Privacy Policy
Last updated: 7 July 2026
1. Who we are
This privacy policy explains how Black Quantum Hospitality (“we”, “us”) processes your personal data when you visit this website, book a stay, or use our online guest services (online check-in, digital room key, and in-stay requests). We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
Data controller: LILIT S.r.l.s., with registered office at Via F. Cordero di Pamparato 9, 10143 Torino (TO), Italy — VAT no. IT 03109640346, REA TO-1354280, operating Black Quantum Hospitality in Rimini. You can reach us for any privacy matter at Riminihotelkennedy@gmail.com or by certified email at lilit.srls@pec.it.
2. What data we collect
- Booking data — name, email address, phone number, billing address, stay dates, room and rate selection, number and ages of guests, and any special requests you add to a booking.
- Payment data — payments are handled by our payment provider Adyen. Your card details are entered in Adyen’s secure components and sent directly to Adyen; we never see or store full card numbers. We receive only a payment reference and its status.
- Online check-in data — for each adult guest: full name, date of birth, and the data required for guest registration under Italian law. If you use online identity verification, we also process a photo of your identity document and a selfie (see section 4).
- In-stay service data — requests you make through the guest area, such as cleaning requests, checkout, and billing-address changes.
- Support conversations — messages you send us through the website chat widget (Chatwoot).
- Technical and usage data — device and browser information, pages visited, and interaction events, collected only if you consent to analytics cookies (see our Cookie & Data Policy), plus error reports when something on the site breaks.
3. Why we process it (purposes and legal bases)
- To manage your booking and stay (booking, payment references, check-in, in-stay requests) — performance of a contract, Art. 6(1)(b) GDPR.
- To comply with legal obligations — Italian law requires accommodation providers to register guests and communicate their details to the State Police (Art. 109 TULPS, via the Alloggiati Web service) and to keep tax and invoicing records — Art. 6(1)(c) GDPR.
- To verify your identity during online check-in — explicit consent, Art. 9(2)(a) GDPR, because the automated face comparison involves biometric data. This is optional: see section 4.
- To understand how the site is used (analytics) — consent, Art. 6(1)(a) GDPR, given through the cookie banner and revocable at any time.
- To keep the site secure and working (error monitoring, abuse and fraud prevention) — legitimate interest, Art. 6(1)(f) GDPR.
4. Online identity verification and biometric data
Our online check-in offers automated identity verification: you photograph your identity document and take a selfie, and we verify that the two faces match and that the name on the document matches the name you entered. The comparison is performed automatically by Amazon Web Services (Amazon Rekognition for the face comparison and Amazon Textract for reading the name on the document), acting as our processor.
This involves a one-time processing of biometric data (facial geometry) solely to confirm that the person checking in is the holder of the document. The images are used only for this verification; they are not used to identify you in any other context, are not shared for any other purpose, and no biometric template is kept after the check.
Online identity verification is based on your explicit consent. If you prefer not to use it, you can always check in in person at the reception desk, where your documents are handled the traditional way.
5. Who receives your data
We share personal data only with service providers who process it on our behalf under data-processing agreements, and with authorities where the law requires it:
- Adyen N.V. — payment processing (PCI-DSS certified).
- Our property-management system — the hotel software in which bookings, guest profiles and check-in records are managed.
- Amazon Web Services EMEA SARL — hosting of this website and automated identity verification during online check-in (section 4).
- PostHog — website analytics and privacy-masked session replay, only after you consent via the cookie banner.
- Sentry (Functional Software, Inc.) — error monitoring, configured to use Sentry’s EU data region.
- Chatwoot — the website chat widget, if you choose to use it.
- Cloudflare — delivery of website images.
- Italian State Police — guest details transmitted via Alloggiati Web, as legally required for all accommodation providers in Italy.
Where a provider processes data outside the European Economic Area, we rely on an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses.
6. How long we keep your data
- Booking and invoicing records — 10 years, as required by Italian tax and accounting law.
- Guest registration data — for the period required by public security regulations.
- Identity document photos and selfies — processed for the verification and not retained afterwards.
- Analytics data — up to 12 months from collection.
- Chat conversations — up to 24 months, so we can follow up on your requests.
7. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw any consent at any time (without affecting the lawfulness of processing carried out before the withdrawal). To exercise any of these rights, write to Riminihotelkennedy@gmail.com.
You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it), or with the supervisory authority of your country of residence.
8. Security
All traffic to this website is encrypted (TLS). Guest-area access is protected by a signed, HttpOnly session cookie tied to your booking reference, and identity verification results are cryptographically bound to the exact images that were verified. Access to personal data is limited to staff and providers who need it to deliver the services described above.
9. Children
Bookings and online check-in are reserved for adults. Data about minors staying at the hotel (such as ages for rate calculation and legally required registration details) is provided by the accompanying adult and processed only for the purposes in section 3.
10. Changes to this policy
We may update this policy as our services or legal obligations change. The date at the top of the page indicates the latest revision; material changes will be highlighted on the website.