1. Controller and contacts
The data controller is Eager S.r.l., which operates the Heart of Sardinia platform.
Controller
Eager S.r.l.
S.V. Baddimanna Filigheddu 73, 07100 Sassari (SS), Italy
2. Scope and categories of data processed
We only process the data needed to provide the platform, handle bookings and payments, comply with
legal obligations, prevent abuse and, where you allow it, measure or monetise website traffic.
Common data
- Identification and account data: name, email, username and profile data if you register.
- Booking data: selected service, date, time slot, quantity, tickets, QR codes and notes you provide.
- Administrative and payment data: outcome, amount, transaction identifiers and tax details where needed.
- Support communications: messages, attachments and contact details sent to customer support.
- Technical and security data: IP address, user agent, application logs, timestamps and error events.
Online and usage data
- Cookie preferences and technical identifiers required to run the website.
- Browsing data connected to visited pages and requests sent to integrated services.
- Location data only if you use a feature that needs geolocation and you grant the permission.
- Third-party feature data when you open pages that embed maps, anti-spam tools or payment components.
3. Purposes and legal bases
- Providing the service: account management, catalogue, bookings, tickets and operational communications. Legal basis: contract or pre-contractual steps.
- Payments and administration: payment handling, refunds, accounting and tax compliance. Legal basis: contract and legal obligations.
- Security, fraud prevention and business continuity: logs, technical checks, abuse prevention and legal defence. Legal basis: legitimate interest and, where applicable, legal obligations.
- Customer support: handling requests, complaints, reports and booking recovery. Legal basis: contract and legitimate interest.
- Chat and online assistance: availability of the ChatData widget only after marketing consent; handling messages sent by the user as support requests. Legal basis: consent for loading the widget, contract or legitimate interest for the reply.
- Website analytics: traffic measurement tools enabled only after consent. Legal basis: consent.
- Website advertising: ad delivery and measurement by third-party providers, only after consent. Legal basis: consent.
- Device permissions and mobile features: notifications, location and access to photos or camera only where a specific function requires them and you authorise them. Legal basis: consent or performance of the requested feature.
4. Website section
The public website currently integrates measurement, advertising, chat, mapping, anti-spam and payment services.
Cookies and tracking tools
We use a banner that allows you to accept, refuse or customise non-essential cookies. Until you give
consent, only the technical tools needed to run the website and remember your choice remain active.
See the Cookie Policy for details.
Services verifiable on the website
- Google Analytics 4: website traffic measurement after consent.
- Google AdSense: ad delivery and measurement after consent.
- ChatData: assistance/chat widget loaded only after marketing consent.
- Google Maps: maps and page-specific location features.
- Google reCAPTCHA: anti-spam protection on forms that use it.
- Stripe and Worldline: payment flows at checkout; PayPal components are also present in parts of the infrastructure/back office.
- Google Fonts and Font Awesome: third-party visual assets loaded from external CDNs.
5. App section
The mobile app may process the data needed for account access, bookings, tickets, payments, support
requests and device-based functions. The exact list of third-party services and SDKs may change depending
on the iOS/Android build and the release actually installed.
Data that may be processed in the app
- Account and booking data: login data, profile data, booking history, tickets and QR codes.
- Device identifiers and technical tokens: where required for session security or notifications.
- Location data: only for distance, map or nearby features and only if you authorise it.
- Diagnostic data: technical events, crash information or support reports sent through the app.
- Payment-related data: processed mainly by payment providers; our systems usually keep only the outcome and the transaction references required for administration.
Device permissions
- Notifications: optional, for operational messages or booking updates.
- Location: optional, for maps and distance-based functions.
- Photos, storage or camera: optional, only where a specific feature needs them.
6. Recipients and main supplier categories
- Booked service operators: receive the data needed to perform the booking or the purchased service.
- Payment providers: Stripe, Worldline and, where enabled for specific flows, PayPal.
- Website technology providers: Google services for analytics, advertising, maps, fonts or anti-spam; ChatData for the assistance/chat widget; CDNs and external libraries where present.
- Infrastructure and hosting suppliers: entities hosting or supporting the platform, email or technical systems.
- Authorised staff and advisers: internal staff, system administrators and advisers where necessary.
- Public authorities: where disclosure is required by law, an official order or to protect rights.
7. Extra-EEA data transfers
Some technology and payment providers may process data outside the European Economic Area. In those
cases, the transfer takes place under Articles 44-49 GDPR, for example on the basis of an applicable
adequacy decision or Standard Contractual Clauses with any required supplementary measures.
8. Retention periods
- Account data: for as long as the account remains active and, afterwards, for the time needed to handle disputes or residual obligations.
- Booking and administrative data: for the time needed to provide the service and, where required for accounting or tax purposes, up to 10 years.
- Technical logs and security data: for the period strictly needed for security, audit and abuse prevention, unless further retention is required because of incidents or legal obligations.
- Cookie preferences: until their technical expiry or until you withdraw or change your choice.
9. Data subject rights
You may exercise the rights available under Articles 15-22 GDPR, where applicable: access, rectification,
erasure, restriction, portability, objection and withdrawal of consent. You also have the right to lodge a
complaint with the Italian Data Protection Authority.
10. Policy updates
We may update this policy when services, suppliers, processing operations or the applicable legal
framework change. The latest version is published on this page with the updated date.