This is the notice on the processing of personal data of people who visit triestebusiness.it and of people who write to us or call us (articles 13 and 14 of Regulation (EU) 2016/679, the “GDPR”). It is written to be read: it says what we do with your data, and what we do not do.
Who processes the data
The controller is TriesteVillas srl, registered office at Via Milano 5, 34132 Trieste, Italy; TriesteBusiness is one of its brands. For any question about your data you can write to richieste@triestevillas.com, or to the certified email address milou@pec.emailc.it. The company's details are set out in full in the legal notice.
Which data, and which not
We process the data you give us when you write or call: a contact (email or telephone), your name if you choose to give it, the language in which you would like a reply, and what you tell us about your enquiry. A contact is enough for us to reply: to begin with, your name is optional.
We do not ask for the address or the name of the property, the names of other people, your assets, identity documents or health data. If you write them anyway, we use them only to reply to you and, if they are not needed, we remove them from the enquiry.
From the website we process the technical data that every visit leaves on the server (IP address, date and time, page requested) to run it and protect it; statistical data only if you have chosen “Accept” for statistics cookies (the cookies page says which they are).
For what purpose, and on what basis
- Replying to your enquiry and doing what you ask of us before any agency agreement: the basis is article 6(1)(b) of the GDPR.
- Complying with legal obligations, first of all anti-money-laundering customer due diligence when an agency agreement or a transaction is reached (Legislative Decree 231/2007): article 6(1)(c).
- Keeping the site secure and stopping spam and abuse: our legitimate interest, article 6(1)(f).
- Counting visits with Google Analytics, only with your consent (article 6(1)(a), and article 122 of the Italian Personal Data Protection Code). You can withdraw it whenever you wish, without consequences.
- Sending you promotional communications: only with a separate, optional consent, which we do not currently ask for. So we send none.
What the agency's system does with your enquiry
Enquiries arrive in the agency's system, where a person at the agency reads and follows them up. We do not take decisions based solely on automated processing (article 22 of the GDPR): whoever replies to you is a person.
In short, what we do and what we do not
- Your enquiry stays in our system and does not leave the agency.
- Enquiries are recorded in the agency's system so that we can follow them up; an artificial intelligence service may read them to record and route them.
- We keep an enquiry that leads nowhere for 24 months after the last contact; then we delete it or anonymise it.
- When we call you back from our system, the call may be recorded and transcribed: recording and text stay in the record of your enquiry.
Who we entrust them to
Your data are seen by the people at the agency who follow your enquiry, and by the suppliers who process them on our behalf under a contract that binds them (article 28 of the GDPR): the website host, the provider of the database behind the agency's system, email and telephony, and the artificial intelligence services the system uses to record and route enquiries. Google receives statistical data only if you have given your consent.
A notary, a surveyor or another party to a transaction receives your data only if they are needed for that transaction and you know about it. Authorities receive them when the law requires it. We do not sell data, and we do not pass them on for advertising.
The list of suppliers, with the safeguards of each, is available on request from richieste@triestevillas.com.
Outside the European Union
Some suppliers are based in the United States or process data there. The transfer takes place on the basis of an adequacy decision of the European Commission, such as the one on the EU-US Data Privacy Framework, or of the standard contractual clauses approved by the Commission (articles 45 and 46 of the GDPR). A copy of the safeguards is available on request from the same address.
For how long
- Enquiries that lead nowhere: for the period stated above, in the box “In short, what we do and what we do not”; then we delete them or make them anonymous.
- Anti-money-laundering due diligence records: 10D.LGS. 231/2007 years, as the law requires (Legislative Decree 231/2007, art. 31).
- Accounting records and documents of an agency agreement: for the period set by article 2220 of the Civil Code.
- Technical data from visits: for as long as the security of the site requires.
Your rights
You can ask us to see your data, to correct them, to erase them, to restrict their use, to receive them in a readable format, or to stop using them (articles 15-22 of the GDPR); and you can withdraw a consent at any time, without affecting what was done before. Simply write to richieste@triestevillas.com or to the certified email address.
If you believe we are processing your data incorrectly, you can lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (article 77 of the GDPR, garanteprivacy.it).
If anything changes
If we change the way we process data, we change this page first, and the journal at the foot of the page says when and what.
Sources (6)
- 1. Regulation (EU) 2016/679 (GDPR), arts 6, 13, 15-22, 28, 45, 46, 77 · read on 7 October 2026
- 2. Legislative Decree no. 196 of 30 June 2003, Personal Data Protection Code, art. 122 · read on 7 October 2026
- 3. Legislative Decree no. 231 of 21 November 2007, arts 17-31 · read on 7 October 2026
- 4. Italian Civil Code, art. 2220 · read on 7 October 2026
- 5. European Commission, Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework · read on 7 October 2026
- 6. Garante per la protezione dei dati personali, official website and how to lodge a complaint · read on 7 October 2026
The figures on this page
- 10 · D.LGS. 231/2007 — D.Lgs. 21 novembre 2007, n. 231, art. 31, c. 3: documenti, dati e informazioni dell'adeguata verifica si conservano per dieci anni dalla cessazione del rapporto o dall'esecuzione dell'operazione · read on 7 October 2026 · open the source
Revision log
- Version 1.0 — First English edition, written for English-language readers from the verified Italian edition (C-EN).Fingerprint of the text (SHA-256):
edda7ae2f225e7cc
The revision log records every version with the fingerprint of its text. If the text changes, the fingerprint changes and a new entry is needed: a review holds only for the text it read.