Privacy Policy

 

Personal Data collected from the Interested Party pursuant to Article 13 of EU Regulation 679/2016

DISCLOSURE /PRIVACY CONSENT IN COMPLIANCE WITH EU REGULATIONS 679/2016

Dear Customer

The present document hereby informs you that at VISTATERRA SRL your Personal Data is processed in compliance with EU Regulation 679/2016.

Data are entered in our databases, and whenever necessary, they will be collected following your explicit consent except for cases referred to in art.6 of EU Regulation 679/2016.

The Data Controller is VISTATERRA SRL in the person of its legal representative pro tempore Erica Ferlito, domiciled for this position, in Parella (To), Via Caradini n. 40.

- Purpose, legal basis and optional nature of the Personal Data Processing

 

Your Personal Data will be processed, without your explicit consent, for the following purposes:

a) Purpose of contract execution/pre-contractual measures

 

The legal basis of the Personal Data Processing is the execution of the contract or the execution of pre-contractual measures, such as the booking of your accommodation at the hotel, with the aim of concretizing and executing the booking, as well as for the provision of the service in question and for sending advertising material via newsletter.

The Data Conferral for the aforementioned purposes is optional, however, if not provided, it will impact the possibility of finalizing the contract. Contrary to the above-mentioned statement, the Conferral of your data and the respective Data Processing Consent for sending communications pursuant to art. 130 of the Privacy Code (Newsletter) are mandatory, as well as the collection of Health Data with a particular attention to those specific categories of data pursuant to art. 9 of EU Regulation 679/2016.

b) Purpose of fulfilling any legal obligations

 

The legal basis of the Personal Data Processing is the fulfillment of the legal obligations to which the Data Controller is subject, as for instance, the enforcement of the Legislative Decree 81/2008 s.m. and i.

The Data Conferral for the aforementioned purposes is optional, however, if not provided, it will impact the possibility of finalizing the contract.

 

- Data Processing Methods: Data Processing is carried out in manual, hard copy, computerized and telematic forms using procedures strictly related to the objective in question, and in any case, guaranteeing the security and confidentiality of the data.

 

- Navigation Data

 

The computer systems and software procedures used to operate the website of Vistaterra Srl obtain, during their normal operation, Personal Data whose transmission is implicit in the use of Internet communication protocols. This kind of information is not collected with the aim of associating it with Interested Parties, but due to its particular nature could, through processing and association with data stored by Third Parties, reveal user’s identity. This category of data includes IP addresses, the time of the request, the methods used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server (for example “successful” or “error”, etc.) and other parameters relating to the operating system and the user´s IT environment.

These data are used exclusively to obtain anonymous statistical information related to the use of the site and to verify its proper functioning and are deleted immediately after processing.

- Data transfer

 

Data are stored on the servers of the Data Controller or at Third Party companies, appointed by the Data Controller as external data processors, to process the data on behalf of the Data Controller; their servers are located within the European economic area.

The Data Conferral for the aforementioned purposes is optional, however, if not provided, it will impact the possibility of finalizing the contract.

- The data collected are comprised in one of the following categories of data;

 

Personal data: any information concerning and identified or an identifiable natural person (“the interested”); it is considered “identifiable natural person” a person that can be identified, directly or indirectly, by means of an identifier such as the name, an identification number, the location data, an online identifier or one or more characteristic elements of his/her physical, physiological, genetic, psychic, economic, cultural or social identity.

- The data collected are comprised in one of the following categories of data:

 

“Health data”: personal data concerning the physical or mental health of a natural person, including the provision of health care services that disclose information relating to his or her state of health.

“Special categories of data”: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or information concerning membership to trade unions, as well as genetic data and biometric data intended to uniquely identify an individual, data relating to health or sexual life or sexual orientation of the person.

 

- Categories of individuals/entities to whom data can be transferred:

 

Consultants and professionals both, individually and associated (for instance for the legal, judicial, fiscal and accounting compliance, as well as those obligations pursuant to legislative Decree 81/2008);

Suppliers; for instance, in the field of event planning and related services/booking services.

Insurance Companies/Brokers;

Banks, credit and/or financial institutions.

- Data retention period: Data processed for the main purposes of the Personal Data Processing will be stored for ten years as requested by current fiscal, civil and anti-money laundering regulations, that is, until the expiry of validity and effectiveness of the contractual relationship and of the related prescribed terms/expiration, except for the legitimate interest of the Data Controller, that is, for obligations pursuant to law. Personal data may be stored for longer periods provided they are processed exclusively for statistical purposes, in accordance with Article 89, paragraph 1, without prejudice to the implementation of adequate technical and organizational measures required by EU Regulation 679/2016 aimed at protecting the rights and freedoms of the individual in question.

 

- Rights of the Interested Party: You may contact the Data Controller to exercise Your rights, as specified by the EU Regulation 679/2016 and by Legislative Decree 196/2003 s.m and i. and therefore; request access to personal data; request the correction or deletion of records related to you; restrict the personal data processing, or oppose to personal data processing. You may also exercise the right to data portability or the right not to be submitted to a decision based exclusively on automated Personal Data Processing.

 

- In case the Personal Data Processing is based on Article 6, paragraph1, letter a) or Article 9, paragraph 2, letter a), or on Article 130 of the Privacy Code, you have the right to revoke the consent at any time without precluding the lawfulness of the Personal Data Processing based on the consent granted before revocation.

 

- You also have the right to lodge a complaint with a supervisory authority.

 

- The Conferral of your Personal Data is a necessary requirement for the conclusion and execution of the contract and for the compliance with current regulations and related obligations, and therefore, you have the obligation to provide your personal data, since you are part of the aforementioned contract, and that means that the execution of precontractual measures is carried out also on the basis of your explicit will and interest.

 

Finally, we inform you that your data will be:

- Processed lawfully, correctly and transparently;

- Collected for the aforementioned explicit and legitimate purposes, and processed in accordance with the above-mentioned purposes;

- Adequate, relevant and limited to what is necessary with respect to the purposes for which they are collected and processed (“data minimization”);

 

 

- Accurate and, if necessary, updated, deleted and/or rectified;

- Stored in such a way to consent your identification for a time not exceeding the time necessary to reach the purposes for which they are processed except for legal and contractual obligations;

- Processed in a way to guarantee adequate security of personal data -including data protection, by means of proper technical and organizational measures- thus protecting them against unauthorized or unlawful processing and against accidental loss, destruction or damage.

- The information referred to in the present document, and communications and actions undertaken pursuant to articles 15 to 22 and article 34 are free. If the requests of Interested Parties are obviously groundless or excessive, particularly due to their repetitive nature, the Data Controller may:

 

a) Charge a reasonable fee to cover the administrative costs in which it incurred, with the aim of providing such information and its transmission, or to proceed as requested; or

b) To refuse to comply with the request. Hence, the Data Controller will be responsible for demonstrating the manifestly unfounded or excessive nature of the request.

 

Parella (TO) VISTATERRA SRL

************************

I, the undersigned (CF ) signing the present document, hereby certify my free consent so that the Data Controller (VISTATERRA SRL in the person of its legal representative pro tempore) proceeds to the Personal Data Processing of my/our personal data for the purposes indicated in the corresponding Disclosure.

Parella (TO) SIGNATURE

I, the undersigned (CF ), sign my free consent with this signature so that the Data Controller (VISTATERRA SRL in the person of its legal representative pro tempore) will process my/our Health Data ex art.4 n. 15) of EU Regulation 679/2016 and of the Special Categories of data pursuant to art.9 of the aforementioned Regulation for the purposes indicated in the corresponding Disclosure.

Parella (TO) SIGNATURE

I, the undersigned (CF ) sign this document, hereby expressing my free consent so that the Data Controller (VISTATERRA SRL) in the person of its legal representative pro tempore) will proceed to the processing of my/our Personal Data aimed at sending communications pursuant to art. 130 of the Privacy Code, such as the newsletter, for the purposes indicated in the corresponding Discolure.

Parella (TO) SIGNATURE