Privacy Policy
Sicilia-Vita: Retreats and Tours
Including Immunity Kitchen experiences
Document version: v1.0
Effective date: 27/08/2026
Our approach to your privacy
Sicilia-Vita: Retreats and Tours respects the trust you place in us when you make an enquiry, book an experience or travel with us. We welcome participants from the European Union and EEA, the United Kingdom, Australia, Canada, the United States and other countries.
Although Sicilia‑Vita is based in Sicily, our community is international. We have prepared this policy with our principal guest jurisdictions in mind. Our aim is not simply to meet a minimum legal requirement, but to show clearly that we have considered where our guests come from and that we value the privacy protections and expectations relevant to them.
This Privacy Policy applies to Sicilia-Vita: Retreats and Tours and experiences offered under our Immunity Kitchen food, cooking and wellbeing brand. It explains what personal information we collect, why we use it, who may receive it, how long we keep it, and the rights and choices available to you.
It applies to our website, enquiries, bookings, retreat administration, tours, Immunity Kitchen experiences and related communications. It should be read with our Terms and Conditions and any short privacy notice shown on a particular form.
1. Who is responsible for your information
The data controller is Sicilia-Vita: Retreats and Tours by Lisa Strickland and Lori Anderson, trading as Sicilia-Vita: Retreats and Tours and Immunity Kitchen, established in Sicily at Sicilia-Vita: Retreats and Tours, Acireale, CT, Italy 95024 (“Sicilia‑Vita”, “we”, “us” or “our”).
Immunity Kitchen is a Sicilia‑Vita brand and is not a separate controller unless we expressly tell you otherwise. The owners’ nationalities do not alter Sicilia‑Vita’s establishment in Italy or its responsibility as controller.
Privacy enquiries and requests may be sent to:
Email: info@sicilia-vita.com
Postal address: Sicilia-Vita: Retreats and Tours, Acireale, CT, Italy 95024
Telephone: +1 (605) 759-4625 / +39 329 553 9502
2. Information we may collect
Depending on how you interact with us, we may collect:
- Identity and contact information: name, address, email address, telephone number, country of residence, date of birth where genuinely required, and preferred language.
- Enquiry and booking information: chosen retreat, tour or Immunity Kitchen experience, dates, party details, booking history, requests, correspondence and agreed arrangements.
- Travel information: information reasonably needed to coordinate included transport or services, such as arrival details and limited passport or identification information where legally or operationally required.
- Payment and transaction information: amounts, currency, status, invoices and limited payment references. Card or bank credentials are normally collected directly by the payment provider and are not stored by us unless expressly stated.
- Dietary, accessibility and health information: allergies, intolerances, mobility or accessibility needs, relevant medical conditions, emergency requirements and other information you choose to provide for safe participation. Some of this is legally protected health data.
- Emergency-contact information: the name, relationship and contact details of the person you nominate. You should tell that person that you have provided their information.
- Communications: emails, forms, WhatsApp communications, complaints, feedback and customer-service notes.
- Website and device information: IP address, browser and device type, operating system, pages requested, timestamps, security logs and cookie or consent choices.
- Marketing preferences: whether and how you have asked to receive news or offers.
- Images and recordings: photographs, video or audio in which you are identifiable, where captured or used with an appropriate legal basis and respect for your choices.
Please do not send full medical records, complete passport copies or information we have not requested. If more detail is genuinely needed, we will explain why and arrange an appropriate collection method.
3. How we receive information
We usually receive information directly from you through our website, email, telephone, WhatsApp, booking or payment process, or in person. We may also receive information from:
- the person who books on your behalf;
- a travel companion or emergency contact;
- a payment provider;
- an authorised travel professional or referral partner; or
- a Supplier involved in your experience.
If another person provides your information, we will provide this policy or an equivalent notice within the period required by law unless you already have it or an exception applies.
4. Why we use information and our legal bases
We use personal information only where we have a lawful reason.
| Purpose | Information commonly used | GDPR legal basis |
|---|---|---|
| Answer enquiries and take requested steps before booking | Contact details, enquiry and proposed experience | Steps before entering a contract — Article 6(1)(b) |
| Confirm and administer a booking and provide the experience | Identity, contact, booking, travel, payment status and communications | Performance of a contract — Article 6(1)(b) |
| Issue invoices, maintain accounts and meet regulatory duties | Identity, contact, transaction and booking records | Legal obligation — Article 6(1)(c) |
| Coordinate accommodation, transport, activities and Suppliers | Identity, booking, travel and necessary service details | Performance of a contract — Article 6(1)(b) |
| Manage accessibility, allergies, health or safety needs | The minimum relevant health or accessibility information | Explicit consent — Articles 6(1)(a) and 9(2)(a); in a genuine emergency, vital interests may apply under Articles 6(1)(d) and 9(2)(c) |
| Protect guests, staff, systems and property; prevent misuse; establish or defend legal claims | Contact, booking, communications, technical and incident information | Legitimate interests — Article 6(1)(f), or legal obligation/claims where applicable |
| Send requested newsletters or promotional messages | Name, contact details and preferences | Consent — Article 6(1)(a), unless a limited existing-customer rule lawfully applies |
| Use identifiable guest photographs or video for promotion | Images, recordings and permission records | Consent — Article 6(1)(a) |
| Operate, secure and diagnose the website | Device, log, security and strictly necessary cookie information | Legitimate interests — Article 6(1)(f), and necessity to provide a requested service where applicable |
| Use non-essential analytics or marketing technologies | Cookie identifiers, usage and device information | Consent — Article 6(1)(a), where required |
Our legitimate interests include operating a safe and effective retreat business, protecting guests and systems, improving services, preventing fraud or misuse, and handling legal claims. We balance these interests against the rights and reasonable expectations of the people concerned.
Where we rely on consent, you may withdraw it at any time without affecting processing that was lawful before withdrawal.
5. Health, dietary and accessibility information
Health information receives additional protection. We request only information reasonably needed to assess safe participation, make agreed arrangements or respond to an emergency. Access is limited to people who need it for those purposes.
Where health information is collected in advance, we will normally request separate, explicit consent. Accepting our general Terms and Conditions does not itself provide that consent. You may withdraw consent, but if information is genuinely required to provide an arrangement safely, withdrawal or choosing not to provide it may mean that we cannot provide that part of the experience. We will explain the practical consequence rather than pressure you to consent.
In a genuine medical emergency, necessary information may be shared with emergency responders, healthcare professionals or an appropriate Supplier to protect life or physical safety.
6. When information is required
Some information is required to answer an enquiry, form or perform a booking, comply with law, or provide a service safely. Other information is optional. Forms will indicate required information where practical.
If required information is not provided, we may be unable to confirm a booking or provide a particular service. We will explain why and identify available options.
Marketing permission, promotional-photography consent and consent to process advance health information are separate choices. They are not conditions of participation except where specific health information is genuinely necessary for safety and no reasonable alternative exists.
7. Who may receive information
We may share the minimum necessary information with:
- accommodation providers, transport operators, guides, activity providers, venues, restaurants and other Suppliers involved in the experience;
- payment, accounting, insurance and professional advisers;
- website hosting, database, email, communications, booking, security and IT-support providers acting under appropriate instructions;
- emergency responders and healthcare professionals in an emergency;
- public authorities, regulators, courts or law-enforcement bodies where disclosure is required or lawfully requested; and
- a purchaser or successor if the business is reorganised, sold or transferred, subject to appropriate safeguards.
Suppliers determining their own purposes may act as separate controllers and should provide their own privacy information. Providers acting only for us must protect information and use it only under our instructions and the law.
We do not sell personal information or share it for cross-context behavioural advertising. If that practice were ever to change, we would update this policy and provide any notice, choice and opt-out mechanism required by applicable law before the change took effect.
8. Inceptivec website hosting
Inceptivec provides Sicilia‑Vita’s managed website hosting and technical services. In that role, Inceptivec may process website, enquiry, booking, database, security-log and support information only to provide, maintain and secure the authorised service.
Inceptivec acts under written instructions and appropriate confidentiality, security, deletion and incident-management obligations. It may use approved infrastructure subprocessors to operate the site. Sicilia‑Vita remains responsible for determining why information is processed, selecting its processor and responding to participants’ rights requests.
Current information about material hosting subprocessors and processing locations may be requested through our privacy contact. This policy will be updated if Inceptivec’s role or the material provider chain changes.
9. International data transfers
We aim to use services located in the European Economic Area where practical. Some Suppliers, technology providers, authorised business personnel or recipients may be outside the EEA, particularly where a participant lives outside Europe, requests coordination with a provider elsewhere, or authorised support or administration takes place from another country.
Inceptivec’s approved infrastructure and support arrangements may involve processing in, or remote access from, countries outside the EEA. Authorised access from the United States is treated as an international transfer where GDPR requires it; it is not considered harmless merely because information remains stored on an EEA server.
Where GDPR applies and information is transferred outside the EEA, we use a lawful mechanism where required, such as an adequacy decision, approved standard contractual clauses or another lawful safeguard, with supplementary measures where appropriate. Transfers are limited to what is necessary. You may contact us for information about safeguards relevant to your information.
10. How long we keep information
We retain information only as long as needed for its purpose and applicable legal, accounting, insurance or claims requirements. Our intended periods are:
- Enquiries that do not become bookings: normally up to 12 months after the last meaningful contact.
- Booking, contract, invoice and payment records: for the period required by Italian accounting, tax and limitation law, normally up to 10 years after the transaction or relationship, unless an active claim requires longer.
- Routine retreat administration and communications: normally up to 24 months after the experience, then deleted or reduced to records required for legal purposes.
- Advance health, allergy and accessibility details: deleted or securely anonymised when no longer needed after the experience, normally within 90 days, unless an incident, duty or claim requires limited retention.
- Emergency-contact details: normally deleted no later than 90 days after the experience unless needed for an incident or claim.
- Marketing records: until consent is withdrawn or the contact has been inactive for 24 months, subject to review. A minimal suppression record may remain so we respect an opt-out.
- Promotional-image permissions and associated published material: while material remains in active use, with permission and withdrawal records retained as needed to demonstrate and manage the choice.
- Security and technical logs: normally no longer than 12 months unless required to investigate an incident or protect legal rights.
11. Cookies and similar technologies
Our website may use strictly necessary cookies or similar storage to provide requested features, preserve security and remember privacy choices. They do not require consent where genuinely necessary but are described transparently.
We do not activate non-essential analytics, advertising or tracking technologies before obtaining consent where Italian or EU law requires it. If used, the site will provide a cookie notice and controls allowing you to accept, refuse and later change choices with comparable ease.
12. WhatsApp, email and external links
If you contact us through WhatsApp or another third-party service, that provider may process account, device, communications and usage information under its own terms and privacy policy. Please avoid sending unnecessary health, identity or financial information through ordinary messaging.
External websites and services control their own privacy practices. We encourage you to review their privacy information.
13. Marketing choices
We send marketing only where permitted by law. You may unsubscribe at any time through the link in a marketing email or by contacting us. Service messages concerning an enquiry, booking, safety matter or experience are not marketing and may still be sent where necessary.
Withdrawing marketing consent does not affect a booking or experience. Marketing is also managed under applicable electronic-marketing and anti-spam rules in the recipient’s jurisdiction where those rules apply, including United States CAN-SPAM requirements for commercial email.
14. Photographs and recordings
We request separate permission before using an identifiable guest photograph, video or recording for our promotion where consent is the appropriate basis. The request will explain the intended channels and use.
You may decline without affecting participation and may withdraw permission for future use. Withdrawal does not affect earlier lawful use and may not permit recall of printed material or copies held by unrelated third parties. We will stop new uses within our control and remove or replace online material where reasonably practicable.
15. Security
We use reasonable technical and organisational measures designed to protect information against accidental or unlawful loss, alteration, access, disclosure or destruction. These include access controls, minimisation, secure service configuration, appropriate provider arrangements and procedures for suspected incidents.
No internet or storage system is completely risk-free. If a personal-data breach creates a risk requiring notice, we will notify the relevant authority and affected individuals as required by law.
16. Your data-protection rights
Subject to applicable conditions and exceptions, you may have the right to:
- receive information about our use of your information;
- request access and a copy;
- correct inaccurate or incomplete information;
- request deletion;
- request restriction of processing;
- object to legitimate-interest processing or direct marketing;
- receive certain information in a portable format and request direct transmission where technically feasible;
- withdraw consent at any time where processing relies on consent; and
- not be subject to certain solely automated decisions producing legal or similarly significant effects.
We do not currently make solely automated decisions producing legal or similarly significant effects about participants.
To exercise a right, contact info@sicilia-vita.com. We may request proportionate information to verify identity. We respond within the legally required period, normally one month under GDPR, and explain any lawful extension or restriction.
17. International participants and additional privacy laws
GDPR and applicable Italian data-protection law are our primary framework because Sicilia‑Vita is established in Sicily. We apply the core standards in this policy regardless of nationality or residence.
Additional rules may apply depending on where Sicilia‑Vita offers services, carries on business or processes information:
- European Union and EEA: rights are governed principally by GDPR and applicable national law. The Italian Garante is our lead supervisory authority unless law provides otherwise.
- United Kingdom: where UK GDPR and the Data Protection Act 2018 apply to our offering or processing, UK participants may exercise applicable UK rights and complain to the Information Commissioner’s Office.
- Australia: where the Privacy Act 1988 and Australian Privacy Principles apply to our activities, Australian participants may exercise applicable rights and complain to the Office of the Australian Information Commissioner. We do not claim that the Act applies merely because an Australian resident makes a booking; its territorial and business thresholds depend on the actual activity.
- Canada: where the Personal Information Protection and Electronic Documents Act or applicable provincial private-sector privacy law governs the activity, Canadian participants receive applicable access, correction, consent and complaint rights and may contact the Office of the Privacy Commissioner of Canada or competent provincial commissioner.
- United States: privacy and consumer-protection laws vary between states, and many apply only when particular business, revenue, processing-volume or targeting thresholds are met. Where an applicable federal or state law governs our activity, United States participants receive the rights it provides. Depending on the law, these may include rights to know or access information, correct it, delete it, obtain a portable copy, opt out of sale, sharing, targeted advertising or certain profiling, limit some uses of sensitive information, appeal a refused request, and receive equal service without unlawful discrimination. We do not claim that every United States state law applies merely because a resident makes a booking.
If applicable overseas law provides a stronger non-waivable protection, we will honour it. Even where a particular overseas statute does not technically apply because Sicilia‑Vita does not meet its commercial or territorial threshold, we will still consider a reasonable privacy request consistently with the values and protections described in this policy wherever practicable. You do not need to identify the correct statute before making a request; we will assess it under the laws that apply and respond in a clear and respectful way.
18. Complaints
We would appreciate the opportunity to address a concern first, but you may contact a competent authority without first complaining to us.
- Italy: Garante per la protezione dei dati personali
- United Kingdom, where applicable: Information Commissioner’s Office
- Australia, where applicable: Office of the Australian Information Commissioner
- Canada, where applicable: Office of the Privacy Commissioner of Canada
- United States, where applicable: the Federal Trade Commission and the relevant state Attorney General or privacy regulator, including the California Privacy Protection Agency for applicable California matters.
19. Children
Our general website and adult experiences are not directed at children. We do not knowingly collect a child’s information through an adult booking except where an experience expressly permits minors and information is supplied by or with the authority of a parent or legal guardian.
Any family or youth offering will use age-appropriate information and consent arrangements.
20. Changes to this Privacy Policy
We may update this policy to reflect changes in services, systems or legal obligations. The current version and effective date will remain on our website. If a change materially affects how we use information already collected, we will provide appropriate notice and seek consent where required.
21. Contact us
Sicilia-Vita: Retreats and Tours
Including Immunity Kitchen
Sicilia-Vita: Retreats and Tours by Lisa Strickland and Lori Anderson
Sicilia-Vita: Retreats and Tours, Acireale, CT, Italy 95024
Privacy email: info@sicilia-vita.com
Telephone/WhatsApp: +1 (605) 759-4625 / +39 329 553 9502
