Privacy policy.
How we process the personal data of those who visit the site and book an excursion, pursuant to Regulation (EU) 2016/679 (GDPR).
1. Data controller
The data controller is Michele Egitto — Mikimar, VAT no. IT04231520927. For any request regarding personal data you can write to info@mikimar.it.
2. Types of data processed
We process only the data needed to book and carry out the excursion:
- Booking data: first name, surname, email, phone, number of participants and any special requests entered in the form.
- Payment data: handled entirely by Stripe. The card number never passes through our systems and is not stored by us; we only keep the transaction reference, needed for confirmations and refunds.
- Marketing consent: optional, given via a dedicated checkbox during booking. Without consent we send no promotional communications.
- Technical browsing data: IP address and logs needed for the security and operation of the service.
Providing the booking data is mandatory: without it the booking cannot be completed.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Managing the booking and payment, including service emails (confirmation with boarding QR, changes, cancellations, refunds) and replies to requests sent through the site | Performance of the contract (Art. 6.1.b GDPR) |
| Recovery of incomplete bookings: sending a single email reminder to those who started a booking without completing payment | Legitimate interest (Art. 6.1.f GDPR), with the right to object immediately |
| Prevention of payment fraud and service security | Legitimate interest (Art. 6.1.f GDPR) |
| Compliance with legal, tax and accounting obligations | Legal obligation (Art. 6.1.c GDPR) |
| Promotional communications | Consent (Art. 6.1.a GDPR), optional and revocable at any time |
| Visit statistics (Google Analytics 4); advertising campaigns planned, not yet active | Consent (Art. 6.1.a GDPR), given via the banner — see cookie policy |
4. Recovery of incomplete bookings
If you start a booking by entering your details in the form but do not complete payment, the booking remains recorded as incomplete and the seat is released. In these cases we may send you a single reminder by email, about an hour later, with a link to complete the booking if you wish.
It is a service message, not promotional, relating to the operation you started yourself: the legal basis is our legitimate interest in recovering incomplete bookings (Art. 6.1.f GDPR). You can object at any time — by replying to the email or writing to info@mikimar.it — and you will receive no further reminders. The data of incomplete bookings is kept only for the time needed for this purpose and then deleted or anonymised (see «Retention periods»), unless you complete the booking.
5. Service providers and non-EU transfers
To run the site we rely on the following providers, who process data on our behalf as data processors:
| Provider | Service | Data involved |
|---|---|---|
| Stripe Payments Europe Ltd | Online payments | Payment data, email |
| Resend | Sending service emails | Email, content of communications |
| Neon Inc. (database in an EU datacenter, Frankfurt) | Bookings database | Booking data |
| Vercel Inc. | Website hosting | Technical browsing data |
| Google Ireland Ltd (Google Analytics 4) | Visit statistics; advertising campaigns planned | Browsing data, only with prior consent |
Some providers are based in the United States: any data transfers take place on the basis of the safeguards provided under Chapter V of the GDPR (standard contractual clauses and, where applicable, the EU-US Data Privacy Framework). Booking data resides on servers within the European Union (Frankfurt).
6. Retention periods
- Booking data and accounting documents: 10 years, in compliance with tax and civil-law obligations.
- Incomplete bookings (abandoned carts): the data of those who start a booking without completing it is kept for 30 days from the start and then deleted or anonymised, unless the booking is completed (in which case the 10-year term applies).
- Marketing consent: until consent is withdrawn or deletion is requested.
- Technical logs: for the time strictly needed for security purposes, indicatively no more than 12 months.
7. Rights of the data subject
At any time you can exercise the rights provided under Arts. 15-22 of the GDPR: access to your data, rectification, erasure, restriction of processing, portability, objection and withdrawal of the consents given (withdrawal does not affect the lawfulness of processing carried out beforehand). To exercise them, simply write to info@mikimar.it; we will reply within 30 days.
If you believe the processing breaches the law, you have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
8. Updates to this notice
This notice may be updated, for example when new services are activated or regulations change: the version published on this page prevails. Last updated: June 2026.