in compliance with the obligations under the European Privacy Regulation UE/2016/679 (GDPR) and legislative decree 196/2003 as amended by legislative decree 101/2018, we hereby inform you that the company I.T.I. S.P.A., acting as controller, will process any personal data regarding you that have been or will be submitted to us – by either you or other subjects – in the course of the relations with our facility.
The processing of the data, either willingly submitted by you or collected in other ways, will be carried out in observance of the privacy laws currently in force; in line with the principles of fairness, lawfulness and transparency and carried out in observance of relevance, completeness and non-exceedance.
Hence, as provided for in the article 13) of the European Privacy Regulation UE/2016/679 (GDPR), we hereby inform you that:
1) Upon check-in at one of our structures, you will be asked the following personal data, which are mandatory in order to proceed with your registration and to comply with the contractual relationship established:
- Name and surname - E-mail address
- Birth date and place - Number and expiry date of your ID
- Permanent address - Telephone number
If you wish to disclose them, our structure may have to collect some peculiar “sensitive” data, such as:
- Health condition - Food intolerances
- Allergies - Disabilities
The above-mentioned data will be processed for the following purposes:
a) For the regular implementation of the institutional activities and/or those required by the business objective.
b) For particular needs pertaining to the drafting of contracts and fulfilment of tasks (management of reservations) and their execution, to all subsequent modifications or variations and for any obligation required for their finalisation;
c) For operative, organisational, management, fiscal, financial, insurance or accounting needs pertaining the contractual and/or pre-contractual relationship in force;
d) To fulfil any duty under laws, regulations or Community legislation.
e) For the registration, management and conservation of any access to the reception facilities or to the Company’s Informative System (Wi-Fi connection etc.);
If you were to decide, after staying in our receptive facilities, to keep in contact with us by either subscribing to our newsletter or receiving our promotional material, you will be asked the following personal data, which are required in order to complete the subscription process:
- E-mail address - Permanent address or registered office
- Name and surname - Telephone number
Such data will be processed for the following purposes:
f) For the communication of updates and periodical information regarding our activity, offers and advertising via newsletter;
g) For direct marketing activities such as: sending of flyers, catalogues and commercial and/or technical documents via regular mail and/or telephone call with an operator.
Said marketing activities will be carried out for us by the company Euro Gestioni Spa, which has been duly appointed external data processor. The data will be thus submitted to said company only after explicit and specific consent on behalf of the interested party, as specified at paragraph 3)
2) The data processing, which will be carried out both manually, partially automated or fully automated, may consist in the following operations: collection, recording, organization and conservation, consultation and utilisation, elaboration, modification, selection, extraction, comparison, submission and communication. The processing will be carried out both utilising paper support and with the help of electronic, IT and computerised instruments which aim at guaranteeing the safety and confidentiality of the aforementioned data, in compliance with art. 32) of the European Privacy Regulation UE/216/679 (GDPR).
During the processing operation, however, we ensure that all possible technical, IT, organisational, logistic and procedural resources aimed at data safety are used. The aforementioned methods of data processing only guarantee access to the data to the subjects specified at paragraphs 4) and 5).
3) Data submission and processing is:
- Mandatory and does not require your consent for the fulfilment of objectives relating to those obligations under laws, regulations or Community legislation. Paragraphs c) d)
- indispensable and does not require your consent for all those personal data which are essential for a correct instalment, management and continuation of the commercial and/or contractual relationship. Paragraphs a) b) c)
- indispensable and does not require your consent for the pursuit of legitimate business interests. Paragraph e)
- facultative and requires your explicit consent by filling out the “Privacy Consent” form which will be handed to you upon check-in for all your peculiar “sensitive” data. Paragraph c)
- facultative and requires your explicit consent by filling out the “Privacy Consent” form which will be handed to you upon check-in for marketing activities. Paragraphs f) g)
4) The subjects or categories of subjects that can be made aware of the data or to whom the personal data may be submitted are the following:
- In charge of the processing: administrative area and direction, booking area, business office, marketing office, duly authorised employees;
- External processors: Euro Gestioni Spa; consultants and consulting companies, professionals, banks and/or insurance companies;
- System administrators.
The personal data may also be disseminated, but only in aggregate and anonymous form and for statistic purposes.
5) The personal data can also be submitted to Public authorities, Law enforcement or other Public or Private Subjects, with the exclusive purpose of complying with the laws, regulations or community legislation.
6) The management and conservation of the personal data makes use of servers located inside the European Union (Italy), belonging to the controller and to third parties, aptly nominated as processors. The processed data can also be processed and submitted, for the purposes specified in paragraph 1) and with the modes specified in paragraph 2), also to those subjects referred to in paragraph 4) located in countries which may or may not be part of the European Union based on the adequacy decisions of the European Commission or on the adequate measures for the safeguard of privacy in use.
7) The data will be collected and recorded for the sole purposes described above, and will only be conserved for the time needed for the completion of the activities under the contractual obligations, which will not in any case be more than 10 years from their collection for administrative and accounting reasons. For marketing purposes, the data will be conserved for a period not exceeding 24 months. In every newsletter or communication, a link is present which allows for removal from the mailing list. Nonetheless, at the end of said term, the controller – if he means to extend the processing of the aforementioned data for an additional 24 months – can send a specific verification notice, containing a link which allows for delisting.
8) Under any circumstances and at any given moment, you can request from the Legal Representative a copy of your personal data, information regarding the location where your data are being processed and an up-to-date list with the identification details of all the processors and the system administrators authorised for processing your data.
9) You can freely revoke the given consent at any moment, without any burden or prejudice concerning the legitimacy of the data processing carried out up to that point, and exercise the following rights of the person concerned towards the controller, under the European Privacy Regulation UE/2016/679: Access, Correction, Cancellation, Limitation, Complaint to the Data Protection Authority.
The request can be submitted by writing an e-mail to email@example.com
10) Identity and contact details of the controller
Legal address in Calle dell’Annunziata, 10
333053 Latisana (Ud)
Tel: +39 0431 430144
11) Identity and contact details of the DPO
Date and Place: 01.01.2019, Bibione