Last updated: 30 September 2026
This translation is provided for convenience. If it differs from the Italian text, the Italian text prevails.
This policy explains how DolceVita Hospitality S.r.l. handles the personal data of people who visit this website, of hotels that ask to try KMBRLY and of the customers who use it, under articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
1. Who is responsible
The data controller is DolceVita Hospitality S.r.l., Via Larga 8, 20122 Milano (MI), Italy, VAT number 04013770138.
For anything about your data, write to info@dolcevitahospitality.com. Our certified email (PEC) is gtosrl@ultracert.it.
2. Two different roles
For the data of this website, of access requests and of the people who sign and manage a contract for a hotel, we are the controller: we decide why and how the data is used.
For the data a hotel enters into KMBRLY about its own staff — shifts, debriefs, observations, recognitions, levels — the controller is the hotel, which decides what is recorded and why. We process that data on the hotel’s behalf as its processor (art. 28 GDPR), under a data processing agreement signed with the hotel and only on its instructions.
If you work at a hotel that uses KMBRLY, the notice that concerns you is your hotel’s. In the app, the “Your data” page shows what KMBRLY records about you and lets you download all of it.
3. What we use, why, and on what legal basis
- Browsing this website. The servers automatically record the IP address, date and time, the page requested, the browser and the operating system, to deliver the site and protect it from abuse. Legal basis: our legitimate interest in running the site securely (art. 6.1.f). We use no analytics, advertising or profiling tools.
- Requests to try KMBRLY. Name and surname, email, telephone (optional), hotel, city, number of rooms and language, to answer you and organise the trial. Legal basis: steps taken at your request before a contract (art. 6.1.b). To limit abuse we also keep a one-way fingerprint (hash) of the network address the request came from, never the address itself (art. 6.1.f). Without the required fields we cannot contact you.
- Requests for the demo. Name and surname, work email, telephone, role, hotel or group, city, how you would like to see the demo and language, to decide on the request, send you a personal link to the demo and, if you ask for it, arrange the call. We also record when the link is used. Legal basis: steps taken at your request before a contract (art. 6.1.b). To limit abuse we keep a one-way fingerprint (hash) of the network address, never the address itself (art. 6.1.f). We accept only work addresses; without the required fields we cannot give you the demo.
- Customer accounts. When a hotel activates KMBRLY, we process the data of the people who activate and administer it — name, work email, sign-in credentials (the password is stored only in encrypted form), language and role — to provide the service and manage the contract (art. 6.1.b), and the administrative and tax data the law requires us to keep (art. 6.1.c).
- Service emails. Messages the service needs in order to work: confirming an address, resetting a password, notices about the account. We do not send newsletters or promotional email.
- Messages you send us. If you write to us, we use your details to answer (art. 6.1.b or 6.1.f).
4. The demo
The website shows a demonstration hotel whose people and figures are invented. The public demo logins are shared with other visitors: do not type real personal data into the demo.
5. Where the data is kept and who handles it for us
The website and the app are hosted by Vercel Inc. in its Frankfurt region (Germany). The database is run by Supabase Inc. on Amazon Web Services infrastructure in Frankfurt. Service emails are sent through Resend. These suppliers process the data on our behalf as processors, under contracts that meet art. 28 GDPR.
Some of these suppliers are based in the United States and may access data from there, for example to provide technical support. Such transfers are protected by the standard contractual clauses approved by the European Commission and, for suppliers certified under it, by the EU–US Data Privacy Framework (articles 45 and 46 GDPR).
Data may also reach our accountants and legal advisers, who are bound to confidentiality, and public authorities where the law requires it. We never sell personal data.
6. How long we keep it
- Technical logs: for as short a time as the service allows, and no longer than 30 days, unless they are needed to investigate an abuse.
- Access requests and demo requests: deleted automatically, by a monthly check, once 24 months have passed since the request. If the request becomes a contract, what the contract needs is kept with the contract.
- Contract, invoicing and tax records: ten years, as Italian law requires (art. 2220 of the Civil Code).
- Customer accounts: for as long as the contract lasts. When it ends, the hotel’s data is returned or deleted as the data processing agreement provides.
7. How we protect it
Every connection is encrypted. Access is limited by role, and the rules on who may read what are enforced by the database itself, not only by the screens. Only the people who need data to do their job can reach it.
8. Your rights
You may ask to access your data, to have it corrected or deleted, to restrict its use, to receive it in a portable format and to object to its use (articles 15–22 GDPR). Write to the address in section 1; we answer within one month.
For data we process on a hotel’s behalf, we pass your request to the hotel and help it answer.
You also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it.
9. Changes
If this policy changes, we publish the new version on this page with its date.