Privacy policy
Last updated: July 2026
Who processes your data
The data controller is Edoardo Biasini, private host of Nolo75 (NoLo, Milan). For any question or request about your data, write to info (at) nolo75.it .
What we collect, why, and on what legal basis
We only collect the data we need to handle your stay and meet legal obligations. Here is what we use and why, activity by activity.
| Activity | Data | Legal basis |
|---|---|---|
| Booking request and management | Name, contact details (email, phone), dates, party composition, any notes | Pre-contractual steps and performance of the contract (Art. 6.1.b GDPR) |
| Payment | Order details; card data is handled directly by Stripe (we neither see nor store it) | Contract (Art. 6.1.b) and legitimate interest in fraud prevention (Art. 6.1.f) |
| Identity verification | Document and selfie, with a biometric face comparison to confirm identity (special category, Art. 9) | Explicit consent given by starting the check (Art. 9.2.a), supporting the security the host requires and the legal registration |
| Guest registration (Italian police / Alloggiati Web) | For each guest: name, place and date of birth, citizenship, residence, document type and number; flag for minors | Legal obligation (Art. 6.1.c GDPR; Art. 109 TULPS, R.D. 773/1931) |
| Tourist-flow statistical reporting (Ross1000 — Lombardy Region/ISTAT) | Stay details (dates, place of origin, group composition) | Legal obligation (Art. 6.1.c GDPR; national and regional statistics legislation) |
| Direct channel / returning-guest offers | Email and, if you provide it, name | Consent (Art. 6.1.a), withdrawable at any time |
| Site security and analytics | IP address for anti-bot protection; aggregated, cookieless traffic statistics | Legitimate interest in the security and proper functioning of the site (Art. 6.1.f) |
We don't use your data for advertising profiling and we don't sell it. We share it only with the providers listed below, strictly as needed.
Identity verification
For direct bookings the host requires identity verification as a security measure against fraud and to support the legal registration. Verification is carried out through Stripe Identity and involves uploading a document and a selfie, with a biometric face comparison to confirm the document belongs to you. As this is special-category data (Art. 9 GDPR), the check relies on your explicit consent, which you give by starting the procedure. We don't keep the images on our servers: they are processed by Stripe for verification only. We do, however, keep the resulting identity and document data (name, surname, date of birth, document type and number, country of issue) and reuse it to pre-fill your guest registration, so you don't have to re-enter it (see the next section). Prefer not to use biometric verification? Write to us and we will agree on a different way to verify your identity.
Guest registration (local police)
Before check-in, by legal obligation (Art. 109 of the Italian TULPS, R.D. 773/1931) we must report the details of all guests — including minors — to the public security authorities, through the Italian State Police Alloggiati Web portal. For this reason, a few days before arrival we ask you to fill in the required details for each guest (name, place and date of birth, citizenship, residence, document type and number).
Any photos of the document and the selfie are used only to verify identity: they are kept in a private, access-restricted store (United Kingdom, a country with an EU adequacy decision) and automatically deleted 30 days after check-out. The personal details needed for the report to the authorities are delivered to the host by email (EU channel) and kept for the period required by law.
On your first access to the apartment we carry out a real-time identity check via the video intercom, as required by Italian public-security rules. The video call is live only: it is never recorded or stored. By legal obligation we also report stay data to the regional statistical system (Ross1000 — Lombardy Region/ISTAT), for tourist-flow monitoring purposes.
Children's data
We process children's data only as part of the mandatory guest registration, and it is provided to us by the adult who makes the booking. The same safeguards as for other guests apply: use limited to the legal obligation, and no photos kept on our servers.
Providers and recipients
We rely on trusted providers, each for a specific purpose:
| Provider | Purpose | Where |
|---|---|---|
| Stripe (incl. Stripe Identity) | Payments and identity verification | USA (Standard Contractual Clauses / Data Privacy Framework) |
| Cloudflare | Site hosting, anti-bot protection, cookieless analytics, caching | EU/USA (SCCs / DPF) |
| Google Ads | Advertising-campaign measurement, only while a campaign is running: receives the click identifier for confirmed bookings, never your name or email | EU/USA (SCCs / Data Privacy Framework) |
| Brevo | Sending direct-channel emails and delivering registration data to the host | European Union (France) |
| Telegram | Anonymised notification to the host (group composition, no identifying data or documents) | Outside the EU |
| n8n and booking store (Payload) | Receiving requests and storing bookings, registrations and documents | United Kingdom (EU adequacy) |
Transfers outside the European Union
Stripe and Cloudflare process data in the USA (Standard Contractual Clauses / EU–US Data Privacy Framework). Registration data and documents are stored in the United Kingdom, a country covered by the EU adequacy decision (a lawful transfer, protection deemed equivalent). The notification to the host on Telegram (a service outside the EU) is anonymised and contains no identifying data.
Cookies and analytics
This website uses no profiling cookies. To understand how many people visit the site we use Cloudflare Web Analytics, an aggregated, cookieless system that doesn't track individual visitors across websites. The only technical cookie we set remembers the language you choose.
When a Google Ads campaign is running, to measure which ads lead to a booking we use the click identifier Google appends to the address (the so-called gclid): we keep it only for the duration of your session in your browser (it is not a cookie) and we share it with Google only for confirmed bookings, never linked to your name, email or any other data. We build no advertising profiles, and you can browse and book normally regardless of this measurement.
How long we keep your data
- Unconfirmed requests: a few months, then deleted.
- Confirmed bookings: for the duration of the stay and for the periods required by tax and accounting obligations.
- Guest registration data: for the period required by public-security law, then deleted.
- Document and selfie photos: in a private store (United Kingdom, EU adequacy), automatically deleted 30 days after check-out.
- Direct-channel subscription: as long as your consent stands (until you unsubscribe, one click in every email).
Your rights
Under the GDPR (EU Regulation 2016/679) you have the right to access your data, correct it, request its deletion or restriction, object to processing, request portability and withdraw consent at any time (without affecting the lawfulness of processing already carried out). To exercise them, write to info (at) nolo75.it : we reply within 30 days. If you believe your data is being handled improperly, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).