Quasi-Hotels

LEGAL INFORMATION · MILAN

Privacy Notice

Notice under Articles 13 and 14 GDPR on personal data processed through quasi-hotels.it, team enquiries, direct booking and Quasi-Hotels digital services.

1. Data controller

Quasi-Hotels S.r.l., VAT 14532740967, registered office at Via San Raffaele 1, Milano, Italia, is the data controller for the processing described in this notice. Privacy requests and data-subject rights: support@quasi-hotels.com.

2. Data we process

We may process identification and contact data (name, surname, email and phone), stay and booking data (dates, guest count, accommodation, rate and conditions), information and notes you choose to submit for owner enquiries or support, interactions with the digital concierge and partner offers, technical security and service data and, only after consent, analytics and attribution data. Do not enter card numbers, identity documents or access codes in the concierge.

3. Purposes and legal bases

Enquiries, quotes, bookings, payments, support and owner requests are processed to perform a contract or take pre-contractual steps requested by you (Article 6(1)(b) GDPR). Tax, administrative and statutory requirements rely on legal obligations (Article 6(1)(c)). Service security, abuse prevention, legal claims, dispute management and non-persistent logging of partner-offer clicks for measurement and commercial reconciliation may rely on our legitimate interests (Article 6(1)(f)), subject to balancing. Google Analytics 4 and related attribution are activated only with consent (Article 6(1)(a) GDPR and applicable Italian tracking rules). Submitting an owner enquiry does not automatically subscribe you to marketing.

4. Bookings and payments

Guesty is used for availability, quotes, rates, booking conditions and reservation management. Payment is handled through Stripe in the checkout flow: full card details are entered directly in Stripe's interface and are not stored by Quasi-Hotels on this website. Quasi-Hotels receives the result and identifiers required to manage the payment and reservation.

5. Digital concierge and support

Messages sent to the digital concierge are processed to answer your request and provide information about stays, availability, guides and support. Chat history is not persistently stored in the browser and remains available in the interface only during the current session. Content may be processed by the technical and AI providers used to deliver the service under the applicable contractual and security safeguards.

6. Recipients and providers

Data may be processed by providers acting for Quasi-Hotels or as independent controllers for their respective services: Base44 infrastructure and hosting, Guesty for booking and operations, Stripe for payments, Google for Analytics only after consent and Google Maps only when you choose to load or open a map. When you open a Tiqets or Viator offer, or choose WhatsApp or another external service, you move to that provider's service and its own privacy notice applies.

7. Transfers outside the EEA

Some technology providers may process data outside the European Economic Area. Where the GDPR applies to a transfer, it is based on an adequacy decision, the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses or another Chapter V GDPR mechanism, together with supplementary safeguards where required.

8. Retention

We keep data only for as long as needed for the relevant purpose. Owner and contact enquiries are normally retained for up to 24 months after the last substantive interaction unless a relationship begins or legal protection requires longer. Booking and support data are kept for the stay and for the subsequent period needed for operations, disputes and legal duties. Administrative, accounting and tax records are retained for statutory periods, normally up to 10 years. Security logs are retained for limited and proportionate periods. Local preferences remain in your browser until changed or cleared; analytics-data retention also depends on the settings of the relevant service.

9. Required and optional data

Data marked as required at checkout are necessary to process and confirm the booking. Required contact or owner-form data are needed to answer the request; free-text notes are optional. If necessary data are not provided, we cannot complete the relevant request or booking.

10. Your rights

Where applicable under Articles 15-22 GDPR, you may request access, correction, deletion, restriction, portability and object to processing. Where processing relies on consent, you may withdraw it at any time without affecting prior lawful processing. Contact support@quasi-hotels.com. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or the competent supervisory authority.

11. Automated decisions

The website does not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Prices, availability and anti-fraud checks may involve automated provider systems, subject to the terms and checks of the requested service.

12. Updates

We may update this notice when features, providers or legal requirements change. The version published on this page is the version applicable to the website at the time you visit it.

Read the Cookie Policy

Last updated: 10 October 2026.

Quasi-Hotels S.r.l. · P.IVA 14532740967 · Via San Raffaele 1, Milano, Italia · support@quasi-hotels.com