Information notice pursuant to art. 13 Regulation (EU) 2016/679 (GDPR)
Pursuant to Regulation (EU) 2016/679 ("GDPR"), this page describes how personal data are processed. This information notice is provided pursuant to art. 13 GDPR and is not valid for other websites of third parties, which may be consulted through links on the present website. The Data Controller is not responsible for the websites of third parties.
Processable personal data
Personal Data: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Recital 26, 27, 30 GDPR).
Data relating to Contracting parties/Users
Computer systems and software procedures used to the operation of this website acquire, during their normal operation, some personal data whose transmission is implicit in the internet communication protocols. This information is not collected to be associated with identified data subject, but by their nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of computers used by users who connect to the site, URI (Uniform Resource Identifier) of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical code indicating the status of the response from the server (successful, error, etc..) and other parameters regarding the operating system and computer environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the site and to check its correct functioning and are deleted immediately after processing. The data will be used to foreseek liabilities in case of computer criminal offences against this site.
Personal data provided by data subjects
The optional, explicit and voluntary sending of messages to the contact addresses indicated on this site and/or the filling in data collection forms results in the acquisition of the sender’s address, necessary to reply to requests, as well as any other personal data provided.
Information on the processing of personal data by way of the social media platforms
As for the processing of personal data that is carried out by the social media platforms used by the Data Controller, please consider the information provided by those platforms through their privacy policies. The Data Controller processes the personal data provided by users through the social media pages in order to handle user interactions (comments, public posts, etc) in full compliance with the applicable legislation.
Specific information notices
Specific information notices may be present on the pages of this site in relation to particular services or processing of personal data provided.
For more information on the cookies used by this website see the cookies policy at the following link.
1. DATA CONTROLLER AND CONTACT DETAILS
The Data Controller is HOTEL LE FONTANELLE SRL, with registered office in Via Roma no. 11 - – 53017 Radda in Chianti (SI), Italy, in person of its Legal Representative, email firstname.lastname@example.org
2. PURPOSES OF THE PROCESSING | LEGAL BASIS OF THE PROCESSING | DATA RETENTION | NATURE OF PROVISION OF PERSONAL DATA
PURPOSES OF THE PROCESSING
i) Website browsing. The broswing data will be processed also for the following purposes: • statistical information on the use of the services (most visited pages, number of visitors and time range, origin, etc.); •check of the correct functioning of the services. The data will be used to foreseek liabilities in case of computer criminal offences against this site.
LEGAL BASIS OF THE PROCESSING
i) Data processing is necessary for the purposes of pursuing the legitimate interests of the data controller or a third party, provided that the interests or the fundamental rights and freedoms of the data subject which require the protection of personal data do not prevail, having regard to the reasonable expectations of the data subject based on his/her relationship with the data controller. Activities strictly necessary for the operation of the site and the provision of the navigation services. (Art. 6, par. 1 lett. F and Recital 47 of the GDPR). Balancing test available upon request.
i) Until the duration of the browsing session and, in any case, no longer than seven days (except where judicial authorities need such data for establishing the commission of criminal offences).
NATURE OF PROVISION OF PERSONAL DATA
i) The provision of data data is necessary for the broswing on this website.
Your personal data will also be processed for the following purposes:
PURPOSES OF THE PROCESSING
A) CONTACTS: collect and fulfill any user requests.
B) DIRECT MARKETING: previous consent and until withdrawal, for direct marketing and promotional purposes, commercial and marketing communications through subscription to the newsletter/mailing list service.
C) MANAGEMENT OF YOUR REQUESTS pursuant to art. 15 and seq. GDPR (data subject’s rights)
LEGAL BASIS OF THE PROCESSING
A) Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Recital 44) - art. 6 par. 1 lett. b) of the GDPR.
B) Consent (Art. 6, par. no. 1 lett. a GDPR).
C) The processing is necessary for compliance with a legal obligation, to which the Data Controller is subject to (Recital 45) - Art. 6 par. 1 lett. C of the GDPR).
A) 1 year
B) Until withdrawal of consent (opt-out)
C) 5 years from the closure of the request, except disputes
NATURE OF PROVISION OF PERSONAL DATA
A) The communication of the data is necessary for the contract. The non provision of personal data may result the impossibility to obtain from the Data Controller the requested information.
B) Personal data provision is optional. The non-provision of personal data may result the impossibility to process your data for the present purpose, without prejudice for the other purposes.
C) The communication of personale data is necessary, because essential for the present legal Obligations. The non provision of personal data may result the impossibility to obtain from the Data Controller the requested information.
3. RECIPIENTS OR CATEGORIES OF RECIPIENTS
Your personal data will be communicated to subjects who will process the data as Data Processor (art. 28 GDPR) and/or as individuals acting under the authority of the Data Controller and Data Processor (art. 29 GDPR), for the purposes listed above. In particular, the data may be communicated to recipients belonging to the following categories:
a) Subjects -based in Italy- that provide services for the website and communication networks, including e-mail, and website management;
b) providers of hosting services (based in Germany)
c) freelancers, firms or companies providing assistance and advice;
d) Competent authorities for compliance with legal obligations and/or provisions of public bodies, upon request.
The list of Data Processors is constantly updated and available by writing to email@example.com or at the registered office of the Data Controller.
4. DATA TRANSFER TO THIRD COUNTRIES AND/OR INTERNATIONAL ORGANIZATION
Personal data provided will not be transferred outside the European Economic Area (EEA). In particular, data will be stored in Italy for the management, development and maintenance of this website, while the hosting is in Germany.
5. EXISTENCE OF AUTOMATED PROCESS
Personal data will be processed by electronic and automated means, but the Data Controller does not use decision-making processes based on a fully automatic elaboration.
6. DATA SUBJECT’S RIGHTS
You may exercise your rights as expressed in articles 15 seq. of the GDPR, by contacting the Data Controller at the email address firstname.lastname@example.org. You have the right, at any time, to request the data Controller to access (art. 15), rectify (art. 16), cancel your personal data (art. 17) or limit their processing (art. 18). The controller shall communicate (art. 19) any rectification or erasure of personal data or restriction of processing carried out to each recipient to whom the personal data have been disclosed. The controller shall inform the data subject about those recipients if the data subject requests it. In the cases provided for, you have the right to the portability of your data (art. 20) and in this case the Data Controller will provide you with a structured, commonly used, and readable form of your personal data electronically. In addition, you have the right to object (art. 21), at any time, to the processing of your data. You have the right to withdrawal your consent without affecting the lawfulness of the processing based on the consent before withdrawal. To stop receiving automated direct marketing communications (e.g. e-mail, newsletter) you can send an e-mail at any time to email@example.com with the subject “cancellation from automated” or use our automatic cancellation systems provided for e-mails only. Without prejudice to any other administrative and judicial remedy. if you believe that the processing of data concerning you violates the provisions of the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (https://www.garanteprivacy.it/web/guest/home_en).
Last update: July 27, 2022