W+ Newbookclloud
Legal

Privacy Notice

Article 13-14 GDPR + Art. 13 D.lgs. 196/2003 · Version 2.4 · in force from 1 April 2026 · registered with Garante per la protezione dei dati personali

1. Data controller

Newbookclloud Retail S.r.l., Via Cavour 47, 00184 Roma, Italia. P.IVA IT 07284916350 · REA Roma RM-1548273. Legal representative: Marco Bellandi, Amministratore Unico. General inbox: support@newbookclloud.org. Data Protection Officer: dpo@newbookclloud.org.

2. Categories of personal data processed

(a) Account data: name, business email, company name, P.IVA, codice fiscale, codice destinatario or PEC address, telephone. Provided by you at checkout. (b) Wubook connection data: the OAuth-style token issued by Wubook when you complete Wubook Login. We never receive your Wubook password. (c) Property data streamed from Wubook: reservations, folios, rate plans, room states, guest first name and surname, arrival and departure dates. Content depends on the module you activate. (d) Technical data: IP address, user agent, session cookies, error logs. Collected automatically.

3. Purposes and legal basis

(a) Provision of the contracted service — legal basis: performance of the contract (Art. 6.1.b GDPR). (b) Italian electronic invoicing through SdI — legal basis: legal obligation (Art. 6.1.c GDPR + D.lgs. 127/2015). (c) Fraud prevention and platform security — legal basis: legitimate interest (Art. 6.1.f GDPR). (d) Product updates and monthly usage reports — legal basis: consent (Art. 6.1.a GDPR), which you can withdraw at any time from your account settings.

4. Retention periods

Contract data: for the duration of the contract plus 10 years for accounting purposes per Art. 2220 Codice Civile. Property data streamed from Wubook: retained for 25 months by default, purged on request within 30 days save for legal-hold cases. Technical logs: 12 months. Marketing consent: until withdrawal, then archived for evidentiary purposes for 2 years.

5. Recipients and sub-processors

Full list is published in Annex B of the Data Processing Agreement. Key sub-processors: Hetzner Online GmbH (Frankfurt) for compute; OVHcloud SAS (Strasbourg) for cold backups mirrored to Milan; Stripe Payments Europe Ltd (Dublin) for payment processing; Postmark Inc. (London EU region) for transactional email; Fatture in Cloud (TeamSystem S.p.A., Bassano del Grappa) for e-invoicing. All sub-processors are bound by written processing agreements under Art. 28 GDPR.

6. Data transfers outside the EEA

No routine transfers outside the European Economic Area. On the rare occasion of a support ticket routed through Postmark's overflow US region, transfer takes place under the European Commission's Standard Contractual Clauses adopted in Decision 2021/914.

7. Your rights

Under Art. 15 to 22 GDPR you have the right to access, rectify, erase, restrict, port and object to the processing of your personal data. To exercise these rights, email dpo@newbookclloud.org — response within 30 days as required by Art. 12.3 GDPR. You may also lodge a complaint with the Italian supervisory authority: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, protocollo@gpdp.it, protocollo@pec.gpdp.it. Additional rights under the Codice Privacy (D.lgs. 196/2003 as amended by D.lgs. 101/2018) apply.

8. Cookies

See our Cookie Notice for detail on essential and analytical cookies used on newbookclloud.org.

9. Data breaches

In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the Garante within 72 hours in accordance with Art. 33 GDPR and communicate the breach to affected individuals without undue delay under Art. 34 GDPR.

10. Contact

Privacy questions: dpo@newbookclloud.org. Postal: Newbookclloud Retail S.r.l., Data Protection Officer, Via Cavour 47, 00184 Roma, Italia.