Within the meaning of Article 13 of EU Regulation 2016/679 the personal data provided by you when filling out the "booking” form will be processed in compliance with the rules laid down in EU Regulation 679/2016.
The data controller is Compagnia Italiana Alberghi C.I.A. S.p.a. with registered office in Piazza dell’Unità Italiana 6, Florence.
DATA PROTECTION MANAGER
The Compagnia Italiana Alberghi C.I.A. S.p.A. does not require the Data Protection Manager within the meaning of Article 37 of EU Regulation 679/2016.
PURPOSE, LEGAL BASIS AND COMPULSORY OR OPTIONAL NATURE OF THE PROCESSING
Data provided freely will be processed for the following purposes:
- execution of a contract to which the data subject is party (e.g.: restaurant reservation) or implementation of pre-contractual measures adopted at the request of the interested party (e.g.: request for information, etc.);
- statistical analyses on anonymous data, therefore with no possibility of identifying the user, aimed at measuring the functioning of the Website, measuring traffic and evaluating usability and interest;
- the fulfilment of a legal obligation to which the Compagnia Italiana Alberghi C.I.A. S.p.A. is subject;
- to ascertain, exercise or defend a right in judicial proceedings or whenever the judicial authorities exercise their judicial functions.
The legal basis of the processing of personal data for the purposes referred to in point a) is the service supply contract or the execution of pre-contractual measures. The processing of personal data by the data controller for the purposes referred to in point a) does not require the consent of the data subject within the meaning of the applicable legislation.
The purpose referred to in point b) does not involve the processing of personal data.
The data processing as set out in points c) and d) represent a legitimate activity insofar as is necessary to fulfil the legal obligations to which the data controller is subject or to exercise the right of defence in court.
With the exception of the browsing data necessary for carrying out IT and electronic protocols, the provision of personal data by the users through the various methods made available is free and optional.
In particular with regard to the purposes referred to in point a) the provision of personal data is optional, but failure to do so could make it impossible to supply the service.
PROCESSING PROCEDURES AND STORAGE
The data is processed mainly with computer tools. Data processing will be carried out by an automated or manual form, in in compliance with Article 32 of GDPR 2016/679 by specially appointed persons. Your personal data will be kept until the eventual withdrawal of consent.
SCOPE OF COMMUNICATION AND DISSEMINATION
Your data may be communicated or may become known to the employees or collaborators of our company, expressly designated by us as “authorised to process data" and/or appointed "external processing manager". Your personal data will not be disseminated.
SPECIAL CATEGORIES OF PERSONAL DATA
In order to achieve the purposes referred to in this policy, the data controller does not need to process personal data of a "special" nature within the meaning of article 9 of EU Regulation n. 2016/679.
EXISTENCE OF AN AUTOMATED DECISION-MAKING PROCESS
The Compagnia Italiana Alberghi C.I.A. S.p.A. shall not adopt an automated decision-making process, including profiling, as referred to in Article 22, paragraphs 1 and 4 of EU Regulation n. 679/2016.
RIGHTS OF THE DATA SUBJECT
You may, at any time, exercise the rights provided for by EU Regulation 2016/679 by Articles 15 to 22 and in particular the right to:
request confirmation of the existence or not of your personal data;
obtain details about the purposes of the processing, the categories of personal data, the recipients or categories of recipients to whom the personal data has been or will be communicated and, when possible, the retention period;
obtain the correction and deletion of personal data;
obtain a restriction of the data processing;
obtain data portability, i.e. receive data by a data controller, in a structured format, commonly used and readable by the automatic device, and to transmit it to another data controller without hindrance;
oppose the processing of data at any time and also in the case of processing for the purpose of direct marketing;
oppose an automated decision-making process concerning natural persons, including profiling;
ask the data controller to access the personal data and to correct or delete said data or to restrict the processing which concerns them or to object to it being processed, in addition to the right to the portability of data;
withdraw your consent, at any time, without prejudice to the lawfulness of the processing based on your consent provided before said withdrawal;
submit a complaint to the Guarantor Authority.
You can exercise your rights by written request sent to email address firstname.lastname@example.org.