Italiano

Ferro Index™ · Privacy


Privacy and legal notice

Who handles your data, which data, for how long and with what rights.

Last updated: 29 September 2026

The controller


Who handles your data

The data controller is Vimana Holidays GmbH, Veithgasse 6, 1030 Vienna, Austria, entered in the commercial register under number FN 476176i (Handelsgericht Wien).

On this page, “we” means the company. Nominations for the Register and proofs of stay are read by one person only, Mattia Ferro.

For any request about your data, write to vimanaholidays@gmail.com. We reply within one month.

The visit


When you visit the site

The site uses no cookies or analytics and carries no advertising. It loads nothing from other sites.

The site is hosted by GitHub, Inc., in the United States. GitHub logs the IP address of people who visit the pages, for security reasons, and does so on its own account: its privacy statement applies. We do not see those logs and we do not know how long GitHub keeps them.

We chose GitHub to keep the site online and secure: that is our legitimate interest. If you want to know how we weighed it, write to us.

The test


When you take the test

Your answers are worked out in your browser, and so is the score. Nothing reaches us unless you nominate a hotel.

When the test ends, the code of your answers appears in the page address. If you reload the page or switch language, that address reaches GitHub, which hosts the site. If you share the verdict, anyone who receives the link can read the code of your answers and, if you wrote them, the hotel's name and your reasoning.

After you leave your email, the browser stores one small item, and a mark in the tab's history, recording that you have already been through. They are only there so that we do not ask for your email on every visit. They do not contain your email and they do not leave your browser. The item stays until you clear the site's data or the browser clears it by itself.

The newsletter


When you leave your email

The test is reserved for people who subscribe to Mattia Ferro's newsletter. To open it we ask for your email: without an email the test does not open. The site does not check whether the subscription goes through.

When you press the button, your browser opens the newsletter's subscription page, on Substack, and hands it your email along with a note that you came from the Ferro Index. Your email travels inside the web address of the page that opens, and that address stays in your browser's history. That page belongs to Substack and uses its own cookies and analytics: Substack's rules apply there.

Substack may ask you to confirm the subscription with a link sent by email: in that case you are subscribed only after you press it.

We use your email only to send you the newsletter. We can do this because you give us your consent. You can withdraw it at any time using the link at the bottom of every email: after that you will receive nothing further.

We keep your email for as long as you stay subscribed. Once you have unsubscribed we no longer use it. If you want it removed from the list altogether, write to us: we do so within 30 days.

The newsletter is sent through Substack, Inc., a United States company, which holds the list of subscribers and uses it to send the letters. For the rest of its services, such as your account and reading suggestions, Substack decides for itself and its own privacy policy applies. The newsletter is for people aged 16 or over, as Substack's terms require.

The Register


When you nominate a hotel for the Sanctuary Register

You send us the hotel's name and city, your reasoning, your email, the code of your answers, the language you use the site in and the proof of stay, meaning an invoice or a final bill. All fields are required: if one is missing the nomination cannot be sent.

On the proof, all we need is the hotel's name and the dates of the stay. Feel free to cover everything else: prices, card numbers, your home address, tax number, what you ordered. If other people appear on the invoice, please cover their names before you send it.

We use these data to check that the stay took place and to decide whether to publish the entry. We can do this because you give us your consent, by ticking the box under the form.

The data pass through a program running on a Google service and arrive by email in a Gmail mailbox. Your reasoning is translated automatically by a Google service. The program keeps the hotel's name and city, your reasoning with its translation, the language you wrote it in and the one you use the site in, the score, the code of your answers, and the day and time the nomination arrived. If you write in a language other than Italian or English, the program keeps the two translations and the text you wrote stays only in the email. It does not keep your email or the proof of stay. These exist in the email we receive and, for 30 days at most, in the bin of the Gmail mailbox the program sends it from.

The choice to publish an entry is always made by a person. The program turns down by itself only nominations that are incomplete, carrying a misspelt email, below 85, carrying a file that is not a PDF or a photo or is larger than 10 MB, filled in by an automated program, or arriving when the cap on nominations has been reached.

If the entry is published, the Register shows the hotel's name and city, your reasoning in Italian and in English with a note saying which one is a translation, the score, the month of the nomination, the words “Verified stay” and a link to the verdict. The link contains the code of your answers: anyone who opens it can see how you answered. The Register's public file and the history of the archive on GitHub also show the day and time the entry was published. Your email does not appear. We never ask for your name.

How long we keep the data:

The program has no clock: it deletes expired nominations when a new valid nomination arrives or when we reject one. Until then, an expired nomination may stay in the archive beyond the periods listed above.

The site is published from a public archive on GitHub. An entry that is removed disappears from the site's pages, but stays in the archive's past versions.

The countries


Where the data go

Substack, Inc. and GitHub, Inc. are United States companies. Google's services are provided to us by Google Ireland Limited, in Ireland, which may also process data on the servers of Google LLC in the United States.

For the United States the European Commission adopted an adequacy decision on 10 July 2023, which covers companies that have joined an agreement between Europe and the United States, the Data Privacy Framework. Substack, Inc., GitHub, Inc. and Google LLC have joined: the list is public at dataprivacyframework.gov.

Substack's terms for publishers also contain the European Commission's standard contractual clauses, which apply should the adequacy decision fall away. The text is public at substack.com/pa. If you would like a copy, write to us.

We do not sell your data and we do not pass them to anyone else.

The rights


Your rights

At any time you can ask us what data we hold about you, and ask us to correct them, delete them, restrict their use or send them to you in a format you can take elsewhere. You can withdraw your consent whenever you like: what was done before remains valid. Write to vimanaholidays@gmail.com.

Right to object. You can object at any time to any use of your data that rests on our legitimate interest, and to receiving the newsletter. Write to us or use the link at the bottom of every email.

No decision with legal or similarly significant effects on you is taken by a program alone.

If you believe your data are being handled badly, you can complain to the data protection authority in your country. In Italy it is the Garante per la protezione dei dati personali. In Austria, where the company is based, it is the Datenschutzbehörde.