Legal
Privacy Notice for Guests
Version 1.0 — July 2026
Who we are and why you receive this notice
You received a WhatsApp message from the digital assistant of an accommodation. This notice explains clearly how your personal data are processed during your stay.
Who processes my data?
The data controller — the party that decides how and why your data are used — is the host (the manager of the accommodation where you are staying). Their name and contact details are provided at the time of booking or upon arrival.
The data processor is DFM Digital Solutions S.r.l.s., the company that operates the Verto platform on behalf of the host:
DFM Digital Solutions S.r.l.s.
Via Nicolò Biondo 256, 41126 Modena (MO), Italy
VAT IT04233950361
Privacy email: privacy@vertoai.it
PEC: dfm.digitalsolutions@pec.it
For any questions about your data, please write to privacy@vertoai.it — you will receive a reply within 30 days.
You are talking to a digital AI assistant
The assistant responding to your WhatsApp messages is an artificial intelligence (AI) system, not a person. It is operated by the host through the Verto platform of DFM Digital Solutions S.r.l.s.
Important things to know:
- The AI never takes binding decisions on its own. Every purchase requires your explicit confirmation before a payment link is generated.
- There are no solely automated decisions with legal or similarly significant effects on you (Art. 22 GDPR).
- The assistant may suggest additional services (e.g. late check-out, experiences, products). You can refuse or object at any time by replying "no thanks" or by writing to privacy@vertoai.it.
- If you ask directly whether you are talking to a bot, the assistant will answer honestly.
What data do we collect?
| Category | Examples | When |
|---|---|---|
| Contact details | WhatsApp phone number, name | When you message us |
| Conversations and attachments | Messages, photos sent in chat | During your stay |
| Personal data for check-in | First name, last name, date and place of birth, nationality, gender | Only if you check in via the assistant |
| Identity document data | Document type, number, place and date of issue, expiry date | Only for mandatory check-in |
| Companions' data | Same personal and document data for each companion, including minors | Only as required by law (see below) |
| Payment data | Amount, Stripe transaction reference | If you purchase services via the assistant |
| Tourism tax data | Calculated amount, receipt | If the accommodation charges a municipal tourism tax |
We do not collect your tax identification number or full home address, unless the host specifically requires them for the accommodation contract (in that case you will be notified separately with the applicable retention period).
Photos of your identity document are used to extract data; a copy is kept encrypted(AES-256) and accessible only to the property, so it can verify the accuracy of the data submitted to the police, for which it is legally responsible (Art. 109 TULPS). The copy is automatically deleted immediately after the registration is transmitted to the police; if the registration is not handled through the platform, within 3 days of arrival; in any case within 30 days. It is also deleted immediately if you exercise your right to erasure. The photo never appears in the chat and cannot be read without the system's encryption keys.
Why do we process your data? (purposes and legal bases)
1. Assistance during your stay
What we do: answer your questions about the property, handle service requests, share useful information.
Legal basis: performance of the accommodation contract (Art. 6.1.b GDPR) and legitimate interest of the host in providing a quality service (Art. 6.1.f GDPR).
2. Check-in and notification to public security authorities
What we do: collect and transmit to the competent Police Headquarters (Questura) the personal and identity document data of each guest and companion, including minors, through the Alloggiati Web portal of the Italian Ministry of the Interior.
Legal basis: legal obligation incumbent on the host pursuant to Art. 109 of the TULPS (Italian Consolidated Public Security Law) and Ministerial Decree of 7 January 2013 (Art. 6.1.c GDPR). Minors' data are processed exclusively for this legal obligation and are not used for any other purpose.
3. Purchase of services via the assistant
What we do: process payment for additional services (e.g. late check-out, experiences, products) via Stripe.
Legal basis: performance of the purchase contract (Art. 6.1.b GDPR).
4. Tourism tax
What we do: calculate and manage the municipal tourism tax on behalf of the host.
Legal basis: legal obligation incumbent on the host (Art. 4 D.L. 50/2017; Art. 6.1.c GDPR). DFM provides only the technical tool; payment to the municipality is the exclusive responsibility of the host.
5. Personalised suggestions (AI)
What we do: the AI assistant may suggest services based on your requests and the context of your stay.
Legal basis: legitimate interest of the host (Art. 6.1.f GDPR). You can object at any time by messaging the assistant or writing to privacy@vertoai.it — suggestions will stop.
How long do we keep your data?
| Data | Retention period |
|---|---|
| WhatsApp conversations and attachments (excluding document photos) | 12 months from the last message |
| Document fields (number, place/date of issue, expiry) | 30 days from transmission of the registration form to the Police Headquarters |
| Basic personal data in the guest register (name, date of birth, nationality) | 5 years from check-out |
| Alloggiati receipts | 5 years |
| Signed accommodation contracts | 10 years (Art. 2220 of the Italian Civil Code) |
| Payment references and purchase receipts | 10 years (Art. 2220 of the Italian Civil Code) |
| Photos of identity documents | Stored encrypted, visible only to the property; automatically deleted immediately after transmission to the police (within 3 days of arrival if not transmitted through the platform; in any case within 30 days) |
Who receives your data?
Your data may be disclosed or made accessible to:
- Police Headquarters / Prefecture — as required by law (Art. 109 TULPS), via the Alloggiati Web portal of the Italian Ministry of the Interior.
- Technical service providers (sub-processors) — companies that DFM uses to operate the service (e.g. cloud infrastructure, AI, messaging, payments). For the full list, see the List of Sub-processors.
- Stripe Inc. — for payment processing (only data necessary for the transaction).
Your data are not sold or transferred to third parties for unsolicited marketing purposes.
Transfers outside the European Union
Some technical providers (such as Meta, OpenAI, Twilio, Stripe) are based in or process data in the United States. These transfers comply with the GDPR on the basis of:
- EU-US Data Privacy Framework (for certified providers), or
- Standard Contractual Clauses (SCC) approved by the European Commission.
My rights
As a data subject, you have the right to:
| Right | What you can do |
|---|---|
| Access (Art. 15) | Request confirmation of whether we process your data and obtain a copy |
| Rectification (Art. 16) | Request correction of inaccurate data |
| Erasure (Art. 17) | Request deletion of your data (subject to legal retention obligations) |
| Restriction (Art. 18) | Request restriction of processing in certain cases |
| Portability (Art. 20) | Receive your data in a machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interest |
| Withdrawal of consent | Where processing is based on consent, you may withdraw it at any time |
How to exercise your rights: write to privacy@vertoai.it. We will reply within 30 days of receipt. Responses are free of charge.
If you believe the processing of your data violates the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante):
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma, Italy
www.garanteprivacy.it
urp@gpdp.it
You also have the right to lodge a complaint with the supervisory authority of your country of habitual residence, place of work, or the place where the alleged infringement occurred.
Updates to this notice
This notice may be updated. The current version is always available at vertoai.eu/guest-privacy. In the event of material changes, you will be informed via the WhatsApp assistant.
Notice drafted pursuant to Arts. 13-14 of Regulation (EU) 2016/679 (GDPR) and Art. 50 of the AI Act (Regulation (EU) 2024/1689).