Last updated 9 May 2026 · Applies to services offered through this website · Italian and EU data-protection framework.

Privacy policy

1. Data controller

The controller is Kyma Charter — Palau (SS), Italy — reachable via the "About" / "Contacts" section of this website.

No Data Protection Officer has been appointed where not legally required; privacy requests should use the same contact channels.

2. Categories of data

Identity and contact details (name, email, phone), booking data (dates, service, party size, free-text notes), payment metadata processed by Stripe (transaction IDs and status; card numbers are not stored by Kyma Charter).

Technical logs (IP address, browser type, timestamps), session cookies and security records.

Any additional content you voluntarily submit through contact forms.

3. Purposes, legal bases and retention

Managing bookings and enquiries — performance of a contract / pre-contractual steps (Art. 6(1)(b) GDPR); retention for the time needed to deliver the service and meet tax/accounting duties (often up to 10 years where invoices apply).

Operational communications about your booking — contract performance / legitimate interests, balanced against your rights.

Legal claims and compliance — legal obligation / legitimate interest (Art. 6(1)(c)/(f) GDPR) within statutory deadlines.

Aggregated traffic analytics — only if enabled and only after consent where required (Art. 6(1)(a) GDPR).

4. Security measures

Processing uses electronic means with encryption where appropriate, access controls for administrators and periodic security updates, applying data minimisation.

5. Recipients

Stripe and payment-related subprocessors; transactional email providers (e.g. Resend); hosting/cloud infrastructure providers;

Advisers or IT contractors bound by confidentiality where strictly necessary; public authorities when legally compelled.

6. Transfers outside the EU

Some vendors may process data outside the EU using Standard Contractual Clauses or other GDPR-compliant safeguards. You may request further information from the controller.

7. Your rights

Under Articles 15–22 GDPR you may request access, rectification, erasure, restriction, portability (where applicable) and object within legal limits.

EU users may lodge a complaint with their supervisory authority (in Italy: Garante per la protezione dei dati personali).

8. Cookies

Strictly necessary cookies support security, checkout flows and language preferences.

Analytics tools load only after banner confirmation where legally required.

Browser settings can block cookies but may limit functionality.

9. Children

The site is not aimed at minors purchasing services on their own; anyone providing children's data warrants parental authority.

10. Changes

This notice may be updated; material changes will be reflected by revising the publication date in the header strip.

Company identifiers (legal name, VAT, registered office), specific cancellation policies and tariffs may be set out elsewhere on the site or in pre-contractual communications. A tailored review by your legal adviser remains advisable before large-scale commercial rollout.