Legal
Privacy Policy
How Trip in Art collects, uses and protects your personal data — under EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
Version 2.0 — last updated 28 July 2026. This version replaces the one dated 1 June 2025 and describes the current website, including the contact and quote forms, the newsletter, the AI assistant and the booking system.
Related documents: Cookies Policy · Terms & Conditions. You can change your cookie choices at any time from Cookie preferences.
1. Who is responsible for your data
The Data Controller is TRIP IN ART S.R.L.S., registered office in Via Enrico Accinni 63, 00195 Rome, Italy — VAT no. IT 14868831000 — Travel Agency Licence no. 180723.
E-mail: info@tripinartitaly.com · PEC: tripinartsrls@legalmail.it · Tel.: (+39) 349 173 7225.
The website, its forms, its newsletter and its AI assistant are built and operated on our behalf by Fenice Digital (fenice.digital), which acts as an external Data Processor under Art. 28 GDPR and is bound by a written data processing agreement. Fenice Digital is not the owner of your data and cannot use it for its own purposes. Its full company details are available on its website; for any request about your data, write to us at the addresses above — we remain your single point of contact.
We have not appointed a Data Protection Officer (DPO), as we are not required to do so under Art. 37 GDPR. All privacy requests are handled directly at the addresses above.
2. What this policy covers
This policy covers the personal data we process through the website tripinartitaly.com and through the direct channels connected to it (e-mail, WhatsApp, phone).
It does not cover what happens on third-party platforms. If you book one of our experiences on GetYourGuide, Viator, Tripadvisor or another marketplace, that platform processes your data as an independent controller under its own privacy policy, and passes us only the information we need to deliver the experience you booked.
3. What we collect, why, and for how long
We only collect data you give us, plus the minimum technical data needed to keep the site working and safe. We do not buy contact lists and we do not build advertising profiles of individuals on this website.
| Where it comes from | Data | Why (purpose) | Legal basis | How long |
|---|---|---|---|---|
| Contact form (Contacts) | Name, e-mail, message, language, and the page/channel you came from | To answer your enquiry | Art. 6(1)(b) — steps taken at your request before entering into a contract | 6 months from the last exchange |
| B2B quote form (agencies & tour operators) | Name, company, e-mail, phone, group size, service, travel dates, notes | To prepare and send you a quote | Art. 6(1)(b) — pre-contractual steps | 6 months if no contract follows; otherwise as per the row on bookings |
| Newsletter and free guide download | E-mail, first name (if given), language, sign-up date and source | To send you travel content and offers from Trip in Art | Art. 6(1)(a) — your consent, ticked explicitly at sign-up | Until you unsubscribe. Unsubscribing stops the emails immediately; we then keep only the minimum record needed to remember your choice and never write to you again |
| AI assistant (see §5) | The messages you type, the language detected, a random session identifier, and any contact details you choose to type into the chat | To answer questions about our experiences and to improve the assistant’s answers | Art. 6(1)(f) — our legitimate interest in providing website assistance | 6 months from the last message in the conversation |
| Bookings through the booking system (see §6) | Name, e-mail, phone, participants, date and time, any booking questions, payment status | To provide the experience you purchased and meet our accounting and tax duties | Art. 6(1)(b) — performance of the contract · Art. 6(1)(c) — legal obligation | 11 years after the end of the business relationship (Italian accounting and tax law) |
| Anti-abuse protection on the forms and on the assistant | A keyed hash of your IP address — computed with a secret key held only by us, so the address cannot be recovered from it — plus the timestamps of your recent requests. The address itself is never written to disk | To stop spam and automated abuse of our forms and of the chat | Art. 6(1)(f) — our legitimate interest in keeping the site usable | 1 hour (rolling window) |
| Analytics and marketing cookies | Pages viewed, approximate area, device and browser, campaign the visit came from | Aggregated statistics and campaign measurement | Art. 6(1)(a) — your consent, given through the cookie banner | Up to 13 months — see the Cookies Policy |
| Server logs of our hosting provider | IP address, date and time, page requested, user agent | Security, diagnostics and abuse investigation | Art. 6(1)(f) — our legitimate interest in the security of the service | Short technical retention by the provider; not used to identify individual visitors |
Providing your data is never mandatory in the abstract: you are free not to fill in a form. However, without the data marked as required we cannot answer you, send you a quote, or complete a booking.
4. Forms: what happens after you press send
When you submit the contact form or the B2B quote form, your message is delivered to info@tripinartitaly.com and you receive an automatic acknowledgement. Your e-mail address and name are also stored in our contact database so that we can follow up.
You are subscribed to the newsletter only if you tick the newsletter box. Sending a message or requesting a quote does not sign you up for marketing e-mails.
Every form is protected by our own anti-abuse layer. It uses a hidden field that only automated bots fill in, a signed one-time token that expires, a per-address submission limit, and simple content checks. It does not profile you and does not use third-party CAPTCHAs. Your IP address is never stored: to count requests we keep only a hash of it computed with a secret key, which cannot be turned back into the address by anyone who does not hold that key.
5. The AI assistant — what it is and what it records
The chat assistant on this website is an artificial intelligence system, not a human being. We say so in the chat itself, in line with Art. 50 of EU Regulation 2024/1689 (AI Act). If you want to speak to a person, the assistant gives you our WhatsApp number, our phone number and our e-mail at any time.
- What it sees. The text you type and the language it detects. It has no access to your name, your bookings or your payment data, and it does not read cookies from other websites.
- Where the text goes. Your messages are sent to Anthropic, PBC (United States), which supplies the language model that produces the answer, and are stored on our website’s server so the conversation continues if you move to another page. They go nowhere else. Our team receives a notice on an internal channel saying that a conversation is happening — the session identifier, the language and how long your message was — but never its content.
- How long. Conversations are kept for 6 months from the last message, then deleted automatically.
- Training. Your conversations are not used to train AI models for third parties.
- Please do not type payment card numbers, identity document numbers, health information or other sensitive data into the chat. If you do, ask us to delete the conversation and we will.
The assistant can make mistakes. Prices, availability and access conditions are always the ones shown on the experience page and in your booking confirmation.
6. Bookings and payments
Bookings and payments on this website are handled by the booking platform Bokun (Bokun ehf., an Iceland-based company of the Tripadvisor group), embedded in our experience pages. When you book:
- the booking details you enter (name, e-mail, phone, participants, date, any questions we need to ask) are processed by Bokun on our behalf and are visible to us in our reservation system;
- your card details are handled by the payment provider inside the Bokun checkout and never reach this website: Trip in Art does not see, receive or store full card numbers;
- the payment appears on your statement as Trip In Art.
If you booked through an online travel agency, that platform handles your payment under its own terms and shares with us only what is needed to run the experience.
7. Cookies and measurement
Cookies and similar technologies are described in full in our Cookies Policy. In short: cookies that are not strictly necessary are blocked until you choose. We use Google Consent Mode v2, so analytics and advertising tags stay denied until you accept them in the banner. You can change or withdraw your choice at any time from Cookie preferences, in the footer of every page.
8. Who else processes your data
Your data may be accessible to our staff and collaborators, to professionals who assist us (accountants, lawyers, insurers) as autonomous controllers, and to the technical providers below, appointed as processors or sub-processors with the safeguards indicated.
| Provider | Role | Location | Safeguard for data leaving the EEA |
|---|---|---|---|
| Fenice Digital — fenice.digital | Website, forms, newsletter and AI assistant operated on our behalf | Italy (EU) | Not applicable — EU |
| Hostinger International Ltd. | Web hosting of the site and of the form endpoints | Lithuania (EU) | Not applicable — EU |
| Bokun ehf. (Tripadvisor group) | Booking engine and checkout | Iceland (EEA) | Not applicable — EEA |
| Sendinblue SAS (Brevo) | Transactional e-mail, newsletter and contact database | France (EU) | Not applicable — EU |
| Anthropic, PBC | Language model behind the AI assistant | United States | EU Standard Contractual Clauses |
| Discord Netherlands B.V. / Discord Inc. | Internal channel that receives service notices about the assistant — session identifier, language, message length. No message content | EU / United States | EU Standard Contractual Clauses |
| Google Ireland Ltd. / Google LLC | Analytics and tag management, only after your consent | Ireland (EU) / United States | EU-US Data Privacy Framework · Standard Contractual Clauses |
We do not sell your personal data, and we do not share it with third parties for their own marketing.
9. Transfers outside the European Economic Area
Some of the providers listed above are established in the United States. Those transfers take place on the basis of the Standard Contractual Clauses adopted by the European Commission under Art. 46(2)(c) GDPR and, where applicable, of the EU-US Data Privacy Framework adequacy decision (Commission Decision 2023/1795). You may ask us for a copy of the safeguards in place.
10. Security
We apply technical and organisational measures proportionate to the risk, as required by Art. 32 GDPR: encrypted connections (HTTPS) on every page and every form, access to management tools restricted to named accounts, credentials kept outside the published website, anti-abuse protection on public endpoints, and regular backups. No system is completely secure, but we work to keep the risk low and we will notify you and the supervisory authority if a breach is likely to affect your rights.
11. Automated decisions and profiling
We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. The AI assistant answers questions; it does not decide whether you can book, at what price, or on what conditions.
12. Children
This website is aimed at adults. We do not knowingly collect data from children under 14 without the consent of a person holding parental responsibility (Art. 8 GDPR and Art. 2-quinquies of Legislative Decree 196/2003). Minors on our tours are booked and accompanied by an adult.
13. Your rights
As a data subject you have the right to:
- obtain confirmation that we process your data and receive a copy of it (Art. 15 — right of access);
- have inaccurate data corrected and incomplete data completed (Art. 16 — rectification);
- obtain erasure in the cases provided for by the Regulation (Art. 17 — right to be forgotten);
- obtain restriction of processing (Art. 18);
- be informed of the recipients of any rectification, erasure or restriction (Art. 19);
- receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller (Art. 20 — portability);
- object to processing based on our legitimate interest, and at any time to direct marketing (Art. 21);
- withdraw a consent you have given at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3)). For the newsletter, one click on the unsubscribe link in any e-mail is enough.
Exercising these rights is free of charge. Write to info@tripinartitaly.com, or by registered letter to TRIP IN ART S.R.L.S., Via Enrico Accinni 63, 00195 Rome, Italy. We reply within one month, extendable by two further months for complex requests (Art. 12(3) GDPR).
You also have the right to lodge a complaint with the Italian supervisory authority — Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome, Italy, tel. (+39) 06 696771, garanteprivacy.it — or with the authority of the EU country where you live or work.
14. Changes to this policy
We update this policy when the services, the tools or the applicable rules change. The version and the date at the top of this page always tell you which text is in force. Substantial changes affecting consent-based processing are also brought to your attention through the cookie banner or by e-mail.