Terms & Privacy

PRIVACY POLICY OF WWW.HOTELHERMITAGEPRATO.IT

This Website collects some Personal Data from its Users.

This document can be printed using the print command present in the settings of any browser.

HOLDER OF THE DATA PROCESSING

HOTEL HERMITAGE S.R.L.

SEDE LEGALE: VIA G. ROSSINI, 24

SEDE OPERATIVA: VIA GINEPRAIA, 112

59016 POGGIO A CAIANO (PO)

P.IVA 00238290977

C.F. 00551890486

N. REA: PO 226985

C.D.: M5UXCR1 – hotelhermitage@pec.it

TYPES OF COLLECTED DATA

Among the Personal Data collected by this Website, independently or through third parties, there are: Cookies; Usage data; e-mail; first name; surname; telephone number; various types of data; username; password; User ID; payment data; address; business name.

Full details on each type of collected data are provided in the dedicated sections of this privacy policy or through specific information texts displayed before data are collected.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Website.

Unless otherwise specified, all data requested by this website are mandatory. If the User refuses to communicate them, it may be impossible for this Website to provide the Service. In cases where this Website indicates some Data as optional, Users are free to refrain from communicating such Data, without having any consequences on the availability of the Service or on its operation.

 

Users who have doubts about which data are mandatory are encouraged to contact the owner.

 

Any use of Cookies - or other tracking tools - by this Website or by the owners of third party services used by this Website, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to for the additional purposes described in this document and in the Cookie Policy, if available.

 

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Website and guarantees that he has the right to communicate them, freeing the Owner from any liability to third parties.

METHOD AND PLACE OF PROCESSING THE COLLECTED DATA

METHOD OF TREATMENT

The Data Controller adopts the appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.

 

The treatment is carried out using IT and / or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to the Owner, in some cases, other subjects involved in the organization of this Website (administrative, commercial, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers, hosting provider, IT companies, communication agencies also appointed, if necessary), may have access to the Data. The updated list of Managers can always be requested from the Data Controller.

 

LEGAL BASIS OF THE TREATMENT

The Data Controller processes Personal Data relating to the User if one of the following conditions exists:

  • the User has given consent for one or more specific purposes; Note: in some systems, the Data Controller may be authorized to process Personal Data without the User's consent or another of the legal bases specified below, as long as the User does not object ("opt-out") to such treatment. However, this is not applicable if the processing of Personal Data is regulated by European legislation on the protection of Personal Data;

  • the processing is necessary for the execution of a contract with the User and / or for the execution of pre-contractual measures;

  • the processing is necessary to fulfill a legal obligation to which the Data Controller is subject;

  • the processing is necessary for the execution of a public interest task or for the exercise of public powers with which the Data Controller is invested;

  • the processing is necessary for the pursuit of the legitimate interest of the owner or third parties.

However, it is always possible to request the Data Controller to clarify the concrete legal basis of each treatment and in particular to specify whether the treatment is based on the law, provided for by a contract or necessary to conclude a contract.

 

PLACE

Data are processed at the Data Controller's operating offices and in any other place where the parties involved in the processing are located. For more information, contact the owner.

The User's Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of treatment, the User can refer to the section relating to the details on the processing of Personal Data.

 

The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization under public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures taken by the Data Controller to protect the Data.

 

The User can check whether one of the transfers described above takes place by examining the section of this document relating to the details on the processing of Personal Data or requesting information from the Data Controller by contacting him at the details indicated at the beginning.

 

RETENTION PERIOD

Data are processed and stored for the time required by the purposes for which they were collected.

Therefore:

  • Personal Data collected for purposes related to the execution of a contract between the Owner and the User will be retained until the execution of this contract is completed.

  • Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until this interest is satisfied. The User can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

When the treatment is based on the User's consent, the Data Controller can keep Personal Data longer until such consent is revoked. In addition, the Data Controller may be obliged to keep Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, Personal Data will be deleted. Therefore, at the end of this term, the right of access, cancellation, rectification and the right to data portability can no longer be exercised.

 

PURPOSE OF THE PROCESSING OF THE COLLECTED DATA

User data are collected to allow the owner to provide the service, fulfill legal obligations, respond to requests or executive actions, protect their rights and interests (or those of users or third parties), identify any malicious activities or fraudulent, as well as for the following purposes: Statistics, Display of content from external platforms, Management of contacts and sending messages, Interaction with social networks and external platforms, Contacting the User, Management of tags, Protection from SPAM, Performance test of content and functionality (A / B testing), Hosting and backend infrastructure, Sale of goods and services online, Registration and authentication and Management of payments.

To obtain detailed information on the purposes of the processing and on the Personal Data processed for each purpose, the User can refer to the "Detailed information on the processing of Personal Data" section.

Details on the processing of personal data

Personal data are collected for the following purposes:

Contact the user

Mailing list or newsletter (This Website)

By registering with the mailing list or the newsletter, the User's email address is automatically inserted in a list of contacts to which email messages containing information, including commercial and promotional information, relating to this Website may be transmitted. The User's email address may also be added to this list as a result of registering on this Website or after making a purchase.

Personal Data collected: surname; e-mail; first name; telephone number.

Contact form (This Website)

By filling in the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other kind indicated by the form header.

Personal Data collected: surname; e-mail; first name; telephone number; various types of data.

Contact by phone (this Website)

Users who provided their telephone number could be contacted for commercial or promotional purposes connected to this Website, as well as to satisfy requests for support.

Personal Data collected: telephone number.

Contact management and sending messages

This type of service allows you to manage a database of email contacts, telephone contacts or contacts of any other type, used to communicate with the User.

These services could also allow you to collect data relating to the date and time of display of the messages by the User, as well as the interaction of the User with them, such as information on clicks on the links inserted in the messages.

Mailchimp (The Rocket Science Group, LLC.)

Mailchimp is an address management and emailing service provided by The Rocket Science Group LLC.

Personal Data collected: email.

Place of treatment: USA - Privacy Policy. Subject adhering to the Privacy Shield.

 

Payment management

The payment management services allow this website to process payments by credit card, bank transfer or other tools. The data used for payment are acquired directly by the payment service manager requested without being processed in any way by this Website.

 

Some of these services may also allow the programmed sending of messages to the User, such as emails containing invoices or notifications regarding the payment.

PayPal (Paypal)

PayPal is a payment service provided by PayPal Inc., which allows the User to make payments online.

Personal Data collected: various types of Data as specified in the privacy policy of the service.

Place of treatment: Consult the Paypal privacy policy - Privacy Policy.

Payment by bank transfer (this Website)

In the event that the payment method chosen is direct bank transfer to the current account indicated on this Website, the Data Controller will collect the data relating to the User's payment, i.e. the settlor's current account number, SWIFT code, Bank and the name of the settlor. These data will be collected and processed exclusively in the context of the transaction and for billing purposes only.

Personal Data collected: surname; payment data; address; first name; business name.

Tag management

This type of service is functional to the centralized management of the tags or scripts used on this website.

 

The use of these services involves the flow of User Data through them and, if necessary, their retention.

Google Tag Manager (Google LLC)

Google Tag Manager is a tag management service provided by Google LLC.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy. Subject adhering to the Privacy Shield.

Hosting and backend infrastructure

This type of service has the function of hosting data and files that allow this website to function, allow its distribution and provide a ready-to-use infrastructure to provide specific features of this website.

Some of the services listed below, if any, may operate on geographically distributed servers, making it difficult to determine the actual location where Personal Data is stored.

Hosting service

Provider

 

https://www.passepartout.net/utility/privacy

 

Purposes

Cloud Hosting

 

 

Personal data collected

 

Various types of data as specified in the privacy policy of the service

 

Privacy Policy

 

The cloud hosting service is provided by PASSEPARTOUT

 

https://www.passepartout.net/utility/privacy

 

Interaction with external social networks and platforms

This type of service allows you to interact with social networks, or with other external platforms, directly from the pages of this website.

The interactions and information acquired from this Website are in any case subject to the User's privacy settings relating to each social network.

This type of service could still collect traffic data for the pages where the service is installed, even when Users do not use it.

It is recommended to disconnect from the respective services to make sure that the data processed on this Website is not connected to the User's profile.

Like button and Facebook social widgets (Facebook, Inc.)

The "Like" button and Facebook social widgets are interaction services with the Facebook social network, provided by Facebook, Inc.

Personal Data collected: Cookies; Usage data.

Place of treatment: USA - Privacy Policy.

Google+ +1 button and social widgets (Google Inc.)

The +1 button and Google+ social widgets are services for interacting with the Google+ social network, provided by Google Inc.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy. Subject adhering to the Privacy Shield.

LinkedIn button and social widgets (LinkedIn Corporation)

The LinkedIn button and social widgets are interaction services with the LinkedIn social network, provided by LinkedIn Corporation.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy.

YouTube button and social widgets (Google Inc.)

The YouTube button and social widgets are interaction services with the YouTube social network, provided by Google Inc.

Personal Data collected: Usage data.

Place of treatment: United States - Privacy Policy. Subject adhering to the Privacy Shield.

Twitter Tweet button and social widgets (Twitter, Inc.)

The Tweet button and Twitter social widgets are interaction services with the Twitter social network, provided by Twitter, Inc.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy. Subject adhering to the Privacy Shield.

"Pin it" button and Pinterest social widgets (Pinterest)

The "Pin it" button and Pinterest social widgets are interaction services with the Pinterest platform, provided by Pinterest Inc.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy.

PayPal button and widget (Paypal)

The PayPal button and widget are interaction services with the PayPal platform, provided by PayPal Inc.

Personal Data collected: Cookies; Usage data.

Place of treatment: Consult the Paypal privacy policy - Privacy Policy.

SPAM protection

This type of service analyzes the traffic of this Website, potentially containing Users' Personal Data, in order to filter it from parts of traffic, messages and content recognized as SPAM.

Google reCAPTCHA (Google Inc.)

Google reCAPTCHA is a SPAM protection service provided by Google Inc.

Use of the reCAPTCHA system is subject to Google's privacy policy and terms of use.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy. Subject adhering to the Privacy Shield.

Registration and authentication

By registering or authenticating, the User allows the Application to identify him and give him access to dedicated services.

Depending on what is indicated below, registration and authentication services could be provided with the help of third parties. If this happens, this application will be able to access some data stored by the third party service used for registration or identification.

Log In with PayPal (Paypal)

Log In with PayPal is a registration and authentication service provided by PayPal Inc. and connected to the PayPal network.

Personal Data collected: various types of Data as specified in the privacy policy of the service.

Place of treatment: Consult the Paypal privacy policy - Privacy Policy.

Direct registration (this website)

The User registers by filling in the registration form and providing his Personal Data directly to this Website.

Personal Data collected: email; User ID; password; username; various types of data.

Statistics

The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to keep track of User behavior.

Google Analytics (Google Inc.)

Google Analytics is a web analysis service provided by Google Inc. ("Google"). Google uses the personal data collected for the purpose of tracking and examining the use of this website, compiling reports and sharing them with other services developed by Google.

Google could use Personal Data to contextualize and personalize the advertisements of its advertising network.

Personal Data collected: Cookies; Usage data.

Place of treatment: USA - Privacy Policy - Opt Out.

 

Performance testing of content and functionality (A / B testing)

The services contained in this section allow the Data Controller to track and analyze the response from the User, in terms of traffic or behavior, in relation to changes in the structure, text or any other component of this Website. .

Google Optimize (Google LLC)

Google Optimize is an A / B testing service provided by Google LLC ("Google").

Google could use Personal Data to contextualize and personalize the advertisements of its advertising network.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy. Subject adhering to the Privacy Shield.

Sale of goods and services online

Online Booking Service

Provider

2019 Passepartout s.p.a. - World Trade Center - Via Consiglio dei Sessanta 99, 47891 Customs Republic of San Marino - Tel. 0549 978011 - Toll-free number 800 414243 - Economic Operator Code SM03473 - Registration in Company Register No. 6210 of 6 August 2010 - Registration in the Register of Activities and- commerce n ° 55 - Share capital € 2.800.000 iv

 

crm@passepartout.sm

 

Purposes

Online Booking Service

 

 

Personal data collected

 

Name, Surname, Email, Telephone number, Address, City, Postal Code, Various Types of Data as specified in the privacy policy of the service

 

 

PRIVACY POLICY

 

The service allows the user to book online and is provided by PASSEPARTOUT

privacy@passepartout.sm

https://www.passepartout.net/utility/privacy

 

Display of content from external platforms

This type of service allows you to view content hosted on external platforms directly from the pages of this Website and to interact with them.

In the event that a service of this type is installed, it is possible that, even if the Users do not use the service, the same collects traffic data relating to the pages in which it is installed.

Google Fonts (Google Inc.)

Google Fonts is a font style visualization service managed by Google LLC or by Google Ireland Limited, depending on the position in which this website is used, which allows this website to integrate such content within its pages.

Personal Data collected: Usage data; various types of data as specified in the privacy policy of the service.

Place of treatment: USA - Privacy Policy. Subject adhering to the Privacy Shield.

Google Maps widget (Google Inc.)

Google Maps is a map visualization service managed by Google Inc. that allows this website to integrate such content within its pages.

Personal Data collected: Cookies; Usage data.

Place of treatment: USA - Privacy Policy.

Vimeo Video (Vimeo, LLC)

Vimeo is a video content visualization service managed by Vimeo, LLC that allows this website to integrate such content within its pages.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy.

YouTube Video Widget (Google Inc.)

YouTube is a video content viewing service managed by Google Inc. that allows this website to integrate such content within its pages.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy. Subject adhering to the Privacy Shield.

TripAdvisor widget (TripAdvisor LLC)

TripAdvisor Widget is a content visualization service managed by TripAdvisor LLC that allows this website to integrate content from this external platform into its pages.

Personal Data collected: Cookies; Usage data.

Place of treatment: United States - Privacy Policy.

 

FURTHER INFORMATION ON PERSONAL DATA

• Selling goods and services online

The Personal Data collected are used for the provision of services to the User or for the sale of products, including payment and possible delivery. The Personal Data collected to complete the payment can be those relating to the credit card, the current account used for the transfer or other payment instruments provided. The payment data collected by this website depend on the payment system used.

 

USER RIGHTS

Users can exercise certain rights with reference to the data processed by the owner.

In particular, the User has the right to:

• withdraw consent at any time. The User can withdraw consent to the processing of their Personal Data previously expressed.

• object to the processing of their data. The user can object to the processing of their data when it occurs on a legal basis other than consent. Further details on the right to object are indicated in the section below.

• access their data. The user has the right to obtain information on the data processed by the owner, on certain aspects of the processing and to receive a copy of the data processed.

• verify and request correction. The User can verify the correctness of his Data and request its updating or correction.

• obtain the limitation of the treatment. When certain conditions are met, the User can request the limitation of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose other than their conservation.

• obtain the cancellation or removal of their Personal Data. When certain conditions are met, the User can request the cancellation of their Data by the Owner.

• receive your data or have it transferred to another holder. The User has the right to receive their Data in a structured format, commonly used and readable by an automatic device and, where technically feasible, to obtain its transfer without obstacles to another holder. This provision is applicable when the Data is processed with automated tools and the treatment is based on the User's consent, on a contract of which the User is a party or on contractual measures connected to it.

• propose a complaint. The User can lodge a complaint with the competent personal data protection supervisory authority or take legal action.

 

Details on the right to object

When Personal Data are processed in the public interest, in the exercise of public powers with which the Data Controller is invested or to pursue a legitimate interest of the Data Controller, Users have the right to oppose the processing for reasons related to their particular situation.

Users are reminded that, if their data were processed for direct marketing purposes, they can oppose the processing without giving any reasons. To find out if the Data Controller processes data for direct marketing purposes, Users can refer to the respective sections of this document.

How to exercise your rights

To exercise the rights of the User, Users can direct a request to the contact details of the Owner indicated in this document. Requests are filed free of charge and processed by the Data Controller as soon as possible, in any case within a month.

 

COOKIE POLICY

This website uses cookies. To learn more and to read the detailed information, the User can consult the Cookie Policy.

 

LEARN MORE ABOUT THE TREATMENT

DEFENSE IN COURT

The User's Personal Data may be used by the Data Controller in court or in the preparatory stages for its possible establishment for the defense against abuse in the use of this Website or related Services by the User.

The User declares to be aware that the Data Controller may be obliged to disclose the Data by order of the public authorities.

Specific information

At the request of the User, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System log and maintenance

For needs related to operation and maintenance, this Website and any third party services used by it may collect system logs, i.e. files that record the interactions and which may also contain Personal Data, such as the User IP address.

Information not contained in this policy

Further information in relation to the processing of Personal Data may be requested at any time to the Data Controller using the contact details.

Response to “Do Not Track” requests

This website does not support "Do Not Track" requests.

To find out if any third-party services used support them, the User is invited to consult their respective privacy policies.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying it to Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users through one of the extremes of contact he has. Please therefore consult this page frequently, referring to the date of the last modification indicated at the bottom.

 

If the changes concern treatments whose legal basis is consent, the Data Controller will collect the User's consent again, if necessary.

Definitions and legal references

Personal Data (or Data)

It constitutes personal data any information which, directly or indirectly, also in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

 

USAGE DATA

This is the information automatically collected through this website (also from third party applications integrated into this website), including: IP addresses or domain names of the computers used by the user who connects with this website, the addresses in URI (Uniform Resource Identifier) ​​notation, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response from the server (successful, error, etc. .) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (for example the time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User's IT environment.

 

USER

The individual who uses this website, unless otherwise specified, coincides with the interested party.

 

INTERESTED

The natural person whom the Personal Data refer to.

Data Processor (or Responsible)

The natural person, legal entity, public administration and any other entity that processes personal data on behalf of the Data Controller, as set out in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, service or other body which, individually or together with others, determines the purposes and means of the processing of personal data and the tools adopted, including the security measures relating to the operation and use of this Website. The Data Controller, unless otherwise specified, is the owner of this Website.

This Website (or this Application)

The hardware or software tool through which Users' Personal Data is collected and processed.

 

SERVICE

The service provided by this website as defined in the relative terms (if any) on this site / application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union contained in this document is intended to be extended to all current member states of the European Union and the European Economic Area.

 

COOKIE

Small portion of data stored within the User's device.

Legal references

This privacy statement is drawn up on the basis of multiple legislative systems, including articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy statement only concerns this Website.

Privacy & Cookie Policy

Powered & Designed by Passepartout