Skip to main content

Privacy Policy


Casa Newton has a strong commitment to providing excellent service to all of its Guests, including respecting your concerns about privacy.
We understand that you may have questions about how We collect and use the information that you provide to Us.
We have, therefore, prepared this statement to inform you of the privacy principles – in accordance with EU Regulation no. 2016/679 (GDPR) – that govern the use that We make of information We obtain from our Guests through our website, e-mail or in paper form, at what conditions We may disclose this information to third parties and how We keep it confidential.
Any questions regarding our Policy and the processing of personal data may be directed by e-mail to Answers will be provided within 7 business days.

  1. What does this Privacy Policy cover?
    This Privacy Policy explains how We process the Personal Data We collect about you:
    • when you make a booking at Casa Newton
    • when you stay at Casa Newton
    • when you use our website or otherwise interact with Us (for example, through social media).

    By agreeing to this Privacy Notice, you understand and acknowledge that We will collect and use Personal Data as described herein.

  2. Who We are and how to contact Us – Data Controller
    Casa Newton (also, “We”, “Us”) is owned by Fabbrica Pienza Soc. Agr. Semplice, with registered offices in Loc. Borghetto, snc, Pienza (SI), VAT and Italian tax code no. 0134795052.
    When you stay at Casa Newton, We will process your Personal Data as independent Data Controller. The processing of data related to our website takes place at the registered offices and/or at the company that physically holds the domain placed “in hosting”, namely Infomaniak SA in Geneva, Switzerland.

  3. What Personal Data do We collect?
    Personal Data means any information or pieces of information that could identify you directly (e.g., your name) or indirectly (e.g., through your email address or telephone number). Personal Data may include a name, an (e-mail) address, a telephone number, credit card information, booking details, preferences, age, gender, health-related data (allergies, etc.), or occupation, among other things.
    The Personal Data that We collect, and how We collect it, depends on how you interact with Us. Generally, We process Booking Data and Guest Data:
    - Booking Data means all information pertaining to a booking made with Us, regardless of the booking channel you used (e.g., via our website, directly with Us). Examples of Booking Data include your contact details, booking details (number, dates of your stay, rate, etc.), personal preferences or billing/financial information;
    - Guest Data means all information pertaining to you as a guest who stayed or is staying with Us. Guest Data may include your contact details, biographical information (such as your gender and birth date), booking history, personal preferences, claims and complaints you have made or marketing communication preferences.

  4. How do We collect your Personal Data?
    We might collect or receive Personal Data from you via our website, social media channels, or when you stay at Casa Newton. Sometimes you give this Personal Data to Us directly (e.g., when you check-in or check-out, when you contact Us), and sometimes We collect it (e.g., using cookies to understand how you use our website).
    In some circumstances, We may also receive Personal Data about you from third-party sources such as booking platforms, travel agents and/or credit card providers.
    These third-party sources may also include publicly available sources of information. In particular, We may receive or collect Personal Data from social networks when you engage with our content, or from online platforms when you provide a review about your stay and/or our services (e.g., on,, Google, etc.).

  5. How We use your Personal Data (legal basis for processing your Personal Data)
    We process your Personal Data based on the following legal grounds, as permitted by applicable law:
    - to fulfil our obligations under a contract with you, or to take steps prior to entering into a contract with you (e.g., when you make a booking with Us);
    - to comply with a legal obligation (e.g., when you check-in, We may need to collect your personal identification details; when you check-out, We need to keep your transaction information to comply with our tax and financial reporting);
    - when it is in our legitimate business interest to use your Personal Data (e.g., to operate, evaluate and improve our organization; to prevent and protect Us and others against fraud, unauthorized transactions, claims and other liabilities; to ensure compliance with company policies and industry standards);
    - based on your consent (e.g., when you opt in to subscribe to our marketing preferences)
    Our use of your Personal Data depends on who you are and how you interact with Us.
    We will only process special categories of Personal Data (e.g., race or ethnicity) when you request Us to do so (i.e., when We have your explicit consent) or in exceptional circumstances and where We have a legal basis to do so (e.g., to protect your vital interests).
    Please contact if you have any questions about how We collect and use your Personal Data.

  6. Transferring your Personal Data
    You understand and agree that We may transfer Personal Data to other jurisdictions as necessary for the purposes described in this Privacy Policy and Notice.
    We may transfer your data to Infomaniak SA in Geneva, Switzerland, where our main servers are located.
    When We transfer your Personal Data to other countries or jurisdictions, We will protect that data as described in this Privacy Policy and Notice and in accordance with applicable law. Where required under applicable law, We will put in place binding contractual obligations with the data recipient to safeguard your data protection rights. Furthermore, We will notify any data transfer and/or data transfer mechanisms to the competent Supervisory Authority where required under applicable law.

  7. Sharing your Personal Data
    When We share your Personal Data as described below, We will take the necessary steps to ensure that any third-party recipients have implemented reasonable security mechanisms to protect your Personal Data.
    a) We do not disclose your Personal Data to third parties for their own direct marketing purposes. However, if you direct Us to share your Personal Data with third-party sites or platforms, such as social networking sites, these third-party sites or platforms could potentially use your data for marketing reasons.
    b) We may share your Personal Data to our trusted third-party suppliers who may process it on our behalf
    We rely on trusted third parties to perform a range of business operations on our behalf. We always use our best efforts to ensure that all third parties We work with will keep your Personal Data secure. We only provide them with the information they need to perform the service, and We require that they do not use your Personal Data for any other purpose. For example, We may entrust services that require the processing of your Personal Data to:
    - suppliers that provide customer care assistance for bookings, complaint handling, etc.;
    - third parties that assist and help Us in providing digital services (such as online check-in), identity management, or ratings, reviews and surveys;
    - advertising, marketing, digital and social media agencies to help Us deliver advertising, marketing, and campaigns, to analyse their effectiveness;
    - third parties that assist and help Us in providing IT services, such as platform providers, hosting services, maintenance and support on our databases as well as on our software and applications;
    - payment service providers for the purpose of verifying your details where this is a condition of entering into a contract with you;
    - lawyers, auditors, financial advisors, and other third-party service providers in connection with their services to Casa Newton.
    c) We may also disclose your Personal Data to other third parties.
    We may disclose your Personal Data to any regulatory, statutory, governmental or other relevant authorities, agencies or bodies and industry regulators, and any other person to whom Casa Newton is compelled, required or permitted to do so by law, rules or regulations, legal process or litigation, or to any person pursuant to any order of a court of competent jurisdiction or comparable legal process.

  8. Cookie policy
    Our website uses cookies, which are small text files that can be used by websites to make a user’s experience more efficient.
    We can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, We need your permission.
    You can choose to accept and agree to this use, or you can manage your settings to adjust your choices. You can change your mind any time by returning to this site. If you do not allow certain cookies some areas of this site may not function as intended.

  9. How We protect your Personal Data
    We protect your Personal Data and implement reasonable security measures including physical (e.g., secured filing cabinets), technical and organizational security measures appropriate to protect your Personal Data against unauthorized or unlawful processing and against any accidental loss, destruction, or damage.
    In particular, We operate data networks and systems protected by industry standard security measures and We make use of secure protocols over untrusted networks to protect the transmission of your Personal Data. Access to this information will be provided only to authorized individuals for legitimate business purposes.
    In addition, access to your Personal Data is restricted to staff and service providers on a need-to-know basis.
    While We endeavour to always protect our systems, sites, operations and information against unauthorized access, use, modification and disclosure, due to the inherent nature of the Internet as an open global communications vehicle and other risk factors, We cannot guarantee that any information, during transmission or while stored on our systems, will be absolutely safe from intrusion by others.
    Please contact if you have any questions about how We protect your Personal Data.

  10. How long do We keep your Personal Data?
    We hold on to your Personal Data for as long as necessary to achieve the processing purposes described above.
    This means, for instance, that We no longer store your Personal Data when our (contractual) relationship with you comes to an end, unless further storage is permitted or required under applicable law.
    To determine the retention period of your Personal Data, We consider several criteria, including:
    - the purpose for which We hold your Personal Data;
    - our legal and regulatory obligations in relation to that Personal Data, for example any financial reporting obligations;
    - whether our relationship with you is ongoing (for example, you have an active Member account, you continue to receive marketing communications, or you regularly browse our Website or Apps);
    - any specific requests from you in relation to the deletion of your Personal Data; and
    - our legitimate interests in relation to managing our own rights, for example the defence of any claims.
    When We no longer need to use your Personal Data, it is removed from our systems and records, or anonymized so that you can no longer be identified from it.

  11. What are your rights regarding your Personal Data?
    The EU General Data Protection Regulation (GDPR) grants specific rights, summarized below, which you can in principle exercise free of charge, subject to statutory exceptions. These rights may be limited, for example if fulfilling your request would reveal Personal Data about another person, or if you ask Us to delete information which We are required by law to keep or have compelling legitimate interests in keeping. Generally, you have the following rights:
    - Information. You have the right to be provided with clear, transparent, and easily understandable information about how We use your Personal Data, and your rights. This is why We are providing you with the information in this Privacy Policy and Notice;
    - Rectification. You have the right to require that any incomplete or inaccurate Personal Data that We process about you is amended;
    - Deletion. You have the right to request that We delete Personal Data that We process about you, subject to certain exceptions, for instance, where We need to keep your Personal Data to comply with a legal obligation;
    - Withdrawing Consent. Wherever We rely on your consent, you will be able to withdraw that consent at any time you choose by contacting Us at The withdrawal of your consent will not affect the lawfulness of the collection and processing of your data based on your consent up until the moment when you withdraw your consent. Please note that We may have other legal grounds for processing your data for other purposes, such as those set out in this Privacy Policy and Notice;
    - Access. Subject to certain exceptions, you have the right to access and request a copy of the Personal Data We are processing about you, which We will provide to you in electronic form and/or in writing;
    - Restriction. You have the right to request that We restrict our processing of your Personal Data under specific conditions;
    - Portability. You have the right to obtain portability of data, i.e., receive them from a data controller, in a structured, commonly used, machine-readable format, and transmit them to another data controller without hindrance;
    - Objection. You have the right to object to automated decision-making related to natural persons, including profiling;
    - Complaint. You have the right to file a complaint to a supervisory authority.

    You can exercise the above rights, where applicable, by contacting We will respond to any of your requests to exercise these above data subject rights within the period prescribed by applicable laws. At our discretion, We may require you to prove your identity before providing the requested information. This is to ensure that your Personal Data is disclosed only to you. We may not be able to appropriately handle your request if you decide not to provide Us with the Personal Data that We need to handle your request. If you are a resident of the European Economic Area and are not satisfied with the way We handled your request, or for violations of applicable data protection laws, you may lodge a complaint or file a claim with the Italian Data Protection Authority (Garante per la protezione dei dati personali).

  12. Your marketing choices
    You can control whether to receive direct marketing from Us (e.g., which We may send through electronic means, such as promotional emails). You will need to provide Us with your consent before receiving marketing communications (for instance, We may ask you to tick a box indicating that you consent to receiving “news via email and commercial offers”). You can choose not to receive such communications at any time. If you no longer wish to receive any marketing communications or remain on a mailing list to which you previously subscribed, please follow the unsubscribe link in the relevant communication.

  13. Your obligations
    We expect that you only communicate Personal Data about yourself to Us. If you also communicate Personal Data about other people to us, then you must ensure that you comply with any legal obligations that may apply to your provision of the information to Us, and to allow Us, where necessary, to use, process and transfer that information. We also expect that the Personal Data that you communicate to Us are correct and that, if your Personal Data require updating, you will promptly inform Us.

  14. Children
    We do not knowingly collect or solicit Personal Data from anyone under the age of 18 or knowingly allow such persons to book a room at Casa Newton. In the event We learn that We have collected Personal Data from a child under the age of 18 without verification of parental consent, steps will be taken promptly to remove that information.
    If you believe that We have or may have information from or about a child or a persona under 18 years of age, please contact Us at

  15. Changes to the Privacy Notice
    We may update this Privacy Policy and Notice from time to time. We will notify you of any significant changes by posting those changes here or by notifying you through other appropriate communication channels We generally use with you. Any changes to this Privacy Notice will be considered effective immediately after the changes are posted on this website unless otherwise indicated.