Privacy Policy
pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
Version 2.0 — in force since 01 August 2026
1. Data Controller
Culturae Heritage Services srls (hereinafter also the "Controller"), with registered office at Via dei Banchi 6, 50123 Firenze, Italy, VAT No. IT07519170489, Tax Code 07519170489, REA FI-709102.
Privacy contact: [email protected]
The Controller has not appointed a Data Protection Officer (DPO) as it does not fall within the mandatory cases set out in Article 37 GDPR (the Controller does not carry out large-scale processing of special categories of data, nor regular and systematic large-scale monitoring). For any request regarding the protection of personal data, please write to the address indicated above.
2. Scope of Application
This privacy notice describes how the Controller processes the personal data of users (hereinafter "User" or "Data Subject") who visit and interact with the website hotairballoon.travel (hereinafter the "Website") and the other websites owned by the Controller.
This notice applies to all processing carried out through the Website, including statistical analysis services (analytics), newsletter subscription, security and abuse-prevention systems, and — where a contact form is made available — the handling of requests submitted through it. Non-essential technologies are activated exclusively with the User's prior consent, expressed through the consent management tool integrated into the Website.
The Website is editorial and informational in nature. The Controller is not a tour operator, travel agency, or travel intermediary under applicable law. For more details on the nature of the service, please refer to the Terms and Conditions of Use.
3. Types of Data Processed
3.1 Browsing and technical data
During normal browsing, the computer systems and software procedures used to operate the Website automatically acquire certain data, the transmission of which is implicit in the use of Internet communication protocols. Such data includes: IP address, browser type and version, operating system, language, requested URLs, date and time of requests, HTTP method, server response code, and security events.
3.2 Data voluntarily provided by the User
Personal data that the User voluntarily provides may include:
- email address (newsletter subscription);
- where a contact form is made available on the Website: first name, email address, and the free-text content of the message;
- any other information the User voluntarily chooses to provide.
The Website does not offer user registration and does not operate a members' area. No account credentials are collected.
3.3 Data collected through cookies and similar technologies
The Website uses a limited number of cookies and equivalent technologies (including browser local storage) to store the User's consent preferences and — subject to consent — to measure the use of the Website. For full details, please refer to the Cookie Policy.
3.4 Consent records
When the User expresses a choice through the consent management tool, the Controller records evidence of that choice (proof of consent) pursuant to Article 7(1) GDPR. The record contains: a randomly generated identifier stored on the User's device, the categories accepted or refused, the version of this notice in force at that time, the page and language of the interaction, the browser user agent, and a non-reversible cryptographic hash (SHA-256 with a secret salt) of the IP address. The IP address itself is not stored.
3.5 Data relating to tours and experiences
The Website does not sell tours or experiences and does not process bookings. When the User chooses to book, they are directed to the website of an independent commercial partner, where the transaction takes place entirely outside the Controller's systems.
The Controller does not collect, process, or store payment data of any kind (card numbers, bank details, security codes). The Controller receives from its partners only aggregate, non-personal data on clicks and commissions.
3.6 Newsletter data
If the User subscribes to the newsletter, the Controller collects the User's email address, the website and language of subscription, and the date of subscription. Subscription is optional and occurs exclusively with the User's explicit prior consent.
Alongside these data, and for the sole purpose of demonstrating that consent was validly obtained (Art. 7(1) GDPR), the Controller records the page from which the subscription was made, the IP address of the request and the text of the consent notice shown at that moment. These data are kept for the same period as the subscription.
Withdrawal: the User may withdraw newsletter consent at any time, with the same ease with which it was given, by writing to the Controller at the address indicated in section 1 — and, once the Controller begins sending communications, through the unsubscribe link included in each of them. Withdrawal results in the erasure of the email address from the list and does not affect the lawfulness of processing carried out before it. The "Manage cookie preferences" control governs cookies and similar technologies, and does not affect a newsletter subscription: they are two separate consents.
3.7 Mandatory or optional nature of data provision
The provision of browsing data is necessary for the technical operation of the Website. The provision of an email address for the newsletter or a contact request is optional; without it, the Controller cannot send the newsletter or reply to the request.
Consent to analytics technologies is entirely optional, and refusing it does not in any way affect browsing of the Website or access to its content.
4. Purposes, Legal Bases, and Retention Periods
The Controller processes personal data for the purposes described below. Where indicated, processing occurs exclusively with the User's prior express consent.
The retention periods indicated are reasonable maximums and may be reduced in application of the storage limitation principle (Article 5(1)(e) GDPR).
Where processing is based on the Controller's legitimate interest (Art. 6(1)(f) GDPR), the Controller has carried out a balancing assessment (Legitimate Interest Assessment — LIA) to ensure that its legitimate interest does not override the rights and fundamental freedoms of the Data Subjects. The User may request a copy of such assessment by writing to the contacts indicated in Section 1.
| Purpose | Data | Legal Basis | Retention | Notes |
|---|---|---|---|---|
| Website operation, technical functioning, security, fraud and abuse prevention | Browsing data, technical logs, IP | Legitimate interest (Art. 6(1)(f) GDPR) — LIA conducted | Up to 12 months | Extendable in case of investigations or litigation |
| Handling requests submitted via contact form or email | Data provided by the User | Pre-contractual measures (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)) — LIA conducted | Up to 24 months from last interaction | Subject to legal obligations or pending litigation |
| Recording and retaining proof of cookie consent | Consent identifier, categories chosen, hashed IP, user agent, page, language | Legal obligation (Art. 6(1)(c)) in conjunction with Art. 7(1) GDPR | Up to 24 months from the choice | Required to demonstrate that consent was validly obtained |
| Newsletter — with consent only | Email, website and language of subscription | Consent (Art. 6(1)(a) GDPR) | Until consent is withdrawn | List cleanup after 24 months of inactivity |
| Statistical analysis and audience measurement (Google Analytics 4) — with consent only | Cookie identifiers, usage events, technical data | Consent (Art. 6(1)(a) GDPR) | Per Cookie Policy | Revocable at any time |
| Legal and tax obligations, litigation management | Data necessary for legal obligations and defence | Legal obligation (Art. 6(1)(c)) and/or legitimate interest (Art. 6(1)(f)) | Up to 10 years or applicable limitation period |
The Website does not use advertising, remarketing, or profiling technologies. Should such tools be introduced in the future, this notice and the Cookie Policy will be updated beforehand and consent will be requested separately.
5. Consent Management
The Website uses a first-party consent management tool, compatible with Google Consent Mode v2, which allows the User to:
- accept, reject, or select individual categories of non-essential technologies;
- change their preferences at any time through the "Manage cookie preferences" control available in the footer of every page;
- be informed that analytics technologies are activated only after valid consent has been obtained.
Prior blocking: no non-essential technology is activated on the User's device before the User has expressed consent. In the absence of consent, only strictly necessary technologies are active.
Withdrawal of consent: the User may withdraw consent at any time with the same ease with which it was given, through the "Manage cookie preferences" control, without affecting the lawfulness of processing based on consent given prior to withdrawal (Art. 7(3) GDPR).
Duration of consent: a choice expressed by the User remains valid for 6 months, after which the User is asked again. This interval follows the more cautious of the European supervisory authorities' recommendations.
6. Data Recipients
Personal data may be disclosed to the following parties, acting as Data Processors (Art. 28 GDPR), independent Controllers, or authorised persons.
Infrastructure and hosting providers
- Hetzner Online GmbH — dedicated servers and application hosting, datacentre in Germany (EEA). Data Processor pursuant to Art. 28 GDPR.
- Cloudflare, Inc. / Cloudflare Germany GmbH — content delivery network, DNS, protection against attacks and abuse, static site hosting, and object storage. Data Processor pursuant to Art. 28 GDPR.
Communication providers
- Amazon Web Services EMEA SARL — Amazon SES and SNS for newsletter and service emails, region eu-west-1 (Ireland, EEA). Data Processor pursuant to Art. 28 GDPR.
Analytics providers (activated with consent only)
- Google Ireland Ltd / Google LLC — Google Tag Manager and Google Analytics 4.
Commercial partners (independent Controllers)
Depending on the content published on each website, the Website may link to the following partners for the booking of tours and experiences: Viator Inc. (Tripadvisor Group), GetYourGuide Deutschland GmbH, Tiqets International B.V., Civitatis, Headout Inc.
When the User follows such a link and leaves the Website, the processing of their personal data is governed exclusively by the privacy policy of the partner concerned. The Controller has no access to the data the User provides on the partner's website.
Other recipients
- Legal, tax, and commercial advisors, as Processors or authorised persons.
- Competent authorities, when required by law.
The Controller does not sell Users' personal data.
7. Data Transfers Outside the EEA
Some providers, particularly groups headquartered in the United States, may involve the transfer of personal data to countries outside the European Economic Area (EEA). In such cases, the Controller adopts adequate safeguards pursuant to Articles 44 et seq. GDPR, including:
- Standard Contractual Clauses (SCCs) of the European Commission (Art. 46(2)(c) GDPR) and, where necessary, Transfer Impact Assessments (TIA) and supplementary measures in accordance with EDPB Recommendations 01/2020;
- adequacy decisions of the European Commission, where available, including the EU-U.S. Data Privacy Framework for certified entities;
- additional technical and organisational measures (data minimisation, pseudonymisation, encryption in transit and at rest, access segregation).
The providers potentially subject to extra-EEA transfers are: Google LLC, Cloudflare, Inc., and Amazon Web Services, Inc. Hosting of the application and of the newsletter service takes place within the EEA.
The User may request information on the specific safeguards adopted and a copy of the applicable SCCs by writing to the contacts indicated in Section 1.
8. Data Subject Rights
The User may exercise at any time the rights provided by Articles 15–22 GDPR:
- right of access to personal data (Art. 15);
- right to rectification and update (Art. 16);
- right to erasure, or "right to be forgotten", where applicable (Art. 17);
- right to restriction of processing (Art. 18);
- right to data portability, where applicable (Art. 20);
- right to object, in particular to processing based on legitimate interest (Art. 21); in case of objection, the Controller shall refrain from further processing the data unless it demonstrates compelling legitimate grounds;
- right not to be subject to decisions based solely on automated processing, including profiling (Art. 22);
- right to withdraw consent at any time, with the same ease with which it was given, without affecting the lawfulness of processing carried out prior to withdrawal (Art. 7(3)).
To exercise your rights, please write to: [email protected]
The Controller will respond as a rule within 1 month of the request, a period that may be extended up to 3 months in cases of particular complexity or high volume of requests (Art. 12 GDPR). In the event of an extension, the User will be informed within 1 month. The exercise of rights is free of charge, unless requests are manifestly unfounded or excessive (Art. 12(5) GDPR).
8.1 Automated decision-making
The Controller does not carry out any fully automated decision-making process, including profiling, that produces legal effects concerning the User or that similarly significantly affects them (Art. 22 GDPR). The analytics tools used by the Website serve aggregate statistical purposes only and do not result in automated individual decisions.
8.2 Complaint to the Supervisory Authority
The User has the right to lodge a complaint with the competent supervisory authority. For Italy:
Garante per la Protezione dei Dati Personali Piazza Venezia, 11 — 00187 Rome (RM), Italy Website: www.garanteprivacy.it PEC: [email protected] Phone: (+39) 06 696771
Users resident in another Member State may lodge a complaint with their own national supervisory authority.
9. Editorial Use of Automated Translation and Content Tools
The Controller uses automated translation services and generative artificial intelligence tools in the production of the Website's editorial content (descriptions of tours, guides, articles). These tools process editorial texts only: no personal data of Users is transmitted to them, and they play no part in the processing described in this notice.
10. Minors
The Website is not intended for individuals under the age of 16 (threshold established by Art. 2-quinquies of Legislative Decree 196/2003 for Italy). The Controller does not intend to knowingly collect personal data from minors. If a parent or guardian believes that data of a minor has been collected without the necessary consent, they may contact the Controller at the details indicated in Section 1 to request prompt deletion.
11. Security Measures
The Controller adopts appropriate technical and organisational measures to protect personal data from unauthorised access, loss, destruction, or alteration (Art. 32 GDPR), including: encrypted communications (HTTPS/TLS), authenticated access with least privilege, protection of administrative interfaces behind an additional authentication layer, one-way hashing of IP addresses in consent records, periodic backups, security updates, access monitoring, and security incident management procedures.
12. Changes to This Privacy Policy
The Controller reserves the right to update this Privacy Policy at any time. Each version carries a version number and an entry-into-force date, shown at the top of this page. Material changes will be communicated by notice on the Website and, where the change concerns the categories of technologies subject to consent, by requesting consent again.
Previous versions of this notice are retained by the Controller and may be requested by writing to the contacts indicated in Section 1.
13. Applicable Law and Jurisdiction
This privacy policy is governed by Regulation (EU) 2016/679 (GDPR), Directive 2002/58/EC (ePrivacy), Italian personal data protection legislation (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018), as well as by applicable Provisions and Guidelines of the Garante per la Protezione dei Dati Personali and of the EDPB.
For any dispute relating to the interpretation or application of this policy, the Court of Florence shall have jurisdiction, unless otherwise provided by mandatory consumer protection provisions.