without prejudice to the limitations for minors referred to in Art. 4.10; Google LLC receives data exclusively as an analytics provider (see Art. 7.1.e), not for advertising purposes;

  • (d) SSO providers (Google, Apple, Meta/Facebook) — for single sign-on authentication services;

  • (e) judicial, tax, administrative, supervisory and public security Authorities, Italian and foreign competent, in fulfilment of regulatory obligations or legitimate authoritative requests, including the Digital Services Coordinators pursuant to the DSA, the Trusted Flaggers recognised pursuant to Article 22 DSA, the EU Commission for exchanges within the Statements of Reasons database;

  • (f) Italian Revenue Agency — for DAC7 and tax obligations;

  • (g) UIF at the Bank of Italy — for anti-money laundering reports.

7.4 OpenStreetMap Foundation. A significant part of the data of the Places catalogue is obtained from OpenStreetMap, distributed under the Open Database License (ODbL) v1.0. Such circumstance does not entail processing of Personal Data of Users by the OpenStreetMap Foundation in relation to the use of the Service by Users, and the attribution «© OpenStreetMap contributors» is displayed on each page presenting OSM data pursuant to Section 15.2 of the General Terms and Conditions.

7.C — Communication between Platform Users

7.5 Transparency between Host and Customer. The Personal Data are communicated between Host and Customer, to the extent strictly necessary for the execution of bookings on the marketplace, according to the following rules:

  • (a) before the confirmation of the booking: the Host sees the first name and the initial of the surname of the Customer, the profile image, the aggregate rating and the number of Experiences already completed;

  • (b) after the confirmation of the booking: the Host receives the full name of the Customer, email and telephone contact for operational communication;

  • (c) the Customer always sees the public profile of the Host, with commercial data (name, city, rating, public reviews).

Host and Customer each act as autonomous Controller for the data thus communicated, and undertake — pursuant to their respective Terms and Conditions — to process the data received exclusively for the purposes of executing the booked Experience, in compliance with data protection regulations. Horizon Servizi Integrati S.r.l.s. is not responsible for the processing carried out by Host or Customer as autonomous Controllers.

7.6 Visibility between Users of the social community. Within the social functionalities of the Platform, the User's Personal Data are visible to other registered Users and — when the Profile is set as public and indexable — to the general public, according to the settings autonomously managed by the Data Subject (par. 3.2 letter g). Such visibility comprises, according to the settings:

  • (a) the username, the profile image and the short bio;

  • (b) the UGC published with public visibility or extended to the mutual-follow network (posts, comments, reviews, photographs, check-ins with «Friends» or «Everyone» visibility);

  • (c) the position in the public leaderboards (Level, XP of the period), for Users who keep the show_in_leaderboards setting active;

  • (d) the mentions received via validly applied UGC Tag;

  • (e) the follow relationships where made visible.

The other Users who enjoy such Content each act for personal purposes or, if commercial, as autonomous Controllers, without prejudice to the use restrictions provided for by the General Terms and Conditions (in particular the prohibition of unauthorised scraping, referred to in Section 14).

7.7 Public reviews. The reviews released by Users on the Experiences, on the Places and on the Hosts are published on the public profile of the Experience/Place/Host with visibility of the reviewer's username, and are indexable by search engines when the reviewer's Profile is set as indexable or when the public is set at the level of the Place. The User who publishes a review:

  • (a) consents to publication and to public visibility;

  • (b) guarantees that the content is truthful, based on a real experience pursuant to Directive (EU) 2019/2161, and does not infringe the rights of third parties;

  • (c) may request the modification or deletion of their review by means of the account panel or a request to support@stravagando.com.

7.8 DSA — Notice & Action and protection of the reporter's anonymity. In compliance with Regulation (EU) 2022/2065 (DSA), Horizon Servizi Integrati S.r.l.s. makes available a mechanism for reporting potentially illegal content or content infringing the rights of third parties (notice and action procedure), accessible from the dedicated section of the Platform. The reports and the moderation decisions are recorded and retained, with reference to the parties involved, according to the retention periods referred to in Art. 9.

The identity of the reporter is not exposed to the reported User at any stage of the procedure, consistently with Section 12-bis.1 of the General Terms and Conditions and as protection against retaliation and as a guarantee of the freedom to report. The identity of the reporter may be revealed exclusively upon request of the competent Authority.

7.D — Communications in the event of extraordinary operations

7.9 Assignment, merger, acquisition. In the event of assignment, merger, acquisition or other extraordinary operation involving Horizon Servizi Integrati S.r.l.s. (or a business branch comprising the Platform), the Personal Data may be transferred to the assignee/incorporating entity as the new Controller, according to methods compliant with Article 4 GDPR and with adequate prior information to the Data Subjects where provided for by applicable law. The right of the Data Subject to object to the transfer remains, where the legal basis of the subsequent processing allows it.

7.E — Prohibition of sale

7.10 Prohibition of sale. Horizon Servizi Integrati S.r.l.s. does not sell the Personal Data of Users to third parties for commercial purposes. Any sharing of data with advertising partners for marketing purposes takes place exclusively on the basis of the consent given by the User pursuant to the Cookie Policy and is withdrawable at any time.

ART. 8 — EXTRA-EEA TRANSFERS

8.1 Principle. Some of the processing operations described entail the transfer of Personal Data outside the European Economic Area (EEA), in particular to the United States of America, the United Kingdom and other third countries, in connection with the provision of services essential to the Platform (payments, cloud hosting, marketing, customer support, KYC, Automated Moderation with artificial intelligence systems).

8.2 Safeguards adopted. Extra-EEA transfers take place in compliance with Chapter V GDPR, by means of one or more of the following safeguards:

  • (a) Adequacy decisions of the EU Commission pursuant to Article 45 GDPR, where applicable (United Kingdom, Switzerland, Israel, partial Canada, Andorra, Argentina, Japan, New Zealand, Republic of Korea, Uruguay, United States limited to organisations certified to the EU-US Data Privacy Framework);

  • (b) EU-US Data Privacy Framework for transfers to the United States, with confirmation of the recipient's certification to the framework approved by the EU Commission with the Adequacy Decision of 10 July 2023;

  • (c) Standard Contractual Clauses (SCC) approved by the EU Commission with Implementing Decision 2021/914, pursuant to Article 46(2)(c) GDPR, supplemented by additional technical and organisational measures where necessary on the basis of the Transfer Impact Assessment (TIA) conducted by Horizon Servizi Integrati S.r.l.s.;

  • (d) Binding Corporate Rules (BCR) approved pursuant to Article 47 GDPR, where applicable to the recipient;

  • (e) derogations under Article 49 GDPR, in specific and residual cases (e.g. explicit consent of the Data Subject, performance of a contract at their request, reasons of public interest).

8.3 Transparency. Horizon Servizi Integrati S.r.l.s. provides the Data Subject who so requests — at the address support@stravagando.com — a copy of the safeguards adopted for the specific extra-EEA transfer, according to methods compliant with Article 13(1)(f) GDPR.

8.4 Main specific transfers. By way of information, the main extra-EEA transfers currently carried out concern:

  • (a) United States — payments: Stripe Payments Europe Ltd shares with Stripe Inc. (parent company) part of the payment data, with the adoption of SCC supplemented by additional technical measures;

  • (b) United States — cloud and security: Cloudflare (including the Cloudflare R2 storage employed by the Platform on Laravel Cloud) and other network/security providers for non-European regions only where exceptionally employed, under the EU-US Data Privacy Framework and residual SCC where necessary;

  • (c) United States — Automated Moderation: Anthropic, PBC for the language model of textual classification of UGC and for automatic translation, under supplemented SCC and — where certification is maintained by the recipient — the EU-US Data Privacy Framework; Google LLC for the Cloud Vision API image analysis service, routed to the EU endpoint, under the same conditions;

  • (d) United Kingdom: some analytics and security providers have part of their operations in the United Kingdom, under the UK Adequacy Decision;

  • (d-bis) providers established in the European Union (by way of example: FattureInCloud — TeamSystem S.p.A. in Italy; Sentry and OpenRouteService — HeiGIT in Germany) — the related processing operations do not entail the transfer of Personal Data outside the EEA;

  • (e) United States — marketing: the advertising partner Meta for marketing purposes, under SCC and EU-US DPF, within the limits of the consent given.

ART. 9 — RETENTION OF PERSONAL DATA

The Personal Data are retained for the time strictly necessary for the pursuit of the purposes for which they were collected, according to the principle of storage limitation referred to in Article 5(1)(e) GDPR. The typical retention periods are set out below, save for causes of extension connected to disputes, to investigations by competent Authorities, to supervening regulatory obligations, to the exercise of rights of the Data Subject, or to the cases of Legal Hold referred to in Art. 9-bis.

9.A — Account and Profile

9.1 Active account. The account and Profile data are retained for the entire duration of the contractual relationship (active account).

9.2 Voluntary self-service deletion. In the event of deletion of the account at the direct request of the Data Subject by means of the self-service functionality of the Platform (route account.gdpr.delete, pursuant to Section 20 of the General Terms and Conditions), the identifying data of the account are subjected to soft-delete and retained for 30 days from the date of the request, after which they are definitively deleted. Such period is justified by the need to manage any complaints, abuse findings and legal obligations, consistently with the retention rules applied to sanctioned Users.

9.3 Suspension, sanction or ban of the account. In the event of suspension or ban of the account pursuant to Section 13 of the General Terms and Conditions, the User's public Content is immediately obscured and retained in soft-delete for 90 days, after which it is definitively deleted, without prejudice to the cases of Legal Hold.

9.4 Account not actively dismissed. In the absence of an explicit deletion request by the Data Subject and in the absence of sanctions, the account data may be retained for a further 24 months after the last significant activity detected, for the purposes of managing any disputes and requests from competent Authorities. Horizon Servizi Integrati S.r.l.s. reserves the right to introduce, pursuant to Section 21 of the General Terms and Conditions, an automatic closure mechanism for prolonged inactivity, subject to prior notice of no less than 30 days by email.

9.B — UGC

9.5 Voluntarily deleted UGC. The UGC deleted by the Data Subject by means of the functionalities of the Platform is subjected to soft-delete: made immediately non-visible from the public interface and retained in the database for 30 days for the purposes of any audits, security checks and internal disciplinary proceedings, after which it is definitively deleted, pursuant to Section 6.5 of the General Terms and Conditions and without prejudice to the cases of Legal Hold.

9.6 Published and active UGC. The published and active UGC is retained for the duration of publication, as a rule for the duration of the account of the Data Subject who published it, save for a deletion request by the Data Subject or exercise of rights.

9.7 Public reviews. The reviews released on the Experiences and on the Places are retained for the time of publication of the profile of the Experience/Place, save for a request for rectification or deletion by the reviewer or exercise of rights of the Data Subject. The cessation of the Host's activity does not automatically entail the deletion of historical reviews, as they are relevant for the User community.

9.C — Check-in and Gamification System

9.8 Check-in. Check-ins are retained in the User's activity history for an indefinite time during the life of the account, save for deletion at the request of the Data Subject or exercise of the rights referred to in Art. 10. The deletion of a check-in removes it from the public interface and from the personal history, but does not automatically entail the reduction of the accrued XP nor the loss of the achieved Achievements, in consideration of the historical irrevocability of the gamification recognitions, without prejudice to the cases of abuse or fraud findings pursuant to Section 7.2 of the General Terms and Conditions.

9.9 Elements of the Gamification System. XP, Levels, Achievements, Streaks and other elements of the Gamification System are retained for the duration of the User's account. In the event of account deletion, the elements are deleted without right to compensation, consistently with their symbolic nature (Section 9.1 of the General Terms and Conditions). The retention in aggregate and anonymised form of statistical data, where technically irreversible, remains.

9.D — UGC Tags and Automated Moderation

9.10 UGC Tags. The UGC Tags associated with Content are retained for the lifetime of the Content to which they are associated. In the event of removal of the Tag by the Data Subject (tagging or tagged party), the association between User identifier and Content identifier is immediately deleted; the historical fact of the removal (timestamp and role of the author — tagging or tagged party — devoid of the personal identifier) remains retained in anonymised form for a maximum of 24 months, for the purposes of moderation audit and abuse prevention, consistently with paragraph 3.26 letter (e).

9.11 Automated Moderation metadata. The metadata of the Automated Moderation decisions (par. 3.27) are retained for up to a maximum of 36 months from the decision — a non-guaranteed period, save for early deletion — extendable in the event of a dispute, a DSA complaint not yet resolved or investigations by competent Authorities. The retention responds to the purposes of audit, improvement of the systems, management of complaints, fulfilment of the transparency obligations under the AI Act and DSA, and protection of the rights of Horizon Servizi Integrati S.r.l.s. in litigation.

9.E — Transaction, tax and anti-money laundering data

9.12 Transaction and invoicing data. Retained for 10 years from the date of the transaction, pursuant to Article 2220 of the Italian Civil Code and the tax rules (Italian Presidential Decree 600/1973, Italian Presidential Decree 633/1972).

9.13 DAC7 data. DAC7 audit log and datasets transmitted to the Italian Revenue Agency: 10 years from transmission, pursuant to Italian Legislative Decree 32/2023.

9.14 Anti-money laundering data. 5 years from the cessation of the relationship, pursuant to Article 31 of Italian Legislative Decree 231/2007 and Regulation (EU) 2024/1624. For suspicious transaction reports to the UIF, retention according to the indications of the applicable regulations and in compliance with the tipping-off prohibition.

9.15 KYC data and identity documents. For the duration of the contractual relationship and, subsequently, for 10 years for parties holding a VAT number and for 5 years for private individuals without a VAT number, pursuant to the documentary retention obligations (Italian Presidential Decree 633/1972 and related tax regulations), save for the further anti-money laundering requirements. KYC verification is carried out internally and does not entail the generation or retention of biometric data.

9.F — Communications, security and marketing

9.16 Communications with customer service. Up to a maximum of 24 months from the date of the communication (a non-guaranteed period, save for early deletion), extendable in the event of a dispute or investigations by Authorities.

9.17 Guest Help conversations. The conversations with Unregistered Visitors managed via email token are subject to automatic closure for inactivity after a determined period (indicated in the Technical Specifications of the Service), after which the data are retained according to the retention rules applied to UGC.

9.18 Messaging between Users through the Platform. Up to a maximum of 18 months from the date of the last message in the conversation (a non-guaranteed period, save for early deletion), extendable in the event of a dispute or DSA report. The operational communications linked to a completed booking may be retained for the duration of the related warranty / complaint period of the service.

9.19 Security and anti-fraud data. Up to a maximum of 24 months from collection (a non-guaranteed period, save for early deletion), extendable in cases of investigative needs or dispute.

9.20 Marketing and profiling data. Up to a maximum of 24 months from the User's last interaction with the marketing communication (a non-guaranteed period, save for early deletion) or, if earlier, until the withdrawal of consent. Disaggregated profiling data: according to the specific periods of the individual Tracking Tools, indicated in the Cookie Policy.

9.21 Newsletter suppression lists. Indefinite retention of the sole minimum information necessary to prevent the re-subscription of a Data Subject who has unsubscribed, until the Data Subject themselves requests the deletion also of the suppression record.

9.22 Tracking Tools data (Cookies). See the Cookie Policy for the specific periods per category.

9.23 Consent log. 10 years from the collection of consent or from the withdrawal, for evidentiary and accountability purposes.

9.24 Security audit log. Up to a maximum of 24 months (a non-guaranteed period, save for early deletion), extendable in the event of investigations or disputes.

9.25 Dispute-related data. For the duration of the dispute and for the subsequent limitation periods pursuant to the Italian Civil Code (typically 10 years from the cessation of the case), or for the longer periods provided for by competent Authorities.

9.G — Deletion and anonymisation

9.26 Automatic deletion. Upon expiry of the retention periods, the Personal Data are deleted or irreversibly anonymised. The deletion is carried out automatically by the IT systems, with periodic verification by means of audit.

9.27 Retention in anonymised form. The data may be retained in anonymised form (namely no longer attributable to an identified or identifiable person) even beyond the periods indicated above, for statistical purposes and for improvement of the Service. The anonymisation is carried out according to recognised technical standards that prevent re-identification.

ART. 9-bis — LEGAL HOLD AND EXTENSION OF RETENTION

This article describes the Legal Hold regime, namely the extension of the retention of specific Personal Data or Content by way of derogation from the ordinary periods indicated in Art. 9, consistently with Section 16.1 of the General Terms and Conditions.

9-bis.A — Conditions

9-bis.1 Legal Hold scenarios. Horizon Servizi Integrati S.r.l.s. reserves the right to extend the retention of specific data or Content beyond the standard period referred to in Art. 9, limited to what and for the time strictly necessary, upon the occurrence of one of the following circumstances:

  • (a) formal request from the judicial Authority, the judicial Police or another competent Authority — by way of example: production orders, evidentiary seizures, preservation orders pursuant to Article 254-bis of the Italian Code of Criminal Procedure, requests pursuant to the Budapest Convention on cybercrime, measures of the Italian Garante;

  • (b) internal disciplinary proceeding or ongoing DSA complaint pursuant to Sections 12-bis and 13 of the General Terms and Conditions, until its resolution;

  • (c) legal dispute, judicial or extra-judicial, pending or reasonably foreseeable, concerning the data or Content in question, for the establishment or defence of a legal claim (Article 17(3)(e) GDPR);

  • (d) specific legal obligation imposing retention — by way of example: tax obligations pursuant to Article 2220 of the Italian Civil Code for data relating to transactions in the marketplace; anti-money laundering obligations pursuant to Italian Legislative Decree 231/2007 and Regulation (EU) 2024/1624; tax reporting obligations pursuant to Directive (EU) 2021/514 (DAC7) and Italian Legislative Decree 32/2023; obligations to retain telematic traffic data pursuant to Italian Legislative Decree 196/2003.

9-bis.B — Methods of application

9-bis.2 Criteria. In all cases of Legal Hold:

  • (a) the retention is limited to the data and Content specifically relevant to the purpose that justifies the extension and does not extend to the entire information assets of the Data Subject;

  • (b) the data under Legal Hold are accessible exclusively to authorised personnel and to the recipients of the legitimate request, and do not fall within the ordinary visibility of the Platform;

  • (c) the duration is that strictly necessary for the achievement of the purpose; once the cause has ceased, the data are deleted without further delay;

  • (d) save when prohibited by the requesting Authority or by rules of law (by way of example: investigative secrecy pursuant to Article 329 of the Italian Code of Criminal Procedure), Horizon Servizi Integrati S.r.l.s. informs the Data Subject of the extension carried out and of the related reason, in a manner compatible with the investigative needs.

9-bis.C — Effects on the rights of the Data Subject

9-bis.3 Exercise of GDPR rights. The existence of a Legal Hold proceeding does not in itself suspend or limit the rights of the Data Subject referred to in Articles 15-22 GDPR, without prejudice to the exceptions provided for by Article 23 GDPR and by applicable regulations (investigative secrecy, requirements of justice, etc.). The exercise of the right to erasure (Article 17 GDPR) may be temporarily suspended, for the data only and for the time strictly necessary, consistently with Article 17(3) GDPR. The Data Subject is informed of any suspension, save as provided in paragraph 9-bis.2 letter (d).

9-bis.4 Right to portability. The export of data for the purposes of portability referred to in Article 20 GDPR does not include Content possibly subject to Legal Hold; the inclusion of such Content is possible exclusively upon formal request of the competent Authority.

ART. 10 — RIGHTS OF DATA SUBJECTS

The Data Subject has the right to exercise, at any time and free of charge (save for manifestly unfounded or excessive requests, in particular for their repetitive character, for which Horizon Servizi Integrati S.r.l.s. may charge a reasonable contribution towards costs or refuse to comply with the request, pursuant to Article 12(5) GDPR), the rights described below.

10.A — Rights provided for by the GDPR

10.1 Right of access (Article 15 GDPR). The Data Subject has the right to obtain confirmation as to whether or not Personal Data concerning them are being processed and, in that case, access to such Personal Data and to the information indicated in this Policy. Upon request, Horizon Servizi Integrati S.r.l.s. provides a copy of the Personal Data undergoing processing.

10.2 Right to rectification (Article 16 GDPR). The Data Subject has the right to obtain the rectification of inaccurate Personal Data concerning them without undue delay, as well as the integration of incomplete Personal Data, including by providing a supplementary statement. Most of the Profile data is autonomously modifiable by the Data Subject from the reserved area of their account.

10.3 Right to erasure («right to be forgotten») (Article 17 GDPR). The Data Subject has the right to obtain the erasure of their Personal Data, in the cases provided for by Article 17 GDPR, in particular when:

  • (a) the data are no longer necessary in relation to the purposes for which they were collected;

  • (b) the Data Subject withdraws consent and there is no other legal ground for the processing;

  • (c) the Data Subject objects to the processing pursuant to Article 21 GDPR and there is no overriding legitimate ground of Horizon Servizi Integrati S.r.l.s. to proceed with the processing;

  • (d) the data have been unlawfully processed;

  • (e) the data must be erased to comply with a legal obligation.

The Data Subject may exercise the right to the integral deletion of their account directly from the Platform, by means of the self-service functionality described in Section 20 of the General Terms and Conditions, or by writing to support@stravagando.com.

Specific limits to erasure. The right to erasure does not apply in the cases provided for by Article 17(3) GDPR, in particular:

  • (i) for compliance with legal obligations (e.g. tax retention of marketplace transaction data under Article 2220 of the Civil Code — 10 years; anti-money laundering retention — 5 years; DAC7 audit log — 10 years);

  • (ii) for the establishment or defence of a legal claim;

  • (iii) in the cases of Legal Hold pursuant to Art. 9-bis;

  • (iv) for public reviews which, although they may be depersonalised (by replacing the reviewer's identifier), may be kept online for the purposes of informational transparency towards the User community.

The deletion of the account entails the symbolic forfeiture of the elements of the Gamification System (XP, Levels, Achievements, Streaks), consistently with their nature pursuant to Section 9.1 of the General Terms and Conditions, without right to compensation. The deletion of an individual check-in does not entail the automatic reduction of the attributed XP nor the loss of the achieved Achievements, in consideration of the historical irrevocability of the gamification recognitions (par. 9.8). The deletion also entails the elimination of the «inbound» UGC Tags (Tags that have tagged the Data Subject in Content of other Users) and the elimination of the active follow relationships.

10.4 Right to restriction of processing (Article 18 GDPR). The Data Subject has the right to obtain the restriction of the processing of their Personal Data, in the cases provided for by Article 18 GDPR. During the period of restriction, the data may be retained but not further processed, save for specific legal exceptions.

10.5 Right to data portability (Article 20 GDPR). The Data Subject has the right to receive their Personal Data — limited to those provided directly by the Data Subject themselves to the Controller and processed by automated means on the basis of consent or the performance of a contract — in a structured, commonly used and machine-readable format, and has the right to transmit them to another Controller without hindrance. Where technically feasible, the Data Subject has the right to obtain the direct transmission of the data to another Controller. Horizon Servizi Integrati S.r.l.s. makes available a self-service export functionality, pursuant to Section 20 of the General Terms and Conditions, which includes, where relevant:

  • (a) the Profile and account data;

  • (b) the published UGC;

  • (c) the history of personal check-ins (with the original coordinates provided by the Data Subject, it being understood that the copies in the system logs remain rounded pursuant to paragraph 3.16);

  • (d) the history of bookings and transactions;

  • (e) the gamification data (XP, Achievements, Streaks);

  • (f) the privacy settings and preferences.

The photographs possibly included in the export are devoid of the original EXIF metadata, pursuant to paragraph 3.22. The Content subject to Legal Hold is not included in the export, pursuant to Art. 9-bis.4.

10.6 Right to object (Article 21 GDPR). The Data Subject has the right to object at any time, on grounds relating to their particular situation, to the processing of the Personal Data concerning them based on Article 6(1)(e) or (f) GDPR (public interest or legitimate interest), unless Horizon Servizi Integrati S.r.l.s. demonstrates the existence of compelling legitimate grounds to proceed with the processing which override the interests, rights and freedoms of the Data Subject, or for the establishment, exercise or defence of a legal claim.

The Data Subject has the right to object at any time and without need for justification to the processing of Personal Data for direct marketing purposes, including the profiling connected to such marketing. Such right may be exercised by means of:

  • (a) the opt-out link present in each marketing communication;

  • (b) the account settings (notification and marketing preferences);

  • (c) the Preferences Panel of the Cookie Policy;

  • (d) the request sent to support@stravagando.com.

Specifically, the Data Subject may autonomously:

  • (i) deactivate their visibility in the public leaderboards by modifying the show_in_leaderboards setting;

  • (ii) disable the possibility of being tagged by modifying the dedicated Profile setting, with immediate effect on subsequent attempts;

  • (iii) modify the visibility of the Profile (profile_visibility) and external indexing (allow_search_indexing);

  • (iv) set the visibility level of each individual check-in at the time of execution (Only me / Friends / Everyone);

  • (v) withdraw consent to the processing of precise geolocation data from the device settings.

10.7 Right to withdraw consent (Article 7(3) GDPR). Where the processing is based on consent, the Data Subject has the right to withdraw it at any time, without prejudice to the lawfulness of the processing based on consent before withdrawal. The withdrawal may be exercised by means of the same channels used to give consent.

10.B — Specific rights linked to automated processing

10.8 Rights under Article 22 GDPR. The Data Subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, save for the exceptions provided for by Article 22(2) GDPR (necessity for the conclusion/performance of the contract, authorisation by law, explicit consent). For the processing operations falling within such case — payment anti-fraud, Trust Score, AI Automated Moderation — the Data Subject has the right to obtain human intervention on the part of Horizon Servizi Integrati S.r.l.s., to express their point of view and to contest the decision, according to the methods described in Art. 11.

10.C — Methods of exercise

10.9 Contact channels. To exercise the rights referred to above, the Data Subject may:

  • (a) send a written request to the email address support@stravagando.com (with subject: «Exercise of privacy rights»);

  • (b) use the self-service functionalities available in the reserved area of the Platform (modification of the Profile, management of privacy and marketing preferences, export of data, deletion of the account);

  • (c) send a registered letter or certified email (PEC) to the Controller at the contacts indicated in Art. 2;

  • (d) contact the DPO, where appointed, at the address support@stravagando.com (with subject: «DPO»).

10.10 Identification of the requester. To guarantee the security of the data and prevent unauthorised access, Horizon Servizi Integrati S.r.l.s. may ask the Data Subject to provide proof of their identity, in a manner proportionate to the request. For sensitive operations carried out from the reserved area of the Platform, re-authentication is required pursuant to Section 4.2 of the General Terms and Conditions.

10.11 Response times. Horizon Servizi Integrati S.r.l.s. provides a response to the Data Subject's request without undue delay and, in any event, within 1 month of receipt of the request. Such period may be extended by a further 2 months where necessary, taking into account the complexity and number of requests; the Data Subject is informed of the extension within 1 month of receipt of the request, together with the reasons for the delay.

10.12 Free response. The requests are processed free of charge. Horizon Servizi Integrati S.r.l.s. may charge a reasonable contribution towards costs only in the cases provided for by Article 12(5) GDPR (manifestly unfounded or excessive requests).

10.D — Right to lodge a complaint

10.13 Complaint. Without prejudice to any other administrative or judicial remedy, the Data Subject has the right to lodge a complaint with the competent supervisory Authority, according to the methods described in Art. 14.

ART. 11 — AUTOMATED DECISION-MAKING AND PROFILING

Horizon Servizi Integrati S.r.l.s. carries out certain processing operations that entail automated decisions pursuant to Article 22 GDPR, apt to produce legal or significant effects on the person of the Data Subject. The relevant processing operations are described separately below, with indication of the logic used, the importance envisaged, the consequences and the procedural safeguards adopted. For the processing operations that do not produce significant effects (by way of example: personalisation of search results, suggestions of Experiences, calculation of the aggregate rating), reference is made to Art. 4.12.

11.A — Anti-fraud on payments and on the marketplace relationship

11.1 Processing. Horizon Servizi Integrati S.r.l.s., jointly with Stripe Payments Europe Ltd as autonomous Controller for the part within its competence, processes an anti-fraud risk score for the transactions of the integrated marketplace and for the relationships with Hosts and Referrers, on the basis of:

  • (a) transaction indicators: amount, frequency, BIN, country of issue, alignment with the User's historical profile, velocity;

  • (b) device indicators: device fingerprinting, user-agent, IP address, emulator indicators, geographic congruence;

  • (c) behavioural indicators: navigation history, time spent in checkout, presence of previous chargebacks;

  • (d) lists of at-risk parties and internal and external reports.

11.2 Logic and importance. The system applies automatic threshold rules and statistical models. Depending on the score, the following may automatically occur: (i) the transaction is allowed; (ii) an additional verification is requested (e.g. 3D Secure, card retry, enhanced KYC); (iii) the transaction is refused; (iv) the delivery of the Service is suspended or the Host/Referrer payout is frozen; (v) a manual anti-fraud investigation is initiated.

11.3 Consequences. Significant effects may be produced on the Data Subject: inability to complete the booking, suspension of payments, blocking of the account, report to the competent Authorities.

11.4 Procedural safeguards. The Data Subject has the right:

  • (a) to human intervention on the part of a Horizon Servizi Integrati S.r.l.s. operator who re-examines the decision;

  • (b) to express their point of view on the situation and to provide elements in their own defence;

  • (c) to contest the decision, according to the methods referred to in Art. 10.

Requests for re-examination may be sent to support@stravagando.com with reference to the identifier of the transaction or of the procedure.

11.B — Trust Score

11.5 Processing. Horizon Servizi Integrati S.r.l.s. processes a numerical score (Trust Score) between 0 and 100, attributed to each User on the basis of the technical consistency of the check-ins carried out, according to the rules described in Section 11 of the General Terms and Conditions and detailed in the Technical Specifications of the Service. The indicators comprise: proximity between transmitted coordinates and POI, congruence of the time elapsed between geographically distant consecutive check-ins, plausibility of the speed of movement, any GPS spoofing indicators, reports received, outcome of previous disciplinary proceedings.

11.6 Logic and importance. The Trust Score affects:

  • (a) attribution of XP for check-ins: lower Trust Scores correspond to a reduction of the XP attributed to the check-in or, in extreme cases, its nullification;

  • (b) automatic approval of reviews: for a high Trust Score, reviews may access the approval fast-track (Section 12.4 of the General Terms and Conditions) and receive immediate visibility; for low Trust Scores manual review is required;

  • (c) access to reserved functionalities: certain functionalities (by way of example: proposal of new Places to the catalogue, participation in beta programs) may require exceeding a minimum Trust Score threshold;

  • (d) visibility of one's own Content: in cases of a very low Trust Score, a downranking factor may be applied in the order of publication.

11.7 Consequences. The Trust Score may produce significant effects on the usability of the Service for the Data Subject, in particular on participation in the Gamification System and on access to reserved functionalities.

11.8 Procedural safeguards. The Data Subject has the right to ask Horizon Servizi Integrati S.r.l.s. for explanations on the attributed Trust Score, to request its manual re-examination and to contest it, consistently with the rights referred to in Article 22 GDPR. Requests for re-examination may be sent to support@stravagando.com. The Trust Score is not itself made visible to the User nor to third parties in its raw numerical form, consistently with the nature of an internal technical indicator; the summary results relating to the attribution of XP for each check-in and the related reason codes are made visible to the User, where requested.

11.C — AI Automated Moderation of UGC

11.9 Processing. The UGC published by Users is subjected, before publication, to automated analysis by means of third-party artificial intelligence systems, pursuant to Section 12 of the General Terms and Conditions and Art. 4.4 of this Policy.

11.10 Logic and importance. The Automated Moderation systems:

  • (a) classify texts by means of a language model into risk categories (by way of example: incitement to hatred, pornographic content, infringement of intellectual property rights, spam, fraud);

  • (b) analyse images by means of an image analysis service for the detection of adult, violent or offensive content;

  • (c) apply confidence thresholds to determine whether the Content is automatically approved, downranked, subjected to manual review or refused;

  • (d) access a fast-track for Users with a positive history and a high Trust Score;

  • (e) operate with a manual review fallback in the event of unavailability of the automated systems or of exceeding the operational limits.

The specific identity of the models employed, the confidence thresholds, the criteria for access to the fast-track and the operational limits are indicated in the Technical Specifications of the Service.

11.11 Consequences. The Automated Moderation decision may entail:

  • (a) approval and publication of the Content;

  • (b) refusal of publication, with notification to the Data Subject and reason code (Statement of Reasons pursuant to Article 17 DSA);

  • (c) downranking of the Content (reduced visibility);

  • (d) submission to manual review before publication;

  • (e) in the most serious cases, initiation of disciplinary proceedings against the Data Subject pursuant to Section 13 of the General Terms and Conditions.

11.12 Procedural safeguards. The Data Subject has the right:

  • (a) to receive the Statement of Reasons of the decision, pursuant to Article 17 DSA, containing at least the reason code, the risk category detected, the indication of the automated system employed and the indication of the right to request human review;

  • (b) to request the human review of the decision within 14 days of the notification of the automated decision, pursuant to Section 12.3 of the General Terms and Conditions. The review is carried out by qualified Stravagando personnel, distinct from the automated system that issued the decision;

  • (c) to express their point of view and provide elements in their own defence within the re-examination procedure;

  • (d) to contest the decision confirmed at the re-examination stage by means of an internal complaint to the Controller and, in the alternative, by means of a complaint to the Garante or judicial appeal, pursuant to Art. 14;

  • (e) limited to the cases falling within the scope of application of the DSA, to access the alternative dispute resolution mechanism provided for by Article 21 DSA, by means of dispute resolution bodies certified by the competent Digital Services Coordinator;

  • (f) to refer to the Trusted Flagger pursuant to Article 22 DSA or to AGCOM as the Italian Digital Services Coordinator.

11.13 AI Act transparency. In compliance with Regulation (EU) 2024/1689 (AI Act), Horizon Servizi Integrati S.r.l.s. ensures adequate transparency on the artificial intelligence systems used in the context of Automated Moderation. The summary information on the models employed, on the known limits of their performance and on the safeguard mechanisms is published in the Technical Specifications of the Service and updated periodically. Horizon Servizi Integrati S.r.l.s. carries out periodic audits on the effectiveness and impartiality of the systems and adopts corrective measures in the event of detected bias.

ART. 12 — PROCESSING OF MINORS' DATA

The Platform is designed for adult Users and for minor Users who have reached the minimum age for access provided for by the regulations applicable to their residence, according to the regime described below. Horizon Servizi Integrati S.r.l.s. actively protects minors from the unauthorised collection of Personal Data and from targeted advertising profiling, in compliance with the GDPR, the Italian Privacy Code and the DSA.

12.A — Minimum age of access

12.1 Residents in Italy: 14 years. For residents in Italy, the minimum age of access to the Platform is 14 years, in implementation of Article 8 GDPR and Article 2-quinquies of the Italian Privacy Code (Italian Legislative Decree 196/2003 as amended by Italian Legislative Decree 101/2018), which sets such threshold for Italy for the direct offer of information society services to minors on the basis of consent. For minors under 14 years resident in Italy, access to the Platform is prohibited and no Personal Data are collected on the basis of the consent of the minor themselves.

12.2 Residents in other EU Member States. For residents in other Member States of the European Union, the respective national minimum age thresholds for consent to the information society apply pursuant to Article 8(1) GDPR (by way of example: 16 years in Germany, Luxembourg, the Netherlands, Poland, Romania, Hungary; 15 years in France, the Czech Republic, Slovenia; 14 years in Austria, Bulgaria, Cyprus, Italy, Lithuania, Spain), or, in the absence of a specific indication, the age of 16 years.

12.3 Residents in other Countries. For residents in other Countries, the minimum age provided for by the applicable national law applies or, in its absence, the age of 16 years.

12.B — Regime for minor Users who have reached the minimum age

12.4 Declaration at the registration stage. Upon registration, the User confirms that they possess the minimum age required by the law applicable to their residence, pursuant to Section 3 of the General Terms and Conditions. Such declaration is made under their own responsibility; the provision of false declarations entails the suspension and closure of the account pursuant to Section 13 of the General Terms and Conditions.

12.5 Restrictions applicable to minor Users (under 18). For Users who have reached the minimum age but are still minors (under 18) pursuant to applicable law, and for whom indicators of minor age subsist according to the procedures adopted by Horizon Servizi Integrati S.r.l.s.:

  • (a) exclusion from targeted advertising based on profiling (Art. 4.10 of this Policy and Article 28 DSA);

  • (b) limitation of access to the marketplace as a Customer, on the basis of the minor's reduced contractual responsibility according to applicable law; for bookings that exceed the minor's contractual capacity, confirmation by a holder of parental responsibility may be required, according to the procedures described in Section 3 of the General Terms and Conditions;

  • (c) limitation of access to 18+ Experiences where categorised by the Host as reserved for adults, where technically applicable;

  • (d) more restrictive default privacy settings (non-public Profile by default, reduced visibility in searches, external indexing disabled), absence of behavioural advertising profiling.

12.6 Joining the Referral Program, Host capacity. Joining the Referral Program is reserved for Users who have reached the age of majority pursuant to applicable law (in Italy, 18 years), pursuant to the Referral Program Terms. The Host capacity is, as a rule, reserved for adults, save for specific cases governed by the Host Terms. Such limitations derive from the economic/commercial nature of such capacities and the related contractual responsibility profiles.

12.C — Age verification

12.7 Measures adopted. Horizon Servizi Integrati S.r.l.s. adopts reasonable and proportionate measures to verify the age of Users, consistently with Article 28 DSA, on the basis of:

  • (a) declaration of the User at the registration stage;

  • (b) date of birth, where required;

  • (c) behavioural and content indicators;

  • (d) request for documentary verification, in borderline or high-risk cases, where technically applicable.

The specific measures are indicated in the Technical Specifications of the Service and are periodically updated in light of industry best practices and the indications of the competent Authorities.

12.8 Reporting of minors not having the minimum age. Where Horizon Servizi Integrati S.r.l.s. becomes aware, including through a report by third parties, of the presence of a minor User below the minimum age required for their residence:

  • (a) it proceeds with the immediate suspension of the account in such a way as to prevent further interactions;

  • (b) it deletes the Personal Data collected without a valid legal basis, unless retention is necessary for compliance with legal obligations, for the exercise of a legal claim or for another purpose permitted by Article 17(3) GDPR;

  • (c) it informs, where possible and when appropriate, the holders of parental responsibility of the existence of the account and of the actions taken.

ART. 13 — AMENDMENTS TO THIS POLICY

13.A — Updates

13.1 Right to amend. Horizon Servizi Integrati S.r.l.s. reserves the right to make amendments to this Privacy Policy, both for adaptation to regulatory, jurisprudential or regulatory developments, and for the introduction of new functionalities of the Platform or new processing operations, and for internal organisational and security needs.

13.2 Version and date of entry into force. Each version of the Policy is uniquely identified by a version number and a date of entry into force, indicated at the opening of the document. The currently in force version is always the one published on the Platform at the dedicated URL.

13.3 Version history. Horizon Servizi Integrati S.r.l.s. keeps available to Data Subjects, in a dedicated section of the site, the history of the previous versions of the Privacy Policy with indication of the main amendments made, in compliance with the principle of transparency under Article 12 GDPR.

13.B — Communication of amendments

13.4 Substantial amendments. For substantial amendments — meaning those that significantly affect the rights of Data Subjects or the essential methods of processing — Horizon Servizi Integrati S.r.l.s. notifies the amendments to Users with prior notice of no less than 30 days with respect to the date of entry into force, consistently with Section 19 of the General Terms and Conditions, by means of:

  • (a) email to the registration address, where the User has an active account;

  • (b) in-app notice and/or banner on the Platform;

  • (c) publication of the new version on the Platform with evidence of the amendments.

During the notice period, the Data Subject who does not intend to accept the amendments may exercise the right of withdrawal from the contract, by means of the self-service closure of their account (Section 20 of the General Terms and Conditions), without charge.

13.5 Non-substantial amendments. For non-substantial amendments (corrections of typos, formal clarifications, updates of Processors or other elements of mere operational detail), Horizon Servizi Integrati S.r.l.s. may proceed with their publication with immediate effect, giving evidence thereof in the register of amendments.

13.6 Amendments for compelling reasons. For amendments that become immediately necessary in fulfilment of supervening legal obligations, of orders of competent Authorities or for security needs, Horizon Servizi Integrati S.r.l.s. may proceed with the introduction of the amendments with immediate effect, providing Data Subjects with subsequent communication as soon as this is possible.

13.C — Processing based on consent

13.7 New purposes based on consent. Where the amendments to the Policy introduce new processing purposes based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, such processing operations will not be initiated for existing Data Subjects except following the specific collection of consent, according to methods compliant with Article 7 GDPR.

ART. 14 — CONTACTS AND COMPLAINTS

14.A — Contacts

14.1 Data Controller. For any request or communication on data protection matters, Data Subjects may contact Horizon Servizi Integrati S.r.l.s. at the following contacts:

Horizon Servizi Integrati S.r.l.s. Registered office: Viale Giovanni Bovio, 103/1 65124 Pescara (PE), Italy Tax Code / VAT No.: 02445190685 General assistance email: support@stravagando.com Email for data protection requests: support@stravagando.com Certified email (PEC): horizonserviziintegrati@pec.it

14.2 DPO. The DPO, where appointed, is contactable at the address:

support@stravagando.com (with subject: «DPO»)

Horizon Servizi Integrati S.r.l.s. retains the right to establish a dedicated address, which will be communicated by means of an update to this Policy pursuant to Art. 13.

14.3 DSA points of contact. Pursuant to Articles 11 and 12 of Regulation (EU) 2022/2065 (Digital Services Act), Horizon Servizi Integrati S.r.l.s. designates the following points of contact, described by Section 12-bis of the General Terms and Conditions:

  • (a) point of contact for Authorities of the Member States, the EU Commission and the European Board for Digital Services pursuant to Article 11 DSA: support@stravagando.com (with subject: «DSA — Authorities»);

  • (b) point of contact for the recipients of the service pursuant to Article 12 DSA: support@stravagando.com (with subject: «DSA — Recipients»);

  • (c) the languages of communication of the Controller for the aforesaid purposes are Italian and English.

14.4 Notice & Action. For reports of potentially illegal Content or Content infringing the rights of third parties, pursuant to Article 16 DSA, a dedicated notice and action mechanism is available on the Platform; alternatively, reports may be sent to support@stravagando.com with subject «DSA — Notice». The identity of the reporter is not exposed to the reported User, save upon request of the competent Authority.

14.B — Right to lodge a complaint

14.5 Complaint to the Italian Garante. Without prejudice to any other administrative or judicial remedy, the Data Subject has the right to lodge a complaint with the Italian Data Protection Authority, pursuant to Article 77 GDPR and Article 141 of the Italian Privacy Code, according to the methods indicated on the Authority's institutional website:

Garante per la protezione dei dati personali Piazza Venezia no. 11 — 00187 Rome Email: protocollo@gpdp.it Certified email (PEC): protocollo@pec.gpdp.it Telephone: +39 06.69677.1 Complaint form: https://www.garanteprivacy.it/home/modulistica-e-servizi-online

14.6 Other EU Member States. For Data Subjects resident in other EU Member States, the possibility remains to lodge a complaint with the supervisory Authority of their own Member State of residence, of work or of the place of the alleged infringement, pursuant to Article 77 GDPR. The list of EU supervisory Authorities is available on the website of the European Data Protection Board: https://www.edpb.europa.eu

14.7 AGCOM as Digital Services Coordinator. For reports falling within the scope of Regulation (EU) 2022/2065 (DSA), Data Subjects resident in Italy may also refer to the Italian Communications Authority (AGCOM), designated as the Italian Digital Services Coordinator, according to the methods indicated on the institutional website: https://www.agcom.it.

14.C — Judicial appeal

14.8 Appeal to the Court. The Data Subject also has the right to bring a judicial appeal against the Controller pursuant to Article 79 GDPR and Article 152 of the Italian Privacy Code, before the judicial authority of their own Member State of habitual residence or of the Member State in which Horizon Servizi Integrati S.r.l.s. has its main establishment.

Document approved and adopted by Horizon Servizi Integrati S.r.l.s.

Version: 1.1 Date of entry into force: 26/04/2026
Main regulatory references:

  • Regulation (EU) 2016/679 (GDPR)

  • Italian Legislative Decree 196/2003 (Privacy Code) as amended by Italian Legislative Decree 101/2018

  • Provision of the Italian Data Protection Authority of 10 June 2021 — Guidelines on cookies and other tracking tools

  • Directive 2002/58/EC (ePrivacy)

  • Regulation (EU) 2022/2065 (Digital Services Act)

  • Regulation (EU) 2024/1689 (AI Act)

  • Regulation (EU) 2019/1150 (Platform-to-Business)

  • Directive (EU) 2022/2555 (NIS2)

  • Italian Legislative Decree 32/2023 (DAC7)

  • Italian Legislative Decree 231/2007 (Anti-money laundering)

Stay in the loop

Subscribe to our newsletter to receive the latest experiences and exclusive offers.