Privacy Notice on the Processing of Personal Data
This privacy notice describes how we process the personal data of users who visit the website dalmaschioveniceboattour.com and who contact Dal Maschio to request information, check availability, ask for quotes or seek clarification regarding the tours and services on offer.
This privacy notice is provided in accordance with Article 13 of EU Regulation 2016/679, known as the GDPR, and the applicable Italian legislation on the protection of personal data.
Last updated: 3 August 2026
1. Data controller
The data controller is:
From Maschio
13/B Via San Nicolò
30126 Lido di Venezia, Venice – Italy
VAT number: 04989990272
Telephone: +39 345 239 97 98
Email: info@dalmaschioveniceboattour.com
For any enquiries regarding the processing of personal data, please contact the Data Controller using the contact details provided above.
2. Types of data processed
The following categories of personal data may be collected via the website:
- first name and surname;
- email address;
- telephone number;
- information entered in the contact form;
- information provided by email, telephone or WhatsApp;
- details of the tour or service requested;
- date, time and content of communications;
Users are asked to provide only the information necessary to receive a reply.
3. Purposes of the processing
Personal data is processed for the following purposes:
Responding to enquiries
The data is used for:
- to respond to questions and requests for information;
- check the availability of the boat;
- provide information on tours and services;
- prepare quotations;
- organise any bespoke itineraries;
- to contact the user again regarding the enquiry received;
- to handle the preparatory steps prior to a potential booking.
Website operation and security
Browsing data may be processed for the following purposes:
- to ensure the website functions correctly;
- to ensure the security of IT systems;
- to prevent unauthorised access, misuse, fraud or malicious activity;
- identify and resolve any technical issues.
Compliance with legal obligations
Data may also be processed where necessary to comply with obligations laid down by law, regulations or requests from the competent authorities.
Data collected via the contact form is not used for newsletters, promotional communications or marketing activities without a separate and specific legal basis.
4. Legal basis for processing
The processing of data provided when requesting information, availability or quotations is based on the implementation of pre-contractual measures taken at the data subject’s request, in accordance with Article 6(1)(b) of the GDPR.
The processing required to comply with legal obligations is based on Article 6(1)(c) of the GDPR.
The processing of technical data necessary to protect the website, prevent misuse and ensure the security of the systems is based on the Data Controller’s legitimate interest, in accordance with Article 6(1)(f) of the GDPR.
5. Nature of the provision of data
The provision of the data marked as mandatory on the contact form is necessary to enable the Data Controller to respond to your enquiry.
Failure to provide this information may make it impossible to supply the requested information or to contact you.
The provision of other data is optional.
6. Health-related data
The general contact form is not intended for the collection of health-related data or other special categories of personal data.
Users are therefore advised not to include detailed information regarding illnesses, medical conditions, disabilities or other health-related details in the form.
Should it be necessary, in connection with a booking, to provide details of specific requirements relevant to the safety of the voyage or of the guests, such information must be collected separately, limited to what is strictly necessary, and in accordance with a specific privacy notice.
7. Processing methods and security
Personal data is processed using IT and telecommunications systems and, where necessary, on paper.
The Data Controller takes appropriate technical and organisational measures to protect personal data from:
- unauthorised access;
- loss or destruction;
- unauthorised disclosure;
- unauthorised modification;
- improper use;
- processing that does not comply with the stated purposes.
Access to data is restricted solely to authorised persons and to suppliers who have a genuine need for it in order to carry out the services entrusted to them.
8. Recipients of the data
Personal data may be disclosed, to the extent strictly necessary, to the following categories of recipients:
- staff and authorised representatives of the Data Controller;
- hosting service providers;
- email service providers;
- technicians and those responsible for site maintenance;
- IT and security service providers;
- professional advisers, where necessary;
- public authorities, law enforcement agencies or other parties to whom disclosure is required by law.
Suppliers who process personal data on behalf of the Data Controller are appointed, where applicable, as Data Processors in accordance with Article 28 of the GDPR.
Personal data is not disclosed or made public.
9. Contact via WhatsApp
Should the user choose to contact Dal Maschio via WhatsApp, the data provided will also be processed via the WhatsApp platform.
Use of this service is subject to the terms and conditions and privacy policy of the relevant provider.
We recommend that you do not send particularly confidential documents or information via WhatsApp, unless this is strictly necessary and has been agreed in advance with the Data Controller.
10. Transfer of data outside the European Economic Area
Some providers of IT, communications, hosting or technical support services may process personal data in countries outside the European Economic Area.
In such cases, the transfer will take place in accordance with Articles 44 et seq. of the GDPR, on the basis of an adequacy decision by the European Commission, the Standard Contractual Clauses or another legal instrument provided for by the applicable legislation.
11. Retention period
Data relating to enquiries are retained for as long as is necessary to respond to and handle the enquiry and, as a rule, for a period not exceeding 12 months since the last notification.
If the enquiry results in a booking or a contractual relationship, the data may be retained for as long as is necessary to manage the service and to fulfil administrative, accounting, tax and legal obligations.
Technical data and security logs are retained for the period strictly necessary to ensure the operation and security of the website, unless it is necessary to retain them for a longer period in order to investigate misuse, fraud or cyber incidents.
12. Automated decision-making and profiling
The data collected in connection with contact and information requests is not subject to fully automated decision-making processes and is not used for profiling purposes.
13. Rights of the data subject
The data subject may, where applicable, exercise the rights set out in Articles 15–22 of the GDPR and, in particular, may request:
- confirmation as to whether personal data relating to him or her exists;
- access to one’s personal data;
- the rectification of inaccurate or incomplete data;
- the erasure of data;
- restriction of processing;
- data portability;
- objection to processing on the grounds of legitimate interest;
- the withdrawal of consent, where the processing is based on consent.
The withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
Enquiries can be sent to:
info@dalmaschioveniceboattour.com
The Data Controller will respond within the time limits laid down by the applicable legislation.
14. Complaint to the Data Protection Authority
Any data subject who believes that their personal data is being processed in breach of the GDPR may lodge a complaint with:
Data Protection Commissioner
or contact the relevant supervisory authority in the European Union country where you live, work or where you believe the breach took place.
15. Cookies and third-party services
This privacy notice mainly concerns the data processed for the purposes of managing contacts and enquiries.
Where the website uses non-technical cookies, statistical tools, embedded content, maps, videos, advertising services or tracking systems, such processing must be described in a specific Cookie Policy and, where required, enabled only after the user’s consent has been obtained.
16. Changes to this policy
The Data Controller may update this Privacy Policy from time to time to bring it into line with regulatory, technical or organisational changes.
The updated version will be published on this page, along with the date of the last update.