1) Lawful basis for processing
This site processes data on the basis of consent. By using or consulting this site users and/or visitors explicitly approve this privacy statement and give their consent to the processing of their personal data, in respect to the methods and the purposes specified here below, including the possible disclosure to third parties, if necessary for the performance of a service.
The provision of data and, thus, the consent to data collection and processing is optional, the User can refuse to give his/her consent and can withdraw his/her consent which had been previously given, at any time (through the link Contacts at the bottom of the page). However, the denial of the consent may imply the impossibility to provide certain services and may limit the browsing experience on this website. Starting from 25 May 2018, this site will process some of the data based on the legitimate interests of the owner.
2) Data collected and purposes
Like all websites, this site also uses log files where information is collected in an automated form during users’ visits to the site.
- The data that may be collected includes:
– internet protocol (IP) address;
– browser type and device parameters used to connect to the site;
– name of the Internet service provider (ISP);
– date and time of visit;
– the website that the visitor visited prior to this website (referral), and the website visited afterwards;
– where applicable, the number of clicks.
- The above information is processed in an automated form and collected in an exclusively aggregated form to ensure the website is functioning properly, and for security reasons from 25 May 2018 such information will be processed according to the legitimate interests of the owner.
- For security purposes (i.e. through spam filters, firewalls, anti-virus software), automatically recorded data might contain personal data such as IP address, which might be used, in compliance with applicable laws, to block attempts to damage the website or to cause harm to other users, or in any case to carry out any other form of harmful activity or offence. This data is never used to identify or profile users, the sole purpose of this processing is to protect the website and its users. From 25 May 2018 this data will be processed based on the legitimate interests of the owner.
- The data received will be used exclusively for the provision of the requested service and only for the time strictly necessary for the provision of the service. The information that the Users of the site deem to make public through the services and tools, are provided by the User knowingly and voluntarily, exempting this site from any liability regarding any violation of laws. It is up to the User to verify that they have permission to enter personal data of third parties or contents protected by national and international regulations.
- The data collected by the site during its operation are used exclusively for the purposes indicated above and kept for the time strictly necessary to carry out the activities specified. In any case, the data collected from the site will never be provided to third parties, for any reason, unless it is a legitimate request by the judicial authority and only in the cases provided by law.
3) Place of processing
The data collected from the site is processed at the headquarters of the Data Controller, and at the data centre of the web hosting. The web hosting (TOTALCOM NETWORK SRL – Via J. Ressel 2 Bolzano, IT – Register of Companies of Bolzano No. BZ – 221463 tax code and VAT number IT-02976770210), which is appointed responsible for data processing. The latter processes data on behalf of the owner, and is based in the European Economic Area and acts in compliance with European legislation.
Session cookies are essential in order to distinguish between connected users, and are useful to avoid that a required feature can be provided to the wrong user, as well as for security purposes to prevent cyber attacks on the site. Session cookies do not contain personal data and last only for the current session, i.e. until the browser is closed. Session cookies do not require the user’s consent.
The functionality cookies used by the site are strictly necessary for the use of the site, in particular they are linked to an express request for functionality by the user (such as Login), for which no consent is required.
Further information on Google Analytics cookies can be found on the Google Analytics Cookie Usage on Websites page.
For more information on the use of data and their processing by Google, you are kindly invited to refer to the information on the page provided by Google, and on the page on how to use the data by Google when using sites or apps of partners.
Social Network Plugins
The collection and the use of information obtained through the plugin are governed by the respective privacy policies of the social networks, to which you are kindly invited to refer.
5) Transfer of personal data to non-EU countries
This site may share some of the data collected with services located outside the European Union area. In particular with Google, Facebook and Microsoft (LinkedIn) through social plugins and the Google Analytics service. The transfer is authorized on the basis of specific decisions of the European Union and the Guarantor for the protection of personal data, in particular the decision 1250/2016 (Privacy Shield – here the information page of the Italian Privacy Guarantor), for which no further consent is required. The companies mentioned above guarantee their adherence to the Privacy Shield.
6) Security measures
This site processes data of the users in a lawful and correct manner, adopting all adequate security measures to prevent any unauthorized access, any disclosure, any unauthorized change or destruction of data. The processing is carried out using IT and/or telematic tools, in an organised manner and strictly in connection to the purposes indicated. In addition to the owner, in some circumstances, may have access to the data categories of authorised persons involved in the management of the website (administrative, sales, marketing and legal staff, as well as system administrators) or external subjects (such as technical service suppliers, postal services, hosting providers or IT companies).
7) User rights
Pursuant to the legislation in force (EU Regulation 679/2016) and national regulations, according to the manners and within the limits set out by the applicable law, the User can exercise the following rights:
– the right to request confirmation as to whether personal data relating to him/her exist (right of access);
– the right to know the source;
– the right to obtain intelligible communication;
– the right to obtain information on the logic, methods and purposes of the processing;
– the right to request that the data is updated, corrected, integrated, erased, anonymised, and to request the block of the data processed in breach of the law, including those no longer necessary for the purposes for which it was collected;
– where processing is based on consent, the right to receive only the cost of any support, the user’s data provided to the owner, at the sole cost of the possible support, in a structured form and in such a form which can be read a data calculator, as well as in a format which is commonly used by an electronic device;
– the right to lodge a complaint with the Supervisory Authority (Garante Privacy – www.garanteprivacy.it);
– as well as, more in general, exercise all the rights that are recognized by the current provisions of the law.
Requests should be addressed to the data controller.
Where data is processed on the basis of the legitimate interests of the company, the rights of the data subjects are however guaranteed (with the exception of the right to portability that is not provided for by the regulations), particularly the right to object to the processing which can be exercised by sending a request to the data controller.
8) Data Controller
The data controller in accordance with the laws in force is Horstmann Hotels Group s.r.l., who can be contacted through the CONTACTS section.
9) Responsible for data processing
Google is appointed data controller, processing data on behalf of the owner (Google Analytics).