This notice explains how personal data are processed when you visit merlintravel.eu or contact its owner. It concerns Merlintravel only and is provided under Regulation (EU) 2016/679 (GDPR) and applicable Italian data protection law.
1. Who is responsible for your data
The data controller is Horacio Fabian Greco, Bettona (PG), Italy. For privacy questions or to exercise your rights, email merlintravel@merlintravel.eu, with “Merlintravel privacy” in the subject line.
2. Browsing and contacting us
When you open a page, the systems delivering the website receive technical information such as your IP address, the requested resource, the time of the request and information sent by your browser. Error and security logs may record failed requests or attempted access. These data are used to deliver the website, diagnose problems and prevent abuse. The legal basis is our legitimate interest in operating and protecting the website, under Article 6(1)(f) GDPR.
If you email us, we process your email address, any name you provide, your message and the attachments you choose to send. We use them to reply, handle corrections or other enquiries and follow up on the correspondence. The legal basis is our legitimate interest in handling communications; Article 6(1)(b) applies where a request concerns steps needed before entering into a contract. Privacy-rights requests and other mandatory obligations are handled under Article 6(1)(c).
You do not need a public account to read the travel guides. Sending us personal information is optional, but we cannot answer an enquiry without a way to contact you. Please do not send identity documents, health information or other people’s personal data unless necessary for your request.
3. Visit statistics
Burst Statistics
Merlintravel uses Burst Statistics within its WordPress installation to understand how visitors use the website. This may include pages visited, referral information, visit times and general browser and device information.
The selected visitor-recognition mode is Cookieless, using a daily hash rather than a persistent tracking cookie. The separate “Cookieless fingerprint” mode, which recognises devices across days, is not selected. The selected mode does not recognise returning visitors across different days or sessions. Statistical information is managed in the website’s own installation.
We use these limited Burst visit statistics to understand readership and improve the website. Where personal data are involved, the basis is our legitimate interest in understanding use of our own content, subject to your right to object. This does not remove any separate requirement to obtain consent for access to a device or for non-essential tracking technologies. Any processing that requires consent must remain inactive until that consent is given.
Google Analytics 4
Merlintravel also uses Google Analytics 4 to collect usage data needed to measure visits, understand how the website is used and improve its travel guides. These data include cookie and browser identifiers, pages viewed, referral information, visit and interaction times, general browser and device information and approximate location. Enhanced measurement can record interactions such as scrolling, outbound link clicks, file downloads and supported embedded-video or form interactions. These are usage measurements; please do not put sensitive information into page URLs or form fields.
The website currently collects these statistics without a separate request for statistics consent. You can contact the controller to exercise your privacy rights. You can also use the Google Analytics opt-out browser add-on on supported browsers to prevent Analytics from using your visit data. Browser cookie controls are also available, although blocking cookies alone does not necessarily stop all Analytics transmissions.
Google processes the information to provide Analytics reports. For traffic from the EU, the UK and Switzerland, Google states that IP addresses are used to derive approximate location and then discarded before Analytics logging. This does not make all Analytics data anonymous. See how Google uses information from sites using its services.
4. Cookies and preferences
Technical cookies or similar technologies may be used for security, administration, caching and remembering privacy choices. Administrative login cookies concern signed-in users and do not mean that a public account is required to read the website.
Accepting optional cookies is voluntary. Use Manage consent or the controls on our Cookie Policy to review the available choices for optional services or withdraw consent where applicable. Withdrawal does not affect processing lawfully carried out before it. For assistance, email merlintravel@merlintravel.eu.
You can also remove site data using your browser settings. Removing the record of your preferences may cause the website to ask for those choices again.
Google Analytics uses first-party cookies such as _ga and _ga_<identifier> to distinguish browsers and maintain session information. Their default expiry is two years and can be renewed by subsequent activity. Cookie expiry is separate from the Analytics data-retention settings below. See the Google Analytics cookie documentation and our Cookie Policy for further information.
5. Hosting, images and other recipients
For Google Analytics, the service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with processing also involving Google LLC and relevant subprocessors. Google receives the Analytics information described above for statistical processing.
Hostinger provides the website’s hosting infrastructure. Data needed to deliver and secure the service may be handled by the hosting provider, authorised technical support providers and their relevant subprocessors. Emails pass through the mail providers used by the sender and recipient. Data may also be disclosed to authorities where legally required.
Most illustrations are served directly from merlintravel.eu. Some existing pages load images from merlintrader.eu; opening those pages therefore sends the usual image request, including your IP address and browser information, to that domain’s infrastructure. This notice does not cover separate browsing on that website.
Links to museums, parks, tourism offices and other sources take you to independently operated websites. Their own privacy notices apply when you visit them. A link is different from content loaded automatically within a Merlintravel page.
6. How long data are kept
Personal data are kept only for as long as needed for the purpose for which they were collected. Correspondence is retained while an enquiry and any necessary follow-up are being handled, or for a relevant legal obligation or specific dispute. Unnecessary personal information should not be retained simply because storage remains available.
Retention of technical logs is determined by the time needed to diagnose incidents and investigate abuse; Burst visit records are retained for the period needed to compare readership trends. Backups are retained for the recovery period covered by the hosting service. The criterion for continued retention is whether the records remain necessary for those purposes or for a specific legal obligation or dispute. Records no longer needed must be deleted or irreversibly anonymised. Backups are used for recovery rather than ordinary access to old personal data. Where a backup is restored, applicable deletion requests and restrictions must be reapplied. You can request information about the applicable retention periods using the contact address above.
The Merlintravel Google Analytics property is currently configured to retain other event data for 2 months and user-level and key-event data for 14 months. Reset on new user activity is enabled: new activity renews the user-level retention period, so a returning user’s data can be retained beyond 14 months from the first visit. Google removes expired data through its monthly deletion process. These settings do not limit standard aggregated reports, which may remain available for longer. See Google’s explanation of data retention.
7. International processing
Hosting, email and technical-support providers may involve processing outside the European Economic Area. Transfers of personal data require a basis under Chapter V GDPR, such as an applicable adequacy decision or appropriate safeguards, including standard contractual clauses where applicable. You can request information about the relevant safeguards and how to obtain a copy by emailing the controller.
Google Analytics may involve processing in the United States and other countries. Google describes its transfer mechanisms, including applicable adequacy frameworks and standard contractual clauses, in its data-transfer framework information and data-processing terms.
8. Your rights
Under the conditions set by the GDPR, you can request access, correction, deletion, restriction of processing and data portability. You can object to processing based on legitimate interests on grounds relating to your particular situation. Where processing relies on consent, you can withdraw it at any time.
Send your request to merlintravel@merlintravel.eu. We may ask only for information reasonably needed to identify the relevant data or verify your identity. We respond without undue delay, normally within one month. If the law permits an extension because of the complexity or number of requests, we will explain it within that first month; the extension cannot exceed two further months.
You may lodge a complaint with the Italian Data Protection Authority (Garante) or the competent supervisory authority in the country where you live, work or believe an infringement occurred. Your right to a judicial remedy remains unaffected.
9. Security, children and automated decisions
The website uses HTTPS and technical and organisational measures intended to protect access and reduce misuse. No system can guarantee absolute security. Protect your device and avoid sending unnecessary confidential information by email.
Merlintravel’s guides can be read without children submitting personal details. If you believe a child’s personal information has been provided improperly, contact the controller. The website does not make decisions based solely on automated processing that produce legal or similarly significant effects on visitors within the meaning of Article 22 GDPR.
10. Updates
This notice is updated when the website’s processing changes. The date above identifies the version. Publishing an amended notice does not itself constitute your consent to new processing.
Contact the data controller