Effective date: 25/05/2018
In accordance with the ORDINANCE (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL, we inform you that we will process personal data of customers and suppliers, as well as data of persons who communicate their data willingly (personally, by phoning, by faxing or by e-mailing to us) and by registering on our website, as well as persons whose data have been acquired by third parties, for example when collecting external data for business information, public directories, etc., whereas in the latter case only personal data of ordinary / common kind and nature is concerned.
Our company guarantees within the framework of legal regulations that the processing of personal data takes into account the fundamental rights and freedoms as well as the dignity of the person concerned, with particular reference to secrecy, personal identity and the right of protecting personal data.
Target and purpose positions in data processing:
In relation to the above stated objectives, your personal information will be forwarded as needed:
- fulfillment of legal obligations, duties arising from regulations, community norms as well as civil and tax laws
- fulfillment of any contractual obligations to the person concerned
- Performing activities related to the business of our company, such as completing internal statistics, accounting, and managing customer / supplier accounting
- Business objectives such as sending business information and promotional material (by post, fax and e-mail), marketing and market research
- Protection of claims and management of liabilities
- Objectives regarding insurance, especially credit insurance
- area of publication and circulation of data
- For the facilitation and realization of guest booking; the successful execution of the guest’s stay; to coordinate the hotel stay according to the wishes and interests of the guest; to ensure the provision of future hotel services which correspond with the interests of the guest; for marketing purposes as pertaining to hotel performance and the improvement of this performance
- to the public administration and authorities, if stipulated by law
- to credit institutions our company has business relations with, concerning the management of receivables / payables and financial intermediation
- to all those natural and / or legal, public and / or private persons (legal, administrative and tax consulting offices, courts, chambers of commerce, etc.), if the forwarding proves necessary or convenient for the performance of our duties
- to suppliers / manufacturers, for the execution of the orders
- The personal data processed by our company are not subject to circulation.
- To contracted service providers who supply cloud-based software and data handling solutions to the hotel. These providers operate with the sole purpose of processing and analyzing guest data for the aforementioned purposes.
What kind of information is collected from you and for how long?
1. Information provided by the user and collected automatically
The personal data stored by our company are collected directly from customers or third parties, such as the hypothesis that the company acquires data from external companies for commercial information, market research, direct offers of products or services. For this last type of data, an informative notice will be provided at the time of its registration or, in any event, no later than the first possible notice.
In addition, our company may possess data that the law defines as "sensitive" in relation to customer-requested transactions. The law requires a specific consent for their utilization.
2. Data Storage
Click on this link
to see the retention period of the data.
Type of data processing:
The data processing may be carried out with or without the aid of electronic means - in any case automatic - and includes all the operations required and necessary for the data processing concerned. In any case, the data processing will be carried out in compliance with all security measures that ensure their security and secrecy.
to learn how to review and disable this information. Please note that the exclusion of interest-based advertising does not prevent the display of advertising that is not based on your interests
Third parties who act as processors of such contractual processing guarantee that they will not store the data received from the client and will not use them for other purposes. Our contractors are contractually committed to use the same privacy and security standards, and we ensure that they are complied with.
Dati di navigazione Internet:
The computer systems and procedures provided for the function of the stephanshof.secure.consisto.net
website collect certain personal information during normal operation, the transmission of which is subject to the use of data exchange protocols on the Internet.
It is information that is not collected to associate with identified persons but, by their nature, enables users to be identified by processing and linking to third party data. This category of data includes the IP addresses or domain names of the computers that connect to the website, the Uniform Resource Identifier (URI) addresses of the resources requested, the time of the request, and other parameters related to the transfer and the data communication of the user's computer environment.
These data are used only for the purpose of collecting anonymous statistical information when using the Website to verify that it works correctly. The data in question may be used to establish liability in the case of offenses by means of information technology to the detriment of our website.
Transfer of data abroad:
We may need to submit your data to service providers in non-European countries (EEA). The EEA consists of countries of the European Union and Switzerland, Iceland, Liechtenstein and Norway, which are considered to be countries with equivalent data protection and privacy laws. This type of data transfer may occur if our servers (i.e. where we store data) or our suppliers and service providers are located outside the EEA or if you use our products and services during your stay in countries outside the EEA from this area.
The updated list of third countries to which the company may transfer data is available on request to the data controller.
Rights of the person concerned:
The Basic Data Protection Regulation 679/2016 gives the data subject the opportunity to exercise certain rights. In particular, it has the right to obtain information on whether and what kind of its data exist and to obtain in an understandable form details of such data, their origin and the reason for and purpose of their processing, as well as details of the holder and controller of the processing and persons and categories of persons to whom such data may be transmitted.
The data subject has the right to update, correct and complete his data and to request that the data be deleted, blocked and converted into anonymous data if the processing violates the legal provisions. He has the right, for a justified reason, to oppose, in whole or in part, the processing of his data, and for no justified reason, to use data for the purposes of trade information, the sending of advertising material, direct sales, market research and opinion polling.
In addition, from 25 May 2018 onwards, the right to data portability will apply. For more information, please contact the data controller.
If you believe that your rights have been violated, you have the right to lodge a complaint with the competent data protection authority (Garante della Privacy) or to take legal action.
The rights can be asserted on the part of the person concerned or a person commissioned by him, by means of a request to the person responsible for data processing at the Granpanorama Hotel StephansHof ****
– St. Stefan 12 - 39040 Villanders - by registered mail or e-mail to email@example.com
Holder of the data processing:
Granpanorama Hotel StephansHof ****
St. Stefan 12
T. +39 0472 843 150
Time information for the data storage of personal data
- 5 years after the last data processing, regarding the established business relationship;
- 5 years after expiry of the notified period of validity of the offer.
The following categories of personal data may be stored for different periods of time:
- Financial information (such as payments, refunds, etc.) will be retained for the duration required by applicable tax and accounting rules;
- All user-generated content (e.g. comments and ratings) is anonymous, but remains available on our platforms.
On our website you have the possibility to buy vouchers. To process your purchase and to save and store your data we use software provided by ADDITIVE s.n.c., 39011 Lana (BZ), Italy (“ADDITIVE”). Through the use of these services and systems your data will be processed and stored, at least in part, also outside of the EU or the EEC. The adequate level of data protection is based on an adequacy decision taken by the European Commission (“Privacy Shield”) or on data processing agreements.
The data you provide is required to fulfil the contract or to carry out pre-contractual measures. Without this data we cannot conclude a contract with you. The data will not be transferred to an outside third party, except for your credit card data which will be transferred to the payment provider and to our tax accountant to fulfil our tax obligations.
The data processing takes place in accordance with the requirements of art. 6 para. 1 lit a (consent) and/or lit b (processing necessary for the performance of a contract) of the GDPR.