Legal documents

Privacy policy.

How we process the personal data of those who visit the site and book an excursion, pursuant to Regulation (EU) 2016/679 (GDPR).

Courtesy translation. In the event of any discrepancy, the Italian version of this document prevails.

1. Data controller

The data controller is Michele Egitto — Mikimar, VAT no. IT04231520927. For any request regarding personal data you can write to info@mikimar.it.

2. Types of data processed

We process only the data needed to book and carry out the excursion:

  • Booking data: first name, surname, email, phone, number of participants and any special requests entered in the form.
  • Payment data: handled entirely by Stripe. The card number never passes through our systems and is not stored by us; we only keep the transaction reference, needed for confirmations and refunds.
  • Marketing consent: optional, given via a dedicated checkbox during booking. Without consent we send no promotional communications.
  • Technical browsing data: IP address and logs needed for the security and operation of the service.

Providing the booking data is mandatory: without it the booking cannot be completed.

3. Purposes and legal bases

PurposeLegal basis
Managing the booking and payment, including service emails (confirmation with boarding QR, changes, cancellations, refunds) and replies to requests sent through the sitePerformance of the contract (Art. 6.1.b GDPR)
Recovery of incomplete bookings: sending a single email reminder to those who started a booking without completing paymentLegitimate interest (Art. 6.1.f GDPR), with the right to object immediately
Prevention of payment fraud and service securityLegitimate interest (Art. 6.1.f GDPR)
Compliance with legal, tax and accounting obligationsLegal obligation (Art. 6.1.c GDPR)
Promotional communicationsConsent (Art. 6.1.a GDPR), optional and revocable at any time
Visit statistics (Google Analytics 4); advertising campaigns planned, not yet activeConsent (Art. 6.1.a GDPR), given via the banner — see cookie policy

4. Recovery of incomplete bookings

If you start a booking by entering your details in the form but do not complete payment, the booking remains recorded as incomplete and the seat is released. In these cases we may send you a single reminder by email, about an hour later, with a link to complete the booking if you wish.

It is a service message, not promotional, relating to the operation you started yourself: the legal basis is our legitimate interest in recovering incomplete bookings (Art. 6.1.f GDPR). You can object at any time — by replying to the email or writing to info@mikimar.it — and you will receive no further reminders. The data of incomplete bookings is kept only for the time needed for this purpose and then deleted or anonymised (see «Retention periods»), unless you complete the booking.

5. Service providers and non-EU transfers

To run the site we rely on the following providers, who process data on our behalf as data processors:

ProviderServiceData involved
Stripe Payments Europe LtdOnline paymentsPayment data, email
ResendSending service emailsEmail, content of communications
Neon Inc. (database in an EU datacenter, Frankfurt)Bookings databaseBooking data
Vercel Inc.Website hostingTechnical browsing data
Google Ireland Ltd (Google Analytics 4)Visit statistics; advertising campaigns plannedBrowsing data, only with prior consent

Some providers are based in the United States: any data transfers take place on the basis of the safeguards provided under Chapter V of the GDPR (standard contractual clauses and, where applicable, the EU-US Data Privacy Framework). Booking data resides on servers within the European Union (Frankfurt).

6. Retention periods

  • Booking data and accounting documents: 10 years, in compliance with tax and civil-law obligations.
  • Incomplete bookings (abandoned carts): the data of those who start a booking without completing it is kept for 30 days from the start and then deleted or anonymised, unless the booking is completed (in which case the 10-year term applies).
  • Marketing consent: until consent is withdrawn or deletion is requested.
  • Technical logs: for the time strictly needed for security purposes, indicatively no more than 12 months.

7. Rights of the data subject

At any time you can exercise the rights provided under Arts. 15-22 of the GDPR: access to your data, rectification, erasure, restriction of processing, portability, objection and withdrawal of the consents given (withdrawal does not affect the lawfulness of processing carried out beforehand). To exercise them, simply write to info@mikimar.it; we will reply within 30 days.

If you believe the processing breaches the law, you have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).

8. Updates to this notice

This notice may be updated, for example when new services are activated or regulations change: the version published on this page prevails. Last updated: June 2026.