Privacy Policy
Information pursuant to Article 13 of European Regulation 679/2016 and consent.
Pursuant to Article 13 of European Regulation (EU) 2016/679 (GDPR), and in relation to the personal data that Il Saraceno B&B will have access to, we hereby inform you of the following:
The website bbilsaraceno.it collects certain personal data from its users.
Data Controller
Ancora Cosimo
Contrada Pagliamonte, 72012 Carovigno (Brindisi) – Italy
Tel. +39 3336199659 – Email: info@bbilsaraceno.it
Types of Data Collected
Through tools such as contact forms, email correspondence and telephone contacts available on this website, we collect certain personal data from users, either directly or via third parties.
The data collected includes: first name, surname, telephone number, VAT number, company name, email address, interests, tax reference number, user ID, a copy of the identity documents submitted for check-in, usage data, tracking tools, and device information.
Full details on each type of data collected are provided in the relevant sections of this privacy policy or via information notices displayed prior to the collection of the data.
Personal data may be freely provided by the user or, in the case of usage data, collected automatically whilst using this website.
Unless otherwise specified, all data requested by this website is mandatory. If the user refuses to provide this data, it may not be possible to provide the requested service.
Where this website indicates that certain data is optional, users are free to refrain from providing such data, without this having any impact on the availability or functionality of the service.
The use of cookies – or other tracking tools – by this website or by the providers of third-party services used by this website, unless otherwise specified, is intended to provide the service requested by the user, in addition to the further purposes described in this document and in the Cookie Policy.
The user assumes responsibility for any third-party personal data obtained, published or shared via this website and guarantees that they have the right to disclose or disseminate such data, thereby releasing the Data Controller from any liability towards third parties.
Methods and location of data processing
Methods of processing
The Data Controller implements appropriate security measures to prevent unauthorised access, disclosure, alteration or destruction of personal data.
Processing is carried out using IT and/or telecommunications tools, with organisational procedures and logic strictly related to the purposes indicated.
In addition to the Data Controller, in some cases, other parties involved in the organisation of this website (administrative, sales, marketing and legal staff, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies and communication agencies) may have access to the data; these parties may also be appointed, where necessary, as Data Processors by the Data Controller.
An up-to-date list of data processors may always be requested from the Data Controller.
Legal basis for processing
The Data Controller processes personal data relating to the user where one of the following conditions applies:
You have given your consent for one or more specific purposes;
NB: in some jurisdictions, the Data Controller may be authorised to process personal data without your consent or any of the other legal bases specified below, until you object (“opt-out”) to such processing.
However, this does not apply where the processing of personal data is governed by European data protection legislation;
– the processing is necessary for the performance of a contract with the User and/or for the implementation of pre-contractual measures;
– the processing is necessary for compliance with a legal obligation to which the Data Controller is subject;
– the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
– the processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.
In any event, you may always ask the Data Controller to clarify the specific legal basis for each processing operation and, in particular, to specify whether the processing is based on law, provided for by a contract or necessary for the conclusion of a contract.
Location
Data is processed at the Data Controller’s operational premises and at any other location where the parties involved in the processing are situated.
For further information, please contact the Data Controller.
Your personal data may be transferred to a country other than the one in which you are located. For further information on the location of processing, please refer to the section detailing the processing of personal data.
You have the right to obtain information regarding the legal basis for the transfer of your data outside the European Union or to an international organisation governed by public international law or constituted by two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the data.
You can check whether any of the transfers described above are taking place by referring to the section of this document detailing the processing of personal data, or by contacting the Data Controller using the contact details provided at the beginning of this document.
Retention period
Data is processed and retained for as long as is necessary for the purposes for which it was collected.
Therefore:
Personal data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of that contract has been completed.
Personal data collected for purposes based on the Data Controller’s legitimate interests will be retained until such interests are satisfied.
The User may obtain further information regarding the legitimate interests pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
Where processing is based on the User’s consent, the Data Controller may retain personal data for a longer period until such consent is withdrawn.
Furthermore, the Data Controller may be obliged to retain personal data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, personal data will be deleted.
Consequently, once this period has expired, the rights of access, erasure, rectification and data portability can no longer be exercised.
Purposes of the processing of collected data
User data is collected to enable the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), identify any malicious or fraudulent activities, as well as for the following purposes: Contacting the User, Tag Management, Displaying content from external platforms and Statistics.
For detailed information on the purposes of processing and the personal data processed for each purpose, the User may refer to the section “Details on the processing of personal data”.
Details on the processing of personal data
Personal data is collected for the following purposes and using the following services:
Contacting the User
Contact forms on this website
By filling in a contact form with their details, the User consents to their use to respond to requests for information, quotes, or any other purpose indicated in the form header.
Personal data processed: Tax Code, surname and first name, email address, User ID, telephone number, copy of identity documents sent by the user for check-in, VAT number, company name, preferences, optional data entered voluntarily by the user in the text fields of the contact forms.
Statistics
The services included in this section enable the Data Controller to monitor and analyse traffic data and are used to track user behaviour.
Display of content from external platforms
This type of service allows content hosted on external platforms to be displayed directly on the pages of this website and to interact with it.
However, this type of service may still collect web traffic data relating to the pages where the service is installed, even when users do not use it.
Google Fonts (Google Ireland Limited)
Google Fonts is a font display service managed by Google Ireland Limited that allows this website to integrate such content into its pages.
Personal Data processed: Usage Data, Tracking Tool.
Place of processing: Ireland – Privacy Policy.
Google Maps (Google Ireland Limited)
Google Maps is a map display service operated by Google Ireland Limited that allows this Application to integrate such content within its pages.
Personal Data processed: Usage Data; Tracking Tool.
Place of processing: Ireland – Privacy Policy.
WhatsApp – WhatsApp Ireland Limited
We use WhatsApp for chat support for customer care purposes.
Personal data collected: Cookies and usage data
Place of processing: Ireland – Privacy Policy.
Facebook (Facebook Ireland Ltd)
The Facebook social widget provides a service for interacting with the Facebook social network, displaying the post feed.
Personal data processed: Cookies and Usage Data.
Place of processing: Ireland
For further information on how users can protect their privacy, please refer to the Facebook Privacy Policy.
Instagram Widget
Instagram is an image viewing service managed by Facebook Ireland Ltd, which allows this Application to integrate such content within its pages.
Personal Data processed: Usage Data, Tracking Tools.
Place of processing: Ireland – Instagram Data Policy
User rights
Users may exercise certain rights in relation to the data processed by the Data Controller.
In particular, the user has the right to:
– Withdraw consent at any time.
The user may withdraw their previously given consent to the processing of their personal data.
– Object to the processing of their data. The user may object to the processing of their data where it is carried out on a legal basis other than consent. Further details on the right to object are set out in the section below.
– Access your data. You have the right to obtain information about the data processed by the Data Controller, about certain aspects of the processing, and to receive a copy of the data processed.
– Check and request rectification. You may check the accuracy of your data and request that it be updated or corrected.
– Obtain restriction of processing. Where certain conditions apply, you may request that the processing of your data be restricted. In such cases, the Data Controller will not process the data for any purpose other than storage.
– Obtain the erasure or removal of your personal data. Where certain conditions apply, you may request that the Data Controller erase your data.
– Receive your data or have it transferred to another data controller. You have the right to receive your data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another data controller. This provision applies where the data is processed by automated means and the processing is based on the user’s consent, on a contract to which the user is a party, or on contractual measures related thereto.
Lodge a complaint. The user may lodge a complaint with the competent data protection supervisory authority or bring legal proceedings.
Details on the right to object
Where personal data are processed in the public interest, in the exercise of official authority vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, users have the right to object to the processing on grounds relating to their particular situation.
Users are reminded that, where their data is processed for direct marketing purposes, they may object to the processing without providing any justification. To find out whether the Data Controller processes data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise your rights
To exercise their rights, users may submit a request to the Data Controller’s contact details provided in this document. Requests are submitted free of charge and processed by the Data Controller as quickly as possible, and in any event within one month.
Cookie Policy
This website uses Tracking Tools. To find out more, please consult the Cookie Policy.
Further information on processing
Defence in legal proceedings
The user’s personal data may be used by the Data Controller in legal proceedings or during the preparatory stages leading to such proceedings to defend against misuse of this website or related services by the user.
The user acknowledges that the Data Controller may be required to disclose the data by order of public authorities.
Specific notices
At the user’s request, in addition to the information contained in this privacy policy, this website may provide the user with additional, context-specific notices regarding specific services, or the collection and processing of personal data.
System logs and maintenance
For operational and maintenance purposes, this website and any third-party services it uses may collect system logs, i.e. files that record interactions and may also contain personal data, such as the user’s IP address.
Information not contained in this policy
Further information regarding the processing of Personal Data may be requested at any time from the Data Controller using the contact details provided.
Response to “Do Not Track” requests
This Application does not support “Do Not Track” requests.
To find out whether any third-party services used support them, the User is invited to consult their respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying users on this page and, where possible and where technically and legally feasible, by sending a notification to users via one of the contact details held by the Data Controller.
Where the changes relate to processing activities based on consent, the Data Controller will seek the User’s consent again, if necessary.
Browsing security and personal data entry
To ensure complete security whilst browsing and entering personal data prior to the actual transaction, Risarcimento Assistito uses SSL (Secure Socket Layer) technology.
This technology encrypts and protects data sent over the internet.
When SSL is enabled, a padlock icon will appear at the top of the browser alongside a green address bar; clicking on it will display information about the SSL digital certificate.
Furthermore, at the top of the browser, the URL will begin with “https” instead of “http”, ensuring that the data on the page the customer is viewing is secure.
—————–
Privacy (Legislative Decree 196/2003)
Safeguarding the confidentiality of personal data is a top priority for Il Saraceno B&B; for this reason, our online activities are managed in accordance with data protection and security laws.
This document, entitled “Privacy”, contains information regarding the collection and management of user data by bbilsaraceno.it.
This Policy may be amended or updated to reflect the nature of the services offered by bbilsaraceno.it. Pursuant to Article 13 of Legislative Decree 196/2003, we hereby declare the following:
Collection and use of personal data.
We collect information regarding the profile of our visitors: personal information (name, company, email address, etc.) provided to us voluntarily by the user. The processing of the personal data provided may include the following activities: collection, recording, organisation, storage, processing, modification, communication, erasure and destruction.
The sole purpose of processing is to enable us to provide our services and to facilitate the necessary administration, as well as to carry out activities including, but not limited to:
- processing data for internal statistics;
- operational activities for internal management. Completing forms or sending messages via the website www.bbilsaraceno.it implies consent to the processing of the personal data provided for the purposes mentioned above. The information collected via the various registration forms for services on www.bbilsaraceno.it will be processed, protected and controlled in accordance with security measures, using means capable of preventing the risk of loss or destruction, unauthorised access or unauthorised processing, or any breach of the integrity or confidentiality of the data.
Il Saraceno B&B reserves the right to provide the data collected to third parties with whom it has a relationship for the management, maintenance and operation of its website, as well as for internal purposes and to comply with legal obligations. However, such third parties are prohibited from using the information to which they have access (for the purpose of providing the services listed above) for any purpose other than the provision of the service itself.
It is important to note that personal data is provided to the website via the internet, travelling through systems that are not controllable or controlled by Il Saraceno B&B and may be intercepted by unauthorised third parties.
- External links on the website www.bbilsaraceno.it may contain links to other websites, operated by affiliated or unaffiliated companies. The latter is not responsible for the content or compliance with privacy regulations by the linked sites referred to. We therefore recommend that you read the privacy policy of each site you visit carefully.
www.bbilsaraceno.it undertakes to resolve any dispute arising from the privacy policy fairly and promptly.
- Express consent of the data subject Pursuant to Articles 23 and 24 of Legislative Decree 196/2003, the express consent of the data subject is required for the use of data by www.bbilsaraceno.it for purposes other than those previously indicated, and in particular: the processing of internal market research and statistics.
PROTECTION OF PERSONAL DATA
Pursuant to Article 13 of Legislative Decree No. 196/03, as amended and supplemented (“Privacy Code”), we hereby inform you that your personal data will be processed, including by electronic means, by Il Saraceno B&B, with registered office at Contrada Pagliamonte
72012 Carovigno (Brindisi) – Italy – info@bbilsaraceno.it, in the person of its legal representative Ancora Cosimo, acting as data controller for the purposes of executing contracts, processing requests and providing the services you have requested, as well as for the fulfilment of obligations under national and/or EU laws and regulations.
Failure to complete the mandatory fields marked with an asterisk [*] will make it impossible for Il Saraceno B&B to continue providing the services you have requested. In relation to this purpose, you will be asked to give your consent to the relevant processing.
Please note that you may exercise the rights set out in Article 7 of the Privacy Code at any time by sending an email to info@bbilsaraceno.it.
We invite you, in any case, to update your details should they change, and to read the full text of the privacy notice set out below.
Transcript of Article 13 of Legislative Decree No. 196 of 30 June 2003
1 – PRIVACY NOTICE
1 The data subject or the person from whom personal data is collected shall be informed in advance, either orally or in writing, of:
1.1 the purposes and methods of the processing for which the data is intended;
1.2 whether the provision of data is mandatory or optional;
1.3 the consequences of any refusal to provide the data;
1.4 the persons or categories of persons to whom the personal data may be disclosed or who may become aware of it in their capacity as data processors or persons in charge of processing, and the scope of such disclosure;
1.5 the rights referred to in Article 7;
1.6 the identification details of the data controller and, where designated, of the representative within the territory of the State pursuant to Article 5, and of the data processor. Where the data controller has appointed more than one data processor, at least one of them shall be indicated, specifying the website or the means by which the updated list of data processors can be easily accessed. Where a data processor has been appointed to respond to the data subject in the event of the exercise of the rights referred to in Article 7, that data processor shall be indicated.
2 The information referred to in paragraph 1 shall also contain the elements provided for by specific provisions of this Code and may omit elements already known to the data subject or the disclosure of which could in practice hinder the performance, by a public body, of inspection or control functions carried out for the purposes of national defence or security, or the prevention, investigation or prosecution of criminal offences.
3 The Data Protection Authority may, by its own decision, establish simplified procedures for the information provided, in particular by telephone assistance and information services to the public.
4 If personal data are not collected from the data subject, the information referred to in paragraph 1, including the categories of data processed, shall be provided to the data subject at the time of data recording or, where communication of the data is envisaged, no later than the first communication.
5 The provision referred to in paragraph 4 shall not apply where:
5.1 the data are processed in accordance with an obligation laid down by law, by a regulation or by Community legislation;
5.2 the data are processed for the purposes of conducting defence investigations as referred to in Law No 397 of 7 December 2000, or, in any event, to assert or defend a right in court, provided that the data are processed exclusively for such purposes and for the period strictly necessary to achieve them;
5.3 informing the data subject would involve the use of means which the Data Protection Authority, in prescribing any appropriate measures, declares to be manifestly disproportionate to the right being protected, or which, in the opinion of the Data Protection Authority, proves impossible.
Transcription of Article 7 (Legislative Decree No. 196 of 30 June 2003)
2 – Right of access to personal data and other rights
1 The data subject has the right to obtain confirmation as to whether or not personal data concerning him or her exist, even if not yet recorded, and to have such data communicated to him or her in an intelligible form.
2 The data subject has the right to obtain information regarding:
2.1 the source of the personal data;
2.2 the purposes and methods of processing;
2.3 the logic applied where processing is carried out with the aid of electronic tools;
2.4 the identification details of the data controller, data processors and the representative designated pursuant to Article 5(2);
2.5 the subjects or categories of subjects to whom the personal data may be disclosed or who may become aware of it in their capacity as designated representative within the territory of the State, data processors or persons in charge of processing.
3 The data subject has the right to obtain:
3.1 the updating, rectification or, where interested, the completion of the data;
3.2 the erasure, anonymisation or blocking of data processed in breach of the law, including data which need not be retained for the purposes for which the data were collected or subsequently processed;
3.3 confirmation that the operations referred to in points (a) and (b) have been brought to the attention, including as regards their content, of those to whom the data have been disclosed or made public, unless this proves impossible or involves a manifestly disproportionate effort compared with the right being protected.
4 The data subject has the right to object, in whole or in part:
4.1 on legitimate grounds, to the processing of personal data concerning him or her, even if pertinent to the purpose of collection;
4.2 to the processing of personal data concerning him or her for the purposes of sending advertising or direct sales material or for carrying out market research or commercial communication.
3 – Secure browsing and entry of personal data
To ensure complete security whilst browsing and entering personal data prior to the actual transaction, Il Saraceno B&B uses SSL (Secure Socket Layer) technology.
This technology encrypts and protects data sent over the internet.
When the SSL protocol is activated, a padlock icon with a green address bar will appear at the top of the browser; clicking on it will provide information regarding the SSL digital certificate.
In addition, at the top of the browser, the URL will begin with “https” instead of “http”, which ensures that the data on the page the customer is viewing is secure.