Privacy Policy (Informativa Privacy)

Effective date: 1 August 2026. This notice is provided under Article 13 of the EU General Data Protection Regulation (GDPR) and the Italian Privacy Code (D.Lgs. 196/2003, as amended). All the personal data described below is collected directly from you. It explains, in plain language, what personal data the website vicino-casa.com collects, why, and what your rights are. We have tried to keep it short and honest — including the parts most websites leave out.

1. Who is responsible for your data (Data Controller)

The data controller is:

Vicino is a home watch and property care service operating in north-west Tuscany, Italy. We have not appointed a Data Protection Officer, as we are not required to; you can contact us directly at the email above for any privacy matter.

2. What data we collect, and where

Our website is a simple, static site available in five languages (English, Italian, German, Dutch, French). It collects data only in the situations described below. There is no user account, no payment on the site, and no advertising tracking.

2.1 Plan builder

If you use our interactive plan builder, we collect the answers you give:

Some answers may simply be "not sure" — that is fine and is stored as such.

2.2 Booking / enquiry form (Winter Health Check)

If you request our one-off "Winter Health Check" inspection, we collect:

This form is a request for a paid inspection. No payment is taken on the website.

2.3 Coverage-request form

If your town is not yet covered, you can tell us: the town or area, the services you would like (free text), and your email address.

2.4 Partner form (for businesses)

Estate agencies and similar businesses can contact us via a form collecting: name, agency name, and email address.

2.5 Technical and session data attached to submissions

When you submit a form, we also record some technical context together with it:

We use this to understand how people find us and where the website is confusing, so we can improve it.

2.6 Abandoned plan-builder sessions — please read this

We want to be transparent about something most sites do not mention. If you start the plan builder but leave without submitting, the partial answers you gave and the session data described in 2.5 are still transmitted to us for funnel analysis (understanding where people give up). In that case we receive no name and no email address — no direct identifiers. This data is therefore not anonymous in the legal sense, but we are not able to attribute it to a specific person. We process it on the basis of our legitimate interest in improving the website (Art. 6(1)(f) GDPR); we do not combine it with other data to try to identify you. You can object to this at any time (see Section 8) — and simply not starting the plan builder means nothing is sent. Please note that, precisely because this data carries no identifiers, if you later ask us to access or delete it we may be unable to link it to you; in that case Articles 15–20 GDPR do not oblige us to do so (Art. 11 GDPR), and we will tell you if that is the situation.

2.7 Storage on your own device (localStorage) — and why there is no cookie banner

The site stores two things in your browser's localStorage, on your device only:

Both are purely technical storage, used only to provide the site as you requested it. Under Article 122 of the Italian Privacy Code and the Garante's cookie guidelines ("Linee guida cookie e altri strumenti di tracciamento", 10 June 2021), technical cookies and equivalent storage do not require consent — which is why this site shows no cookie banner — but must be disclosed, which is what this section does. We use no third-party analytics, no advertising pixels, no marketing cookies and no profiling cookies. You can clear localStorage at any time through your browser settings; the only effect is that your language choice and any unsent draft are forgotten.

2.8 Anti-spam measures (honeypots)

Our forms contain hidden "honeypot" fields that only automated spam bots fill in. They help us discard spam (our legitimate interest in protecting the site, Art. 6(1)(f) GDPR). No data from genuine visitors is collected through them, and no data from bots is stored.

2.9 Google Fonts and hosting logs (IP addresses)

The website currently loads its typefaces from Google's font servers (Google Fonts CDN). When a page loads, your browser therefore sends your IP address — which is personal data — to Google, and this may involve a transfer to the United States (see Section 5). We rely on our legitimate interest in displaying the site correctly (Art. 6(1)(f) GDPR) for this, and we are evaluating serving the fonts from our own site instead, which would remove this transmission to Google entirely. [TO CONFIRM AT DEPLOY: if fonts are self-hosted before launch, this paragraph and the Google Fonts references in Sections 4 and 5 will be removed.]

Our hosting provider, [HOSTING PROVIDER — TBD, e.g. Netlify/Cloudflare], also processes visitor IP addresses in ordinary server logs, for security and to deliver the site (Art. 6(1)(f) GDPR).

2.10 If you become a client

If you go on to become a Vicino client, we process further data during service delivery: your property's details and access information, key-custody records, visit photo reports (which may show your home's interior), moisture readings, and our correspondence with you. We use this data to perform the contract with you (Art. 6(1)(b) GDPR) and to comply with legal and fiscal obligations (Art. 6(1)(c) GDPR). Client and contract data is kept for the duration of the contract and then for 10 years for fiscal records (see Section 6); photo reports are kept for the duration of the contract plus 2 years, unless you ask us to delete them earlier. Reports are shared only with you, the client.

3. Why we use your data, and the legal basis

Providing your data is never a statutory obligation at the enquiry stage; once you become a client, some identification data (for example your name and address on invoices) is required by Italian invoicing law. If you choose not to provide the data marked as required in a form, we simply cannot respond to that request; there is no other consequence.

4. Who receives your data (recipients and processors)

We do not sell your data, and we do not share it with anyone for advertising. Your data is handled by a small number of service providers:

Data may also be disclosed to public authorities where the law requires it, and to our professional advisers (e.g. accountant) where necessary.

5. Transfers outside the EU/EEA

Because we use Google services (Apps Script, Sheets, Gmail — and currently Google Fonts, which receives your IP address), your data may be processed on servers in the United States. Google LLC is certified under the EU–US Data Privacy Framework (DPF) — an adequacy decision of the European Commission whose certification list can be checked at dataprivacyframework.gov — and transfers are additionally covered by the Standard Contractual Clauses (SCCs) approved by the European Commission. [TO CONFIRM AT DEPLOY: whether the chosen hosting provider stores logs outside the EU/EEA; if so, the safeguards used will be stated here.] If you correspond with us via WhatsApp (Section 4), Meta Platforms may likewise process your number and message metadata in the United States; Meta is certified under the EU–US Data Privacy Framework and those transfers are additionally covered by SCCs. If you would like a copy of the relevant safeguards, contact us at ciao@vicino-casa.com.

6. How long we keep your data

7. No automated decisions, no profiling for marketing

We make no automated decisions about you that have legal or similarly significant effects (Art. 22 GDPR), and we do not profile you for marketing purposes. The plan builder simply reflects your own answers back as a suggested plan; a human (us) reads every submission.

8. Your rights

Under Articles 15–22 GDPR you have the right to:

To exercise any right, email ciao@vicino-casa.com. We will reply within one month; in complex cases the GDPR allows us to extend this by up to two further months, and we would tell you within the first month if so. For abandoned-flow data, the identification limit described in Section 2.6 (Art. 11 GDPR) may apply.

You also have the right to lodge a complaint with the Italian supervisory authority — Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome, www.garante.it — or with the authority of the EU country where you live or work, and to seek a judicial remedy.

9. Children

Our services and website are aimed at adult property owners. We do not knowingly collect data from anyone under 18, and the site is in no way directed at children (for information-society services, Italian law sets the age of digital consent at 14 — Art. 2-quinquies of the Privacy Code). If you believe a minor has sent us data, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time — for example when we confirm our hosting provider, self-host our fonts, obtain our VAT number, or introduce payments. The current version, with its effective date, will always be published on this page. If a change materially affects how we use data you have already given us, we will tell you by email where we can.

11. Questions

If anything here is unclear, write to us at ciao@vicino-casa.com — in English, Italian, German, Dutch or French — and a person will answer.

← vicino-casa.com