
LH HOTELS CASTELLETTO MILANO
LH HOTELS MILANO FIERA
LH HOTELS TOWER BUSTO ARSIZIO
LH HOTELS CONCORDE LAGO MAGGIORE
LH HOTELS ATLANTIC ARONA
Privacy Policy – LH Tower Hotel Busto Arsizio
Last updated: August 2026
This Privacy Policy describes how the personal data of users who visit this website is processed, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable data protection laws.
1. Data Controller
Data Controller:
Luvete Srl
Registered office: Via Asiago 19, 28066 Galliate (NO), Italy
VAT No.: 02720040035
Email: info@towerhotelbustoarsizio.it
2. Types of Data Processed
The following data may be processed through the website:
• browsing and technical data, such as IP address, device and browser type, pages visited and security data;
• cookie preferences and consent choices;
• data and content voluntarily provided when the user contacts the hotel by email or telephone.
The website does not contain contact forms and does not directly collect data entered to make a booking. The “Book now” button redirects the user to the external TeamSystem Hospitality platform, where data processing is described in the privacy notice presented during the booking process.
3. Purposes of Processing
Personal data is processed for the following purposes:
• to enable website navigation and ensure its operation and security;
• to respond to information requests received by email or telephone;
• to record and manage the user’s cookie preferences;
• to compile website usage statistics and improve its content, exclusively in accordance with the choices expressed by the user;
• to comply with legal obligations and protect the rights of the Data Controller.
The website does not contain registration forms, newsletters or its own systems for sending marketing communications.
4. Legal Bases for Processing
Processing is based on:
• the legitimate interest of the Data Controller in ensuring the operation, security and protection of the website, pursuant to Article 6(1)(f) of the GDPR;
• taking steps at the user’s request prior to entering into a contract, when the user voluntarily contacts the hotel to request information, pursuant to Article 6(1)(b) of the GDPR;
• compliance with legal obligations, pursuant to Article 6(1)(c) of the GDPR;
• the user’s consent for non-essential cookies and tools, where required, pursuant to Article 6(1)(a) of the GDPR. Consent may be withdrawn at any time.
5. Methods of Processing
Personal data is processed using electronic and organizational tools designed to ensure its security, confidentiality, and integrity.
The Data Controller adopts appropriate technical and organizational measures to prevent unauthorized access, loss, or unlawful disclosure of personal data.
6. Data Retention
Browsing and security data is retained for the time technically necessary for the operation and protection of the website, in accordance with the settings and retention periods applied by the technical service providers.
Cookie preferences are retained for the period indicated in the consent management panel.
Data voluntarily provided by email or telephone is retained for the time necessary to respond to the request and manage any resulting relationship, unless longer retention periods are required by law or necessary to protect the rights of the Data Controller.
At the end of the applicable retention periods, the data is deleted or anonymized.
7. Recipients and Data Transfers
Personal data may be processed, within the limits necessary for the respective functions, by:
• personnel authorized by the Data Controller;
• Wix and other technical service providers used for hosting, security and website operation;
• Usercentrics, used to manage cookie preferences;
• consultants and service providers acting on behalf of the Data Controller in accordance with applicable law;
• public authorities or other parties where disclosure is required by law.
Data entered on the external TeamSystem Hospitality platform is provided directly by the user and processed in accordance with the privacy notice displayed during the booking process.
Some technical service providers may process data outside the European Economic Area. In such cases, transfers are carried out on the basis of an adequacy decision or other safeguards provided for in Articles 45 and 46 of the GDPR.
Personal data is neither sold nor disseminated.
8. User Rights
Where the conditions set out in Articles 15–22 of the GDPR apply, users may exercise the following rights:
• obtain confirmation as to whether personal data concerning them is being processed and access such data;
• request rectification, erasure or restriction of processing;
• object to processing where applicable;
• receive their data in a structured format and request data portability, where applicable;
• withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
Requests may be submitted to: info@towerhotelbustoarsizio.it.
Users also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), following the procedures indicated at www.garanteprivacy.it.
9. Cookies
The website uses technical cookies that are necessary for its operation and, only with the user’s prior consent, any non-essential cookies or tools.
Updated information on cookie categories, service providers, purposes and retention periods is available in the Cookie Policy and in the consent management panel. Users may change their choices at any time through the dedicated link or button available on the website.
10. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect regulatory requirements, technical changes or changes to the services used by the website.
The most recent version is always available on this page and is identified by the update date shown at the beginning of the document.