How we collect, use and protect your personal data, under Regulation (EU) 2016/679 (GDPR).
Last updated: 25 July 2026
The controller of the personal data collected through this website is Piccolo di Kato Sakiko & co. s.n.c., registered office at Via Ricasoli 23, 50122 Florence (FI), Italy, VAT no. 05127720489.
For anything concerning your data you can write to info@piccoloflorence.com or call +39 055 280723.
We collect only the data we need in order to answer your enquiries, manage your stay and comply with the law. We do not sell your data or pass it to third parties for marketing purposes.
At check-in we are required to record the details of every guest's identity document and to report them to the Italian State Police (Questura) within 24 hours through the Alloggiati Web portal, as required by Art. 109 of the Italian Consolidated Public Security Act (TULPS). We are also required to report statistical data to the Tuscany Region and to collect the tourist tax on behalf of the City of Florence. This processing is mandatory: without it we cannot accommodate you. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
The website records technical browsing data (IP address, browser type, pages visited) in the server logs, for security and diagnostic purposes. Cookies and similar technologies are described in detail in the Cookie Policy.
Your data may be disclosed only to:
| Recipient | Why |
|---|---|
| Octorate S.r.l. | Booking management system and online booking engine (data processor) |
| payment provider configured in Octorate — to be specified | Collection and handling of payments |
| Netsons S.r.l. | Hosting of the website and the email accounts |
| Accountant and advisers | Tax and accounting obligations |
| Questura di Firenze, Tuscany Region, City of Florence | Legal obligations (guest registration, statistics, tourist tax) |
If you booked through a travel site (Booking.com, Airbnb, Expedia), the data they pass to us is handled by us as described in this notice; for the processing carried out by the travel site itself, their own privacy notice applies.
Our main suppliers operate within the EU. Where a service (Google Maps, for example) involves a transfer to a third country, that transfer is made on the basis of the standard contractual clauses approved by the European Commission or of an adequacy decision.
At any time you can ask us to give you access to your data, to correct it, to erase it, to restrict its processing, to provide it in a portable format and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw that consent at any time, without affecting the lawfulness of the processing carried out before the withdrawal.
To exercise these rights write to info@piccoloflorence.com: we will reply within 30 days. If you believe the processing breaches the GDPR you can lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
The website uses an encrypted HTTPS connection. Access to booking data is limited to the people who run the business and is protected by individual credentials.
If we change the way we handle data we will update this page and show the date of the latest revision at the top.