<!DOCTYPE html>
<html lang="it">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Privacy & Cookie Policy — Siena by Vespa</title>
<style>
body {
font-family: Arial, sans-serif;
font-size: 15px;
line-height: 1.7;
color: #000;
background: #fff;
max-width: 800px;
margin: 40px auto;
padding: 0 20px;
}
h1 { font-size: 24px; margin-bottom: 4px; }
h2 { font-size: 17px; margin-top: 36px; margin-bottom: 8px; border-bottom: 1px solid #ccc; padding-bottom: 4px; }
h3 { font-size: 15px; margin-top: 20px; margin-bottom: 6px; }
p { margin-bottom: 10px; }
ul { margin: 8px 0 12px 20px; }
li { margin-bottom: 4px; }
.meta { font-size: 13px; color: #555; margin-bottom: 30px; }
table { width: 100%; border-collapse: collapse; margin: 12px 0; font-size: 14px; }
th { background: #f0f0f0; text-align: left; padding: 8px 10px; border: 1px solid #ccc; }
td { padding: 8px 10px; border: 1px solid #ccc; vertical-align: top; }
a { color: #000; }
</style>
</head>
<body>
Privacy & Cookie Policy
<div class="meta">
www.sienabyvespa.com — Last updated: March 2025
1. Data Controller
The Data Controller for personal data collected via the website www.sienabyvespa.com is:
Siena by Vespa
Operational headquarters: Siena (SI), Italy
Email: <a href="mailto:This email address is being protected from spambots. You need JavaScript enabled to view it.">This email address is being protected from spambots. You need JavaScript enabled to view it.
2. Types of Data Collected
Data provided voluntarily by the user
First name and surname
Email address
Telephone number
Any additional information entered in contact or booking forms
Data collected automatically
Device IP address
Browser type and operating system
Pages visited and time spent on the site
Browsing data collected via cookies and similar technologies
3. Purposes of Processing
Personal data is processed for the following purposes:
Management of enquiries and bookings
Provision of requested services (Vespa hire, guided tours, etc.)
Sending of service communications (confirmations, updates)
Compliance with legal and tax obligations
Improving the browsing experience and statistical analysis of the website
Sending promotional communications, subject to the user’s explicit consent
4. Legal Basis for Processing
The processing of personal data is based on the following legal bases under the GDPR:
Art. 6(1)(b) — Performance of a contract or pre-contractual measures
Art. 6(1)(c) — Compliance with a legal obligation
Art. 6(1)(a) — Explicit consent of the data subject
Art. 6(1)(f) — Legitimate interests of the Data Controller
5. Data Retention Periods
Bookings and contracts: 10 years from the last interaction, in accordance with tax and civil law obligations
Marketing purposes: until consent is withdrawn
Browsing data (cookies): in accordance with the periods indicated in the Cookies section of this policy
6. Disclosure and Sharing of Data
Personal data will not be disclosed to third parties, except in the following cases:
Technical service providers (hosting, booking platforms, payment systems) acting as Data Processors
Competent authorities, where required by law
Third parties with the prior explicit consent of the data subject
Data is not transferred to third countries outside the European Union, except where adequate safeguards are provided for under the GDPR.
7. Rights of the Data Subject
In accordance with EU Regulation 2016/679 (GDPR), the user has the right to:
Access their personal data (Art. 15 GDPR)
Request the rectification of inaccurate data (Art. 16 GDPR)
Request the erasure of their data — ‘right to be forgotten’ (Art. 17 GDPR)
Request restriction of processing (Art. 18 GDPR)
Receive their data in a structured format — data portability (Art. 20 GDPR)
Object to processing for marketing purposes (Art. 21 GDPR)
Withdraw consent at any time, without prejudice
