Privacy Policy
- Company
- La Baita 3L Ski Lab di Longo Giuseppe e Bruno Alfio Antonino & C. S.n.c.
- Registered office
- Via Giuseppe De Felice 7, 95052 Nicolosi (CT)
- VAT number
- IT02920070873
- Tax code
- 02920070873
- REA
- CT-196466
- Certified email
- labaita3l@pec.it
- info@etnasudquad.it
- Phone
- 0952938843
This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. It describes how we process the personal data of users who browse etnasudquad.it and who use our services: booking quad bike excursions and trekking on Mount Etna, purchasing gift vouchers and contacting customer support.
Last updated: 1 August 2026.
1. Data controller
The data controller is La Baita 3L Ski Lab di Longo Giuseppe e Bruno Alfio Antonino & C. S.n.c., registered office at Via Giuseppe De Felice 7, 95052 Nicolosi (CT), Italia — VAT no. IT02920070873, tax code 02920070873, REA CT-196466, certified email labaita3l@pec.it. Excursions depart from Piazzale Rifugio Sapienza, Nicolosi (CT).
For any request concerning personal data you may write to info@etnasudquad.it or to the certified email address above. The controller has not appointed a Data Protection Officer (DPO), as the legal requirements for such appointment do not apply.
2. Categories of data processed
We process the following categories of data:
- Identification and contact data provided voluntarily in order to book or purchase: first name, last name, email address, telephone number, preferred language.
- Booking data: chosen experience (quad excursion, quad and tasting, trekking), date and time slot, number of participants and quad bikes, any notes or special requests.
- Data required for the safety of the activity: declaration of fitness to drive, valid driving licence for drivers, age of participants (in particular for minors carried as passengers) and signature of the liability waiver.
- Payment data handled by external providers: we do not store full payment card details on our systems. We retain the outcome of the transaction, the amount and the payment reference.
- The content of communications with customer support, including WhatsApp conversations and emails exchanged with us.
- Browsing data automatically collected by our IT systems (for example IP addresses, browser type, pages visited), necessary for the operation and security of the website.
- Data contained in cookies: please refer to the Cookie Policy.
We do not process special categories of data (Article 9 GDPR). Any health information spontaneously provided by the user for the safety of the excursion is processed solely for that purpose, for the time strictly necessary and subject to consent.
3. Purposes and legal basis of processing
Data are processed for the following purposes:
- Managing bookings, gift vouchers and payments — legal basis: performance of a contract or pre-contractual measures (Article 6.1.b GDPR).
- Sending service communications relating to the booking, such as confirmations, bank transfer instructions, reminders and notices of changes or cancellation due to bad weather — performance of the contract.
- Managing the safety of the excursion and insurance obligations, including verification of participation requirements — performance of the contract and compliance with legal obligations (Articles 6.1.b and 6.1.c GDPR).
- Compliance with legal, tax, accounting and insurance obligations — Article 6.1.c GDPR.
- Handling support requests, WhatsApp communications and complaints — legitimate interest in providing customer assistance (Article 6.1.f GDPR).
- Website security and prevention of fraud and abuse — legitimate interest (Article 6.1.f GDPR).
- Sending promotional communications and newsletters, where applicable — only with free, specific consent, which may be withdrawn at any time (Article 6.1.a GDPR).
4. Processing methods and security
Data are processed mainly by electronic means and with technical and organisational measures appropriate to ensure their security, confidentiality and integrity: encrypted connections (HTTPS), access control with two-factor authentication for staff, encryption of sensitive credentials and regular backups. Processing is carried out by the controller and by persons expressly authorised and instructed for this purpose.
5. Payments
Payments by credit or debit card, Apple Pay, Google Pay and PayPal are handled directly by the respective providers — Stripe Payments Europe Ltd. and PayPal (Europe) S.à r.l. et Cie, S.C.A. — which act as independent controllers or as processors for the data required to execute the transaction. This website does not store full card numbers. Payment by bank transfer is also available: in that case we process the data required to reconcile the payment. Please refer to the privacy notices of Stripe and PayPal on their respective websites.
6. Bookings through external platforms
Our experiences may also be booked through travel intermediation platforms such as GetYourGuide. In that case the platform transmits to us the data required to deliver the service (participant name, contact details, date and time, number of participants) and acts as an independent controller for the data collected on its own platform, in accordance with its own privacy notice.
7. Customer support via WhatsApp
If you contact us via WhatsApp, the content of the conversation and your telephone number are processed in order to reply to your requests and manage your booking. The service is provided through the WhatsApp Business Platform operated by Meta Platforms Ireland Ltd., which acts as an independent controller for traffic data under its own terms. Conversations are stored in our management system for as long as necessary to manage the customer relationship.
8. Recipients of the data
Within the limits of the purposes set out above, data may be disclosed to: IT and hosting service providers; payment service providers; tax and accounting advisers; insurance companies; travel intermediation platforms; competent authorities in the cases provided for by law. Providers processing data on our behalf are appointed as processors pursuant to Article 28 GDPR. Data are neither disseminated nor sold to third parties.
9. Transfers of data outside the European Union
Data are processed primarily within the European Economic Area. Some providers (for example payment or messaging services) may transfer data to third countries: in such cases the transfer takes place on the basis of adequacy decisions of the European Commission or standard contractual clauses, with appropriate safeguards pursuant to Articles 44 et seq. of the GDPR.
10. Retention period
Data relating to bookings and payments are retained for as long as necessary to manage the relationship and, thereafter, for the limitation period provided for by law (as a rule ten years for accounting and tax records). Contact data processed on the basis of consent for promotional purposes are retained until consent is withdrawn. Browsing data and technical logs are retained for a limited period, unless required for the investigation of offences.
11. Rights of the data subject
Pursuant to Articles 15 to 22 of the GDPR, users have the right to request from the controller access to their personal data, rectification, erasure, restriction of processing and data portability, as well as to object to processing based on legitimate interest. Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
Requests should be sent to info@etnasudquad.it or to the certified email address labaita3l@pec.it. The controller will reply within one month of receipt of the request.
12. Complaint to the supervisory authority
Users who believe that the processing of their data infringes data protection law have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) or with the supervisory authority of the country in which they habitually reside.
13. Nature of the provision of data
Providing the data marked as mandatory is necessary in order to book the experiences and to comply with legal and safety obligations: refusal makes it impossible to provide the service. Providing data for promotional purposes is optional.
14. Automated decision-making
No automated decision-making or profiling producing legal effects on the user is carried out.
15. Changes to this notice
The controller may update this notice to reflect legal or organisational changes. The current version is always published on this page together with the date of the latest update.