SkyAlps Holidays GmbH/srl · Last updated: June 2026
In accordance with the General Data Protection Regulation (GDPR, EU 2016/679) and Italian data protection law (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018).
1. Data Controller (Art. 4 No. 7 GDPR)
The data controller within the meaning of the GDPR and the applicable national data protection laws is:
Company: SkyAlps Holidays GmbH/srl
Legal form: Limited liability company (Gesellschaft mit beschränkter Haftung / Società a responsabilità limitata)
Registered office: Kornplatz 3, 39100 Bolzano, Province of Bolzano – South Tyrol, Italy
Company register no.: BZ-239461
VAT ID: IT03187850213
Managing Director: Giovanni Cocco
E-mail: info@skyalps-holidays.com
Phone: +39 0472 978 101
Website: www.skyalps-holidays.com
If you have any questions about data protection, please contact us at the address shown above.
2. Type and Source of Personal Data
We process personal data that we receive through different channels:
- Data you provide to us directly – e.g. when making a booking, submitting an enquiry via our website, by e-mail or telephone, or as part of a job application
- Data collected automatically when you visit our website – e.g. through cookies and similar technologies
- Data we receive from third parties – e.g. from partner hotels, travel agents, payment service providers, or our group airline SkyAlps S.r.l.
Further details on the individual categories of data, their source and the purposes of processing can be found in the following sections.
3. Categories of Personal Data Processed
As a premium inbound tour operator, we process the following categories of personal data:
3.1 Booking and Contract Data
- First and last name, date of birth, nationality
- Postal address, e-mail address, telephone number
- Travel data: travel period, destination, booked services (flight, transfer, hotel, add-ons)
- Payment data: bank details, credit card data (encrypted), payment history
- Booking reference numbers and contract documents
3.2 Special Categories of Data (Art. 9 GDPR) – only with explicit consent
- Health-related information (e.g. dietary requirements, allergies, disabilities) – only to the extent necessary for the provision of the trip and with consent
- Religious requirements (e.g. meal preferences) – only with consent
3.3 Website and Communication Data
- IP address, browser type, operating system, referrer URL
- Date and time of access, pages viewed
- Contact form entries, e-mail correspondence, chat transcripts
- Newsletter sign-up data (e-mail, opt-in timestamp)
3.4 Partner Data (Hoteliers, Agencies)
- Company name, legal form, company register number
- Name and contact details of contact persons
- Bank details for commission and payment processing
- Contract documents and correspondence
3.5 Job Application Data (Careers)
As part of recruitment processes (e.g. via our careers page, by e-mail or post), we process:
- Name, contact details, CV, cover letter, certificates and proof of qualifications
- Information on professional experience and, where provided, salary expectations
- Where provided by the applicant or required as part of the selection process: special categories of personal data (e.g. health data in case of disability) – only with explicit consent or where legally required
- In individual cases: publicly accessible professional profiles (e.g. LinkedIn), to the extent this is relevant and proportionate for assessing professional suitability
The legal basis is Art. 6(1)(b) GDPR (entering into an employment relationship) or Art. 9(2)(a) GDPR for special categories. For retention periods, see Section 7.
3.6 Data of Third Parties (e.g. Fellow Travellers)
If, as part of a booking, you provide data relating to other persons (e.g. fellow travellers, family members), you confirm that you are authorised to disclose this data and that you have informed the persons concerned about this privacy policy. This data is processed exclusively for entering into and performing the travel contract (Art. 6(1)(b) GDPR).
4. Purposes of Processing and Legal Bases (Art. 6 GDPR)
Entering into and performing travel contracts
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
Retention period: 10 years after end of contract (tax law obligation)
Booking processing, payment processing
Legal basis: Art. 6(1)(b) GDPR
Retention period: 10 years (statutory retention, Art. 22 D.P.R. 600/1973)
Compliance with legal obligations (accounting, reporting)
Legal basis: Art. 6(1)(c) GDPR
Retention period: As required by law (5–10 years)
Customer communication and support
Legal basis: Art. 6(1)(b) / (f) GDPR
Retention period: 3 years after last contact
Direct marketing / newsletter (existing customers)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest) or consent
Retention period: Until withdrawal / unsubscription
Website operation and security (server logs)
Legal basis: Art. 6(1)(f) GDPR
Retention period: 30 days (security purposes)
Partner relationships (hoteliers, agencies)
Legal basis: Art. 6(1)(b) / (f) GDPR
Retention period: Duration of business relationship + 10 years
Health data (travel requirements) – only with consent
Legal basis: Art. 9(2)(a) GDPR
Retention period: Immediate deletion unless a legal obligation requires retention
Recruitment process (careers)
Legal basis: Art. 6(1)(b) GDPR; Art. 9(2)(a) GDPR for special categories
Retention period: 6 months after completion of the process, unless consent is given for longer retention
Automated processing for offer generation (see Section 12)
Legal basis: Art. 6(1)(b) / (f) GDPR
Retention period: Duration of the booking enquiry or contract
5. Recipients and Categories of Recipients (Art. 13(1)(e) GDPR)
As part of our business activities, we transfer personal data to the following categories of recipients:
5.1 Performance of the Travel Contract
- SkyAlps S.r.l. airline (as a group company and contractual partner)
- Partner hotels in destination areas – only booking-relevant data
- Transfer companies and ground service providers
5.2 Payment Processing
- All payment processing is handled via Pay One GmbH.
5.3 Authorities and Statutory Obligations
- Tax and financial authorities (Agenzia delle Entrate) upon legal request
- Law enforcement authorities to the extent required by law
6. Transfers to Third Countries (Art. 44 et seq. GDPR)
Personal data is only transferred to countries outside the European Economic Area (EEA) if:
- the European Commission has recognised an adequate level of protection (adequacy decision, Art. 45 GDPR), or
- appropriate safeguards within the meaning of Art. 46 GDPR are in place (in particular EU Standard Contractual Clauses), or
- one of the exceptions under Art. 49 GDPR applies (e.g. performance of a contract for trips outside the EEA).
Where your travel services include destinations outside the EEA, the transfer of data to local service providers for the performance of the contract is permitted under Art. 49(1)(b) GDPR. We will inform you of this as part of the booking process.
7. Retention Periods and Deletion
Personal data is deleted or restricted as soon as the purpose of storage no longer applies and no statutory retention obligations apply. In particular, the following periods apply:
- Booking and contract data: 10 years after end of contract (statutory retention obligation under Art. 2220 of the Italian Civil Code and D.P.R. 600/1973)
- Payment data: 10 years (tax law)
- Health and special category data: immediate deletion after completion of the trip, unless a legal obligation requires retention
- Website logs (server logs): 30 days
- Marketing data (newsletter): until withdrawal of consent or unsubscription
- Job application documents: 6 months after completion of the recruitment process (unless consent is given for longer retention)
- CCTV recordings (where applicable): 48–72 hours, except in the case of a specific incident
8. Your Rights as a Data Subject (Art. 15–22 GDPR)
As a data subject, you have the following rights against the controller. Please direct all requests to the contact address given in Section 1.
8.1 Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation of and access to the personal data we hold about you (categories, purposes, recipients, retention period, source of the data).
8.2 Right to Rectification (Art. 16 GDPR)
You have the right to obtain, without undue delay, the rectification of inaccurate personal data or the completion of incomplete personal data.
8.3 Right to Erasure (Art. 17 GDPR – "right to be forgotten")
You have the right to erasure of your data, in particular where the purpose of processing no longer applies, consent has been withdrawn, or the processing was unlawful. This right does not apply where statutory retention obligations exist.
8.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request the restriction of processing, e.g. while the accuracy of your data is being verified or while an objection is being considered.
8.5 Right to Data Portability (Art. 20 GDPR)
For data you have provided to us on the basis of consent or a contract, you have the right to receive it in a structured, machine-readable format or to have it transferred to another controller.
8.6 Right to Object (Art. 21 GDPR)
You have the right to object at any time to the processing of your personal data carried out on the basis of legitimate interest (Art. 6(1)(f) GDPR) – in particular for direct marketing purposes. Once you object to direct marketing, your data will no longer be processed for that purpose.
8.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where processing is based on consent, you have the right to withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
8.8 Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent data protection supervisory authority:
Italy (primary jurisdiction): Garante per la protezione dei dati personali · Piazza Venezia 11, 00187 Rome
www.garanteprivacy.it | urp@gpdp.it
Germany / Austria: If you reside in Germany or Austria, you may also contact the data protection authority responsible for your region.
9. Cookies and Tracking Technologies
Our website uses cookies and similar technologies. In particular:
9.1 Strictly Necessary Cookies
These cookies are required for the operation of the website and cannot be disabled. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).
ASP.NET_SessionId / PHPSESSID
Provider / Purpose: Own website – session management, cart/booking flow
Retention: End of session
cookie_consent_status
Provider / Purpose: Own website – storing cookie consent
Retention: 6–12 months
XSRF-TOKEN / CSRF-Token
Provider / Purpose: Own website – protection against cross-site request forgery
Retention: End of session
lang / currency
Provider / Purpose: Own website – language and currency settings
Retention: 12 months
9.2 Analytics and Tracking Cookies (consent-based)
Where we use analytics tools (e.g. Google Analytics, Matomo), this only takes place with your explicit consent via our cookie banner. Legal basis: Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future.
_ga, _ga_*
Provider / Purpose: Google Analytics – distinguishing website visitors
Retention: up to 14 months
_gid
Provider / Purpose: Google Analytics – distinguishing website visitors
Retention: 24 hours
_gat
Provider / Purpose: Google Analytics – throttling request rate
Retention: 1 minute
Further information on data processing by Google can be found in Google's privacy policy (policies.google.com/privacy).
9.3 Marketing Cookies (consent-based)
For remarketing and personalised advertising, we use [NAME TOOLS] only with your consent.
10. Technical and Organisational Measures (Art. 32 GDPR)
SkyAlps Holidays GmbH/srl takes appropriate technical and organisational measures to protect personal data, including:
- SSL/TLS encryption for all data transmissions (HTTPS)
- Access control and role-based permission management
- Pseudonymisation and encryption of sensitive data categories
- Regular data backups and tested recovery procedures
- Staff training and awareness programmes
- Confidentiality obligations for all employees and data processors
- Internal obligation to report data breaches within 24 hours (Art. 33 GDPR: notification to the supervisory authority within 72 hours)
11. Data of Minors
Our services are not directed at persons under the age of 18. Where data of minors must be processed as part of family bookings, this is done exclusively for the performance of the contract and with the explicit consent of a parent or legal guardian. Parents and legal guardians may request the deletion of a minor's data at any time.
12. Automated Decision-Making and Profiling (Art. 22 GDPR)
As part of our automated pricing system (dynamic pricing), automated processing is used to calculate daily travel prices. This processing is based on general factors such as demand, availability and travel period, and does not relate to individual characteristics of specific persons.
Automated decision-making within the meaning of Art. 22 GDPR – i.e. a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects the data subject – does not take place. Should this change in the future, we will inform you separately and grant you the rights provided for by law, in particular the right to obtain human intervention, to express your point of view, and to contest the decision.
13. Changes to this Privacy Policy
We reserve the right to update this privacy policy to reflect changes in the law, technology or our business processes. The current version is always available on our website. In the event of material changes, registered users and contractual partners will be informed separately.