According to art. 13 of the Regulation (EU) 2016/679 (General Data Protection Regulation) we provide you with the due information concerning the processing of your personal data carried out through this website.
This privacy statement applies only to our site and does not apply to other websites that the user may consult via links on the websites under the data controller’s domain name that shall not be held liable under any circumstances for websites of third parties. The information notice has also been based on the Directive 2002/58/EC, updated by Directive 2009/136/EC, on cookies as well as on the Provision of the Italian Data Protection Authority on cookies dated 08.05.2014.
1.DATA CONTROLLER, pursuant to art. 4 and art. 24 of the Regulation (EU) 2016/679 is Lagodicomo.com S.r.l. , via Giulini 10, Como as represented by the pro-tempore legal representative. You can contact the Controller at any time at the following contacts: email: firstname.lastname@example.org telephone number: 339.2217588.
2.PROCESSED PERSONAL DATA
Personal data: any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (such as name, last name, date of birth, address, email, telephone number).
During their ordinary course of operation, the IT systems and software procedures required to run this website acquire certain Personal Data, whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified Data Subjects but, by its very nature, it could enable identification of the users through the processing and matching of data held by third parties.
This data category includes IP addresses or domain names of computers used by the users who visit the site, as well as the URI addresses (Uniform Resource Identifier) of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in reply, the numerical code indicating the status of the reply from the server (done, error, etc.) and other parameters related to the operating system and the IT environment of the user.
These data are only used to obtain anonymous statistical information on the use of the website and to control its correct functioning. They are cancelled immediately after processing.
The user’s Personal Data may be used by the owner of the website in a legal defence, or during the preparatory stages of potential proceedings, against any abuse by the user of the website or its connected services. The data may be used to ascertain responsibility in the event of any potential crimes, including computer crimes, against the Controller.
The User’s Personal Data may be processed due to additional procedures and purposes linked to maintenance of the website.
Data provided voluntarily by the user
The optional and voluntary disclosure of personal data (e.g.: dispatching of electronic mail to the addresses indicated on this website and/or the completion of a data collection form on this website) entails the acquisition and processing of the voluntary disclosed user’s data (e.g. sender’s address, name, last name), necessary to reply to the request, as well as other personal data included in the email message (such as name, last name, address, telephone number, email address).
Specific information notices will be provided or made available in the website’s pages in relation to particular services or processing activities upon user’s request (e.g.: booking”).
3.PURPOSES AND LAWFULNESS OF THE PROCESSING
Your personal data will be processed in accordance to the requirements for the lawfulness of processing set forth by art. 6 lett. a) of the Regulation (EU) 2016/679 (data subject’s consent) for the following purposes:
1. With reference to the browising data, to obtain anonymous statistical information on the use of the website and to control its correct functioning;
2. Upon user’s request, to send info/ to supply services as requested through the compilation of the data collection form or through the request of info or services;
3. Upon user’s request and consent, to send newsletter, periodic satisfaction surveys, special offers and promotions or other marketing communications in general, by e-mail, upon the compilation of data collection form for subscription to the newsletter. The user can revoke at any time the consent given for the receipt of marketing communications.
4. in relation to contractual and legal obligations (Article 6, letter b) and c) EU Reg. 2016/679), for the purposes of administrative and accounting management connected to the performance of organizational, administrative, financial and accounting activities.
4.PERSONAL DATA RECIPIENTS
Your personal data may be communicated to recipients processing your data as processors (art. 28 Reg. UE 2016/679) or persons in charge of processing activities under the authority of the Controller (art. 29 Reg. UE 2016/679), for the above described purposes. Your personal data may be communicated to third parties belonging to the following categories:
– service providers for the management of the information system and the telecommunications networks (including e-mail, newsletter and website management service) of the Controller;
– professionals, firms or consultancy companies;
– competent authorities for the fulfilment of obligations of law and/or regulations of public bodies, upon request.
The above mentioned subjects will act as data processors or may carry out their processing activities as independent data controllers. The list of respective appointed data processors is constantly updated and it is available at Controller’s headquarters and by contacting the same at email@example.com
5.DATA TRANSFER TO THIRD COUNTRIES
Your personal data may be communicated to companies contractually involved with the controller, located inside and outside the European Union, in order to comply with contractual obligations or related purposes and subject to the limits and conditions set forth by art. 44 and subsequent articles of the Regulation (EU) 2016/679.
The data subject may obtain information on the appropriate safeguards provided by the Controller pursuant to Article 46 of the Regulation (EU) 2016/679 relating to the transfer of the personal data by writing to firstname.lastname@example.org
6.METHODS OF DATA PROCESSING – DATA RETENTION
The processing will be carried out with methods and tools aimed at ensuring the best security and confidentiality, by persons specifically appointed to perform such processing activities pursuant to articles 28 and 29 of the Regulation (EU) 2016/679. According to the provisions set forth in art. 5 par. 1 lett. e) of the Regulation (EU) 2016/679, collected personal data shall be kept in a form which permits identification of data subjects for a period not exceeding the purposes for which the personal data were collected and subsequently processed.
Data retention periods depend on the purposes of the processing:
1. purposes related to technical navigation data for the correct functioning of the website: retention only for the related session, after which the data are deleted;
2. purpose of reply to info request/services supply request (up to 36 months for contact requests ; 10 years for administrative / accounting / financial documentation relating to the provision of a service);
3. newsletter, marketing or promotional communications in general (up to 36 months);
4. purpose of di administrative / accounting / financial management: 10 years as as required by law for the conservation of administrative / accounting / financial documentation.
7.NATURE OF DATA PROVISION AND REFUSAL
The provision of your personal data through the data collection form or provided in specific websites areas is optional but necessary. The refusal to provide your personal data will entail the impossibility to provide you with the services requested through the website and to obtain the information requested.
8.DATA SUBJECT’S RIGHTS
You may exercise your rights pursuant to articles 15, 16, 17, 18, 19, 20, 21, 22 of the Regulation EU 2016/679, in respect of and against each of the controllers, by contacting the controllers at the following contacts: email@example.com or writing at Controller’s headquarters.
You have the right, at any time, to request the data Controller to access your personal data and receive the information concerning their processing such as the purposes of the processing, the categories of personal data concerned, the recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period, the existence of automated decision-making, including profiling. You have the right to rectify, erase your personal data or limit their processing. Where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You have the right to be informed of the appropriate safeguards pursuant to Article 46 of the Regulation (EU) 2016/679 relating to the transfer of your personal data. You have the right to the portability of your personal data; in such case the Controller shall provide you with your personal data in a structured, commonly used and machine-readable format, and you have the right to transmit those data to another controller. Furthermore, you have the right to object, at any time, to the processing of your data which is based on point (e) or (f) of Article 6(1) of the Regulation (EU) 2016/679, including profiling based on those provisions. Where your personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing (including profiling to the extent that it is related to such direct marketing). You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Without prejudice to any other administrative or judicial remedy, if you consider that the processing of your personal data infringes the Regulation (EU) 2016/679, you have the right to lodge a complaint with a supervisory authority.
Last update: May 2018
Data Controller – Lagodicomo.com S.r.l.