Privacy
Privacy Policy of www.hotel-rosalpina.com
This Application collects some Personal Data from its Users.
Data Controller (Article 4, Paragraph 7 of GDPR)
GIORDANI ENRICO E C S.N.C.
Frazione Stumiaga di Fiavè, 8
38075 Fiavè - TN -
Italy
Tel: +39 0465.735012
E-Mail: info@hotel-rosalpina.com
Types of Data Collected
Among the Personal Data collected by this Application, either independently or through third parties, there are: Cookies, Usage Data, and email.
Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific informative texts displayed prior to the collection of the data.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. Failure to provide such Data may make it impossible for this Application to provide its services. In cases where this Application indicates some Data as optional, Users are free not to communicate such Data without affecting the availability or operation of the Service.
Users who are unsure about which Data is mandatory are welcome to contact the Data Controller.
Any use of Cookies – or other tracking tools – by this Application or by the owners of third-party services used by this Application, unless otherwise stated, serves to provide the Service requested by the User, in addition to the other purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application and guarantees that they have the right to communicate or disseminate them, freeing the Controller from any responsibility towards third parties.
Methods and Location of Data Processing
PROCESSING METHODS
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.
The processing is carried out using IT and/or telematic tools, following organizational procedures and practices strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to other parties involved in the operation of this Application (administrative, commercial, marketing, legal staff, system administrators) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communication agencies) appointed, if necessary, as Data Processors by the Data Controller.
The storage of personal data provided will occur in the corporate database to provide the best possible service to customers. Data is stored on corporate servers protected by external access through firewall systems and password access to the database.
Paper data is stored in archives with access reserved for the data processing owners.
LEGAL BASIS FOR PROCESSING
The Data Controller processes Personal Data relating to the User if one of the following conditions is met:
- The User has given their consent for one or more specific purposes. Note: In some jurisdictions, the Data Controller may be authorized to process Personal Data without User consent or another legal basis specified below, as long as the User does not object to ("opt-out") such processing. However, this does not apply when the processing of Personal Data is subject to European legislation on the protection of Personal Data.
- The processing is necessary for the performance of a contract with the User and/or for any pre-contractual obligations thereof.
- The processing is necessary to comply with a legal obligation to which the Data Controller is subject.
- The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.
- The processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.
It is always possible to request the Data Controller to clarify the specific legal basis applicable to each processing operation, in particular whether the processing is based on law, is foreseen by a contract, or is necessary to conclude a contract.
LOCATION
The Data is processed at the operational offices of the Data Controller and in any other places where the parties involved in the processing are located. For more information, contact the Data Controller.
The User's Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User can refer to the section detailing the processing of Personal Data.
The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organization governed by public international law or established by two or more countries, such as the UN, and the security measures adopted by the Controller to protect the Data.
If one of the transfers described above takes place, the User can refer to the respective sections of this document or inquire with the Controller using the contact information provided at the beginning.
STORAGE PERIOD
Data is processed and stored for the time required for the purposes for which it has been collected.
- Personal Data collected for purposes related to the execution of a contract between the Data Controller and the User will be retained until the contract has been fully executed.
- Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained as long as needed to fulfill such purposes. The User may obtain specific information regarding the legitimate interests pursued by the Data Controller within the relevant sections of this document or by contacting the Data Controller.
When processing is based on the User's consent, the Data Controller may retain Personal Data longer until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period to comply with a legal obligation or by order of an authority.
Once the retention period expires, Personal Data will be deleted. Therefore, the right to access, delete, rectify, and the right to data portability cannot be enforced after the retention period expires.