INFORMATION ON THE PROCESSING OF PERSONAL DATA
of the users visiting the websites of Grand Hotel Tremezzo
This page contains a description of the policies for managing the website in regard to processing the personal data of the users who visit the site and their privacy. This information is provided pursuant to article 13 of GDPR 679/2016 – Laws concerning the Protection of Personal Data and the individuals who interact with the web services of Grand Hotel Tremezzo, which is accessible by telematics means through the following web address:
which corresponds to the home page of the official website of Grand Hotel Tremezzo at Via Regina, 8 - 22016 Tremezzina (CO - Italy). This informative note is provided only for the aforementioned website and not for other websites eventually accessed by the user through links.
Following access to this website, data pertaining to persons that are identified or identifiable may be processed. The “Data Controller” of the personal data collected following a visit to our website or any other data used for providing our services is Meta Spa, Viale Masia, 34 - 22100 Como.
PLACE WHERE DATA IS PROCESSED
Data processing pertaining to the web services of this website [(physically hosted by Microsoft Azure (https://azure.microsoft.com/) by our web service provider partner “Positioner” (https://www.positioner.com)] is carried out at the aforementioned headquarters and said data is processed only by the technical personnel in charge of processing of the Data Processing Office, or by eventual persons in charge of processing who are entrusted to process occasional maintenance operations.
The personal data obtained from the users who submit hotel reservation requests or through informative material (informative notes, newsletters, registration, etc) is used only to carry out the services or assistance requested and is not transmitted to third parties, except in the following possible cases:
- Business partners of Meta Spa, Grand Hotel Tremezzo to whom Meta Spa transmits the data exclusively in order to avoid on-line reservations, including Preferred Hotel Group (https://preferredhotels.com) by the SynXis reservation system (https://www.sabre.com) - and Positioner, our web & communication agency;
- Persons, companies or professional offices who lend assistance and consulting services to Meta Spa, Grand Hotel Tremezzo concerning accounting, administrative, legal, financial and tax matters;
- Subjects who are authorized to have access to the data by law or through requests by the authorities;
CATEGORIES OF PROCESSED DATA
The information systems and software procedures relied upon to operate this web site acquire personal data as part of their standard functioning; the transmission of such data is an inherent feature of Internet communication protocols.
Such information is not collected in order to relate it to identified data subjects, however it might allow user identification per se after being processed and matched with data held by third parties.
This data category includes IP addresses, and/or the domain names of the computers used by any user connecting with this web site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of such requests, the method used for submitting a given request to the server, returned file size, a numerical code relating to server response status (successfully performed, error, etc.), and other parameters related to the user's operating system and computer environment.
These data are only used to extract anonymous statistical information on website use as well as to check its functioning; they are erased immediately after being processed. The data might be used to establish liability in case computer crimes are committed against the website; except for this circumstance, any data on web contacts is currently retained for no longer than seven days.
Data voluntarily provided by the user
Sending e-mail messages to the addresses mentioned on this website, which is done on the basis of a freely chosen, explicit, and voluntary option, entails acquisition of the sender's address, which is necessary in order to reply to any request, as well as of such additional personal data as is contained in the message(s).
Data will be retained only for registration request to send the newsletters or special offers, and will not be disclosed to anyone.
The personal information regarding the individual who visited the website is not collected or used. The visitors remain anonymous. The only exception to this rule concerns the information for personal identification needed to fulfill the contractual obligations of reservations on behalf of the user.
In the event of reservations made through the website, the user must provide his name, address, telephone number and information regarding the payment manners and credit card used. Meta Spa will use said information only to process the reservations and to send specific information, which is relevant to the confirmation of said, such as a receipt, the reservation code and the conditions.
The information provided will not be used for marketing purposes and will not be sold, transmitted, given by contract or sent to third parties an any way, with the exception of our provider of on-line reservation services, Preferred Hotel Group, (https://preferredhotels.com/) by his Synxis web tool, to whom elaboration of the reservations is entrusted to, only for online reservations purposes, and Positioner, our web & communication agency.
In any event, the administrator of the website guarantees the use of scrupulous procedures in order to protect the navigational data and the use of particular precautions to protect the data pertaining to the credit card, which is provided during on-line reservations.
Site visitors can register for our newsletter service. By registering, the user's e-mail address will automatically be included in a list of contacts to which e-mail messages will be sent. The newsletter will be containing periodic updates with commercial and promotional information relating to initiatives, events or promotions of the data controller.
To subscribe to the newsletter, you can use the registration forms on the site by entering your name and e-mail address. The information supplied with the registration form will be only used to sending our newsletter via e-mail and will not be disclosed to third parties. The newsletters will be sent through the MAGNEWS platform (https://www.magnews.it/) owned by " DIENNEA S.R.L." acting as data processor.
Personal Data Processing Collected from Curriculum Vitae
Meta Spa accepts personal Curriculum Vitae of possible candidates either via e-mail or in hard paper format. Providing spontaneous and voluntary Curriculum Vitae data will be considered as implicitly informed consent by the data subjects for the personal data processing, limited to the purpose related to the selection of potential candidates.
The data processed for the purpose of selection of candidates are personal, useful to search the particularly requested profile. In general, the nature of the data is normal, except in some cases where you may indicate any sensitive data necessary to meet the specific requirements of the regulations, such as specifying a particularly protected class, the suitability for certain jobs and / or mandatory start-ups, within the limits set by the General Provision of June 5, 2019 which modified the General Authorisation of the Garante (Italian Supervisor Authority) no. 1 of December 15, 2016 on the processing of sensitive data in work relationships.
The provision of personal data relating to the selection of candidates is mandatory. Any refusal to provide such data makes it impossible to perform an orderly selection and the possible recruitment. The data in question will not be disclosed to anyone.
General Rules for providing the CV
Any CV received spontaneously, replying to a job advertisement or to our request, will be stored directly by person in charge of the data processing in accordance with the safety guidelines of personal data adopted adopted in compliance with the security measures according to Chapter IV Section 2 of GDPR 679/2016. These will be printed only on the occasion of a meeting and / or a conference all with the data subject. After the interview, if the candidate is not selected, the CV will be deleted and / or destroyed within 12 months.
In any other case, after a reasonable period of time, consistent with the typical processed business, CVs will be erased and / or destroyed.
Curriculum Vitae have to be sent exclusively to :
- Meta Spa - Viale Masia, 34 - 22100 Como - c.a. Human Resources Director
- E-mail : [email protected]
Meta Spa has adopted an internal communication channel that can be reached through a specific link on this website, pursuant to and for the purposes of Legislative Decree no. 24 of 10 March 2023 concerning "the protection of people who report breaches of Union law and containing provisions regarding the protection of people who report breaches of national regulatory provisions", implementing Directive (EU) 2019/1937. The data will be processed through the platform made available by the Data Processor supplier ML Informatica Srl, and will be managed in compliance with the organisational, physical and logical measures in compliance with the provisions of the art. 32 of the GDPR 2016/679.
PERIOD FOR DATA RETENTION - CRITERIA USED
According to the provisions set forth in art. 5 par. 1 lett. e) of the Regulation (EU) 2016/679, collected personal data shall be kept in a form which permits identification of data subjects for a period not exceeding the purposes for which the personal data were collected and subsequently processed.
Data retention periods depend on the purposes of the processing:
- purposes related to technical navigation data for the correct functioning of the website: retention only for the related session, after which the data are deleted;
- purpose of reply to info request/services supply request (up to 12 months for contact requests; 10 years for administrative / accounting / financial documentation relating to the provision of a service);
- data collection for staff recruitment (up to 12 months);
- newsletter, marketing or promotional communications in general (up to 24 months -until withdrawal of consent)
- purpose of administrative / accounting / financial management: 10 years as as required by law for the conservation of administrative / accounting / financial documentation.
- Whistleblowing communication, 5 years from the last communication
TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES
Personal data is not transferred to non-EU third countries, except for any cases described above where the controller provide appropriate safeguards. For transfers to the USA or others extra EU countries, in the absence of an adequacy decision pursuant to Article 45(3), or of appropriate safeguards pursuant to Article 46, it takes place on the basis:
- Reservation Data - Preferred Hotels:
- the transfer is necessary for the performance of a contract between the data subject and the controller, or the implementation of pre-contractual measures taken at the data subject's request, pursuant to art. 49, 1 b) GDPR;
- the adequacy decision of the EU Commission vs third country or an international organization (Article 45 GDPR), particularly the decision on the adequacy of the protection provided by the EU-U.S. Privacy Shield Framework of 10 July 2023.
OPTIONAL DATA PROVISION
Subject to the specifications made with regard to navigation data, users are free to provide the personal data listed in the request forms of Grand Hotel Tremezzo or referred to in contacting the hotel in order to provide CV, to make on-line reservations or to request delivery of information materials and other communications. Failure to provide such data may entail the failure to be provided with the items requested.
PROCESSING ARRANGEMENTS AND DATA PROTECTION MEASURES
Personal data is also processed with automated means for no longer than is necessary to achieve the purposes for which it has been collected indicated in this information. The Data Controller and the Data Processors ensures the adoption of appropriate technical and organisational measures to ensure a level of security appropriate to the risk and that personal data are processed adequately and in accordance with the purposes for which they are processed, in compliance with the provisions of the art. 32 of the GDPR 2016/679. Specific security measures are implemented to prevent the data from being lost, used unlawfully and/or inappropriately, and accessed without authorisation. There is no provision for an automated decision-making process for the processing of personal data.
DATA SUBJECTS' RIGHTS
The Data Controller is Meta Spa, Grand Hotel Tremezzo. The Data Protection Officer is Mr. Massimo Bruno. You may contact them at any time to exercise your rights as provided for in Chapter III GDPR 679/2016, in particular, the right to obtain confirmation as to whether or not personal data concerning you exist and the logic applied to the processing, the right to ask for their integration, the right to object to their processing on legitimate ground, and the right to request rectification, updating, erasure (right to be forgotten) or blocking of data that have been processed unlawfully, the right to obtain a copy of the personal data being processed as well as the right to data portability, also by sending a written request to the following e-mail address: [email protected].
RIGHT TO LODGE A COMPLAINT
If a data subject considers that the processing of personal data relating to him or her infringes the Regulation, he or she has the right to lodge a complaint with the Garante pursuant to Article 77 of the Regulation, or else to bring a judicial proceeding pursuant to Article 79 of the Regulation.