Privacy Policy

Last updated: April 11, 2026

This Privacy Policy describes how Orosei Servizi e Turismo SRLS, with registered office at Via Santa Veronica 24, 08028 Orosei (NU), Italy, VAT No. 01445870916, e-mail ostsardinia@gmail.com, telephone +39 346 539 3009 (hereinafter, the “Data Controller”), processes the personal data of users who visit the website, request information, book intermediary services or purchase services sold directly through the website.

This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”).

  1. Data Controller

The Data Controller is:

Orosei Servizi e Turismo SRLS

Via Santa Veronica 24

08028 Orosei (NU), Italy

VAT No. 01445870916

E-mail: ostsardinia@gmail.com

Telephone: +39 346 539 3009

For any request relating to the processing of personal data, users may contact the Data Controller using the contact details provided above.

  1. Categories of personal data processed

Depending on the case, the Data Controller may process the following categories of personal data:

  • identification data, such as first name and last name;
  • contact details, such as e-mail address and telephone number;
  • data relating to the request submitted by the user;
  • data necessary for booking excursions, activities or other intermediary services;
  • data necessary for the purchase of services sold directly through the website, including the tourist card;
  • payment and transaction data, to the extent necessary to manage the purchase;
  • technical browsing data, IP addresses, access logs and data collected through cookies and similar technologies;
  • any additional data voluntarily provided by the user through website forms, by e-mail or through other contact channels.
  1. Purposes of processing and legal bases

Personal data are processed for the following purposes.

a) Management of contact and information requests

To respond to requests for information, quotes, availability or assistance submitted through forms, e-mail, telephone or other contact channels.

Legal basis: performance of pre-contractual measures requested by the data subject.

b) Management of bookings for intermediary services

To collect, manage and transmit booking requests relating to excursions, activities or services provided by third-party operators, as well as to provide commercial and organizational assistance connected to the booking.

Legal basis: performance of pre-contractual measures and/or of a contract requested by the data subject.

c) Management of the direct sale of services offered by the Data Controller

To manage the online purchase of services sold directly by the Data Controller, including the tourist card, as well as the related administrative, accounting, tax and operational requirements.

Legal basis: performance of a contract to which the data subject is party and compliance with related legal obligations.

d) Compliance with legal obligations

To comply with obligations provided for by applicable legislation, including administrative, tax and accounting obligations, and requests from authorities.

Legal basis: compliance with legal obligations to which the Data Controller is subject.

e) Protection of the Data Controller’s rights

To establish, exercise or defend a right of the Data Controller in judicial or extrajudicial proceedings, as well as to prevent abuse, fraud or unlawful use of the website or services.

Legal basis: legitimate interest of the Data Controller in protecting its business and its rights.

f) Direct marketing

Subject to the user’s specific consent, to send newsletters, offers, promotional initiatives, commercial communications or updates relating to the Data Controller’s services.

Legal basis: consent of the data subject. The user may withdraw consent at any time.

g) Cookies, analytics and tracking technologies

To ensure the proper functioning of the website, analyze traffic, measure performance, store preferences and, where applicable, provide content or communications consistent with the preferences expressed by the user.

Legal basis: for technical cookies, legitimate interest and/or the need to provide the requested service; for non-technical cookies or trackers, the user’s consent where required by applicable law.

  1. Nature of the provision of data

The provision of data for pre-contractual, contractual and legal purposes is necessary. Failure to provide such data may prevent the Data Controller from responding to user requests, managing a booking, completing a purchase or complying with legal obligations.

The provision of data for marketing purposes is optional. Failure to provide consent does not affect the possibility of using the website or purchasing/booking the available services.

  1. Processing methods

Processing is carried out using paper, IT and telematic tools, with organizational methods strictly related to the purposes indicated above and with appropriate measures designed to protect personal data against unauthorized access, loss, destruction, unlawful disclosure or improper use.

  1. Intermediary services and communication of data to third-party operators

For intermediary services published on the website, the Data Controller may communicate the data necessary to manage the booking to third-party operators who materially provide the service requested by the user.

In such cases, the communication concerns only the data necessary for organizing, confirming and carrying out the booked activity. Third-party operators may process the data received according to their own privacy policies, where applicable.

  1. Recipients of personal data

Personal data may be disclosed, within the limits strictly necessary, to:

  • internal staff authorized by the Data Controller;
  • administrative, tax, accounting, IT and legal consultants;
  • technical service providers connected to the functioning of the website;
  • hosting, maintenance, security and WordPress website management providers;
  • payment system and transaction management providers;
  • third-party operators who provide the intermediary services booked by the user;
  • platforms or providers that enable the sending of commercial communications, where activated and subject to consent;
  • authorities or public bodies, where disclosure is required by law or by a legitimate order.

Such parties may act, depending on the case, as independent data controllers or as data processors appointed by the Data Controller.

  1. Transfer of data to third countries

If the website or certain technical services used by the Data Controller involve transfers of data to countries located outside the European Economic Area, such transfers will take place in compliance with the safeguards provided for by the GDPR, including, where applicable, adequacy decisions or standard contractual clauses.

  1. Retention periods

Personal data are retained for the time strictly necessary to pursue the purposes for which they are collected and, subsequently, for the time required by legal obligations or necessary to protect the rights of the Data Controller.

In particular:

  • data relating to contact requests are retained for the time necessary to manage the request and for a reasonable subsequent period connected to any developments in the negotiation;
  • data relating to bookings and purchases are retained for the duration of the contractual relationship and for the subsequent periods provided for by applicable administrative, tax and accounting legislation;
  • data processed for marketing purposes are retained until consent is withdrawn or until the user objects;
  • data collected through cookies and tracking technologies are retained according to the provisions of the Cookie Policy and the settings of the consent management platform.
  1. Cookies and other tracking technologies

The website uses cookies and other tracking technologies. Detailed information about the cookies used, their purposes, categories, retention periods and how to give, deny or change consent is contained in the website’s Cookie Policy.

Cookie preferences are managed through the dedicated consent platform installed on the website. Italian rules require adequate information, the possibility of granular choice and prior consent for non-technical cookies and trackers.

  1. Rights of the data subject

In the cases provided for by applicable legislation, the data subject may exercise the rights recognized by Articles 15-22 of the GDPR, including:

  • right of access to personal data;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to object;
  • right to data portability, where applicable;
  • right to withdraw consent at any time;
  • right to lodge a complaint with the competent supervisory authority.

To exercise their rights, users may write to: ostsardinia@gmail.com.

  1. Complaint to the supervisory authority

Users who believe that the processing of their data is carried out in violation of applicable legislation may lodge a complaint with the Italian Data Protection Authority, according to the procedures provided by the competent authority.

  1. Changes to this Privacy Policy

The Data Controller reserves the right to update or modify this Privacy Policy at any time, including in consideration of regulatory, organizational or technical changes. The updated version will be published on this page with an indication of the date of the latest update.

Nara Nara
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.