Política de Privacidad
Last updated: 1 January 2025
This Privacy Policy describes how OVERCORE SRL (VAT 02521780441), data controller, collects, uses, stores and protects the personal data of users of the overcore.it website and the Stay platform ("Service"), in compliance with EU Regulation 2016/679 (GDPR) and applicable data protection legislation.
Please read this document carefully before using the Service. Use of the Service implies acceptance of the practices described in this Privacy Policy.
Table of Contents
1. Data Controller
The data controller for personal data processed through the Service is:
OVERCORE SRL
VAT / Tax Code: 02521780441 — SDI: KRRH6B9
Via dei Mutilati e Invalidi del Lavoro 108F, 63100 Ascoli Piceno (AP), Italia
Email: info@overcore.it
Privacy Email: privacy@overcore.it
2. Types of Data Collected
2.1 Data provided directly by the user
- Registration data: first name, last name, email address, property name, phone number, VAT/tax number (for invoicing).
- Payment data: billing information. Credit card data is processed directly by our payment provider (Stripe Inc.) and is never stored in Overcore's systems.
- Communications: messages sent via the contact form, email or support chat.
- Guest data: when using the PMS, the Customer enters personal data of their property's guests. In this case Overcore acts as a data processor under Art. 28 GDPR and the Customer acts as data controller.
2.2 Automatically collected data
- Navigation data: IP address, browser type, operating system, referral URL, pages visited, access time.
- Cookies: technical cookies necessary for the website to function, analytical cookies (in anonymous or aggregated form) and language preference cookies. See section 8 for details.
- Service usage data: access logs, features used, usage statistics in aggregated and anonymized form.
2.3 Third-party data
Overcore may receive data from booking channels (OTAs) that integrate with the Service via the Channel Manager, limited to the data necessary for executing the reservation.
3. Purposes and Legal Bases
| Purpose | Legal Basis | Data Processed |
|---|---|---|
| Service delivery and account management | Contract performance (Art. 6.1.b GDPR) | Registration data, usage data |
| Invoicing and tax compliance | Legal obligation (Art. 6.1.c GDPR) | Personal and fiscal data |
| Customer support and handling requests | Contract performance / Legitimate interest (Art. 6.1.b-f GDPR) | Registration data, communications |
| Service security and fraud prevention | Legitimate interest (Art. 6.1.f GDPR) | Navigation data, access logs |
| Marketing communications and newsletter | Consent (Art. 6.1.a GDPR) | Email, name |
| Service improvement and statistical analysis | Legitimate interest (Art. 6.1.f GDPR) — anonymized data | Aggregated usage data |
| Regulatory compliance (Alloggiati Web, ISTAT) | Legal obligation (Art. 6.1.c GDPR) | Guest data (on behalf of Customer) |
4. Processing Methods
Data is processed using IT and electronic tools, with logic strictly correlated to the stated purposes, in a manner that ensures the security and confidentiality of the data. Data is not subject to automated decision-making or profiling that produces legal effects on the data subject, unless explicit consent has been obtained or contractual necessity exists.
5. Data Retention
- Active account data: for the duration of the contractual relationship.
- Closed account data: 30 days from closure to allow data export, then secure deletion. Fiscal data is retained for 10 years as required by Italian tax law.
- Navigation data and logs: maximum 12 months, unless needed for criminal investigations.
- Support communications: 3 years from ticket closure.
- Analytical cookies: as specified in section 8.
- Guest data (processed on behalf of the Customer): according to the instructions of the Customer as data controller.
6. Disclosure and Sharing
Personal data is not sold to third parties. Data may be shared with:
- Technical service providers acting as data processors: cloud infrastructure and hosting providers (Microsoft Azure), payment processors (Stripe Inc.), transactional email providers, application monitoring services;
- Competent authorities when required by law or judicial order;
- Professional advisors who need the data to fulfill their mandates (accountants, lawyers), bound by confidentiality obligations.
An updated list of data processors is available upon request at privacy@overcore.it.
7. International Transfers
Some service providers used by Overcore may operate outside the European Economic Area (EEA). In such cases, transfers occur exclusively to countries that ensure an adequate level of protection (European Commission adequacy decision) or on the basis of Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR), or under the EU-US Data Privacy Framework for participating US providers.
For more information on the safeguards adopted, please contact privacy@overcore.it.
8. Cookies and Tracking Technologies
8.1 Technical cookies (necessary) — used without consent:
.Overcore.Culture: language preference cookie, 30-day duration. Contains no personally identifiable information.- ASP.NET session cookie: authenticated session management, browser session duration.
- Anti-CSRF cookie: Cross-Site Request Forgery protection, session duration.
8.2 Third-party cookies — with specific notice:
- Google reCAPTCHA v3: used to prevent automated activity in forms. Processes IP address and browsing patterns. Google Privacy Policy: policies.google.com/privacy.
8.3 Analytical cookies — only where present and with consent:
Overcore may use traffic analysis tools in anonymous or aggregated form. Data collected is not associated with identifiable individuals.
8.4 Cookie management
Users can manage or disable cookies through their browser settings. Disabling technical cookies may impair the proper functioning of the Service.
9. Your Rights
Under Arts. 15–22 GDPR, you have the right to:
- Access (Art. 15): obtain confirmation of whether personal data concerning you is being processed and, if so, obtain a copy;
- Rectification (Art. 16): obtain correction of inaccurate data or completion of incomplete data;
- Erasure / "right to be forgotten" (Art. 17): obtain deletion of your personal data in the cases provided by law;
- Restriction (Art. 18): obtain restriction of processing where applicable conditions are met;
- Data portability (Art. 20): receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller;
- Objection (Art. 21): object at any time to processing based on legitimate interest;
- Withdrawal of consent: withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal;
- Lodge a complaint: lodge a complaint with the competent supervisory authority.
To exercise your rights, send a request to privacy@overcore.it. Overcore will respond within 30 days, extendable by a further 60 days in cases of particular complexity.
10. Children
The Service is intended exclusively for adults (18 years or older) or the legal entity they represent. Overcore does not knowingly collect personal data from children under 16. If we become aware of unauthorized processing of children's data, such data will be immediately deleted.
11. Data Security
Overcore implements appropriate technical and organizational measures to ensure a level of security commensurate with the risk, including:
- Encryption of data in transit (TLS 1.2/1.3) and at rest;
- Access control based on the principle of least privilege;
- Multi-factor authentication for administrative access;
- Regular backups with integrity verification;
- Continuous monitoring and anomaly detection;
- Documented data breach management procedures, with notification to the supervisory authority within 72 hours and to data subjects without undue delay, where required by Arts. 33–34 GDPR.
12. Changes to this Policy
Overcore reserves the right to update this Privacy Policy at any time. Changes will be published on this page with an updated date. For material changes, registered users will be notified by email at least 30 days in advance. Continued use of the Service after the changes take effect constitutes acceptance.
13. Contact and Complaints
For any questions regarding the processing of personal data or to exercise your rights:
OVERCORE SRL — Data Controller
Via dei Mutilati e Invalidi del Lavoro 108F, 63100 Ascoli Piceno (AP), Italia
Privacy Email: privacy@overcore.it
General Email: info@overcore.it
You also have the right to lodge a complaint with your local supervisory authority. For users in Italy: Garante per la Protezione dei Dati Personali — garanteprivacy.it. For the full list of EU supervisory authorities: edpb.europa.eu.