PrenotaTU
Privacy Policy
This policy explains how PrenotaTU processes personal data collected through the website, landing page, contact forms, commercial requests, registration and use of the SaaS platform.
Version 1.1 — last updated: July 23, 2026.
1. Controller
The controller is Mancuso Milite Francesco, sole trader and owner of PrenotaTU, VAT no. 06449790655, tax code MNCFNC96D18C361C, REA SA-524255, registered office at Via Gaetano Filangieri 132, 84013 Cava de' Tirreni (SA), Italy, emailinfo@prenotatu.com and certified emailmancusomf@pec.it.
2. Privacy roles in the SaaS service
For end-user, staff, employee and collaborator data entered by a Business Customer/Merchant, the Business Customer/Merchant normally acts as controller and PrenotaTU acts as processor, processing such data on behalf of the Merchant under aData Processing Agreement or equivalent appointment.
PrenotaTU acts as independent controller for commercial relationship data, billing, account management, security, contractual, administrative and pre-contractual communications.
3. Data processed
- identity and contact data, including name, email, phone, role and submitted messages;
- business and billing data, including company name, VAT number, tax code, address, certified email and billing codes;
- account and usage data, including credentials, plan, access logs, settings, permissions and consents;
- technical and analytics data, including IP address, user agent, visited pages, app screens, security logs, diagnostics, crashes and performance data;
- platform data, including services, hours, staff, bookings, images, descriptions and end-user data entered by the Merchant;
- support data, including tickets, messages, attachments, reports, assistance requests and communication history;
- AI data, including prompts, strictly necessary tenant context and outputs processed transiently to provide the requested feature, without storing content in the PrenotaTU database;
- geographic data, including addresses, cities, coordinates and data needed for geocoding, maps or nearby-business search;
- payment and billing data managed directly by PrenotaTU or authorized third-party providers;
- cookie preferences, analytics/marketing consents and banner interactions.
4. Purposes and legal bases
- responding to contact or demo requests: pre-contractual steps or legitimate interest;
- creating accounts, managing plans, support and SaaS features: contract performance;
- invoicing, payments, renewals and tax obligations: legal obligation and contract performance;
- security, abuse prevention and diagnostics: legitimate interest and security obligations;
- analytics, performance, crash reporting, funnels, campaigns and service quality: consent where required or legitimate interest for necessary and aggregate technical data;
- AI assistant and operational automations requested by the Customer: contract performance or pre-contractual steps;
- geocoding, maps, area search and public business pages: contract performance or legitimate interest.
5. Recipients and Providers
Data may be processed by authorized personnel and technical, administrative or professional providers, including hosting, cloud infrastructure, databases, email, push notifications, payment providers, analytics, AI tools, authentication systems, maps, geocoding, support and professional advisors. Providers may include Amazon SES or equivalent email providers, Firebase/Google, PostHog Cloud EU, OpenRouter and selected model providers, authorized hosting, security and traffic-delivery providers, OpenStreetMap/Nominatim and payment or billing providers identified in the applicable documents. The operational list is available on theSubprocessors page.
6. Retention
Contact and demo requests are kept for up to 24 months after the last contact, unless the data subject objects. Technical and security logs are kept for up to 12 months, support tickets for up to 24 months after closure, PostHog events for no longer than 12 months and Crashlytics data normally for 90 days. AI prompts and outputs are processed transiently with Zero Data Retention and are not stored in the PrenotaTU database. After termination, active tenant data is deleted or anonymized within 60 days and encrypted backups within a maximum 90-day cycle, subject to legal retention requirements.
7. International Transfers
Some providers may process data outside the European Economic Area. Where applicable, PrenotaTU uses adequacy decisions, standard contractual clauses, the Data Privacy Framework, supplementary measures or other GDPR safeguards.
8. Rights
Where provided by the GDPR, you may request access, rectification, erasure, restriction, objection, portability and withdrawal of consent. You may also lodge a complaint with the competent supervisory authority. For data processed on behalf of a Business Customer/Merchant, the request may need to be handled by that Merchant as controller.