Privacy Policy
Last updated: September 2026
This Privacy Policy explains how personal data is collected and used when you visit wolftrails.it or contact WolfTrails to enquire about or book a guided tour. It is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended).
1. Data Controller
The Data Controller is:
Roberto Maselli, sole proprietor, trading as WolfTrails
Registered office: Via Ferrovieri 29/b, 12017 Robilante (CN), Italy
VAT number (Partita IVA): 01561570084
Email: info@wolftrails.it | Phone: +39 349 7221433
No Data Protection Officer (DPO) has been appointed, as this is not required for the Controller’s activity.
2. What data we collect, why, and on what legal basis
2.1 Enquiries and contact requests
Data: name, email address, phone number (if provided), and the content of your message (e.g. dates, group size, route of interest) sent through the contact form, by email or by phone/messaging.
Purpose: replying to your request and preparing a tour proposal.
Legal basis: steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
Retention: for the time needed to handle your request and, if no booking follows, up to 12 months afterwards, unless you ask us to delete it earlier.
The contact form is provided by the WordPress plugin SureForms, which runs on our own website; submissions are stored in our website database and forwarded to our email account.
2.2 Bookings and payments
Data: name, contact details, billing details, and the names of tour participants.
Purpose: performing the tour contract, organising logistics, accommodation and transfers, invoicing and receiving payments (by bank transfer or PayPal).
Legal basis: performance of a contract (Art. 6(1)(b)); legal obligations, including tax and accounting (Art. 6(1)(c)).
Retention: accounting and tax records are kept for 10 years as required by Italian law; other booking data for 24 months after the tour, unless a longer period is needed to defend legal claims.
We do not ask for health data through the website. If you choose to tell us about something that matters for your safety on the tour, we will use it only for that purpose.
2.3 Newsletter and marketing communications
Data: name and email address.
Purpose: sending news, tour dates and offers by email. Newsletters are sent manually by the Controller.
Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time by replying to any of our emails or writing to info@wolftrails.it.
Retention: until you withdraw consent.
2.4 Website usage data
The website and its hosting infrastructure automatically process technical data such as IP address, browser type, pages requested, and date/time of access (server logs), which is necessary for security and correct operation (legitimate interest, Art. 6(1)(f)). Server logs are kept for a limited period, normally not more than 30 days.
2.5 Cookies, analytics and advertising
Cookies and similar technologies that are not strictly necessary are used only after you give consent through the cookie banner (Art. 6(1)(a) GDPR and Art. 122 of the Italian Personal Data Protection Code). These are:
- Analytics: Google Analytics 4, to measure how the site is used;
- Advertising and measurement: Google (Google Ads, Google tags) and Meta (Meta Pixel), to measure the effectiveness of our advertising campaigns and, where you consent, show you relevant ads on Google and Meta platforms, including to people who have previously visited the site (remarketing);
- Embedded content: YouTube videos and Google Maps maps.
Full details, including the list of cookies, are in our Cookie Policy. We also store a record of your cookie choices (date and time, selected categories, country and a partially masked IP address) in our website database, to be able to demonstrate that consent was given; these records are kept for up to 24 months.
For the Meta Pixel, Meta Platforms Ireland Ltd. and the Controller may act as joint controllers for the collection and transmission of data to Meta; Meta is responsible for the subsequent processing. More information is available in Meta’s Privacy Policy and Google’s Privacy Policy.
2.6 Google reviews
Customer reviews from our Google Maps profile are displayed on the site through a WordPress plugin. The reviews are public and come from Google; we do not collect additional data about you through this feature.
3. Who receives your data
Your data is not sold. It may be shared only with:
- the hosting provider of the website (Hostinger) and email provider, acting as data processors;
- accommodation providers, restaurants, transport and other local partners, strictly as needed to deliver your tour;
- banks and PayPal, for payments you make to us;
- our accountant/tax advisor and, where required, public authorities;
- Google and Meta, if you accept the related cookies.
4. Transfers outside the EU/EEA
Some providers (notably Google and Meta) may process data in the United States. Such transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework or on Standard Contractual Clauses. Visitors from Switzerland are covered by equivalent safeguards under the Swiss Federal Act on Data Protection.
5. Your rights
Under Articles 15–22 GDPR you have the right to: access your data; have it rectified or erased; restrict or object to processing; receive your data in a portable format; and withdraw consent at any time (without affecting processing carried out before withdrawal). To exercise these rights, write to info@wolftrails.it. We will reply within one month.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or with the supervisory authority of your country of residence.
6. Providing data is voluntary
Providing your data is voluntary. However, without the data marked as required in the contact form or booking process, we cannot answer your request or organise your tour.
7. Security
We apply appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access, including HTTPS encryption on the website.
8. Changes to this policy
We may update this Privacy Policy from time to time, for example when we add new tools or services. The date of the latest update is shown at the top of this page.
