1. Data controller
The data controller is
Prode Tours Soc. Coop., VAT No. 03241640600, REA KRRH6B9. Registered office: Via Sabatino 17, 03012 Anagni (FR), Italia. Operational office: Via Corrado Parona 132, 00134 Roma (RM), Italia. Contact:
Info@prodetours.com; PEC:
prodetours@legalmail.it; telephone/WhatsApp: +39 388 884 5333.
2. Data we process
We may process: data you provide through the contact form or direct communications (name, email, phone number, requested experience, preferred date, number of guests, pick-up location and message); technical data generated when the website is used (IP address and request logs normally recorded by the hosting infrastructure, browser and device information, date and time); the selected language stored in the browser; and a short-lived session identifier used only when the contact form is submitted to prevent repeated automated submissions.
3. Purposes and legal bases
We process contact and travel-request data to answer enquiries, prepare personalised proposals and take steps requested before a possible contract (Article 6(1)(b) GDPR). Technical security data may be processed to protect the website, prevent abuse and diagnose faults on the basis of our legitimate interest in operating a secure service (Article 6(1)(f) GDPR). Data may also be processed to meet legal, accounting or authority obligations (Article 6(1)(c) GDPR). We do not use contact data for newsletters or promotional marketing unless a separate, specific consent is requested in the future.
4. Required and optional information
Name and email are required to answer the request. The other form fields are optional, although missing information may limit our ability to prepare an accurate proposal. The checkbox in the form confirms that this notice has been read; it is not the legal basis for handling the enquiry.
5. Recipients, processors and international transfers
Personal data may be accessed by authorised Prode Tours personnel and by providers necessary to operate the service.
Amazon Web Services (AWS) provides website hosting, storage, network and security infrastructure. Google Workspace/Gmail provides business email and message storage. Technical maintenance providers and selected professional partners may receive only the information necessary to prepare or perform the requested service.
AWS and Google act under the applicable contractual data-processing terms. Where processing or support involves a country outside the European Economic Area, the transfer is based on an applicable adequacy decision, Standard Contractual Clauses or another safeguard permitted by Chapter V GDPR. Data are not sold and are not disclosed for independent advertising purposes.
6. Maps and external services
Experience pages load Leaflet resources from the unpkg CDN, map tiles from OpenStreetMap and road routes from the public OSRM service. When these resources load, the relevant provider may receive technical data such as the IP address, browser information and the requested resource. Links to WhatsApp, Instagram, WeChat and Google open external platforms only when selected; their own privacy terms then apply.
7. Retention periods
Enquiries that do not become bookings, including the corresponding Gmail messages, are normally retained for up to 24 months from the last meaningful contact. The customer may request earlier deletion unless the information is still required for a legal claim, fraud prevention or another legitimate obligation.
If a booking is concluded, contractual, payment and accounting records are retained for the periods required by applicable Italian law.
Website and security logs hosted on AWS are to be configured for a normal maximum retention of 30 days, unless a longer period is necessary to investigate a security event, prevent abuse or comply with a legal request. Google Workspace service and security metadata are retained according to the applicable Google Workspace contract and administrative settings.
8. Your rights
Under Articles 15–22 GDPR, you may request access, rectification, erasure, restriction, portability where applicable, or object to processing based on legitimate interest. You may exercise your rights by writing to the controller at the email or PEC address above. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
9. Automated decisions and minors
The website does not use automated decision-making or profiling. Services are intended to be requested and booked by adults. Information concerning children should be provided only by a parent or lawful guardian and only where necessary for the requested service, for example to arrange an appropriate child seat.
10. Security, complaints and policy updates
Prode Tours applies proportionate organisational and technical measures, including access controls, protected business accounts, HTTPS in production, restricted administrative access and security settings available through AWS and Google Workspace.
Privacy requests or complaints may be sent to Info@prodetours.com or to the PEC address prodetours@legalmail.it. Prode Tours aims to acknowledge and provide a substantive response within 15 working days, without affecting the statutory GDPR response periods.
No internet transmission can be guaranteed as completely secure. This notice may be updated when the website, providers, retention settings or legal requirements change.