Simplified Privacy Policy
Personal Data processed for the following purposes and using the following services:
Contacting the User
-
Mailing list o newsletter
Personal Data: email
-
Contact form
Personal Data: surname; first name; email; phone number;
various types of Data
Contact information
Data Controller
-
Holiday Home "Everyone at the Sea" Via S.Francesco 19,
88811 Cirò Marina (KR)
-
Email address of the Data Controller:
postmaster@casavacanzeciromarina.it
Complete Privacy Policy
Data Controller
Holiday Home "Everyone at the Sea" Via S. Francesco 19,
88811 Cirò Marina (KR)
Data Controller's email address:postmaster@casavacanzeciromarina.it
Types of Data collected
Among the Personal Data collected by this Application, either independently or through third parties, are: email; surname; phone number; various types of Data; first name.
Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data collection itself.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to provide them, it may be impossible for this Application to provide the Service. In cases where this Application indicates certain Data as optional, Users are free to refrain from communicating such Data, without this affecting the availability of the Service or its operation.
Users who have doubts about which Data is mandatory are encouraged to contact the Data Controller.
The possible use of Cookies - or other tracking tools - by this Application or by third-party service providers used by this Application, unless otherwise specified, aims to provide the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application and guarantees that they have the right to communicate or disseminate them, holding the Data Controller harmless from any liability towards third parties.
Methods and place of processing of the collected Data
Processing methods
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.
Processing is carried out using IT and/or telematic tools, with organizational methods and with logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the organization of this Application (administrative, commercial, marketing, legal staff, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) appointed, if necessary, as Data Processors by the Data Controller, may have access to the Data. The updated list of Data Processors can always be requested from the Data Controller.
Legal basis for processing
The Data Controller processes Personal Data relating to the User if one of the following conditions is met:
-
the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Data Controller may be allowed to process Personal Data without the need for the User's consent or another of the legal bases specified below, until the User objects (“opt-out”) to such processing. However, this does not apply where the processing of Personal Data is governed by European data protection legislation;
-
the processing is necessary for the performance of a contract with the User and/or for the implementation of pre-contractual measures;
-
the processing is necessary to comply with a legal obligation to which the Data Controller is subject;
-
the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
-
the processing is necessary for the pursuit of the legitimate interests of the Data Controller or third parties.
It is always possible to ask the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on the law, required by a contract, or necessary to conclude a contract.
Place
Data are processed at the Data Controller's operational offices and in any other place where the parties involved in the processing are located. For more information, contact the Data Controller.
The User's Personal Data may be transferred to a country other than the one in which the User is located. For further information about the location of the processing, the User can refer to the section related to details on the processing of Personal Data.
The User has the right to obtain information regarding the legal basis of the transfer of Data outside the European Union or to an international organization under public international law or constituted by two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.
The User can verify whether any of the aforementioned transfers take place by examining the section of this document relating to details on the processing of Personal Data or by requesting information from the Data Controller using the contact details provided at the beginning.
Retention period
Data are processed and stored for the time required to achieve the purposes for which they were collected.
Therefore:
-
Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the completion of such contract.
-
Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is fulfilled. The User can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
When processing is based on the User's consent, the Data Controller may keep Personal Data for a longer period until said consent is withdrawn. Additionally, the Data Controller may be obliged to keep Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
After the retention period, Personal Data will be deleted. Therefore, upon the expiration of this period, the right to access, deletion, correction, and the right to data portability can no longer be exercised.
Purposes of the processing of the collected Data
The User's Data are collected to allow the Data Controller to provide the Service, comply with legal obligations, respond to requests or perform actions, protect their rights and interests (or those of Users or third parties), identify possible fraudulent or malicious activities, as well as for the following purposes: Contacting the User.
For detailed information on the purposes of processing and the Personal Data processed for each purpose, the User can refer to the section “Details on the processing of Personal Data”.
Details on the processing of Personal Data
Personal Data are collected for the following purposes and using the following services:
Contacting the User
Mailing list or newsletter (this Application)
By subscribing to the mailing list or newsletter, the User's email address is automatically added to a contact list to which email messages containing information, including commercial and promotional information, related to this Application may be sent. The User's email address may also be added to this list as a result of registering with this Application or after making a purchase.
Personal Data processed: email.
Contact form (this Application)
By filling out the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other nature indicated by the header of the form.
Personal Data processed: surname; email; first name; phone number; various types of Data.
User Rights
Users can exercise certain rights with respect to the Data processed by the Data Controller.
In particular, the User has the right to:
-
withdraw consent at any time. The User can withdraw consent to the processing of their Personal Data previously given.
-
object to the processing of their Data. The User can object to the processing of their Data when it is based on a legal basis other than consent. Further details on the right to object are provided in the section below.
-
access their Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the Data processed.
-
verify and request correction. The User can verify the accuracy of their Data and request its update or correction.
-
obtain the restriction of processing. When certain conditions apply, the User can request the restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose than its retention.
-
obtain the deletion or removal of their Personal Data. When certain conditions apply, the User can request the deletion of their Data by the Data Controller.
-
receive their Data or have them transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transferred without hindrance to another controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User's consent, on a contract to which the User is a party, or on contractual measures related to it.
-
lodge a complaint. The User can lodge a complaint with their competent data protection authority.
To exercise their rights, Users can address a request to the Data Controller using the contact details provided in this document. Requests are made free of charge and will be addressed by the Data Controller as soon as possible, in any case within one month.
Further information about Data collection and processing
Legal Action
The User's Personal Data may be used for legal purposes by the Data Controller in court or in the stages leading to possible legal action arising from improper use of this Application or related Services.
The User declares to be aware that the Data Controller may be required to reveal Personal Data upon request of public authorities.
System Logs and Maintenance
For operation and maintenance purposes, this Application and any third-party services used by it may collect System Logs, i.e., files that record interactions and may also contain Personal Data, such as IP addresses.
Information not contained in this policy
More details regarding the collection or processing of Personal Data may be requested from the Data Controller at any time. Please refer to the contact information at the beginning of this document.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying its Users on this page. It is strongly recommended to check this page often, referring to the date of the last modification indicated at the bottom.
If the User objects to any of the changes to the Policy, the User must cease using this Application and may request the Data Controller to delete their Personal Data. Unless otherwise specified, the previous privacy policy will continue to apply to the Personal Data collected until that moment.
Definitions and legal references
Personal Data (or Data)
Any information regarding a natural person, identified or identifiable, even indirectly, by reference to any other information, including a personal identification number.
Usage Data
Information collected automatically through this Application (or third-party services employed in this Application), which includes: IP addresses or domain names of the computers used by the User connecting with this Application, URI addresses (Uniform Resource Identifier), the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.), the country of origin, the features of the browser and operating system used by the User, the various time details per visit (e.g., the time spent on each page) and details about the path followed within the Application, with particular reference to the sequence of pages visited and other parameters related to the device operating system and/or the User's IT environment.
User
The individual using this Application, who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refer.
Data Processor
The natural or legal person, public authority, agency, or other body that processes Personal Data on behalf of the Data Controller, as described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency, or other body that, alone or together with others, determines the purposes and means of the processing of Personal Data and the tools used, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.
This Application
The means by which the User's Personal Data are collected and processed.
Service
The service provided by this Application as described in the relative terms (if available) on this site/application.
European Union (or EU)
Unless otherwise specified, all references made in this document to the European Union include all current member states of the European Union and the European Economic Area.
Cookies
Small piece of data stored in the User's device.
Legal references
This privacy statement has been prepared in compliance with multiple regulatory frameworks, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation), Art. 13/14 of Regulation (EU) 2018/1725 (applicable to EU institutions and bodies), and the provisions of the Data Protection Act 2018 (UK) and the Swiss Federal Act on Data Protection (FADP).