Last updated: September 2026.
Information provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
This notice describes how personal data of users visiting the website www.ricasolirealty.com, interacting with its services and approaching the Controller for real estate services under the Ricasoli Realty brand are processed.
Ricasoli Group S.r.l. is a single company operating on the market through several brands, each specialised by sector and none of which has separate legal personality: Ricasoli Travel (travel and mobility services), Ricasoli Realty (real estate services) and Ricasoli Stays (short lets and property management). Any reference to a brand in this document is to be understood as a reference to Ricasoli Group S.r.l.
The controller of personal data is:
Controller: Ricasoli Group S.r.l.The Controller has not appointed a Data Protection Officer, the conditions set out in Article 37 GDPR not being met. Any request concerning the processing of personal data may be sent to the e-mail address indicated above.
The websites www.ricasoligroup.com, www.ricasolitravel.com, www.ricasolirealty.com and www.ricasolistays.com all belong to a single data controller, Ricasoli Group S.r.l., which operates through the Ricasoli Travel, Ricasoli Realty and Ricasoli Stays brands. Those brands are not separate companies but operating divisions of the same company.
Accordingly, the use of personal data across the different divisions does not constitute disclosure to third parties, but processing internal to the same controller, and in any event takes place solely within the limits of the purposes and legal bases set out in this notice. In particular, data collected through one website is not used to send promotional communications concerning the services of another division without the specific consent of the data subject.
The Controller processes the following categories of personal data:
In the course of its real estate activity the Controller also processes personal data that have not been provided directly by the data subject. This is the case, in particular, of data relating to:
Source of the data. Such data come from the client granting the engagement or from the counterparty, or from public registers, lists and publicly accessible documents: cadastral searches and floor plans, land registry searches and inspections at the Land Registry, company register searches, notarial deeds, condominium documentation, energy performance certificates and technical certifications.
Categories of data. Identification and contact data, tax code, data relating to title and rights in rem over the property, data on encumbrances, charges and contractual relationships concerning the property.
Purposes and legal basis. The data are processed to perform the engagement granted to the Controller, to carry out preliminary checks on the property and its marketability and to comply with legal obligations; the legal bases are performance of the contract with the client and the legitimate interest of the Controller and of the client in the proper conduct of the transaction (Article 6(1)(b) and (f) GDPR), as well as, where applicable, legal obligation (point (c)).
Pursuant to Article 14(3) GDPR, the Controller provides this notice to data subjects whose data have not been obtained from them within a reasonable period and in any event no later than one month from collection, or at the time of the first communication with the data subject, if earlier.
Personal data are processed for the purposes and on the legal bases set out below.
Providing the data requested through the website forms is optional; failure to provide the data marked as mandatory, however, makes it impossible to follow up on the request. Providing the data and documents necessary to perform the engagement and to carry out checks on the property is necessary for the conclusion and performance of the contract.
The forms on the website include a non-pre-ticked acknowledgement box confirming that the user has read this notice; ticking it is a condition for submitting the request. That box does not constitute consent to the processing: a privacy notice is an information document, and the processing operations connected with handling the request rely on the legal bases set out in the preceding paragraph.
Subscribing to the newsletter requires a separate consent box, likewise not pre-ticked and independent of the submission of the request: declining to subscribe in no way affects the possibility of contacting the Controller or using its services. Consent may be withdrawn at any time through the unsubscribe link included in every communication or by writing to the addresses set out in paragraph 1.
Choices concerning cookies and similar technologies are collected through the dedicated banner on first access and may be changed or withdrawn at any time through the Cookie preferences control in the website footer, as described in the Cookie Policy.
Personal data may be disclosed, for the purposes set out above, to the following parties, which process them as processors or as separate controllers:
Parties processing data on behalf of the Controller are appointed as processors under Article 28 GDPR. An up-to-date list of processors is available on request by writing to the addresses set out in paragraph 1. Personal data are not disseminated.
Some of the providers listed in the preceding paragraph may process personal data outside the European Economic Area. In that case, the transfer takes place solely subject to appropriate safeguards under Articles 44 et seq. GDPR, such as an adequacy decision of the European Commission (including the decision concerning the EU-U.S. Data Privacy Framework, for US providers certified thereunder) or the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional measures. A copy of the safeguards adopted may be requested at the addresses set out in paragraph 1.
Personal data are retained for no longer than is necessary to achieve the purposes for which they were collected and, in particular:
The Controller does not carry out automated decision-making, including profiling, producing legal effects concerning the data subject or similarly significantly affecting them within the meaning of Article 22 GDPR. Should the Controller intend to introduce such processing in the future, it will give prior notice by updating this notice, setting out the logic involved as well as the significance and the envisaged consequences for the data subject.
The services offered through the website are not intended for minors. Data of minors are processed only where necessary because they hold rights over a property or belong to the household concerned, and are communicated by the holder of parental responsibility.
The Controller implements appropriate technical and organisational measures under Article 32 GDPR to protect personal data against unauthorised destruction, loss, alteration, disclosure or access, including encryption of communications through the HTTPS protocol, restriction of access to authorised personnel instructed under Article 29 GDPR, and the appointment of providers as processors under Article 28 GDPR.
Data subjects have the right to obtain from the Controller, in the cases provided for by Articles 15 et seq. GDPR: access to their personal data; rectification of inaccurate data; erasure of data (right to be forgotten); restriction of processing; data portability; and objection to processing based on legitimate interest. Data subjects have in any event the right to object at any time, without giving reasons, to the processing of their data for direct marketing purposes. Where processing is based on consent, data subjects have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
These rights may be exercised by writing to the addresses set out in paragraph 1. The Controller replies without undue delay and in any event within one month of the request, extendable by two months where the request is particularly complex. Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the Member State of their habitual residence or place of work.
The website is also published in languages other than Italian. This notice is drafted in Italian and is made available, for transparency purposes under Article 12 GDPR, also in the other languages in which the website is available. In the event of any discrepancy between versions, the Italian version prevails.
The Controller reserves the right to amend or update this notice at any time, giving notice by publication on the website. The version in force is the one published on this page on the date of consultation; the date of the last update is shown at the top of the document.