Planning tool

Privacy notice

This notice covers the planning tool of BASIS Vinschgau Venosta and its public pages – the production form for artists, the info pages behind our links and QR codes, and the sign-in page. In line with Art. 13 GDPR, it explains which data we process there.

Controller

BASIS Vinschgau Venosta, Kortscher Straße 97 / Via Corzes 97, 39028 Schlanders/Silandro, Italy

Email: hoi@basis.space · Phone: +39 376 2379910

Production form for artists

Via a personal link, we ask bands and artists for the details we need for their show:

  • Contact: name of the band or project, contact person, email, phone
  • Billing: company, address, tax or VAT number, bank details
  • Travel and accommodation: number of people, catering and accommodation requests, identity documents for the legally required registration of overnight guests
  • Technical: rider, stage instructions and other technical details
  • Promotion and press: short bio, press photos, links, Instagram handle, music files
  • Fee and terms, if we show them in the form for you to confirm

We need these details to prepare and run your show (contract or pre-contractual steps, Art. 6(1)(b) GDPR). We also use billing data for accounting and tax purposes, and identity data to register overnight guests with the authorities (legal obligation, Art. 6(1)(c) GDPR). We use press texts, photos and music to promote your event – on our website and on our social media channels, as agreed with you.

Without the necessary details we cannot organise the show; some fields are optional. There is no automated decision-making.

Uploaded files are stored encrypted. When you reopen the form, bank details and tax number are only shown shortened. Identity documents are deleted automatically 30 days after the event, and files from forms that were never submitted after one day.

Info pages and QR codes

You do not enter any data on the pure info pages (e.g. directions or instructions for equipment in the house). When you open them, our server only processes what is technically necessary to deliver the page and protect it from misuse (see “Server logs”; legitimate interest, Art. 6(1)(f) GDPR). Pages where you can send us something are described in the next section.

Damage reports, cleaning and room requests

On some pages you can send us something without signing in:

  • Report damage (door sign of a room or QR code on an item): your description and, if you like, a photo plus your name and contact details for questions
  • Cleaning done (with the code from the cleaning plan): if you like, name, note and photo
  • Room request via an availability link: name, email address, optionally phone number and message, plus room, day and time

We use these details to fix the damage, document the cleaning, and answer and, where applicable, book your request (legitimate interest in running the house, Art. 6(1)(f) GDPR; for room requests pre-contractual steps, Art. 6(1)(b) GDPR). They are visible to BASIS staff who look after rooms and facility management; a room request is also sent as a notification to the person responsible for the link. Photos are stored encrypted.

To prevent misuse, we limit how many reports or requests can be sent per hour. For damage reports and room requests we store a fingerprint of your IP address for this purpose – computed with a secret key and the date, so the address cannot be recovered from it and entries from different days cannot be linked.

We delete room requests 12 months after receipt. There is no automatic deletion period for damage reports and completed cleanings: they stay in the tool as a record until we delete them manually. On request we delete name, contact details or photo earlier – write to us at hoi@basis.space.

Map (Google Maps)

Some info pages show a map. It only loads when you click “Show map”. Only then does your browser connect to Google; Google (Google Ireland Limited, Ireland, and Google LLC, USA) receives, among other things, your IP address and the page address, and may set cookies. The legal basis is your consent given by clicking (Art. 6(1)(a) GDPR). You can withdraw it at any time by not loading the map again – after reloading the page it is off again.

“Get directions” opens Google Maps in a new window, where Google’s privacy policy applies.

Sign-in and access for project partners

Signing in is reserved for our team. We process the email address and password (stored only as a hash) and record every sign-in and every failed attempt with email address, IP address and time, to slow down password guessing. We delete these entries after 90 days (Art. 6(1)(f) GDPR).

Partner organisations in joint funded projects get their own access via link and code. There they edit details about their organisation, costs, dates and contact persons in the project (Art. 6(1)(b) and (f) GDPR).

Signed-in users can allow notifications on their device (web push); these are delivered via their browser’s push service (e.g. Google, Apple, Mozilla).

Cookies

The form, the info pages and this page set no cookies and use no analytics or tracking tools. Cookies are only used where technically necessary:

  • basis_session – keeps the team signed in, 14 days
  • basis_leiste – remembers in the internal area whether the sidebar is open or collapsed, 1 year
  • basis_mitarbeit – keeps partners signed in to the partner area, at most 7 days, only under /mitarbeit
  • basis_mitarbeit_sprache – remembers the chosen language there, 1 year

Once a Google map has been loaded, Google may set its own cookies (see above).

Server logs

Our web server logs every request with IP address, time, requested address, browser identifier and server response. Personal links (such as the link to the form) and cookies are masked. A new file starts at 10 MB; we keep at most five older files and none for longer than 90 days. Application error messages are limited to 3 × 10 MB per service and then overwritten (Art. 6(1)(f) GDPR: operation and security).

Recipients and service providers

Your details are visible to BASIS staff with access to event planning. We also use service providers who process data on our behalf:

  • netcup GmbH (Germany): the server hosting the tool and its data, including daily backups (kept for 14 days)
  • Odoo S.A. (Belgium): accounting, invoices and bookings – billing data goes here
  • Google Ireland Limited (Ireland): email and calendar (Google Workspace), e.g. sending the link to the form
  • Anthropic (USA): AI assistance for our team (Claude). This may involve planning details such as band or artist name, times, number of people or the name for the accommodation. The tool does not pass bank details, tax numbers or identity documents from the form to the AI; however, if the AI reviews documents or emails for accounting, these may also contain artists’ details (e.g. on an invoice).

Authorities only receive data where the law requires it (e.g. registration of overnight guests, tax).

Transfers to the USA (Google LLC, Anthropic) are based on the EU-US Data Privacy Framework or on the European Commission’s standard contractual clauses.

How long we keep data

We keep your details for as long as we need them to plan, run and settle the event. Documents relevant for accounting and tax are kept as long as the law requires (in Italy usually 10 years). Fixed periods in the tool:

  • Identity documents: 30 days after the event
  • Files uploaded but never submitted: 1 day
  • Room requests via an availability link: 12 months after receipt
  • Sign-in log: 90 days
  • Backups: 14 days

Your rights

You have the right of access, rectification, erasure and restriction of processing, the right to data portability and the right to object to processing based on legitimate interest (Art. 15–21 GDPR). You can withdraw consent at any time with effect for the future. Just write to us at hoi@basis.space.

You can also lodge a complaint with a data protection authority – in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it).

Last updated: 3 October 2026

PrivacyBASIS Vinschgau Venosta · Kortscher Straße 97 · 39028 Schlanders/Silandro · Italy