Privacy
Privacy policy
Last updated: 28 August 2026
This page explains which personal data Dimora Suite processes, why, and for how long. It is written to actually be read: no boilerplate, just what happens.
Who processes your data
The data controller is Mario D'Anna, Via degli Scipioni 145, 00192 Roma, Italy β tax code DNNMRA60D26H501P. For any request concerning your data, write to info@dimorasuite.com: a person answers.
Two roles worth keeping apart
Dimora Suite is a platform, and there are two distinct sets of processing. On one side there is this site, where we present the service. On the other there are the properties' own websites built with the platform, each on its own address.
On dimorasuite.com the controller is the person named above. On a property's website β booking requests, messages, guest reviews β the controller is the property itself, and Dimora Suite acts as its processor (art. 28 GDPR): it holds that data and processes it only to run the service, never for its own purposes.
If you stayed at a property, the policy that concerns you is the one published on that property's website, and the controller to address is whoever runs it.
What this site collects while you read it
Nothing. The pages of dimorasuite.com are static: they set no cookies, use no analytics or statistics tools, profile nobody, and load no third-party resources. You will not find a cookie banner because there is nothing to consent to.
What remains is the data any server unavoidably records while delivering a page β IP address, time of the request, browser type β processed by the hosting provider for security and diagnostics, and kept for a limited period. Our legitimate interest in keeping the service running and safe from abuse is the legal basis for this.
If you write to us through the βStartβ form
The request form collects only what you type:
- the property name and, if you provide them, a contact email and phone number
- the property address and the list of rooms, where the type of site calls for it
- the email address or GitHub username you would like to sign in with
- the domain you have in mind, and the message you add
Why we use it, and for how long
That data serves to assess your request, reply to you and β if we go ahead β prepare your site. The legal basis is taking steps at your request prior to entering into a contract.
There is no automatic deletion: requests stay on file as long as they serve that purpose or help reconstruct how a relationship began. If you want them gone sooner, ask at the address above and they are deleted.
We do not use these contacts for newsletters or commercial messages, and we pass them to nobody: we do not do list marketing.
If you become a customer
Signing in to the admin panel requires an account. Depending on how you sign in, we process the name, email address and profile picture that GitHub or Google pass on to us at login, or the email address alone if you use the link we send you by mail.
The session is held by a technical cookie, which is indispensable: without it the panel cannot recognise you. It does not track your browsing and feeds no statistics.
If you turn on push notifications, your browser generates a delivery address that we store together with your administrator email, so we can alert you when a booking arrives. Turning notifications off deletes it.
The legal basis for this processing is performance of the service contract; the data stays for the duration of the relationship and, for tax and accounting records, for the periods the law requires.
Who we entrust the data to
To run the service we rely on providers that process data on our behalf, as processors, and only for the purposes described here:
- Vercel β hosting and running the application
- Neon β the database where the data lives
- Resend β sending service emails
- GitHub and Google β only if you choose to sign in with one of those accounts
- Anthropic β analysis of a public listing's text when a customer uses the Airbnb or Booking import (an optional feature: it reads the listing's public page, never credentials)
- Stripe β guest payments go through each property's own Stripe account: card details are handled by Stripe and never pass through our systems
Transfers outside the European Union
Some of these providers are based in the United States and may process data outside the European Economic Area. Transfers rely on the standard contractual clauses approved by the European Commission, or on the provider's adherence to recognised adequacy frameworks.
Your rights
You may at any time ask to access your data, correct it, erase it, restrict its processing, object to processing, or receive it in a machine-readable format. Write to info@dimorasuite.com: we answer without delay and in any case within one month.
If you believe the processing breaches the Regulation, you have the right to lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of your own country.
Changes to this policy
If the way we handle data changes, this page changes with it and the date at the top is updated. There are no hidden versions: what you read here is what applies today.