1. Data Controller
The data controller for personal data is:
- Company Name: Pagnotta Shipping Tourism
- Registered Office: Via Firenze 21 — 86039 Termoli (CB), Italy
- VAT Number: 01863770705
- Contact Email: info@costantinotour.it
For any requests regarding personal data protection, you can write to the email address mentioned above.
2. Reference Regulations
This notice is provided in accordance with the Regulation (EU) 2016/679 (GDPR — General Data Protection Regulation) and the Legislative Decree 196/2003 (Code regarding the protection of personal data), as amended by Legislative Decree 101/2018, as well as the Guidelines of the Guarantor for the Protection of Personal Data.
3. Types of Data Collected
3.1. Data Provided Voluntarily by the User
Through the contact form available on the homepage, the user can voluntarily provide:
| Data |
Mandatory |
Purpose |
| First and Last Name |
Yes |
Identification of the interlocutor |
| Email Address |
Yes |
Response to the request |
| Phone Number |
No |
Phone contact upon request |
| Text Message |
Yes |
Description of the request/booking |
The form is protected by an anti-spam verification system (text captcha "Tremiti") and requires explicit acceptance of this notice (checkbox) before submission.
3.2. Data Collected via the AI Chatbot ("Skipper AI")
The site integrates a virtual assistant powered by artificial intelligence (language model via OpenRouter API). When the user interacts with the chatbot:
- The text messages sent are processed in real-time to generate a contextual response and are not persistently stored on the Controller's server.
- The user's IP address is subjected to one-way hashing (MD5 with salt) exclusively for the rate limiting system (hourly message limit) and is never stored in plain text.
- A daily usage counter is stored in the
chatbot_usage table for aggregated statistical purposes (total number of messages per day).
- Messages are sent to a third-party API service (OpenRouter — openrouter.ai) for linguistic processing.
IMPORTANT: The chatbot is activated only after the user has given consent via the cookie banner.
3.3. Browsing Data (Technical Logs)
The site's internal logging system records the following information for statistical purposes:
| Data |
Detail |
Retention |
| IP Address |
Not recorded — replaced with 0.0.0.0 (complete anonymization) |
— |
| Browser User-Agent |
Type of browser and operating system (truncated to 250 characters) |
90 days |
| URL of the visited page |
Path of the page (truncated to 250 characters) |
90 days |
| Referrer |
Page of origin (truncated to 250 characters) |
90 days |
| Session ID |
Technical session identifier PHP |
90 days |
Note: The anti-refresh system prevents duplicate recordings of the same page in the same session within 5 minutes.
4. Purpose and Legal Basis of Processing
| Purpose |
Legal Basis (Art. GDPR) |
Description |
| Response to contact requests |
Art. 6(1)(b) — Execution of pre-contractual measures |
The data provided through the contact form is necessary to respond to user requests regarding quotes and excursions. |
| Technical operation of the site |
Art. 6(1)(f) — Legitimate interest of the Controller |
Session cookies, language preferences, CSRF token for site security. |
| Virtual Assistant (AI Chatbot) |
Art. 6(1)(a) — Consent of the data subject |
The user expresses consent via the cookie banner before being able to interact with the chatbot. |
| Anonymized traffic statistics |
Art. 6(1)(f) — Legitimate interest |
Aggregated and anonymous analysis of visited pages to improve the site. The IP is never recorded. |
| Advanced statistical analysis (Google Analytics / GTM) |
Art. 6(1)(a) — Consent of the data subject |
Activated only upon explicit consent of the user in the "Statistical Cookies" category. |
| Marketing and profiling (Meta Pixel) |
Art. 6(1)(a) — Consent of the data subject |
Activated only upon explicit consent of the user in the "Marketing Cookies" category. |
| Map display |
Art. 6(1)(f) — Legitimate interest |
Integration of Google Maps to show the location of the boarding point. |
| Security and abuse prevention |
Art. 6(1)(f) — Legitimate interest |
CSRF protection, rate limiting, Content Security Policy, HSTS, anti prompt-injection in the chatbot. |
5. Processing Methods
Personal data is processed using automated IT tools, adopting appropriate technical and organizational security measures to ensure an adequate level of protection, including:
- Encryption in transit: mandatory HTTPS connection with HSTS (max-age 1 year).
- Prepared Statements (PDO): all database queries use parameterized queries to prevent SQL Injection.
- Password hashing: bcrypt algorithm with cost factor 12.
- CSRF Token: protection against Cross-Site Request Forgery attacks on every form.
- Content Security Policy (CSP): HTTP header that limits the sources of executable scripts.
- Security Headers: X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy.
- Rate Limiting: limiting the number of requests to the chatbot and contact forms to prevent abuse.
- Anti prompt-injection: active filtering of chatbot messages to block attempts to manipulate the AI model.
6. Data Retention Periods
| Type of Data |
Retention Period |
Deletion Mechanism |
| Contact Messages |
24 months from the date of sending |
Automatic daily deletion (GDPR Auto-Cleanup) |
| Visit Logs |
90 days |
Automatic daily deletion |
| Chatbot Statistics |
12 months |
Automatic daily deletion |
| Session Cookies |
Until the browser is closed |
Automatic deletion |
| Language Preference Cookies |
Duration of the session |
Automatic deletion |
| Consent Cookies |
12 months (365 days) |
Natural expiration of the cookie |
The automatic deletion system (GDPR Auto-Cleanup) runs once a day in a transparent and silent manner.
7. Communication and Dissemination of Data
Personal data is not sold, transferred, or disclosed to third parties for the Controller's direct marketing purposes.
Data may be communicated to:
- Technology Service Providers: hosting providers for the operation of the server infrastructure, bound by confidentiality agreements.
- OpenRouter (openrouter.ai): messages sent to the chatbot are transmitted to this API service for processing via artificial intelligence models. Messages are processed in real-time and are not retained by the Controller after the session.
- Google LLC: if the user has consented to statistical cookies, browsing data is transmitted to Google Analytics and/or Google Tag Manager.
- Meta Platforms Inc.: if the user has consented to marketing cookies, the Meta Pixel may transmit browsing data to Meta (Facebook).
- Open-Meteo (open-meteo.com): public and free API for weather data. No personal data of the user is transmitted to this service.
8. Integrated Third-Party Services
| Service |
Provider |
Purpose |
Conditional on Consent |
| Google Fonts |
Google LLC |
Loading of typefaces (Outfit, Inter) |
No (only requests for static files) |
| Bootstrap 5 |
jsDelivr CDN |
CSS/JS framework for layout |
No (functional) |
| Font Awesome 6 |
Cloudflare CDN |
Vector icons |
No (functional) |
| Google Maps (iframe embed) |
Google LLC |
Interactive map of the boarding point |
No (functional) |
| Google Analytics |
Google LLC |
Statistical analysis of traffic |
Yes — Statistical Cookies |
| Google Tag Manager |
Google LLC |
Centralized tag management |
Yes — Statistical Cookies |
| Meta Pixel |
Meta Platforms Inc. |
Measuring advertising conversions |
Yes — Marketing Cookies |
| WhatsApp (direct link) |
Meta Platforms Inc. |
Quick contact via message |
No (external link, no data transmitted) |
| OpenRouter API |
OpenRouter |
AI Chatbot (natural language processing) |
Yes — subject to cookie consent |
| Open-Meteo API |
Open-Meteo |
Real-time weather widget |
No (no personal data transmitted) |
9. Data Transfer to Third Countries
Some third-party services (Google, Meta, OpenRouter) may involve the transfer of data to the United States of America or other non-EU countries.
Such transfers occur based on:
- Adequacy Decision by the European Commission (EU-U.S. Data Privacy Framework), where applicable.
- Standard Contractual Clauses (SCC) approved by the European Commission, incorporated into contracts with suppliers.
- Supplementary technical measures: encryption in transit (TLS/HTTPS), minimization of transmitted data, pseudonymization (IP hashing).
10. Rights of the Data Subject
| Right |
GDPR Article |
Description |
| Access |
Art. 15 |
Obtain confirmation of the existence of personal data and access it. |
| Rectification |
Art. 16 |
Obtain correction of inaccurate or incomplete data. |
| Deletion |
Art. 17 |
Obtain deletion of personal data ("right to be forgotten"). |
| Restriction |
Art. 18 |
Obtain restriction of processing in certain cases. |
| Portability |
Art. 20 |
Receive personal data in a structured and machine-readable format. |
| Objection |
Art. 21 |
Object at any time to processing based on legitimate interest. |
| Withdrawal of Consent |
Art. 7(3) |
Withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. |
How to exercise your rights: send a written request to: info@costantinotour.it. The Controller will respond within 30 days.
Right to lodge a complaint: The data subject also has the right to lodge a complaint with the Guarantor for the Protection of Personal Data (Website: www.garanteprivacy.it).
11. Data of Minors
The site is not intended for individuals under the age of 16. The Controller does not knowingly collect personal data from minors.
12. Changes to the Privacy Policy
The Controller reserves the right to modify this notice at any time. The updated version will always be available on the website.