Legal

Privacy Policy

This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). Mamma Mia Holidays is a brand of Suite Service S.r.l., the Data Controller.

Last updated: 23 September 2026

1. Data Controller and contacts

Mamma Mia Holidays is a commercial brand of SUITE SERVICE S.R.L. The Data Controller is SUITE SERVICE S.R.L.

  • Registered office: Via Michelangelo Buonarroti 37-39, 40069 Zola Predosa (BO), Italy
  • VAT number and Tax Code: 03652651203
  • Bologna Companies Register – REA: BO-536352
  • Share capital: €30,000.00 fully paid
  • Certified email: suiteservice@pec.it
  • Privacy email: info@mammamiaholidays.com
  • Website: www.mammamiaholidays.com
  • Legal representative: Sole Director

2. Categories of personal data

We process browsing data; data voluntarily provided through contact forms, email or WhatsApp; booking data such as name, contact details, dates, number of guests and special requests; and identity-document details required by law for hosted guests.

Payment data are processed by the relevant payment providers. We do not store complete payment-card data.

3. Purposes, legal bases and retention

PurposeLegal basisRetention
Handling information requestsPre-contractual measures, Art. 6(1)(b) GDPRFor the time required to reply and, unless a relationship follows, no longer than 24 months
Booking and stay managementPerformance of a contract, Art. 6(1)(b) GDPRFor the relationship and thereafter for applicable statutory periods
Reporting guest details to the Police through Alloggiati Web (Art. 109 TULPS)Legal obligation, Art. 6(1)(c) GDPRFor the period required by public-security law
Bologna tourist tax administrationLegal obligation, Art. 6(1)(c) GDPRFor municipal and tax-law retention periods
Tourism-flow statistics to Emilia-Romagna Region and ISTATLegal obligation, Art. 6(1)(c) GDPR; data are aggregated where requiredFor the period required by applicable law
Tax and accounting complianceLegal obligation, Art. 6(1)(c) GDPR10 years, subject to longer periods for disputes or audits
Website security and fraud preventionController’s legitimate interest, Art. 6(1)(f) GDPROnly as long as necessary and normally no longer than 12 months
Newsletter and marketing communications, only if activated on the websiteConsent, Art. 6(1)(a) GDPR, withdrawable at any timeUntil consent is withdrawn or the service ends
Statistics and marketing through cookies, if activatedConsent, Art. 6(1)(a) GDPRUntil withdrawal and according to the Cookie Policy

4. Processing methods and security

Data are processed with electronic and, where necessary, paper-based tools by authorised personnel. We apply appropriate technical and organisational measures to protect confidentiality, integrity, availability and resilience, and periodically review access permissions and safeguards.

5. Recipients and external processors

Data may be shared, within the limits required for each purpose, with the channel manager and booking engine Lodgify; online travel agencies such as Booking.com and Airbnb when a booking is made through them, acting under their own privacy roles; payment providers; website hosting and infrastructure providers; Google Workspace for email; tax and professional advisers; and public authorities. We do not sell personal data.

6. Transfers outside the EEA

Some suppliers, including Google, may process data in the United States or other countries outside the European Economic Area. Where applicable, transfers rely on an adequacy decision, including the EU–US Data Privacy Framework for certified recipients, or on the European Commission’s Standard Contractual Clauses and additional safeguards.

7. Retention periods

The applicable periods are set out in the table above. Once they expire, data are deleted or irreversibly anonymised, unless further retention is necessary to establish, exercise or defend legal claims.

PurposeLegal basisRetention
Handling information requestsPre-contractual measures, Art. 6(1)(b) GDPRFor the time required to reply and, unless a relationship follows, no longer than 24 months
Booking and stay managementPerformance of a contract, Art. 6(1)(b) GDPRFor the relationship and thereafter for applicable statutory periods
Reporting guest details to the Police through Alloggiati Web (Art. 109 TULPS)Legal obligation, Art. 6(1)(c) GDPRFor the period required by public-security law
Bologna tourist tax administrationLegal obligation, Art. 6(1)(c) GDPRFor municipal and tax-law retention periods
Tourism-flow statistics to Emilia-Romagna Region and ISTATLegal obligation, Art. 6(1)(c) GDPR; data are aggregated where requiredFor the period required by applicable law
Tax and accounting complianceLegal obligation, Art. 6(1)(c) GDPR10 years, subject to longer periods for disputes or audits
Website security and fraud preventionController’s legitimate interest, Art. 6(1)(f) GDPROnly as long as necessary and normally no longer than 12 months
Newsletter and marketing communications, only if activated on the websiteConsent, Art. 6(1)(a) GDPR, withdrawable at any timeUntil consent is withdrawn or the service ends
Statistics and marketing through cookies, if activatedConsent, Art. 6(1)(a) GDPRUntil withdrawal and according to the Cookie Policy

8. Your rights

Under Articles 15–22 GDPR, you may request access, rectification, erasure, restriction, portability and object to processing. You may withdraw consent at any time without affecting prior processing. Requests may be sent to info@mammamiaholidays.com or suiteservice@pec.it. You may lodge a complaint with the Italian Data Protection Authority at www.garanteprivacy.it.

9. Minors

The booking service is reserved for adults. Data relating to minors may be provided by a parent, guardian or accompanying adult only where required to manage the stay and comply with the law.

10. Changes to this notice

This notice may be updated following legal, organisational or service changes. The current version is published on this page. Last updated: 23 September 2026.