I.C.M. S.N.C. di Bruno, Cristiano e Fabrizio Maggi, with registered office in Località Romealla n. 25 – 05018 Orvieto (TR), fiscal code no. and VAT no. 00090910555, owner of the Emme Palace Hotel & Spa, as Data Controller (hereinafter, “Data Controller” or “Hotel”), hereby provides you, pursuant to and for the purposes of EU Regulation No. 2016/679 (hereinafter, “GDPR”), with information regarding the processing of personal data collected while browsing the website and booking page and during the activities of booking rooms and purchasing its products and services.
As part of the activities of booking rooms and purchasing hotel products and services, the Data Controller processes personal data and contact details (e.g., name, surname, e-mail address, mobile phone number, nationality, etc.) relating to future guests, payment and credit card details, as well as any other information indicated in the “Notes” field. All this information is provided directly by the person making the booking. With reference to the “Notes” field, the Data Controller invites you not to provide particular categories of data such as data relating to your state of health (information on any motor disabilities, allergies, intolerances, etc.), religious beliefs, sexual orientation, political and philosophical opinions.
When browsing the website and booking page, the Data Controller processes navigation data such as the IP addresses or domain names of the devices used and connected to, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment.
As part of the activities of booking rooms and purchasing hotel products and services, your data will be processed for the following purposes:
The legal basis of the processing is the performance of contractual obligations pursuant to Article 6(1)(b) of the GDPR.
The provision of personal data is necessary; therefore, the omission of the personal data requested makes it impossible to conclude and execute the room booking and the purchase of services and ancillary products.
The legal basis of the processing is the fulfilment of regulatory obligations pursuant to Article 6(1)(c) of the GDPR.
The provision of personal data is necessary; therefore, the omission of the personal data requested makes it impossible to conclude and execute the room booking and the purchase of services and ancillary products.
The legal basis for the processing of the data is the pursuit of the legitimate interest consisting in the protection of the interests and rights of the Hotel pursuant to Article 6(1)(f) GDPR.
The provision of personal data is necessary; therefore, the omission of the personal data requested makes it impossible to conclude and execute the room booking and the purchase of services and ancillary products. However, you may request to object at any time, by sending a motivated request to the Data Controller, to the processing of personal data carried out on the basis of legitimate interest, pursuant to and for the purposes of Article 21 GDPR; your request, in this sense, will be subject to evaluation and response by the Data Controller.
The legal basis for the processing of the data is the consent pursuant to Article 6(1)(a) GDPR and Article 130 of Legislative Decree no. 196/2003.
The provision of personal data for this purpose is optional; therefore, failure to provide the requested personal data does not make it impossible to conclude and execute the room reservation and the purchase of additional services and products, and your right to withdraw your consent or object to such processing at any time, easily and free of charge, in the ways indicated in the “Data subject’s rights” section of this information notice and/or with those indicated in the promotional communications that will be sent to you from time to time, remains unaffected.
The legal basis for the processing of the data is the pursuit of the legitimate interest consisting of sending commercial communications relating to products or services similar to those already purchased pursuant to Article 6(1)(f) GDPR.
The provision of personal data is necessary; therefore, the omission of the personal data requested makes it impossible to conclude and execute the room booking and the purchase of services and ancillary products. However, you may request to object at any time, by sending a motivated request to the Data Controller or through the specific unsubscribe feature, to the processing of personal data carried out based on legitimate interest, pursuant to and for the purposes of Article 21 GDPR.
The legal basis for the processing of the data is the pursuit of the legitimate interest consisting of carrying out business intelligence activities and improving promotional activities pursuant to Article 6(1)(f) GDPR.
The provision of personal data is necessary; therefore, the omission of the personal data requested makes it impossible to conclude and execute the room booking and the purchase of services and ancillary products. However, you may request to object at any time, by sending a motivated request to the Data Controller, to the processing of personal data carried out based on legitimate interest, pursuant to and for the purposes of Article 21 GDPR; your request, in this sense, will be subject to evaluation and response by the Data Controller.
The data may be communicated for the pursuit of the aforementioned purposes to other entities such as, for example, public authorities and law enforcement agencies, law firms, accountants, etc., who will process the data as independent data controllers for their own purposes. The following subjects may also have access to the data:
Personal data are not disseminated.
Personal data processed for the purposes indicated in points (a), (b) and (c) of section 2 above are kept only for the time strictly necessary to carry out the activities/purposes described above and, in particular, for the time required by the tax law (10 years) or for the period of prescription of possible legal actions.
The personal data processed for the purposes of direct marketing and soft spam indicated in points (d) and (e) of section 2 above are kept until the revocation of consent or opposition to the processing or for 24 months from the moment of the last renewal of consent and of the will not to oppose the processing.
The personal data processed for the purpose of classification indicated in point (f) of section 2 above are processed in anonymous and aggregated way.
The Data Controller may transfer you personal data to the United Kingdom and/or the United States of America on the basis of the relevant Adequacy Decisions adopted by the European Commission and, in the case of the United States of America, of the recipients’ adherence to the EU-US Data Privacy Framework programme.
Data subjects may assert their rights and/or request information on the processing of their data by contacting the Data Controller. The GDPR grants the right to:
In cases of exercise of the rights referred to in points c), d), and e), the data subject has the right to know the recipients to whom the personal data have been transmitted and the right that the Controller communicates to them the rectification, erasure or restriction of the processing, unless this proves impossible or involves a disproportionate effort.
You may contact the Data Controller and exercise your right listed in the previous Paragraph by sending an email to privacy@emmepalace.com.