Last updated: 10/05/2026
The company ST.AR HOLIDAYS SAS VAT No. 12499211006, with registered office at Via Arenula, 41 – 00186 Rome (RM), Italy, as the personal data controller (hereinafter the “Controller”) of the website https://adm-hospitality.com/ (hereinafter the “Site”), informs the visitors of the Site (hereinafter the “Data Subjects”) pursuant to Article 13 of European Regulation No. 2016/679, the General Data Protection Regulation (GDPR).
The Controller is aware of the importance of processing the personal data of Data Subjects and, for this reason, takes care to indicate which data is processed and how it is processed. By continuing to browse the Site or by indicating the intention to use the services provided through it, the Data Subject declares that they have read and accepted this notice (hereinafter the “Notice”), thereby giving consent to the processing of personal data by the Controller.
For any information, doubts, or requests relating to this Notice, the Controller provides Data Subjects with the following email address: info@adm-hospitality.com
What are the Data Subject’s rights in relation to the processing of personal data?
The Data Subject has the following rights:
- the right to be informed that data processing concerning them is taking place and, if so, to access the personal data being processed;
- the right to rectify personal data;
- the right to erasure (“right to be forgotten”) of personal data concerning them;
- the right to restriction of the processing of personal data concerning them;
- the right to data portability, in order to receive, or have transmitted to another Controller, the personal data concerning them in a structured, commonly used and machine-readable format;
- the right to object to the processing of personal data;
- the right to withdraw previously given consent;
- the right to lodge a complaint with the competent authorities for violations in the processing of personal data.
How can rights be exercised?
The Data Subject may exercise their rights by writing to the email address indicated above.
The Controller does not intend to charge Data Subjects any cost for exercising one of their rights; however, in order to do so, the Controller may request specific information to follow up on the Data Subject’s communications regarding their rights.
The aforementioned communications are usually answered within 30 days of receipt of the communication itself. However, if this deadline cannot be met — for example, due to an excessive number of requests or the complexity of the response — the Controller will inform the Data Subject and keep them updated on the progress of the communication sent.
Which personal data is processed?
The Controller processes the personal data provided both by the Data Subject and by third parties in order to follow up on the Data Subject’s contact requests received through the Site (hereinafter the “Services”).
Data provided directly by the Data Subject
| Category of personal data | Types of data |
|---|---|
| Identification and contact data | Name, surname, residence/domicile, email address, telephone number, website |
| Technical data | IP address |
Data collected from third parties
| Third party source of personal data | Types of data |
|---|---|
| Analytics providers |
|
Aggregated data
The Controller may collect, use, and share aggregated data, such as statistical or demographic data, for any purpose.
Aggregated data may derive from the Data Subject’s personal data, but once aggregated it does not constitute personal data under the GDPR, as it is not capable of directly or indirectly identifying the Data Subject. However, if the Controller combines or connects aggregated data with the Data Subject’s personal data in such a way as to allow the Data Subject to be identified, directly or indirectly, the Controller will process the resulting data in accordance with the provisions of this Notice.
Special Categories of Data
The Controller does not process any special categories of data of the Data Subject. Special categories of data mean data relating to ethnic or racial origin, religious or philosophical beliefs, sexual orientation, political opinions, trade union membership, genetic, biometric, and health data. The Controller also does not process any data relating to criminal convictions and offences concerning the Data Subject.
Why is personal data processed?
The Controller processes personal data for the purposes indicated in the table below. The GDPR requires that, for each purpose of personal data processing, the Controller has a legal basis for carrying out the processing.
The Controller may process the personal data of Data Subjects on the basis of their consent as the legal basis for the processing. Consent may be withdrawn at any time, but the processing carried out before the withdrawal of consent shall not be affected.
| Purpose | Description | Legal basis | Retention |
|---|---|---|---|
| Providing the Services | The Data Subject may, through the Site, request to be contacted in order to receive information, appointments, or estimates regarding the activities carried out by the Controller | Performance of a contract | The data will be retained until the provision of the individual Services has been completed |
| Providing support to Data Subjects | Resolving technical issues encountered by Data Subjects while browsing, handling their support requests, improving the Services and the Site, and providing the support requested by Data Subjects | Performance of a contract | The data will be retained until the Data Subjects’ support request has been fulfilled |
| Newsletter | The Controller may send updates, not of a commercial nature, to inform the Data Subject about developments in its business, such as agreements with commercial partners and participation in events | Consent | The data will be retained for 24 months |
| Complying with legal and regulatory obligations and protecting the Controller’s business | The Controller may process the Data Subject’s personal data in order to comply with legislative and regulatory obligations, as well as to comply with measures issued by judicial and administrative authorities. Furthermore, the Controller may process the data to protect its own rights and interests, such as in the case of legal protection or due diligence in the event of assessments regarding changes in the corporate structure | Legal obligations | Personal data will be retained for the period of time determined by law, regulation, and/or the relevant authority |
What happens if the Data Subject does not provide the necessary personal data?
If the data is necessary to provide the Services and to provide support to Data Subjects, the Controller will not be able to provide such Services or support the Data Subject in their requests. In this case, the Controller may alternatively request the integration of the personal data or delete the Data Subject’s personal data, thereby preventing the provision of the Services.
For purposes other than the provision of the Services and the provision of support to Data Subjects, the provision of data is optional and failure to provide personal data will not affect the aforementioned Processing purposes.
To whom is personal data communicated and disclosed?
Communication
The personal data of Data Subjects may be communicated to third parties other than the Controller, as better indicated in the following table:
| Recipients | Purpose of communication |
|---|---|
| Suppliers | The Controller’s suppliers support it in providing the Services, including, by way of example and not limitation, development of the Site, hosting, maintenance, backups, and virtual infrastructure |
| External consultants | In the event of legal obligations or obligations relating to a relationship established with the Data Subject, the Controller may communicate personal data to external consultants, such as, for example, the accountant and the lawyer |
| Authorities and judicial proceedings | The Controller may communicate the personal data of Data Subjects to state and/or administrative and/or judicial authorities where this is mandatory under the law, regulations, or measures issued by the authorities, or in order to defend its own rights and/or interests |
Disclosure
The personal data of Data Subjects will not be disclosed.
Where do we store personal data?
The Controller stores personal data in paper archives within the Controller’s premises, as well as in electronic archives located both within the European Union and outside it, where this is instrumental to pursuing the purposes indicated above. In the latter case, the Controller ensures that companies not based within the European Union process personal data with the utmost confidentiality, in compliance with the adequacy decisions of the European Commission, any Privacy Shields, or, where necessary, by entering into agreements that guarantee an adequate level of protection.
How is personal data processed?
The Controller processes the personal data of Data Subjects by adopting appropriate security measures aimed at preventing unauthorized access, disclosure, modification, and destruction.
Data processing is carried out through IT procedures, telematic means, and, on a residual basis, on paper media by specifically authorized internal personnel as well as by external processors, where appointed, also on the basis of existing contractual agreements.
What is the policy on the processing of minors’ data?
The Controller is aware of the sensitive nature of processing minors’ data. In particular, the Services are not intended to be provided to minors under the age of 14, and the Controller does not knowingly process data of minors under the age of 14. In this regard, Data Subjects are requested not to request the provision of the Services if they are under 14 years of age.
The Controller encourages those exercising parental responsibility over minors under the age of 14 to ensure that such minors do not request the provision of the Services and, in any case, to educate minors under the age of 14 not to disclose their personal data through the Site.
If the Controller becomes aware that certain personal data relates to minors under the age of 14, the Controller will take steps to delete such personal data.
What happens if there are links to other websites?
The Controller informs Data Subjects that this Notice applies only to the Site and, where there are links to other websites, the Data Subject must check the notices of those websites before providing their personal data.
The Controller assumes no responsibility for personal data provided by Data Subjects on other websites.
Changes to the Notice
The Controller reserves the right to amend this Notice at any time. In the event of changes, the Controller will upload the new notice to this page and, in this regard, the Data Subject is encouraged to check for changes to the Notice: the Data Subject may view the history of the notices by checking the date provided.
By continuing to use the Site after the changes, the Data Subject accepts such changes and consents to the processing of data as amended.
