Privacy Policy
Status: December 2025
The protection of your personal data is important to us. Below, we transparently inform you about how personal data is processed on the visit-sanremo.com platform. This privacy policy applies to all offers, functions, and services of visit-sanremo.com.
This privacy policy complies with the requirements of the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR), and applicable Italian regulations.
1. Data Controller
Sami International GmbH
Aarauerstrasse 35
5102 Rupperswil
Switzerland
UID: CHE-356.811.845
Email: datenschutz@visit-sanremo.com
Sami International GmbH is the data controller within the meaning of the FADP and the GDPR for the processing of personal data on visit-sanremo.com.
2. EU Representative pursuant to Art. 27 GDPR
As personal data of individuals in the European Union is processed, an EU representative has been appointed:
Giuseppe Simonetta
Strada Comunale Poggi 15
18015 Pompeiana
Italy
Email: eurep@visit-sanremo.com
The EU representative serves as a contact point for data subjects and supervisory authorities within the European Union.
3. Platform model and allocation of roles
visit-sanremo.com is a platform on which hosts (e.g. holiday apartment landlords, hotel operators, service providers, and shop owners) can publish listings and offer services.
- Sami International GmbH is responsible for operating the platform, technical infrastructure, payment processing, marketing, tracking, and central guest registration.
- Hosts act, within the scope of their accommodation business, as independent data controllers for the guest data transmitted to them and its lawful processing.
Personal data of guests is forwarded to the respective host in the context of a booking or registration, provided this is necessary for contract performance or compliance with legal obligations.
4. Categories of processed personal data
4.1 Guests
- First and last name
- Address
- Email address
- Phone number
- Date of birth
- Nationality
- Type of identification and ID number
- Copy of an official identification document (if required)
- Stay and booking data
- IP address
4.2 Children
Where required (e.g. for tourist tax purposes), data of children may be processed:
- First and last name
- Address
- Date of birth
- Identification data
Children cannot create their own user accounts. Data entry is carried out exclusively by legal guardians.
4.3 Hosts and business partners
- Name / company name
- Address
- Email address
- Phone number
- Contractual and billing data
4.4 Payment and transaction data
- Payment status
- Transaction ID
- Amount and currency
- Billing data
Credit card or bank account details are not stored on visit-sanremo.com systems.
5. Purposes and legal bases of processing
Personal data is processed for the following purposes:
- Processing bookings, listings, subscriptions, and services
(Art. 6(1)(b) GDPR – performance of a contract) - Guest registration and handling of the tassa di soggiorno
(Art. 6(1)(c) GDPR – legal obligation) - Transmission of legally required data to the Comune di Sanremo
(Art. 6(1)(c) GDPR) - User accounts and support
(Art. 6(1)(b) and (f) GDPR) - Marketing, advertising, and analytics (only with consent)
(Art. 6(1)(a) GDPR) - Fraud prevention and IT security
(Art. 6(1)(f) GDPR)
6. Authorities and statutory disclosures
Depending on the type of accommodation and legal obligations, personal data of guests is transmitted to the Comune di Sanremo, in particular for guest registration and tourist tax processing.
Reporting is carried out:
- by Sami International GmbH for its own holiday apartments;
- by the respective host for their accommodation.
7. Identification data
Identification data and copies of identification documents are collected exclusively for statutory guest registration and internal security purposes.
- Storage is encrypted and access-restricted.
- Access is limited to authorised administrators and, where required, the respective host.
- Copies of identification documents are deleted no later than 6 months after check-out.
Transmission by email is intended only as a temporary solution. A secure upload solution is planned.
8. Payment processing
Payment processing is carried out via external payment service providers:
- Stripe
- PayPal
The respective privacy policies of the providers apply. visit-sanremo.com has no access to credit card or bank account data.
9. Marketing, tracking, and analytics
visit-sanremo.com uses the following services, subject to consent:
- Google Analytics (GA4)
- Google Tag Manager (client- and server-side)
- Google Ads (including conversion tracking, enhanced conversions, remarketing)
- Meta Pixel including Conversion API
- LinkedIn Insight Tag
- TikTok Pixel
- Mouseflow
Integration takes place exclusively after consent via a consent management tool (Cookiebot).
10. Transfers to third countries
The use of certain services may result in transfers of personal data to third countries (in particular the USA).
Such transfers are based on:
- EU Standard Contractual Clauses (SCC)
- additional technical and organisational measures
A residual risk (e.g. due to access by foreign authorities) cannot be completely excluded despite these measures.
11. Hosting and technical service providers
- Hosting and email: Green.ch, Switzerland
- Cloudflare Turnstile (spam and abuse protection)
- Google Maps API
- External fonts (Google Fonts)
12. Data retention period
- Accounting and invoicing data: 10 years
- Booking and account data: purpose-bound, max. 10 years
- Copies of identification documents: max. 6 months after stay
- Marketing data: max. 5 years or until consent is withdrawn
- Server and security logs: according to hosting provider requirements
13. Rights of data subjects
Data subjects have the right to:
- access
- rectification
- erasure
- restriction of processing
- data portability
- withdrawal of granted consent
Requests must be sent to datenschutz@visit-sanremo.com. Processing usually takes place within one month.
14. Data security
Appropriate technical and organisational measures (TOMs) are implemented, in particular:
- HTTPS/TLS encryption
- Access restrictions and role-based models
- Backups
- Planned two-factor authentication for administrators
15. Amendments
This privacy policy may be amended if legal or technical changes require it. The current version is available on visit-sanremo.com.
