Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

1. Data Controller

ALBERGO RISTORANTE IL SOLE SRL Via Bartolomeo Colleoni 1 – 24129 Bergamo (BG), Italy VAT no. and Tax code: 02323610168 – EU VAT: IT02323610168 – REA: 280333 Phone: +39 035 218 238 Email: info@ilsolebergamo.com Certified email (PEC): ristoranteilsole@legalmail.it

2. Types of data processed

Browsing data. The IT systems and software used to operate this website collect, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols (IP addresses, browser type and operating system, time of the request, pages visited, server response code, etc.). This data is used only to ensure the proper functioning and security of the website and is kept for the time strictly necessary, except where needed to investigate computer crimes. Data voluntarily provided by the user. Sending emails, messages or calling the contact details shown on the website involves the collection of the sender's contact data (name, email, phone) and of the information contained in the communication. Booking and stay data. Personal, contact, payment and stay-related data provided to book rooms or tables and for guest registration upon arrival. Cookies and tracking tools. For information on cookies, please see our Cookie Policy.

3. Purposes and legal bases of processing

  • Replying to requests for information and quotes sent by email or phone – legal basis: pre-contractual measures taken at the data subject's request (Art. 6.1.b GDPR).
  • Managing bookings of rooms and restaurant and providing hotel and catering services – legal basis: performance of a contract (Art. 6.1.b GDPR).
  • Compliance with legal obligations, including the communication of guests' personal details to the Public Security Authority (Art. 109 of the Italian Consolidated Law on Public Security – T.U.L.P.S.), tax and accounting obligations and city tax requirements – legal basis: legal obligation (Art. 6.1.c GDPR).
  • Sending the newsletter with offers, events and news about the Hotel, upon subscription via the dedicated form – legal basis: consent (Art. 6.1.a GDPR), which can be withdrawn at any time via the unsubscribe link in every email or by writing to the Controller.
  • Website security and operation and protection of the Controller's rights in legal proceedings – legal basis: legitimate interest (Art. 6.1.f GDPR).

4. Nature of the provision of data

Providing data for contact, booking and legal compliance purposes is necessary: failure to provide it makes it impossible to handle the request or to provide the service. Providing data for the newsletter is optional.

5. Processing methods

Data is processed using electronic and paper-based tools by authorised and trained staff, with appropriate technical and organisational measures to ensure its security and confidentiality. No automated decision-making or profiling is carried out.

6. Recipients of the data

Data may be disclosed, to the extent necessary, to:
  • technical service providers acting as Data Processors, including the website hosting provider (Aruba S.p.A., Italy) and the online booking system provider (Octorate), which users access via the "Book" button and which processes data according to its own privacy policy;
  • tax advisors, accountants, banks and payment institutions;
  • Public Security Authorities, public bodies and competent authorities where required by law.
Data is not disseminated.

7. Third-party services on the website

  • Google Maps (Google Ireland Ltd.): interactive map that may collect browsing data and set cookies; it is loaded only after consent is given via the cookie banner. Google Privacy Policy.
  • Google Fonts (Google Ireland Ltd.): font display service, which involves transmitting the IP address to Google.
  • Links to social networks (Facebook, Instagram, TripAdvisor): simple links that do not transmit any data until the user clicks on them; once on the social network, the privacy policy of the relevant provider applies.

8. Transfer of data outside the EU

Some providers (e.g. Google) may process data outside the European Economic Area. In such cases the transfer takes place on the basis of an adequacy decision of the European Commission (EU-US Data Privacy Framework) or of Standard Contractual Clauses.

9. Retention period

  • Information requests: for the time needed to handle the request and in any case no longer than 12 months, unless a contract is concluded.
  • Booking and stay data: for the duration of the relationship and thereafter for the periods required by tax and civil law (10 years).
  • Newsletter: until consent is withdrawn.
  • Browsing data: for the time strictly necessary for website security.

10. Rights of the data subject

Data subjects may at any time exercise the rights under Articles 15-22 GDPR: access, rectification, erasure, restriction of processing, data portability, objection to processing and withdrawal of consent (without affecting the lawfulness of processing based on consent before its withdrawal). Requests should be sent to info@ilsolebergamo.com or by certified email to ristoranteilsole@legalmail.it. Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali – www.garanteprivacy.it) or with the supervisory authority of their country of residence.

11. Changes to this policy

The Controller reserves the right to amend this policy at any time. Please check this page periodically. Last updated: 29 September 2026

Subscribe to our newsletter

Stay up-to-date on our exclusive offers, special events, and Hotel Il Sole news. 
A quick and easy way to receive everything that makes your next stay in Bergamo unique, directly in your inbox.

Albergo Ristorante il Sole

Via Colleoni 1, 
24129 Bergamo (BG)
+39 035 218 238
info@ilsolebergamo.com
VAT no. 02323610168