Legal

Privacy Notice for Guests

Version 1.0 — July 2026

Note. This is the official English translation of the Italian guest privacy notice. In the event of any discrepancy, the Italian text prevails. Read the Italian version →

Who we are and why you receive this notice

You received a WhatsApp message from the digital assistant of an accommodation. This notice explains clearly how your personal data are processed during your stay.

Who processes my data?

The data controller — the party that decides how and why your data are used — is the host (the manager of the accommodation where you are staying). Their name and contact details are provided at the time of booking or upon arrival.

The data processor is DFM Digital Solutions S.r.l.s., the company that operates the Verto platform on behalf of the host:

DFM Digital Solutions S.r.l.s.
Via Nicolò Biondo 256, 41126 Modena (MO), Italy
VAT IT04233950361
Privacy email: privacy@vertoai.it
PEC: dfm.digitalsolutions@pec.it

For any questions about your data, please write to privacy@vertoai.it — you will receive a reply within 30 days.

You are talking to a digital AI assistant

The assistant responding to your WhatsApp messages is an artificial intelligence (AI) system, not a person. It is operated by the host through the Verto platform of DFM Digital Solutions S.r.l.s.

Important things to know:

What data do we collect?

CategoryExamplesWhen
Contact detailsWhatsApp phone number, nameWhen you message us
Conversations and attachmentsMessages, photos sent in chatDuring your stay
Personal data for check-inFirst name, last name, date and place of birth, nationality, genderOnly if you check in via the assistant
Identity document dataDocument type, number, place and date of issue, expiry dateOnly for mandatory check-in
Companions' dataSame personal and document data for each companion, including minorsOnly as required by law (see below)
Payment dataAmount, Stripe transaction referenceIf you purchase services via the assistant
Tourism tax dataCalculated amount, receiptIf the accommodation charges a municipal tourism tax

We do not collect your tax identification number or full home address, unless the host specifically requires them for the accommodation contract (in that case you will be notified separately with the applicable retention period).

Photos of your identity document are used to extract data; a copy is kept encrypted(AES-256) and accessible only to the property, so it can verify the accuracy of the data submitted to the police, for which it is legally responsible (Art. 109 TULPS). The copy is automatically deleted immediately after the registration is transmitted to the police; if the registration is not handled through the platform, within 3 days of arrival; in any case within 30 days. It is also deleted immediately if you exercise your right to erasure. The photo never appears in the chat and cannot be read without the system's encryption keys.

Why do we process your data? (purposes and legal bases)

1. Assistance during your stay

What we do: answer your questions about the property, handle service requests, share useful information.

Legal basis: performance of the accommodation contract (Art. 6.1.b GDPR) and legitimate interest of the host in providing a quality service (Art. 6.1.f GDPR).

2. Check-in and notification to public security authorities

What we do: collect and transmit to the competent Police Headquarters (Questura) the personal and identity document data of each guest and companion, including minors, through the Alloggiati Web portal of the Italian Ministry of the Interior.

Legal basis: legal obligation incumbent on the host pursuant to Art. 109 of the TULPS (Italian Consolidated Public Security Law) and Ministerial Decree of 7 January 2013 (Art. 6.1.c GDPR). Minors' data are processed exclusively for this legal obligation and are not used for any other purpose.

3. Purchase of services via the assistant

What we do: process payment for additional services (e.g. late check-out, experiences, products) via Stripe.

Legal basis: performance of the purchase contract (Art. 6.1.b GDPR).

4. Tourism tax

What we do: calculate and manage the municipal tourism tax on behalf of the host.

Legal basis: legal obligation incumbent on the host (Art. 4 D.L. 50/2017; Art. 6.1.c GDPR). DFM provides only the technical tool; payment to the municipality is the exclusive responsibility of the host.

5. Personalised suggestions (AI)

What we do: the AI assistant may suggest services based on your requests and the context of your stay.

Legal basis: legitimate interest of the host (Art. 6.1.f GDPR). You can object at any time by messaging the assistant or writing to privacy@vertoai.it — suggestions will stop.

How long do we keep your data?

DataRetention period
WhatsApp conversations and attachments (excluding document photos)12 months from the last message
Document fields (number, place/date of issue, expiry)30 days from transmission of the registration form to the Police Headquarters
Basic personal data in the guest register (name, date of birth, nationality)5 years from check-out
Alloggiati receipts5 years
Signed accommodation contracts10 years (Art. 2220 of the Italian Civil Code)
Payment references and purchase receipts10 years (Art. 2220 of the Italian Civil Code)
Photos of identity documentsStored encrypted, visible only to the property; automatically deleted immediately after transmission to the police (within 3 days of arrival if not transmitted through the platform; in any case within 30 days)

Who receives your data?

Your data may be disclosed or made accessible to:

  1. Police Headquarters / Prefecture — as required by law (Art. 109 TULPS), via the Alloggiati Web portal of the Italian Ministry of the Interior.
  2. Technical service providers (sub-processors) — companies that DFM uses to operate the service (e.g. cloud infrastructure, AI, messaging, payments). For the full list, see the List of Sub-processors.
  3. Stripe Inc. — for payment processing (only data necessary for the transaction).

Your data are not sold or transferred to third parties for unsolicited marketing purposes.

Transfers outside the European Union

Some technical providers (such as Meta, OpenAI, Twilio, Stripe) are based in or process data in the United States. These transfers comply with the GDPR on the basis of:

My rights

As a data subject, you have the right to:

RightWhat you can do
Access (Art. 15)Request confirmation of whether we process your data and obtain a copy
Rectification (Art. 16)Request correction of inaccurate data
Erasure (Art. 17)Request deletion of your data (subject to legal retention obligations)
Restriction (Art. 18)Request restriction of processing in certain cases
Portability (Art. 20)Receive your data in a machine-readable format
Objection (Art. 21)Object to processing based on legitimate interest
Withdrawal of consentWhere processing is based on consent, you may withdraw it at any time

How to exercise your rights: write to privacy@vertoai.it. We will reply within 30 days of receipt. Responses are free of charge.

If you believe the processing of your data violates the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante):

Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma, Italy
www.garanteprivacy.it
urp@gpdp.it

You also have the right to lodge a complaint with the supervisory authority of your country of habitual residence, place of work, or the place where the alleged infringement occurred.

Updates to this notice

This notice may be updated. The current version is always available at vertoai.eu/guest-privacy. In the event of material changes, you will be informed via the WhatsApp assistant.

Notice drafted pursuant to Arts. 13-14 of Regulation (EU) 2016/679 (GDPR) and Art. 50 of the AI Act (Regulation (EU) 2024/1689).