Documents
Privacy Policy
Which data we process, why, for how long, with which providers and which rights you can exercise.
Last updated: 24 August 2026
Controller and contacts
Meridia operates meridiagency.it and the connected services for independent hotels, B&Bs, agriturismi and restaurants.
Meridia is the trading name of Reinier Berrillo Bello, sole trader based in Castrovillari (CS), Italy — Italian VAT no. 04027290784. For any privacy question or to exercise your rights, write to info@meridiagency.it.
Data we process
We only process the data each situation requires. We do not request special categories of data under Art. 9 GDPR: please do not send sensitive data through forms or conversations.
| Situation | Data | Legal basis |
|---|---|---|
| Website visit | Technical logs, IP address, user agent, locally stored cookie preference. | Technical operation and security; consent for non-essential tools. |
| Screening or contact request | Business type, work email, category, current website status, request content. | Pre-contractual measures requested by the data subject. |
| Conversations with Sofia | Messages sent, conversation context, technical identifier. | Response to the request or service delivery. |
| Purchase and billing | Email, billing details, chosen service, payment status, Stripe identifiers. | Contract performance and accounting or tax obligations. |
| Client area | Credentials, session tokens, operational service data. | Contract performance, security and account management. |
| B2B outreach | Publicly available professional data: business name, city, business email, website, sector. | Legitimate B2B interest, with an immediate right to object. |
Purposes
We use data only for declared and proportionate purposes.
- Answering requests, screenings, quotes and service questions.
- Delivering contracted modules: websites, Sofia, Stay, Table and connected tools.
- Managing payments, renewals, onboarding and support.
- Keeping technical logs for security, abuse prevention and service continuity.
- Sending transactional and operational messages: confirmations, credentials, service notices.
- Contacting professional businesses proportionately with relevant B2B proposals, always with the option to object.
What we do not do
We do not sell data, we do not run advertising profiling and we do not use client data to train Meridia-owned models. The language-model providers behind Sofia are configured not to retain data for training, within the contractual limits each provider offers.
Providers
We use selected technical providers that process data only as needed for the service. This is the complete, current sub-processor list: if it changes we update it here and tell active clients.
| Provider | Role |
|---|---|
| Stripe Payments Europe, Ltd. — Ireland (EU) | Payments, checkout and fraud prevention. May transfer data to Stripe, Inc. (USA) under standard contractual clauses. |
| Brevo (Sendinblue SAS) — France (EU) | Transactional email and commercial communications. |
| OpenRouter, Inc. — United States | Routes Sofia's messages to the language model. Conversation content leaves the European Union. |
| "DeepSeek v3" model via OpenRouter | Generates Sofia's reply from the knowledge the client approved. The provider hosting the model may sit outside the EU. |
| Contabo GmbH — Germany (EU) | Server infrastructure, database and backups. |
Transfers outside the EU
One transfer outside the European Union exists, and this is it: messages handled by Sofia pass through OpenRouter, Inc. (United States) to reach the language model, and the provider hosting that model may sit outside the EU. The transfer relies on standard contractual clauses. Stripe may likewise transfer payment data to the United States under the same safeguards.
Everything else — servers, database, backups, email delivery — stays in the European Union. If you enable Sofia this transfer is part of the service: we state it before signature, in the data processing agreement.
Retention
Technical logs: up to 12 months unless security requires longer. Commercial requests without follow-up: up to 24 months. Contractual and fiscal data: for the legally required period. Demo conversations with Sofia: the technical minimum.
Roles with clients
For services delivered to clients (for example Sofia on the client's channels), the client remains the controller towards their own guests; Meridia acts as a processor under Art. 28 GDPR based on a data processing agreement.
Your rights
You can exercise access, rectification, erasure, restriction, portability and objection rights by writing to info@meridiagency.it. We reply within 30 days. You may also lodge a complaint with the Italian data protection authority.
Updates
This notice may be updated. The last update date is shown above; substantial changes are announced on the website.