PRIVACY NOTICE 

Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”)

Dear Guest,

AZ. AGR. LA CASELLA S.R.L. hereby informs you that your personal data will be processed in compliance with Regulation (EU) 2016/679 (“GDPR”) and applicable Italian legislation, in accordance with the principles of lawfulness, fairness, transparency, data minimisation, security and confidentiality.

1. DATA CONTROLLER

The Data Controller is:

AZ. AGR. LA CASELLA S.R.L.
Piazza San Valentino 11, Penna in Teverina (TR), Italy
Tax Code: 01327250559
E-mail: lacasellasrl@libero.it
Tel.: +39 0744 987112
Mobile: +39 366 3205611

2. DATA PROCESSED AND SOURCE OF THE DATA

Personal data may be collected directly from you or, where applicable, through booking platforms, travel agencies, tour operators, event organisers or other intermediaries.

The following data may be processed:

  • identification and contact data: first name, last name, date and place of birth, nationality, address, telephone number and e-mail address;
  • identity document data, where required by law;
  • reservation and service data: arrival and departure dates, information relating to the stay, restaurant services, banqueting, events and any ancillary services requested;
  • administrative, tax, invoicing, payment and transaction data;
  • special categories of personal data, such as information relating to allergies, intolerances, disabilities or other health-related needs, only where voluntarily provided and necessary to supply a specific service requested.

Where payment is handled by an external payment service provider, the Data Controller may not receive or retain the complete payment card details.

3. PURPOSES, LEGAL BASIS AND RETENTION

Reservations and accommodation, restaurant and banqueting services

Personal data are processed to manage enquiries and quotations, acquire and confirm reservations, provide accommodation, restaurant, banqueting and event services, any ancillary services requested, and related communications.

Legal basis: Article 6(1)(b) GDPR – taking steps at the request of the data subject prior to entering into a contract and performance of a contract.

Retention: for the duration of the contractual relationship and thereafter for the period necessary to comply with legal obligations and protect the rights of the Data Controller.

Allergies, intolerances, disabilities and health-related needs

Information falling within special categories of personal data is processed exclusively to meet specific needs voluntarily communicated by the data subject, for example to provide food suitable for allergies or intolerances or services adapted to particular health-related needs or disabilities.

Legal basis: the data subject’s explicit consent pursuant to Article 9(2)(a) GDPR, unless another condition under Article 9 GDPR applies.

Retention: for the time strictly necessary to provide the requested service and, as a rule, until the end of the stay or event, unless further retention is required by law or necessary for the establishment, exercise or defence of legal claims.

Public Security obligations – Alloggiati Web

Guests’ identification data are collected and communicated to the Public Security Authority within the time limits provided for by Article 109 TULPS and the related implementing legislation.

Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation.

Data and any copies of identity documents collected exclusively for this purpose are not retained after the reporting obligations have been fulfilled. The digital transmission receipt generated through Alloggiati Web is retained for five years.

Administrative, accounting and tax obligations

Personal data are processed for invoicing, accounting and compliance with civil, administrative and tax obligations.

Legal basis: Article 6(1)(c) GDPR – compliance with legal obligations.

Retention: normally 10 years, without prejudice to longer periods required by law or necessary in the event of inspections or disputes.

Facilitated registration for future stays

Subject to consent, the necessary data may be retained in order to facilitate reservation and check-in procedures during future stays.

Legal basis: Article 6(1)(a) GDPR – consent.

Retention: maximum 12 months from check-out, unless consent is withdrawn earlier.

Promotional communications

Subject to consent, contact details may be used to send newsletters, offers, rate updates, initiatives and information about events by e-mail or other authorised communication channels.

Legal basis: Article 6(1)(a) GDPR – consent.

Retention: maximum 12 months from the date consent is obtained, unless consent is withdrawn earlier.

Video surveillance

Certain areas of the property may be monitored by video surveillance, as indicated by appropriate signage, in order to protect persons, property and company assets and to prevent or detect unlawful conduct.

Legal basis: Article 6(1)(f) GDPR – the Data Controller’s legitimate interest in security and the protection of property.

Retention: images are normally deleted within 24 hours, except where longer retention is justified by public holidays, closures, specific incidents, investigative requirements or requests from the competent Authorities.

4. NATURE OF THE PROVISION OF DATA AND CONSENT

The provision of data necessary for reservations, performance of services, tax obligations and Public Security obligations is mandatory; failure to provide such data may prevent the conclusion of the contract or the provision of the requested service.

The provision of data for marketing purposes, facilitated registration for future stays and special categories of personal data is optional.

Any consent given may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.

5. RECIPIENTS OF PERSONAL DATA

Personal data may be processed, where necessary and within the limits of the relevant purposes, by authorised personnel of the Data Controller and by parties providing services necessary for the business, including:

  • providers of management software, booking systems, IT services, cloud services and technical support;
  • booking platforms and intermediaries;
  • payment service providers;
  • accountants, tax advisers, legal advisers and other professionals;
  • communication and marketing service providers, where used;
  • Public Authorities, Judicial Authorities and Law Enforcement Authorities where required by law.

Parties processing personal data on behalf of the Data Controller are, where necessary, appointed as Data Processors pursuant to Article 28 GDPR.

Personal data are not sold or disclosed to third parties for purposes unrelated to those set out in this Privacy Notice.

6. TRANSFERS OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA

Where the use of service providers involves the transfer of personal data outside the European Economic Area (“EEA”), such transfers will be carried out in compliance with Chapter V of the GDPR, on the basis of an adequacy decision adopted by the European Commission or other safeguards provided for by applicable law, such as Standard Contractual Clauses.

Further information on any applicable safeguards may be requested from the Data Controller.

7. DATA SECURITY

Personal data are processed using paper-based, electronic and telematic means, with appropriate technical and organisational measures designed to protect them against loss, destruction, alteration, unauthorised access or disclosure.

Access to personal data is permitted only to authorised persons and only to the extent necessary for the performance of their respective duties.

8. RIGHTS OF THE DATA SUBJECT

In the cases provided for under Articles 15–22 GDPR, you may exercise the following rights:

  • access to your personal data;
  • rectification of inaccurate data;
  • erasure;
  • restriction of processing;
  • data portability;
  • objection to processing;
  • objection at any time to direct marketing;
  • withdrawal of previously given consent.

To exercise these rights, you may send a request using the Data Controller’s contact details indicated in Section 1.

You also have the right to lodge a complaint with:

Garante per la protezione dei dati personali
Piazza Venezia n. 11 – 00187 Rome, Italy
www.garanteprivacy.it

Your right to seek judicial remedies before the competent courts remains unaffected.