Address: Via del Carroccio n. 16 – 20123 Milano
Share Capital € 50.000,00 i.v.
REA n° 2040285
INFORMATION ON THE PROCESSING OF PERSONAL DATA
of the users visiting the websites of Grand Hotel Portovenere
Pursuant to Article 13 of the Italian Lgs. Decree 196/03 and EU Regulation 2016/679
This page contains a description of the policies for managing the website in regards to processing the personal data of the users who visit the site and their privacy. This information is provided pursuant to article 13 of Italian Legislative Decree no. 196/2003 – Laws concerning the Protection of Personal Data and the individuals who interact with the web services of Grand Hotel Portovenere, which is accessible by telematics means through the following web address:
which corresponds to the home page of the official website of Grand Hotel Portovenere on Via Giuseppe Garibaldi, 5 - 19025 Portovenere (SP)
This informative note is provided only for the aforementioned website and not for other websites eventually accessed by the user through links.
Following access to this website, data pertaining to persons that are identified or identifiable may be processed. The “Data Controller” of the personal data collected following a visit to our website or any other data used for providing our services is Frontemare Srl, Via del Carroccio n. 16 – 20123 Milano. The Data Protection Coordinator is Mr. Massimo Bruno, who can be contacted at firstname.lastname@example.org.
PLACE WHERE DATA IS PROCESSED
Data processing pertaining to the web services of this website [(physically hosted by Travelclick ("www.travelclick.com")) is carried out at the aforementioned headquarters and said data is processed only by the technical personnel in charge of processing of the Data Processing Office, or by eventual persons in charge of processing who are entrusted to process occasional maintenance operations.
The personal data obtained from the users who submit hotel reservation requests or through informative material (informative notes, newsletters, registration, etc) is used only to carry out the services or assistance requested and is not transmitted to third parties, except in the following possible cases:
Business partners of Frontemare Srl, Grand Hotel Portovenere to whom Frontemare Srl transmits the data exclusively in order to avoid on-line reservations;
• Persons, companies or professional offices who lend assistance and consulting services to Frontemare Srl, Grand Hotel Portovenere concerning accounting, administrative, legal, financial and tax matters;
• Subjects who are authorized to have access to the data by law or through requests by the authorities;
The credit card data used for booking will be automatically unavailable at the end of the stay.
CATEGORIES OF PROCESSED DATA
The information systems and software procedures relied upon to operate this web site acquire personal data as part of their standard functioning; the transmission of such data is an inherent feature of Internet communication protocols.
Such information is not collected in order to relate it to identified data subjects, however it might allow user identification per se after being processed and matched with data held by third parties.
This data category includes IP addresses and/or the domain names of the computers used by any user connecting with this web site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of such requests, the method used for submitting a given request to the server, returned file size, a numerical code relating to server response status (successfully performed, error, etc.), and other parameters related to the user's operating system and computer environment.
These data are only used to extract anonymous statistical information on website use as well as to check its functioning; they are erased immediately after being processed. The data might be used to establish liability in case computer crimes are committed against the website; except for this circumstance, any data on web contacts is currently retained for no longer than seven days.
Data voluntarily provided by the user
Sending e-mail messages to the addresses mentioned on this website, which is done on the basis of a freely chosen, explicit, and voluntary option, entails acquisition of the sender's address, which is necessary in order to reply to any request, as well as of such additional personal data as is contained in the message(s).
Data will be retained only for registration request to send the newsletters or special offers, and will not be disclosed to anyone.
Specific summary information notices will be shown and/or displayed on the pages that are used for providing services on demand.
The personal information regarding the individual who visited the website is not collected or used. The visitors remain anonymous. The only exception to this rule concerns the information for personal identification needed to fulfill the contractual obligations of reservations on behalf of the user.
In the event of reservations made through the website, the user must provide his name, address, telephone number and information regarding the payment manners and credit card used. Frontemare Srl will use said information only to process the reservations and to send specific information, which is relevant to the confirmation of said, such as a receipt, the reservation code and the conditions.
The information provided will not be used for marketing purposes and will not be sold, transmitted, given by contract or sent to third parties an any way, with the exception of our provider of on-line reservation services, TravelClick, Inc., (www.travelclick.com), to whom elaboration of the reservations is entrusted to, only for online reservations purposes..
In any event, the administrator of the website guarantees the use of scrupulous procedures in order to protect the navigational data and the use of particular precautions to protect the data pertaining to the credit card, which is provided during on-line reservations.
Personal Data Processing Collected from Curriculum Vitae
The Frontemare Srl accept Personal Curriculum Vitae of possible candidates exclusively via e-mail in PDF format. Providing spontaneous and voluntary of the Curriculum Vitae data will be considered as implicitly informed consent by the data subjects for personal data processing contained, only following the purposes related to the selection of potential candidates.
The data processed for the purpose of selection of candidates are personal useful to search for the particular profile. In general, the nature of the data is normal, except in some cases where you may indicate any sensitive data necessary to identify the specific requirements of the regulations, such as specifying a particular protected classes, the suitability for certain jobs and / or start-ups required, within the limits set by the General Authorisations of the Garante no. 1 and 2 of December 15, 2016 (Published in the Official Gazette no. 303 of December 29, 2016);
The provision of data relating to the selection of candidates is required. Any refusal to provide such data makes it impossible to perform an orderly selection and the possible recruitment. The data in question will not be disclosed to anyone.
General Rules for providing the CV
Any CV received spontaneously, replying to a job advertisement, will be stored directly by person in charge of the processing in accordance with the safety guidelines of personal data adopted in compliance with the security measures ex Title V Chapter I and II of the Code and Chapter IV Section 2 of GDPR 679/2016. These will be printed only on the occasion of a meeting and a conversation with the data subject. After the interview, if the candidate is not selected, the CV will be deleted and / or destroyed.
In all other cases, after a short period of time and after the talks and after the trial period (60 days) CVs will be deleted from the PC and, if printed, they will be destroyed.
To send Curriculum Vitae use the following addresses: email@example.com or Human Resources Dpt, Frontemare Srl, Via Giuseppe Garibaldi, 5 - 19025 Portovenere (SP)
PERIOD FOR DATA RETENTION - CRITERIA USED
According to the provisions set forth in art. 5 par. 1 lett. e) of the Regulation (EU) 2016/679, collected personal data shall be kept in a form which permits identification of data subjects for a period not exceeding the purposes for which the personal data were collected and subsequently processed.
Data retention periods depend on the purposes of the processing:
• purposes related to technical navigation data for the correct functioning of the website: retention only for the related session, after which the data are deleted;
• purpose of reply to info request/services supply request (up to 12 months for contact requests ; 10 years for administrative / accounting / financial documentation relating to the provision of a service);
• data collection for staff recruitment (up to 24 months);
• newsletter, marketing or promotional communications in general (until withdrawal of consent);
• purpose of di administrative / accounting / financial management: 10 years as required by law for the conservation of administrative / accounting / financial documentation.
In this website we are applied cookies technologies for different purposes, including computer technology authentication or to monitor sessions, and to store specific technical information regarding the users that access the server of Travelclick, the website maintenance and hotel booking service provider.
Description of the cookie mechanisms adopted:
• Cookie implanted in the user/contracting party's terminal directly (that will not be used for other purposes) such as session cookies used for on-line booking on the website, authentication or customisation cookie (for example, the choice of the browsing language); these cookie remain active only for the duration of the session.
• Cookie used to statistically analyse accesses/site visits (the so-called "analytic" cookie) that are used for statistical purposes, profiling or marketing, and to collect aggregate information with the possibility of tracing back to the identification of the individual user personal computer. In these cases, since current legislation requires that, when using analytic cookie, the user is given clear and adequate instructions to easily oppose implementation of such (including any mechanisms to make the cookies anonymous), we give instructions on how to disabled installed cookies below. The duration of analytic technical cookie is averagely of 30 minutes.
How to modify settings on the cookies
Most browsers allow to clear cookies from your computer hard drive, block acceptance of cookies or receive a warning before a cookie is stored.
Therefore, to remove cookies we encourage you to follow the instructions on the pages of the various browsers:
Fire fox: https://support.mozilla.org/it/kb/Gestione%20dei%20cookie
Microsoft Edge: https://privacy.microsoft.com/it-IT/windows-10-microsoft-edge-and-privacy
Third-party cookies are code parts set by a website different than the website you are currently browsing.
This involves the transmission of cookies from third parties. Management of information collected from “third parties” is governed by the relative information notices to which we ask you to refer. If you block or erase cookies, it may not be possible to reset previously specified preferences or customised settings, and our capacity to customize the user experience will be limited. More google analytics privacy policies available on http://www.google.com/policies/technologies/ads/
Website & Booking Engine
1- Required cookies
These cookies enable core site functionality and are automatically enabled when you use the site. Without them, services that you’ve asked for can’t be provided. Examples:
- Server cookie (BIGipServerpool_htb-clusterX)
- Toolbox login status cookie (CONDORSESSIONID and toolboxBarPosition)
- Cookie banner (useCookies and useCookiesCounter)
2- Performance cookies
These cookies are used to monitor the use of your website. They help you understand how people are interacting with your website. Examples:
- Google Analytics (_ga, _gid, _gat, _gac, __utmX): o _ga (expiration time: 2 years) - Used to distinguish users
o _gid (expiration time: 24 hours) - Used to distinguish users
o _gat (expiration time: 1 minute) - Used to throttle request rate
o _gac_<property-id> (expiration time: 90 days) - Contains campaign related information for the user. If you have linked your Google Analytics and AdWords accounts, AdWords website conversion tags will read this cookie unless you opt-out
o _utma (expiration time: 2 years from set/update) - Used to distinguish users and sessions
o _utmt (expiration time: 10 minutes) - Used to throttle request rate
o _utmb (expiration time: 30 mins from set/update) - Used to determine new sessions/visits
o __utmz (expiration time: 6 months from set/update) - Stores the traffic source or campaign that explains how the user reached your site
o __utmv (expiration time: 2 years from set/update) - Used to store visitor-level custom variable data
3- Advertising and Third-party cookies
These cookies are used by TravelClick and third parties to show other content that is relevant to the visitor’s interest, and to measure the effectiveness of online marketing campaigns on your site. Examples:
- Google DoubleClick
- Google Maps
iHotelier: For those customers who enable location-based or currency-based promotions (and require the end-user to consent to receiving those promotions), a cookie is dropped on the end user’s browser so that when the user completes the booking, the correct promotional pricing is provided. This cookie active for 30 days so that the user is not asked to consent again while the cookie is active and that the meta data about the consent (exact wording of the agreed upon consent and time and date stamp) can be stored when the user books a room.
GMS: The following cookies or tokens are dropped by the Guest Management Solutions product:
Employee Login Status Cookies. This is a session-based cookie that tracks the Customer’s employees (hotel employees) logged in status and expires with the browser session (though expunged from the server after 30 minutes of inactivity).
End User Login Status Tracking. This is a token used by the TravelClick loyalty API for tracking an end-user’s logged in status. Does not contain any personally identifiable information and expires after 45 minutes from last issue.
Clickstream Marketing Tracking Cookie. This is a cookie dropped on hotel websites & booking engines (that are receiving Clickstream marketing services) to track marketing email click-throughs and to optionally tag known end users who made specific page visits and/or for remarketing to booking abandonments. This cookie expires after one year.
Media: These are cookies that are dropped on a Customer’s website through a tag manager implementation. This tag is generated through the advertising platforms used for the applicable media network, e.g., Google. These cookies contain information about the users’ browser such aspreferences, browser type, location, IP and language. This information is used to deliver advertisements to the user on other websites within a media network. Depending on the settings of the advertising campaign and the strategy in place, the cookie duration might vary from 2 to 45 days. After this period, the cookie expires.
Meta: These are cookies dropped on end user’s browser to track attribution of a booking on a meta site such as Kayak. These cookies contain information related to the booking. For
example, search cookies collect check-in date, check-out date, purchase currency, hotel property, # rooms, Property ID, # of travelers). Once an end user hits a pixel (i.e. search pixel) that has been placed on a webpage, a cookie is dropped on the browser of that end user.
Nevertheless, if you block or erase cookies, it may not be possible to reset previously specified preferences or customised settings, and our capacity to customize the user experience will be limited.
More google analytics privacy policies available on http://www.google.com/policies/technologies/ads/.
OPTIONAL DATA PROVISION
Subject to the specifications made with regard to navigation data, users are free to provide the personal data listed in the request forms of Grand Hotel Porto Venere or referred to in contacting the hotel in order to provide CV, to make on-line reservations or to request delivery of information materials and other communications. Failure to provide such data may entail the failure to be provided with the items requested.
Personal data is processed with automated means for no longer than is necessary to achieve the purposes for which it has been collected. Specific security measures are implemented to prevent the data from being lost, used unlawfully and/or inappropriately, and accessed without authorisation.
DATA SUBJECTS' RIGHTS
The data Controller is Frontemare Srl, Grand Hotel Portovenere. The Data Protection Coordinator is Mr. Massimo Bruno. You may contact them at any time to exercise your rights as provided for in Section 7 of Law 196/03 and Chapter III GDPR 679/2016, in particular, the right to obtain confirmation as to whether or not personal data concerning you exist and the logic applied to the processing, the right to ask for their integration, the right to object to their processing on legitimate ground, and the right to request rectification, updating, erasure (right to be forgotten) or blocking of data that have been processed unlawfully, the right to obtain a copy of the personal data being processed as well as the right to data portability, also by sending a written request to the following e-mail address: firstname.lastname@example.org.
RIGHT TO LODGE A COMPLAINT
If a data subject considers that the processing of personal data relating to him or her as performed via this website infringes the Regulation, he or she has the right to lodge a complaint with the Garante pursuant to Article 77 of the Regulation, or else to bring a judicial proceeding against the Garante pursuant to Article 79 of the Regulation.