Information notice pursuant to Art. 13 of the Regulation (EU) 2016/679 (“GDPR”)
DATA CONTROLLER,pursuant to art. 4 and art. 24 of the Regulation (EU) 2016/679 is Villa d’Este S.p.A., Via Regina, 40, 22012 Cernobbio (Como), as represented by legal representative.You can contact the Controller at any time at the following contacts: fax +39 031 348873; email: firstname.lastname@example.org; telephone number: 031-3481.
PROCESSED PERSONAL DATA
Personal data: any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (such as name, last name, date of birth, address, email, telephone number).
During their ordinary course of operation, the IT systems and software procedures required to run this website acquire certain Personal Data, whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified Data Subjects but, by its very nature, it could enable identification of the users through the processing and matching of data held by third parties.
This data category includes IP addresses or domain names of computers used by the users who visit the site, as well as the URI addresses (Uniform Resource Identifier) of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in reply, the numerical code indicating the status of the reply from the server (done, error, etc.) and other parameters related to the operating system and the IT environment of the user.
These data are only used to obtain anonymous statistical information on the use of the website and to control its correct functioning. They are cancelled immediately after processing.
Data provided voluntarily by the user
The optional and voluntary disclosure of personal data (e.g.: dispatching of electronic mail to the addresses indicated on this website and/or the completion of a data collection form on this website) entails the acquisition and processing of the voluntary disclosed user’s data (e.g. sender’s address, name, last name), necessary to reply to the request, as well as other personal data included in the email message (such as name, last name, address, telephone number, email address, credit card number, preferences about the reservation).
Specific information notices will be provided or made available in the website’s pages in relation to particular services or processing activities upon user’s request (e.g.: area “work with us”).
|Purposes||Legal basis||Data Retention Period|
|Navigation of this website / obtaining anonymous statistical information on the use of the website and services / control of website’s correct functioning||Controller’s legitimate interest: ensure the correct browsing and usage of the website||Duration of the browsing session, (except for any need to ascertain criminal offenses by the judicial authorities)|
|Request of contacts or information||Controller’s legitimate interest: reply to users’ requests||1 year|
|Staff recruitment and evaluation|
of CVs provided through
the “work with us” area
|Controller’s legitimate interest: staff recruitment||2 years|
|Subscription to the newsletter by filling-in the relevant form||User’s consent||Subscription duration |
Until users’ objection (opt-out) | unsubscription from the mailing list
|Direct e-mailing marketing in order to promote goods or services similar to those already purchased by the data subject|
(so called “soft spam”)
|Controller’s legitimate interest: promoting marketing activities|
towards its clients
|Until users’ objection (opt-out) | unsubscription from the mailing list|
|Organizational, administrative, financial and accounting activities and clients / users management||Performance of a contract and|
compliance with a legal obligation
PERSONAL DATA RECIPIENTS
Your personal data may be communicated to employees or collaborators in charge of processing activities under the authority of the Controller (art. 29 Reg. UE 2016/679), for the above described purposes. Your personal data may be communicated to companies contractually involved with the controller, located outside the European Union, in order to comply with contractual obligations or related purposes and subject to the limits and conditions set forth by art. 44 and subsequent articles of the Regulation (EU) 2016/679. The data subject may obtain information on the appropriate safeguards provided by the Controller relating to the transfer of the personal data by writing to email@example.com.
In order to comply with contractual obligations or related purposes, your data may be processed by companies contractually involved with the Controller and in particular to third parties belonging to the following categories: – service providers for the management of the information system and the telecommunications networks (including e-mail, newsletter and website management service) of the Controller; – professionals, firms or consultancy companies; – competent authorities for the fulfilment of obligations of law and/or regulations of public bodies, upon request. The above mentioned subjects will act as data processors or may carry out their processing activities as independent data controllers. The list of data processors is constantly updated and it is available at Controller’s headquarters and by contacting the same at firstname.lastname@example.org.
NATURE OF DATA PROVISION
Except for what specified for navigation data which are necessary in order to allow navigation of the website, users are free to provide their personal data and their refusal may result in the impossibility of obtaining the information or services requested and provided via this website.
DATA SUBJECT’S RIGHTS | COMPLAINT TO SUPERVISORY AUTHORITY
You may exercise your rights pursuant to articles 15, 16, 17, 18, 19, 20, 21, 22 of the Regulation EU 2016/679 by writing to email@example.com or to Controller’s headquarters.
You have the right, at any time, to request the Controller to access your personal data and receive the information concerning their processing. You have the right to rectify, erase your personal data or limit their processing.
Where appropriate, you have the right to object, at any time, to the processing of your data, including profiling, and you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
You have the right to the portability of your personal data; in such case the Controller shall provide you with your personal data in a structured, commonly used and machine-readable format.
Without prejudice to any other administrative or judicial remedy, if you consider that the processing of your personal data infringes the Regulation (EU) 2016/679, you have the right to lodge a complaint with the Data Protection Authority.
Last update: May 25th 2018
DATA CONTROLLER – VILLA D’ESTE S.P.A.
The Data Controller is Villa D’Este SpA, via Regina 40, 22012 Cernobbio (CO) Italy, in the person of its pro tempore legal representative.
The Data Processor is Robert Webber c/o Hotel Barchetta Excelsior • Piazza Cavour 1, 22100 Como Italy.