Privacy Policy
Last updated: 23 June 2026
This Privacy Policy describes how personal data of users of the booking website tools.acroba.to/pesaro2026 ("Service") are processed, in compliance with EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
1. Data Controller
Esatour S.r.l.: Tour operator and party issuing the invoice for hotel packages and entry tickets sold through the Service.
Tax code and VAT number: 02258920418
Email: events@esatourgroup.com
2. Data processed and how they are collected
The Service processes the following categories of personal data, all provided directly by the booking person ("Contact person") via the booking form:
2.1 Contact person / invoice recipient
- First name and last name
- Italian tax code (codice fiscale)
- Residential address (street, postal code, city, province)
- Email and phone number
- If applicable: company name and VAT number
2.2 Participants
- First name and last name of each participant included in the room
- Date of birth (only if marked as minor by the contact person, for hotel registration and city tax exemption rules)
- Optional notes (dietary restrictions, accessibility needs): only if voluntarily provided
2.3 Travel and logistics data
- Train arrival/departure data (date, time, train number) if the user requests a station transfer
- Selected shuttle service to/from Vitrifrigo Arena
- Booking history (status, dates, payment receipt uploaded)
2.4 Automatically collected technical data
- Server access logs (IP address, browser, request timestamp) for security and abuse-prevention purposes, retained 30 days
- Strictly necessary session and CSRF cookies, see Cookie Policy
3. Purposes and legal basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Manage booking, confirm rooms, organise transfers | Performance of a contract (Art. 6(1)(b) GDPR) | 2 years after the event |
| Issue electronic invoice, accounting and tax obligations | Legal obligation (Art. 6(1)(c)) | 10 years |
| Send transactional emails (confirmation, IBAN, payment reminder, paid receipt) | Performance of a contract | For the duration of the booking |
| Provide participant lists to the hotel (rooming list) | Performance of a contract | Until completion of the stay |
| Defend against legal claims, dispute management | Legitimate interest (Art. 6(1)(f)) | Up to legal terms |
4. Communication and disclosure of data
Data may be communicated to:
- Selected hotels (3* standard or 4* on upgrade): first/last name, room type, dates, minor status, dietary notes (rooming list)
- Transport service providers: station transfer and shuttle service operators, only data strictly required (date/time/people)
- Vitrifrigo Arena ticketing: list of attendees for entry ticket issuance
- Tax authorities (Italian Revenue Agency): for electronic invoicing
- Banking institution: for receipt of payment (Unicredit S.p.A., the Controller's bank)
- Authorities: only if required by law or judicial order
Data are not transferred outside the EU/EEA and are not used for marketing, profiling, automated decision making.
5. Data processors
The following entities act as data processors on behalf of the Controller:
- Turin Acro Eventi: initiative promoter, no commission, technical and organisational support
- Acroba.to: website development and technical hosting (
tools.acroba.to, server located in Italy) - Aruba S.p.A.: email service provider (SMTP) for transactional messages
6. Rights of the data subject
Pursuant to Articles 15–22 GDPR, the data subject has the right to:
- access their data and obtain a copy
- rectify incorrect or out-of-date data
- request erasure ("right to be forgotten"), where applicable
- restrict or object to processing
- data portability in machine-readable format
- lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it)
To exercise these rights, contact: events@esatourgroup.com
7. Security
The Service uses HTTPS encryption for all communications, CSRF protection on forms, hashed authentication credentials, segregated database access. Uploaded payment receipts and invoices are stored in a private directory accessible only to authorised personnel.
8. Minors
Data of minors are processed only as part of the booking made by the legal guardian (the Contact person), who declares to have the authority to communicate the data and assumes responsibility for it. The minor's date of birth is collected solely to comply with hotel registration regulations and any city tax exemptions.
9. Changes
This Policy may be updated. Significant changes will be communicated via the website. The current version takes effect from the date indicated at the top of this page.