Pursuant to the Regulation, Hotel & Residence Dorner shall process Personal Data based on the principles of lawfulness, fairness, transparency, limitation of purpose and retention, data minimisation, accuracy, integrity and confidentiality.
TABLE OF CONTENTS
In relation to the data processing carried out through our website, the Data Controller as defined above is Hotel Dorner & Residence d. Götsch Egon & Co. OHG. For any information regarding the processing of Personal Data by the Data Controller, including the list of Data Processors, please write to the following address: firstname.lastname@example.org
Please be informed that as a result of website browsing, the Data Controller will collect and process Personal Data that may consist of information like name and surname, identification number, online identifier, mail address, e-mail address, landline and/or mobile telephone number or information on one or more physical, physiological, psychological, financial, cultural or social features relating to an identified or identifiable person (hereafter “Personal Data”).
The following Personal Data is processed through our Website:
During normal operation, the computer systems and software used to operate our Website acquire some Personal Data the transmission of which is implicit in the Internet communication protocols. The collection of this information is intended to be associated with identified parties; however, the data collected might by its nature allow users to be identified through processing and association with data held by third parties. This category of data includes IP addresses or domain names of computers used by users who connect to the Website, URI (Uniform Resource Identifier) of requested resources, the time of request and method used to submit it to the server, the size of the file obtained in reply, the numerical code indicating the server response status (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment. This data is used for the sole purpose of obtaining anonymous statistical information on the use of the Website and to ensure its correct functioning by identifying any anomalies and/or abuses, and are therefore deleted immediately after processing. The data could be used to ascertain responsibility in the event of possible computer crimes against the Website or third parties; except for this possibility, the data collected from the Website is removed within a short period of time.
If you send us your application via e-mail or through our website, you might provide us with Personal Data that falls within special categories as set forth in art. 9 of the Regulation, namely: “[…] personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and […] genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation”. Please do not disclose this type of data unless it is strictly necessary. Please be informed that if you do choose to provide this type of data without giving your specific consent to the processing (e.g. by sending a CV), the processing on our part will relate to data made manifestly public by the Data Subject, as provided for by art. 9(1)(e) of the Regulation. Therefore, the Data Controller will be released from any liability or dispute whatsoever in connection with the processing of such data. As previously mentioned, explicit consent to the processing of special categories of Personal Data is fundamental if you do choose to disclose such information.
Please be also informed that the Data Controller may view any social media profiles made openly available on professional networking sites or platforms (e.g. LinkedIn).
We may process Personal Data of third parties that you send to the Data Controller when using certain services on our Website (e.g. the request/contact/booking forms). In these cases, you act as independent Data Controller, thereby assuming all the obligations and liabilities set by law. In this sense, you release the Data Controller from any and all responsibilities and obligations with respect to any dispute, claim, compensation for damages etc. that may be received from third parties whose Personal Data has been processed through the Website functions in violation of applicable data protection laws. In any case, if you provide or process Personal Data of third parties while using our Website, you warrant – assuming full liability – that processing has a lawful basis in compliance with art. 6 of the Regulation.
General information about cookies
Cookies are small text files which can be stored by a website, and with the help of the browser, on the hard drive of a client computer, to save smaller amounts of website information for a specific period of time. Generally, there are different types of cookies; some are essential for the functioning of the website, such as navigation or shopping cart cookies. Furthermore, there are so-called Analytics cookies, which collect information, for instance about the number of website visitors and the way they found the website. Function cookies allow the website to remember your selection (e.g. selected filter settings or automatic language setting of a website).
In addition, so-called profiling cookies record the user’s preferences and actions. A user profile is created on the basis of this information. This serves to combine advertising messages with the interests of the user and thus enables more target-group-specific advertising. In many cases, cookies from third parties are used by the website operator to broadcast personalised advertising.
Compulsory consent for cookies
How to block cookies in your browser settings
Click here for more details and information: https://support.mozilla.org/en-US/kb/block-websites-storing-site-preferences
Click here for more details and information: https://support.google.com/chrome/answer/95647?hl=en-GB
Click here for more details and information: http://windows.microsoft.com/en-us/windows-vista/block-or-allow-cookies
Click here for more details and information: https://support.apple.com/kb/PH5042?locale=en_US
If necessary and with your specific consent, we will process your Personal Data for the following purposes:
The lawful basis for the processing of Personal Data for the purposes referred to in section 3 (a-b-c) is art. 6(1)(b) of the Regulation (performance of a contract) as the data is necessary to provide the services required and/or to respond to requests from the interested party. Giving your Personal Data for these purposes is optional, but indispensable to activate the services provided by the Website, to answer requests or evaluate CVs. With specific reference to the purpose 3.c and the viewing of profiles on professional networking platforms made freely available on the Internet, as mentioned in section 2.b, the lawful basis is art. 6(1)(f) of the Regulation, i.e. the legitimate interest of the holder in verifying the candidate’s suitability for the open position and any potential risks.
For the purposes illustrated in section 3.d, the lawful basis is art. 6(1)(c) of the Regulation (compliance with legal obligations). Once provided, Personal Data must be processed for the Data Controller to comply with legal obligations.
Art. 6(1)(a) of the Regulation (your consent) is the lawful basis for the processing of data for the purposes referred to in section 3.e. In this respect, activities that involve the direct sending of advertising material, direct sales or market surveys and commercial communications in relation to products or services similar to those you purchased, the Data Controller may use your e-mail and mail addresses without your consent, in accordance with and within the limits allowed by art. 130, paragraph 4 of the Italian Data Protection Code and the by the Decision of the Italian Data Protection Authority of 19 June 2008. The lawful basis for the processing of your data for this purpose is Art. 6(1)(f) of the Regulation (legitimate interest).
For the purposes listed in section 3, your Personal Data may be shared with:
Some of your Personal Data is shared with Recipients who may be located outside the European Economic Area. The Data Controller ensures that these Recipients process your Personal Data in compliance with the Regulation. Transfer of Personal Data may be based on an adequacy decision, on Standard Contractual Clauses approved by the European Commission or on another appropriate legal basis. For further information please contact the Data Controller by sending an e-mail to: email@example.com
Personal Data processed for the purposes referred to in section 3(a-b) will be kept only for as long as strictly necessary to achieve those purposes. In any case, since data is used in order to provide services, the Data Controller will process the Personal Data up to the time allowed by Italian law (art. 2946 of the Italian Civil Code and subsequent amendments). With regard to any CVs submitted through the Website or by e-mail (see section 3.c), the Personal Data will be kept for as long as necessary for the purpose. The Data Controller may contact the candidate again shortly before the indicated deadline to ask for an extension of the retention period.
Personal Data processed for the purposes referred to in section 3(d) will be stored for as long as provided for by applicable laws and regulations.
Personal Data processed for the purposes referred to in section 3(e) will be kept until we have consent; if you do not withdraw your consent, your data will be stored for a time deemed appropriate.
For more information on our data retention policy and criteria, please contact: firstname.lastname@example.org
Pursuant to Art. 15 and following of the Regulation, you have the right to obtain access to your Personal Data at any time. You have the right to request from the Data Controller rectification or erasure of your data, as well as to object to and restrict processing of your data in the cases provided for by Art. 18 of the Regulation. You have the right to obtain the Personal Data concerning you in a structured, commonly used and machine-readable format in compliance with Art. 20 of the Regulation.mm m
Requests must be submitted in written form and sent at:email@example.com
In any case, you also have the right to lodge a complaint with the competent Supervisory Authority (Italian Data Protection Authority) if you consider that the processing of your Personal Data infringes the applicable law, pursuant to Art. 77 of the Regulation.
On our website you have the possibility to buy vouchers. To process your purchase and to save and store your data we use software provided by ADDITIVE s.n.c., 39011 Lana (BZ), Italy (“ADDITIVE”). Through the use of these services and systems your data will be processed and stored, at least in part, also outside of the EU or the EEC. The adequate level of data protection is based on an adequacy decision taken by the European Commission (“Privacy Shield”) or on data processing agreements.
The data you provide is required to fulfil the contract or to carry out pre-contractual measures. Without this data we cannot conclude a contract with you. The data will not be transferred to an outside third party, except for your credit card data which will be transferred to the payment provider and to our tax accountant to fulfil our tax obligations.
The data processing takes place in accordance with the requirements of art. 6 para. 1 lit a (consent) and/or lit b (processing necessary for the performance of a contract) of the GDPR.
ADDITIVE+ DIRECT MARKETING
In order to increase customer loyalty and to sell our services and additional services we use software provided by ADDITIVE s.n.c., 39011 Lana (BZ), Italy (“ADDITIVE”).
Therefore your data, which we gather and process in connection with your request, reservation, order, activation, registration or the transmission of other contact forms on our website, will be analysed and used to provide you with automatically generated offers for our services and additional services. Through the use of these services and systems your data will be processed and stored, at least in part, also outside of the EU or the EEC. The adequate level of data protection is based on an adequacy decision taken by the European Commission (“Privacy Shield”) or on data processing agreements.
You can deny the use of your data for this purpose anytime by clicking on the “unsubscribe” link in the respective message.
The data processing takes place in accordance with the requirements of art. 6 para. 1 lit f (legitimate interests) of the GDPR.
Our objective in accordance with the GDPR (legitimate interests) is the prevention of competitive disadvantages, the increase in brand awareness and the maximisation of our economic success through an optimal use of the acquired contacts.