Skip to content
Travel One

— Legal notice

Privacy Policy

Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

This notice explains how Travel One S.r.l. processes the personal data of those who visit the travelone.it website, write to us or book our services, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 ("Privacy Code").

This notice concerns this website. Third-party sites reachable through links (for example Facebook and Instagram, to which the site refers with simple links, without plugins) have their own privacy notices.

Data controller and contact details

The data controller is Travel One S.r.l.

For any question about this notice or your data you can write to info@travelone.it, send a letter to the registered office or use the Contact page.

Data Protection Officer (DPO)

Travel One S.r.l. has not appointed a Data Protection Officer (DPO), since none of the cases in which the appointment is mandatory applies (Art. 37 GDPR). For any matter concerning personal data you can contact the controller directly at the details given above.

What data we process and why

For each processing activity we state what data we process, for what purpose, on what legal basis, whether providing the data is mandatory, to whom it may be disclosed and how long we keep it. Within Travel One, data is processed by persons authorised to process it under the authority of the controller (Art. 29 GDPR and Art. 2-quaterdecies of Legislative Decree 196/2003), who are bound by confidentiality; technical providers are listed in the section Recipients and processors.

Data processed
IP address, user agent (browser type and operating system), address (URL) of the requested resource, date and time of the request.
Purpose
Operating the website, ensuring its security and detecting misuse or malfunctions. This data is not used for statistics or to profile visitors.
Legal basis
The controller's legitimate interest in the security and proper functioning of the website (Art. 6(1)(f) GDPR).
Provision of data
Necessary: this data is transmitted automatically by the browser when using Internet protocols, and the website cannot be displayed without it.
Recipients
The hosting provider Vercel Inc., as processor, in whose technical logs the data is recorded.
Retention
A few days, according to the hosting provider's timescales, unless it is needed to investigate computer crimes against the website.

2. Enquiries sent through the website forms

The enquiry forms are on the Contact, School Specialist, Atmosfere natalizie (Christmas atmospheres), Lignano Zoo & Fun and Udine chiavi in mano (Udine turnkey) pages.

Data processed
Name, e-mail address, telephone number (mandatory only in the form for schools, optional in the others), subject of the enquiry, text of the message together with any other information you choose to write to us, page from which the enquiry was sent and website language.
Purpose
Replying to your enquiry and providing the information or quotation requested.
Legal basis
Taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR). The form only asks you to confirm that you have read this notice: no consent is required and the data is not used to send you advertising.
Provision of data
Optional, but without the data marked as mandatory we cannot reply to the enquiry.
Recipients
Authorised Travel One staff, who read enquiries in the restricted area of the website; Google (Firebase), which stores the data in the database; Vercel Inc., which hosts the website; the e-mail notification service that may be used (Resend Inc., USA), which forwards a copy of the enquiry to the address info@travelone.it; the provider of Travel One's business e-mail mailbox. All of them act as processors.
Retention
24 months from submission, then automatic deletion. If e-mail notification is active, a copy of the enquiry reaches the info@travelone.it mailbox and our staff delete it within the same 24-month period. You may ask for earlier deletion at any time. If a contract follows the enquiry, the necessary data is processed to manage it (see Online booking and Retention).

3. Newsletter

Data processed
E-mail address, website language, text of the consent given and date of subscription (kept as proof of consent, Art. 7(1) GDPR).
Purpose
Sending you the Travel One newsletter with offers and news by e-mail.
Legal basis
Your consent (Art. 6(1)(a) GDPR and Art. 130 of Legislative Decree 196/2003), given by ticking a separate, unticked checkbox.
Provision of data
Optional: not subscribing has no consequences for your use of the website or your enquiries.
Recipients
Authorised staff; Google (Firebase), which stores the list of subscribers; Vercel Inc., which hosts the website; any e-mail delivery service provider that may be used, appointed as processor.
Retention
Until consent is withdrawn. You can unsubscribe at any time via the unsubscribe link included in every newsletter e-mail or by writing to info@travelone.it. Withdrawal does not affect the lawfulness of mailings sent before it (Art. 7(3) GDPR).

4. Marketing communications

Travel One sends promotional e-mails only to newsletter subscribers. Anyone who has only asked us for information or a quotation, through the forms or otherwise, does not receive marketing communications.

Art. 130(4) of Legislative Decree 196/2003 allows communications about similar services to be sent to customers who have already purchased a service, at the e-mail address provided at the time of purchase (legal basis: legitimate interest, Art. 6(1)(f) GDPR). Travel One does not currently make use of this option. Should it decide to do so, it will inform customers when they provide their e-mail address, giving them the opportunity to object straight away, and will remind them of their right to object in every mailing. Customers may object free of charge at any time via the link in the e-mail or by writing to info@travelone.it: after objecting they will receive no further mailings. The data will be used for this purpose until an objection is made and in any case for no longer than 24 months from the last purchase.

5. Virtual assistant "One"

"One", a virtual assistant based on artificial intelligence that answers questions about our services, is available on every page of the website.

Data processed
When you write a message, the following are transmitted: the text of the message, the previous messages of the same conversation (up to 20), the address and title of the page you are visiting and the website language. The initial welcome message is generated by the website and does not go through the artificial intelligence model.
Purpose
Generating an answer to your question and giving you information about our services.
Legal basis
Travel One's legitimate interest in providing the informational assistance you yourself request (Art. 6(1)(f) GDPR) and, where the question concerns a service you intend to purchase, taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
Provision of data
Optional: the assistant is not needed to browse the website, write to us or book.
Recipients
Anthropic PBC (San Francisco, USA), provider of the artificial intelligence model, as processor; Vercel Inc., which hosts the website.
Retention
Travel One does not save conversations: they remain only in the browser tab and disappear when you reload or close the page. Anthropic keeps the data received and the answers for a limited period, under its commercial terms normally no longer than 30 days (unless kept longer in the event of a breach of its usage policies), and does not use them to train its models.

Do not enter unnecessary personal data in the chat, data concerning health or other special categories, or data about other people. For requests that require your data, use the contact forms, e-mail or telephone.

Answers are generated automatically and may contain errors or inaccuracies: prices, dates and availability must always be confirmed by our staff. One does not take decisions concerning you (see Automated decision-making). Anthropic's privacy policy: anthropic.com/legal/privacy.

Transparency on artificial intelligence (Regulation (EU) 2024/1689, "AI Act", Art. 50). One is an artificial intelligence system, not a person: the website states this in the chat window. If you prefer to speak to a person you can contact us by telephone, WhatsApp or e-mail.

6. "Travel One AI" quiz

The quiz on the Travel One AI page suggests an experience based on your answers. The answers are processed exclusively in your browser: they are not sent to Travel One or to third parties and are not saved. We do not collect any personal data for this feature.

7. Online booking

On the tour pages the "Book" button opens, where available, the booking form of Regiondo GmbH (Munich, Germany). The form is loaded only after you consent to the "Online booking" category (see Cookie Policy); until then no data is sent to Regiondo.

For some tours the button instead leads to the provider's online booking page (normally Regiondo), which opens in a new tab on the provider's website; in that case the provider's privacy policy also applies. Bookings made via WhatsApp, telephone or e-mail follow the processing described under Contact by e-mail, telephone and WhatsApp.

Data processed
Participants' data, contact details (name, e-mail, telephone), booking details and payment data entered in the form.
Purpose
Managing the booking and the package travel or travel service contract, collecting payment and complying with tax and accounting obligations.
Legal basis
Performance of the contract and of pre-contractual steps (Art. 6(1)(b) GDPR); compliance with legal tax and accounting obligations (Art. 6(1)(c) GDPR).
Provision of data
Necessary to book: without the data requested the booking cannot be completed.
Recipients
Regiondo GmbH, which operates the booking system on behalf of Travel One as processor; payment service providers, for payment transactions; authorised staff; public authorities, where disclosure is required by law.
Retention
For the duration of the contractual relationship and, for accounting and tax records, 10 years (Art. 2220 of the Italian Civil Code).

Source of the data (Art. 14 GDPR). The data of participants other than the person booking is provided to us by the person making the booking, who warrants that they are entitled to do so and undertakes to inform the participants by showing them this notice. It consists of identification and contact data and the data needed to provide the service.

Regiondo's privacy policy: pro.regiondo.com/privacy-policy.

8. Contact by e-mail, telephone and WhatsApp

Data processed
The data you give us: name, contact details (e-mail address, telephone number) and the content of the communication.
Purpose
Replying to and following up on your requests.
Legal basis
Performance of pre-contractual steps or of the contract (Art. 6(1)(b) GDPR) or, for other communications, the legitimate interest in replying to those who contact us (Art. 6(1)(f) GDPR).
Provision of data
Optional, but necessary to receive a reply.
Recipients
Authorised staff. If you write to us on WhatsApp, WhatsApp Ireland Ltd. (Meta group) processes the data as an independent controller of its own service, under its own privacy policy.
Retention
For the time needed to handle the request and any subsequent communications; if a contract follows, according to the periods stated for booking.

9. Job applications

Applications are sent by e-mail, as explained on the Work with us page.

Data processed
The data contained in the CV and in the covering e-mail (personal details, contact details, experience, qualifications). Please do not include data concerning health or other special categories unless strictly necessary.
Purpose
Assessing the application for staff recruitment, including seasonal staff.
Legal basis
Pre-contractual steps at your request (Art. 6(1)(b) GDPR) and Art. 111-bis of Legislative Decree 196/2003: no consent is required for unsolicited CVs.
Provision of data
Optional, but without the data we cannot assess the application.
Recipients
Authorised staff responsible for recruitment.
Retention
24 months from receipt, then deletion. If the application leads to an employment relationship, the data becomes part of the records of that relationship.

10. Published reviews

Data processed
Name and text of the review, as given by the author.
Purpose
Publishing customers' opinions on the Reviews page.
Legal basis
The author's consent to publication (Art. 6(1)(a) GDPR).
Provision of data
Optional.
Recipients
Once published, the name and text are visible to anyone who visits the website; Google (Firebase) and Vercel Inc. for storage and hosting, as processors.
Retention
For as long as the review remains published. The author may ask for its removal at any time by writing to info@travelone.it.

11. Maps

The Contact page contains a Google Maps map (Google Ireland Ltd.) and the tour pages contain OpenStreetMap maps (OpenStreetMap Foundation, United Kingdom). Maps are loaded only after you consent to the "Maps" category; until then a placeholder is shown and no data is sent to these providers.

Data processed
When the map is loaded, your browser connects to the provider's servers, which receive your IP address, browser data and the page address; Google may set or read its own cookies.
Purpose
Showing you the location of our office and the departure point of the tours.
Legal basis
Your consent (Art. 6(1)(a) GDPR and Art. 122 of Legislative Decree 196/2003), which you can withdraw at any time from "Cookie preferences" in the footer.
Provision of data
Optional: without consent the map is not shown, but the rest of the website works.
Recipients
Google Ireland Ltd. and OpenStreetMap Foundation. For the collection and transmission of data when the map is loaded, and for that stage only, Travel One and the provider may be regarded as joint controllers (Court of Justice of the EU, Case C-40/17, Fashion ID), and for that stage you may also contact Travel One to exercise your rights; for any subsequent processing the provider acts as an independent controller under its own privacy policy: Google, OpenStreetMap.
Retention
Set by each provider; Travel One neither receives nor keeps this data. Your consent choice is stored for 6 months in the technical cookie t1_consent.

12. Staff restricted area

The restricted area of the website is accessible only to authorised Travel One staff, through Firebase Authentication (Google). For access, the staff member's e-mail address and credentials and a technical session cookie (see Cookie Policy) are processed, on the basis of the employment or collaboration relationship (Art. 6(1)(b) GDPR) and the legitimate interest in the security of the systems (Art. 6(1)(f) GDPR), for as long as the account remains active.

The website uses only cookies and technical tools necessary for it to work (for example to remember the language and your choices about third-party content) and no analytics, profiling or advertising cookies. Third-party content that may set its own cookies (maps and booking form) is loaded only after your consent. Full details are in the Cookie Policy.

You can change your choices at any time:

Recipients and processors

Data may be disclosed to the following categories of recipients:

  • persons authorised by Travel One to process data (Art. 29 GDPR and Art. 2-quaterdecies of Legislative Decree 196/2003), bound by confidentiality;
  • providers processing data on our behalf, appointed as processors by contract under Art. 28 GDPR;
  • third parties processing data as independent controllers when you use their services (WhatsApp, payment services) and map providers, joint controllers with Travel One for the data transmission stage only and independent controllers for any subsequent processing;
  • public authorities, where disclosure is required by law.

Data is neither sold nor disseminated, except for reviews that their authors authorise us to publish. The main providers are:

Providers receiving personal data from the website
ProviderServiceRoleCountryPrivacy policy
Vercel Inc.Website hosting and content delivery network (CDN); server functions in the Washington D.C. regionProcessor (Art. 28)USAvercel.com
Google (Firebase: Cloud Firestore, Cloud Storage, Authentication)Database, file storage and access to the restricted area (project travelone-be7cd)Processor (Art. 28)USApolicies.google.com
Anthropic PBCArtificial intelligence model of the One assistantProcessor (Art. 28)USAanthropic.com
Regiondo GmbHOnline booking and payment systemProcessor (Art. 28)Germany (EU)regiondo.com
Resend Inc.E-mail service for enquiry notifications, where usedProcessor (Art. 28)USAresend.com
Google Ireland Ltd. (Google Maps)Map on the Contact page, only after consentJoint controller for the transmission / independent controllerIreland (EU)policies.google.com
OpenStreetMap FoundationMaps on the tour pages, only after consentJoint controller for the transmission / independent controllerUnited Kingdomosmfoundation.org
WhatsApp Ireland Ltd.Messaging, if you write to us on WhatsAppIndependent controllerIreland (EU)whatsapp.com

Payment data entered in the Regiondo form is also processed by payment service providers, under the conditions stated in the form itself. The up-to-date list of processors is available on request from info@travelone.it.

Transfers of data outside the European Union

Some providers process data in the United States: the website's server functions are run by Vercel in the Washington D.C. region (iad1), with a worldwide delivery network; the Firestore database is located in the US multi-region (nam5) and Cloud Storage files in the us-east1 region; the One assistant relies on the services of Anthropic PBC; the Resend notification service, where used, operates in the USA. Google Ireland Ltd., for Google Maps, may also transfer data to the United States under its own privacy policy.

These transfers take place on the basis of the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, for certified providers (the list can be consulted at dataprivacyframework.gov), and in any case of the standard contractual clauses adopted by the European Commission (Art. 46 GDPR) included in the providers' contracts. You can obtain a copy of the safeguards adopted (standard contractual clauses) by writing to info@travelone.it.

OpenStreetMap Foundation is based in the United Kingdom, a country covered by an adequacy decision of the European Commission.

How long we keep data

Retention periods by processing activity
ProcessingRetention
Browsing data (technical logs)A few days, unless needed to investigate computer crimes
Enquiries from the website forms24 months from submission, then automatic deletion from the database; any copy received by e-mail is deleted by our staff within the same period
NewsletterUntil consent is withdrawn (unsubscription)
Marketing communications to customers (Art. 130(4)), if activatedUntil an objection is made and in any case no longer than 24 months from the last purchase
Conversations with the One assistantNot saved by Travel One; kept by Anthropic for a limited period, normally no longer than 30 days
"Travel One AI" quizNot kept
Bookings and contractsDuration of the relationship; accounting and tax records 10 years (Art. 2220 Italian Civil Code)
Contact by e-mail, telephone and WhatsAppThe time needed to handle the request
Job applications24 months from receipt
Published reviewsWhile published or until removal is requested
Choice about third-party content (t1_consent cookie)6 months
Staff accounts for the restricted areaWhile the account remains active

Once these periods have expired, data is deleted or anonymised. It may be kept longer only where necessary to comply with a legal obligation or to establish, exercise or defend legal claims.

Your rights

At any time and free of charge you can exercise the rights provided for in Articles 15-22 GDPR:

  • access (Art. 15): to know whether we process data concerning you and to receive a copy;
  • rectification (Art. 16): to correct or complete inaccurate or incomplete data;
  • erasure (Art. 17): to have the data erased in the cases provided for;
  • restriction (Art. 18): to ask that the data only be stored, for example while we examine a dispute;
  • portability (Art. 20): to receive in a structured, machine-readable format the data you have provided to us, processed by automated means on the basis of consent or a contract, and to transmit it to another controller;
  • objection (Art. 21): to object at any time, on grounds relating to your particular situation, to processing based on legitimate interest and, without giving reasons, to any processing for direct marketing purposes;
  • withdrawal of consent (Art. 7(3)): to withdraw at any time the consent given (newsletter, maps, online booking, reviews), without affecting the lawfulness of processing carried out before the withdrawal.

Requests should be sent to info@travelone.it or by post to Travel One S.r.l., Via Sabbiadoro 1, 33054 Lignano Sabbiadoro (UD), Italy. We reply without undue delay and in any case within one month of receipt; this period may be extended by two further months for more complex requests, in which case we will inform you within the first month (Art. 12(3) GDPR). We may ask you for information to verify your identity.

If you believe that the processing of your data infringes the law, you have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it), or with the supervisory authority of the EU Member State in which you live or work, or to take legal action (Articles 77-79 GDPR).

Automated decision-making

Travel One does not take decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).

The One assistant generates answer texts with an artificial intelligence model, but decides nothing: it does not accept or reject bookings, does not set prices or conditions and does not assess people. Quotations, confirmations and all other decisions are made by our staff.

Minors

Services for minors (camps, school activities) are requested and booked by parents, holders of parental responsibility or teachers, who provide us with the necessary data of the participants. The website does not knowingly collect personal data of minors. If you believe that a minor has provided us with their data, write to info@travelone.it and we will delete it.

Source of the data (Art. 14 GDPR). The data of enrolled minors is provided to us by the parent, the holder of parental responsibility or the teacher making the request or booking, who warrants that they are entitled to do so and undertakes to inform the data subjects (the participants and their families) by showing them this notice. It consists of identification and contact data and the data needed to provide the service.

Data security

We adopt technical and organisational measures appropriate to the risk (Art. 32 GDPR), including:

  • encrypted HTTPS connection for all pages and forms;
  • restricted area accessible only to authorised staff, with authentication and a session cookie that scripts cannot read (httpOnly);
  • access rules for the database and file storage that prevent visitors from reading the stored data;
  • HTTP security headers which, among other things, prevent the website from being embedded in third-party pages and disable access to camera, microphone and location;
  • data minimisation: we collect only what is needed, conversations with One are not saved, enquiries are deleted after 24 months and third-party content is loaded only after consent.

In the event of a personal data breach likely to result in a risk to your rights, we will notify the Garante and, where required, you as well, in accordance with Articles 33 and 34 GDPR.

Changes to this notice

We may update this notice following changes in the law or in the website's services. The version in force is always published on this page with the date of the last update; significant changes will be highlighted on the website.

Last updated: 25 September 2026.