This page explains what personal data we collect through mimishouse.it, why we collect it, who we share it with and what you can ask us. It is written to be read: if anything is unclear, write to us and we will explain.
Who handles your data
The data controllers are Sina Vilson and Albana Shehu, who run the Mimi's House apartment at Via Luigi Gordigiani 32, Florence (Italy) — CIN IT048017C2RF55GGIC.
You can write to us at any time: vilsonsina@hotmail.it · albanashehu@hotmail.it
We have not appointed a Data Protection Officer: for a business of this size the law does not require one.
What we collect and why
When you request a booking
The form collects your name, email address, phone number (optional), number of guests, arrival and departure dates and the message you write. We need them to record the request, block the dates on the calendar and reply to you: the legal basis is the performance of a contract and of the pre-contractual steps you asked for (Art. 6(1)(b) GDPR). Without this data we cannot take the booking.
To keep bots out
Before the form is sent, an anti-spam check by Cloudflare (Turnstile) verifies that there is a person on the other side. To do so Cloudflare processes your IP address and some technical information about your browser. We do this on the legitimate interest of not receiving fake bookings (Art. 6(1)(f) GDPR).
Technical logs
Like any website, the server records IP address, date and time, the page requested and the browser type: they keep the site running and protect it from abuse (Art. 6(1)(f) GDPR).
If you cancel and ask for a refund
To give your money back you send us by email the reason for the cancellation and the bank details in the name of the person who booked. We use them only to make the refund transfer (Art. 6(1)(b) GDPR).
If you arrive from an ad
If you land on the site from an advertisement, the address carries a code identifying the click (on Google Ads it is called gclid). If you then send the form, that code travels with your request and tells us which ad produced it. It is not stored on your device: no cookie, no browser storage. We process it on the legitimate interest of understanding whether the advertising works (Art. 6(1)(f) GDPR).
When you arrive
At check-in we are required by law to record guests' identity documents and report them to the Italian police through the Alloggiati Web portal, along with tourist tax, statistical returns and tax documents (Art. 6(1)(c) GDPR). This data does not go through the website: we ask for it in person.
Who we share your data with
We do not sell your data and we do not pass it to anyone for advertising. It is processed on our behalf only by the providers we need to run the service:
- Cloudflare, Inc. — hosts the website and provides the Turnstile anti-spam check. Cloudflare
- Smoobu GmbH (Pappelallee 78/79, Berlin, Germany) — the booking system your reservation lands in and where we keep the calendar. Smoobu
- EmailJS Pte. Ltd. (Singapore) — sends the confirmation email to you and the notification to us. EmailJS
- Microsoft — our mailboxes are on Outlook/Hotmail, so messages pass through their servers. Microsoft
- Google — only if you choose to load the map in the contact section (see cookies, below). Google
We also share data with public authorities where the law requires it: the police headquarters, the City of Florence and the Italian Revenue Agency.
Transfers outside the European Union
Smoobu is in Germany, so inside the European Union. Cloudflare is a US company: the transfer relies on the EU-US Data Privacy Framework adequacy decision and on the European Commission's standard contractual clauses. EmailJS is based in Singapore, a country with no adequacy decision: that transfer relies on the standard contractual clauses under Art. 46 GDPR.
How long we keep it
- Requests that do not become bookings: 12 months, then we delete them.
- Confirmed bookings: 10 years from the end of the stay, the period Italian law sets for accounting records (Art. 2220 of the Civil Code).
- Bank details for a refund: deleted as soon as the refund is complete, except for what must remain in the accounts.
- Technical logs: a few days, according to Cloudflare's retention periods.
Your rights
At any time you can ask us to give you access to your data, to correct it, erase it, restrict its processing, hand it to you in a machine-readable format or let you object to the processing based on our legitimate interest. An email to either address above is enough: we reply within one month.
If you believe something is wrong you can turn to the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or to the authority of the country where you live.
Cookies and similar technologies
This site sets no cookies when you open it. We use no analytics, no advertising pixels, and we profile nobody. Even the fonts are hosted on our own server, so they call no outside service.
Turnstile anti-spam
When you fill in the booking form, Cloudflare Turnstile may store on your device technical information needed to tell a person from a bot. These are technical tools, essential to the service you asked for, and therefore require no consent (Art. 122 of the Italian Privacy Code). They are not used to recognise you or follow you across other sites.
The Google map
In the contact section the map does not load by itself: in its place you find a box with the address and a button. Until you press it, Google receives nothing from this site. If you press it, the map is loaded from Google, which receives your IP address and may store its own cookies on your device: that click is your consent.
To go back, simply reload the page without pressing the button and delete Google's cookies from your browser settings.
Changes to this policy
If we change the services we use, we update this page and the date at the top. The version you find here is always the one that applies.