Legal
Privacy & Cookie Policy
Pursuant to Regulation (EU) 2016/679, Legislative Decree 196/2003 as amended, and Regulation (EU) 2024/1689.
1. Data controller
Sierra Hospitality Group S.r.l., with registered office at Piazzetta Umberto Giordano 2, 20122 Milano (MI), Italia, P.IVA and C.F. 13994050964, REA MI‑2755236 (the "Controller"), processes personal data collected through this website in accordance with Regulation (EU) 2016/679 ("GDPR") and applicable Italian law. The Controller may be reached in writing at the registered office or at investment@sierrasignature.com.
2. Categories of data processed
Browsing data acquired by the systems that operate this website in the course of their normal functioning, including IP addresses, request timestamps and technical parameters of the browser and device; data voluntarily provided through the contact, reservation and investor forms, including name, email address, telephone number, requested dates and cities, and the content of the message; and consent records relating to the use of cookies.
3. Purposes and legal bases
Data is processed to respond to enquiries and manage reservation requests, on the legal basis of pre-contractual and contractual measures under Art. 6(1)(b) GDPR; to ensure the security, stability and abuse prevention of the website, including rate limiting of the request endpoints, on the legal basis of the Controller's legitimate interest under Art. 6(1)(f) GDPR; to comply with legal obligations connected to hospitality and corporate law under Art. 6(1)(c) GDPR; and, only where consent has been given, to measure aggregate audience and performance through analytics instruments under Art. 6(1)(a) GDPR.
4. Cookies and similar technologies
The website uses strictly necessary technical cookies, which are essential for navigation, security and the memorisation of your consent choices; these do not require consent pursuant to Art. 122 of the Italian Privacy Code. Subject to your consent expressed through the banner, the website may use first party analytics instruments configured to collect aggregate and non-identifying measurements of traffic and performance. No advertising cookies, no cross-site tracking and no sale of personal data take place. Your choice is stored locally on your device and may be modified or withdrawn at any time by clearing the site data of your browser, after which the banner will be presented again.
5. Analytics
Analytics measurements, where consented, are used exclusively to understand how the website performs and how its contents are read, in aggregate form. The resulting statistics do not permit the identification of individual visitors and are retained only for the time necessary to the stated purpose.
6. Artificial intelligence transparency
In accordance with Regulation (EU) 2024/1689 on artificial intelligence (the "AI Act"), the Controller informs users that Sierra operates proprietary artificial intelligence systems as an internal operational layer of its hospitality services, including conversational assistance available to guests around the clock. Wherever a user or guest interacts with such a system, the artificial nature of the interlocutor is clearly disclosed. These systems operate under human oversight, are not used for biometric identification, social scoring or emotion recognition, and are never used to take automated decisions that produce legal effects or similarly significant effects on individuals within the meaning of Art. 22 GDPR. Guest-facing decisions remain the responsibility of Sierra's personnel.
7. Recipients
Data may be disclosed to service providers acting as processors under Art. 28 GDPR, including hosting and infrastructure providers and the transactional email provider used to deliver form submissions, all bound by confidentiality and data processing agreements. Data may further be disclosed to public authorities where required by law, including the obligations of hospitality operators. Data is not sold and is not disclosed for third party marketing.
8. Transfers outside the European Economic Area
Where technical providers process data outside the EEA, transfers take place on the basis of adequacy decisions of the European Commission or of the standard contractual clauses approved by the Commission, with supplementary measures where appropriate.
9. Retention
Browsing and security data is retained for the time strictly necessary to the purposes described. Data provided through forms is retained for the time necessary to handle the enquiry and for the applicable statutory limitation periods where a contractual relationship follows. Consent records are retained as evidence of compliance.
10. Your rights
You may at any time exercise the rights provided by Arts. 15 to 22 GDPR, including access, rectification, erasure, restriction, portability and objection, and you may withdraw any consent given without affecting the lawfulness of processing carried out before withdrawal, by writing to the Controller at the registered office or at investment@sierrasignature.com. You also have the right to lodge a complaint with the Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Roma.
11. Updates
This policy may be updated to reflect regulatory or operational changes. The version published on this page is the version in force. Last updated: August 2026.
