Privacy Policy

Version 1.1 - Last updated: June 27, 2026

This privacy policy details how Local Way S.r.l. processes personal data collected when using the website, web-app, mobile application, booking interfaces, and associated platform solutions (collectively, the 'Platform'). The integrated Cookies Policy provides added specifics regarding analytical storage systems.

Data Controller Details

Company Legal Identity: Local Way S.r.l.
Registered Corporate Address: Via Libero Attardi 85, 92020 Santo Stefano Quisquina (AG), Italy
VAT Number / Tax ID: 03109950844
REA Entry Reference: AG-227566
Subscribed Share Capital: Euro 13,333.00 i.v.
Direct Data Protection Channels: [email protected] (Recommended subject: 'Privacy') - PEC: [email protected]
01

Data Controller and Scope of Application

The designated data controller is Local Way S.r.l. ('Local Way', 'we'), matching the identity structures summarized above. This disclosure applies to all visual Platform visitors, registered Local Wayers, standard data inquiries, Experience participants, and, where contextually required, corporate Local Advisors and their associated legal representatives. A specialized Data Protection Officer (DPO) has not been appointed; should an expert be commissioned, update entries will publish immediately on this node.

02

Privacy Roles within the Platform

Local Way oversees the operational core of the Platform, collecting identifiers required to drive discovery functions, booking actions, system assistance workflows, payment validation routines, protective security models, and foundational business ledger logs. To coordinate a finalized experience, the relevant Local Advisor receives the strict structural data elements necessary to clear, frame, and safely deliver the selected event. Concerning independent post-execution logistics, the Local Advisor functions independently as an autonomous data controller. External settlement clearing hubs execute validation services subject to their isolated operational policies.

03

Categories and Sources of Data

We collect and organize the following personal data categories:

  • Identity and connection info: Given name, surname, email address, telephone contact, system language state, home territory, and master profile parameters.
  • Reservation files: Targeted local experience choices, scheduled timestamps, participant counts, organizational discussions, custom preferences, voucher balances, and historical orders.
  • Payment and transaction logs: Final transaction amounts, step-by-step payment status tracking, technical routing IDs, refund files, and incident claims. Complete card credentials are never saved on Local Way servers.
  • Content inputs and support records: Voluntary messaging histories, platform reviews, uploaded images, feedback elements, and standard service desk requests.
  • Technical logs and tracking analytics: Active IP configurations, server telemetry, terminal structures, browser variants, system tracking identifiers, navigation paths, threat flags, and related cookies.
  • Experience-specific special parameters: Optional accessibility mandates, documented ingredient allergy vectors, or explicit medical constraints. Users must only supply these special attributes when strictly required; these items are managed with heightened safeguards matching targeted regulatory criteria.

We normally fetch data objects straight from you. However, our layers may accept transactional details from active Local Advisors, handling networks, associated integration partners, or public registries to protect platform integrity, satisfy statutory obligations, or combat fraudulent entities.

04

Purposes, Legal Bases and Retention Limits

Processing PurposeLegal Basis Framework (GDPR)Indicative Retention Timeline
Profile administration, reservation handling, voucher coordination, and structural service communications.Contract performance execution or mandatory pre-contractual steps (Art. 6.1.b GDPR).Active relationship timeframe. Extended up to 10 years after termination to satisfy civil law requirements, auditing practices, or legal defense needs.
Payment settlement routing, refund actions, systemic infrastructure security, fraud prevention matrices, and chargeback disputes.Contract execution, legal compliance steps, and corporate legitimate interests in system protection (Art. 6.1.b, c, f GDPR).Transactional profiles up to 10 years. Infrastructural security server files are normally purged within 12 months, unless required for ongoing forensic investigations.
Corporate tax compliance, financial reporting rules, DAC7 platform disclosure directives, and official authority directives.Compliance with binding legal obligations (Art. 6.1.c GDPR).Preserved strictly matching localized guidelines; standard 10-year lock applies to core bookkeeping files and matching fiscal documents.
Infrastructural performance improvement, aggregated telemetry models, platform abuse prevention, and operational quality reviews.Legitimate tracking interest (Art. 6.1.f GDPR). Explicit user consent parameters apply to optional, non-technical tracking files.Limited to the period required for active analysis. Deeply anonymized data pools or fully aggregated datasets are stored indefinitely.
Brand newsletter items, curated experience offers, localized marketing communication tracks, and targeted interest profiling.Freely granted, granular explicit user consent (Art. 6.1.a GDPR).Maintained until consent is revoked. Maximum lifespan parameters limit marketing tracks to 24 months and profile modeling to 12 months unless actively renewed.
Formal customer complaints, ongoing courtroom actions, and organizational rights protection.Legitimate interest to pursue legal remedies or defend statutory assertions (Art. 6.1.f, 9.2.f GDPR).Kept throughout the full lifecycle of active legal disputes until official statutory limitation thresholds lapse completely.
05

Nature of Data Provision

Submitting specific data blocks to support user onboarding, checkout routines, payment clearances, or legal obligations is strictly mandatory; choosing to withhold these parameters will disrupt Platform operations and block bookings. Conversely, parameters required to drive marketing newsletters, non-technical analytics cookies, or voluntary community reviews are entirely optional and do not limit core platform access.

06

Recipients and Categories of Data Processors

  • Local Advisors: Restricting data access exclusively to the specific parameters needed to manage and execute your chosen tour.
  • Authorized Financial Providers: Specialized entities including Stripe or additional processors revealed explicitly inside checkout views.
  • IT and Infrastructure Vendors: Outsourced partners handling system hosting, secure cloud nodes, automated notifications, technical support desks, data metrics, and application maintenance under formal processor agreements.
  • Professional Consultants: External accounting firms, corporate legal counsels, banking consultants, insurers, and risk investigators assessing claims or fraud indicators.
  • Judicial and Public Authorities: Tax bureaus, compliance bodies, and judicial courts when strictly required by enforceable legal statutes or to shield our operational rights.
07

Transfers Toward Third Countries

Specific computing operations or payment verification tasks may trigger technical processing pipelines based outside the boundaries of the European Economic Area (EEA). To safeguard these transfers, Local Way incorporates standard validation models recognized under the GDPR, applying European Commission adequacy decisions, official Standard Contractual Clauses (SCCs), or equivalent binding legal instruments. Specific validation documentation can be requested through our primary privacy contact channel.

08

Automated Decisions, System Security and Search Ranking

The Platform utilizes background algorithmic routines to filter out payment fraud threats, verify user account states, balance search index rankings, suggest contextually relevant experiences, and streamline reservations. These automated scripts do not generate definitive legal classifications or heavily compromise user choices under Art. 22 GDPR. If such logic is introduced, targeted disclosures detailing the processing safeguards will deploy. We maintain strict physical and electronic defenses, including role-based administrative access filters, infrastructure isolation, action logging, system backups, incident management protocols, and data minimization routines.

09

Data Concerning Minors

The Platform is exclusively designed for legal adults who are fully capable of executing binding contractual engagements. Any personal information detailing minor children joining an experience must be supplied strictly by a verified parent or legal guardian, restricted to elements needed to complete the booking.

10

Rights of Data Subjects and Complaint Channels

Subject to local statutory limits, users can demand access to personal data, request correction of files, command absolute deletion, impose execution restrictions, request digital data portability, challenge actions based on legitimate interests, or cancel active consent options. To invoke these protections, submit an email to [email protected] using the subject header 'Privacy'. Official complaints can also be filed directly with the Italian Data Protection Authority (Garante per la protezione dei dati personali). We fulfill standard requests within one calendar month, barring complex extensions authorized under GDPR rules.

11

DAC7 and Mandatory Tax Reporting

As a platform operator, Local Way faces binding tax compliance mandates requiring the tracking, verification, safe storage, and reporting of data regarding registered Local Advisors, transacted fees, booking volumes, tax registration codes, and required operational files under the DAC7 regulatory reporting framework. Supplying this financial data is a statutory requirement; failing to cooperate with reporting requests requires Local Way to lock profile tools or disable payout functions completely.

12

Policy Updates and References

We periodically alter this documentation to stay aligned with technological updates, internal workflow changes, or regulatory updates. The active, authoritative version remains continuously pinned to this Platform layout node, marked with an explicit update timestamp. If alterations substantially change paths that rely on visitor consent, renewed clearance flows will trigger. Core regulatory touchstones include EU Regulation 2016/679 ('GDPR'), Italian national privacy laws, and the digital tracking regulations enacted by the Italian Garante authority on June 10, 2021.