OVVO Camping
GDPR Compliant — Zero Trust Architecture

Your guests' data is safe.

Strong encryption, two-factor authentication, CSRF protection and full GDPR compliance. Every identity document is protected from the moment it is scanned and completely deleted after being submitted to Alloggiati Web.

AES-256 encryption
MFA required
Complete JSON export
Campsite data security and backups
AES-256 encryptionActive
MFA authenticationRequired
Automatic backupLast: 2 min ago
Zero Trust Architecture

Every layer is protected.

We trust no component by default. Every access is verified, every piece of data is encrypted, and every operation is recorded.

Strong document encryption

Images of identity documents captured during check-in are automatically deleted when the verification and submission process is complete. Only the data required to manage the stay and meet legal obligations is retained in the database. Data is protected with AES-256 encryption, is not publicly accessible, and is never sent to the operator's browser except for information strictly necessary to verify and manage the application.

MFA authentication

Two-factor authentication using a one-time password sent by email is mandatory for any access from an unrecognized device. An active layer of security even if a password is compromised.

CSRF protection and input validation

Every API endpoint is protected against CSRF attacks and rigorously validates all input. Non-compliant data is rejected before reaching the database.

Sensitive credentials never exposed

Questura portal credentials (WSKEY), SMTP keys and payment APIs are encrypted on the server and never pass to the browser. Even an administrator cannot see them in plain text.

Complete JSON export

Download the entire database in JSON format at any time. Your data is yours: moving it to another system, archiving it offline or importing it into accounting software takes one click.

Dedicated VPS for the Structure plan

The Structure plan includes installation on your own server (VPS or on-premise). Data physically hosted in your infrastructure, backups configurable on your storage, and full digital sovereignty.

Regulatory compliance

Designed for GDPR from the start.

Personal data protection is not an add-on — it is part of the architecture. Every technical choice has been evaluated from a GDPR perspective, from document collection to automatic deletion after the mandatory retention period.

Guest data stored only for the legally required period
Data access request (DSAR) managed independently by the Admin
DPA contract under GDPR Art. 28 included in the Structure plan
No data shared with third parties without explicit consent
Verification logs available for inspections and audits
Secure deletion of user accounts at the end of the season

Questions about data security?

Our technical team is happy to answer any questions about encryption, GDPR compliance or installation on your own VPS.

Frequently asked questions

Chat with us