Privacy EU Regulation 2016/679 GDPR and 
Legislative Decree no. 196/2003

Pursuant to art. 13 of Legislative Decree no. 196/2003 (hereinafter, " Privacy Code ") and art. 13 EU Regulation 2016/679 (hereinafter, " GDPR "), which will process the data of the users (hereinafter "User" and / or "Users") collected through the website www.lachiccasiena.com (hereinafter also " Site ") in the manner and for the following purposes.

  • Types of personal data through the Site

The Data Controller is the following types of personal data (hereinafter, "data") awarded by the Users of the Site at their consultation and navigation, and in particular:

  • Data obtained during the navigation of a user on the site

The information systems, cookie technology and software procedures used to operate the web site acquire, during their normal operation, some data whose transmission is implicit in the Internet. This information is not collected to be associated with identified data subjects, but by their very nature could, through processing and associations with data held by third parties, to identify users navigators. This category of data includes, for example, the IP addresses or domain names the computers used by users who connect to the site, the pages visited by users within the same, domain names and addresses of Internet sites from which the user is logged in (via referrals) to the Site, the URI (Uniform resource Identifier) ​​of requested resources, time of request, the method used to submit the request to the web server, the size of the file obtained in reply, the numerical code indicating the status of the response from the web server and other browser type parameters (eg. Internet Explorer, Chrome, Firefox ...), operating system (eg. Macintosh, Windows) and computer environment.

These data are collected through technical cookies owners of the first part and analytical cookies third party.  

  • Personal Data provided by Users

The site is available to the User without the need for its identification for consultation. It did, however, if you want, the right to provide their holder identification data which may include name, e-mail address in order to receive information on the structure and commercial activities on the products / services on the site and this either directly, or by filling the contact form or form of subscription to the newsletter.

Purpose of treatment:

  • The information you provide will be treated, without the prior consent of the User in accordance with art. 24 lett. b) Privacy Code and art. 6 letter. b) GDPR, for the following purposes Service:

  • for the management and processing of statistical surveys on the use of the Site;

  • to carry out the maintenance and technical assistance needed to ensure the proper functioning of the Site and services connected to it;

  • to improve the quality and structure of the Site and to create new services, features and / or features of it;

  • to enable the User to find information to increase his knowledge on the topics on the site and the products and services offered by it;

  • to process any contact request submitted by you through filling out the form or by email;

  • to allow the holder to exercise their rights in court and suppress illegal activities;

  • to fulfill legal obligations or regulations.

- Nature of: necessary - Consequences of refusing data transfer : Failure to provide the data will prevent the Data Controller to run the business from 'user request. - Measures Data Protection: The server operating system, which is allocated to the website and the database is installed on a cloud-based hardware infrastructure provided by wix.com can ensure high levels of integrity, availability and confidentiality of information.
The data held by the owner of the site (email and names of any contacts) are kept within the computer and are accessible only to the holder and password protected access and external antivirus and anti-intrusion systems.

 

  • The information you provide will be processed prior consent User pursuant to art. 23 Privacy Code and art. 6 letter. a) GDPR, for the following commercial purposes:

  • to allow the User sending of commercial communications by e-mail about products, initiatives and / or services offered through this website and / or newsletter containing information on services offered by the property.

 

  • Nature of: optional

  • Consequences of refusing data transfer: Failure to grant consent, although it will similarly to the data controller to execute processing required activity, prevent the Data Controller to identify services compliant and better suited to their needs.

 

  • Nature of Data Conferment

  • The provision of data by the user is required for service purposes referred to in point 1 of the preceding paragraph and optional for service purposes referred to in point 2. The refusal to provide such data may result in the impossibility to provide the services.

  • Mode, Place and Duration of Treatment

 

The processing of data of users is achieved by means of the operations indicated in art. 4 Privacy Code art. 4 n. 2) GDPR and in particular: collection, recording, organizing, storing, retrieving, processing, modification, selection, retrieval, comparison, access, use, interconnection, block, communication, cancellation and destruction of data. 
The Holder is the Personal Data of the Users taking all necessary security measures to prevent unauthorized access, disclosure, alteration or unauthorized destruction of Personal Data. 
The treatment is done by computer and / or internet tools, With organizational and strictly related to the purposes indicated mode. In addition to the data, in some cases, may have access to data external parties (such as third party technical services, hosting providers, IT companies, communications agencies) appointed, if necessary, in charge of by the Data Processing. 
The updated list of Managers may be requested from the Data Controller.

Place

The data are processed at the headquarters of the owner and in any other place where those involved in the treatment are located. For more information, contact the owner. Duration of treatment : only for the time strictly necessary to achieve the purposes for which they were collected and, in any event no later than two years from their collection for service purposes of paragraph 1, section II and no later than one year after their collection for commercial purposes of paragraph 2 of paragraph II.

 

Details on the processing of personal data:

  

In order to contact you

Contact form in the site

The User, by filling with your data in the contact form, you agree to use them for responding to requests for information, estimate, or any other kind indicated by the form.

Personal Data collected: name, email, phone number, and various types of data as specified by the privacy policy of the service.

Contact by phone

Users who have provided their phone number could be contacted to provide more information on the service requested, or, following the consent, for commercial or promotional purposes related to this activity, as well as to satisfy requests for support.

Personal Data collected: phone number.

 

To manage site statistics

The services contained in this section allow the Data Controller to monitor and analyse traffic data and are used to keep track of User behaviour.

Google Analytics (Google Inc.)

Google Analytics is a web analytics service provided by Google Inc. ("Google"). Google uses Personal Information collected for the purpose of evaluating the use of this website, compiling reports and share them with other services developed by Google. 
Google may use the Personal Data to contextualize and personalize the ads of its own advertising network.

Personal data collected: Cookie and data usage.

Place of treatment: USA -  Privacy Policy  -  Opt Out

Google Tag Manager (Google Inc.)

Google Tag Manager is a statistical service provided by Google Inc.

Personal data collected: Cookie and data usage.

Place of treatment: USA -  Privacy Policy

 

To display content from external platforms

This type of service allows you to view content hosted on external platforms directly from the pages of this site and to interact with them. 
If it is possible that even a service of this kind, is installed if the Users do not use the service, the same collect traffic data on pages where it is installed.

Widgets Google Maps (Google Inc.)

Google Maps is a display mapping service run by Google Inc. that allows this application to integrate those contained within its pages.

Personal data collected: Cookie and data usage.

Place of treatment: USA -  Privacy Policy

 

  • Data access

The data will be made available exclusively for the purposes mentioned above to the following parties:

Data processor (owner of the site) in his capacity as appointed / authorized and / or responsible for internal treatment and / or system administrator and any additional charge / interior authorized specifically indicated by the Holder.

Company or other third parties who carry out outsourcing activities on behalf of the owner, (eg. Email service manager, web agency, advertising agency, webmaster) in their capacity as external controllers in accordance with Article 29 of the Code on protection of personal data.

  • Data Communications

Without the User's express consent (art. 24 lett. A), b), d) Privacy Code art. 6 letter. b) and c) GDPR), the data processor can communicate the user data for the purposes of service of art. II.1) to supervisory bodies, judicial authorities as well as to all other persons to whom disclosure is required by law for the fulfilment of those purposes, as autonomous controllers. Users' data will not be disclosed.

  • Data Transfer

 

The personal information you provide can only be used to allow the sending of communications related to the service requested, via e-mail or telephone to initiatives and / or services offered on the site and / or, in the case of specific consent, newsletters containing in-depth than the main topics related to the services offered.

Outside of this case, the management and storage of data will occur on servers located within the European Union or the United States and / or, in particular for the web server where the web site ( http://www.wix.com/which provides its own privacy policy - https://it.wix.com/about/privacy). The data collected with the user's consent in accordance with section 2 of the processing purposes, will not be transferred outside the European Union.

  • Third Party Websites

It should be noted from the outset that, if the Site may contain links to websites of third parties, the data controller cannot exercise any control over the content of such web sites or have any access to personal data of the visitors of such users .

The owners of the aforementioned web sites will, therefore, the sole and exclusive owners and controllers of personal data of its users, remaining, the data processor stranger to this activity as well as to any liability, damage, cost, which may arise by its failure or incorrect completion.

  • Rights of Users

The User shall be entitled to exercise the rights under Art. 7 Privacy Code and to ' art. 15 GDPR .

In particular, the User has the right at any time to obtain from the confirmation of the existence or otherwise of personal data concerning him, though not yet recorded and their communication in intelligible form.

In relation to the treatments described in this Disclosure, l 'interested party may, under the conditions provided for in GDPR, exercise the rights set out in Articles 15 to 21 of GDPR and, in particular, the following rights:

  • access rights - Article 15 GDPR : the right to obtain confirmation of whether or not the current processing of personal data in this case concerning him, and gain access to your personal information, including a copy of the same.

  • right of reply - Article 16 GDPR : the right to obtain, without undue delay, correction of inaccurate personal data concerning him and / or completion of incomplete personal data;

  • Cancellation right ( right to oblivion ) - Article 17 GDPR : the right to obtain, without undue delay, cancellation of personal data concerning him.

  • right to treatment limitation - Article 18 GDPR : the right to limitation of treatment when:

  1. the applicant disputes the accuracy of the personal data, for the period necessary to the owner to verify the accuracy of such data;

  2. the processing is unlawful and the data subject opposes deletion of personal data and would instead suggest that the use is limited;

  3. personal data is necessary to the person to ascertain, the exercise or defence of a legal claim;

  4. the person concerned is opposed to treatment pursuant to art. 21 GDPR, in the waiting period of the verification on the possible reasons for the prevalence of the legitimate holder of the treatment compared to those concerned.

  • right to data portability - Article 20 GDPR : right to receive, in a structured format, common and readable use by an automatic device, the personal data concerning him provided to the Owner and the right to send it to another holder without hindrance, if the treatment is based on consensus and is carried out by automated means.

  • right of objection - Article 21 GDPR: Right to object, at any time for reasons relating to his particular situation, to the processing of personal data relating to him based on the condition of legitimate interest legality or performance of a public interest task or the exercise of official authority, including profiling, unless there are legitimate reasons for the owner to continue treatment that prevail on interest, on the rights and freedoms of or for the establishment, exercise or defence of a legal claim. In addition, the right to object at any time to treatment if personal data are processed for direct marketing purposes, including profiling, to the extent that is connected to this direct marketing.

The above rights may be exercised against the data by contacting the references described above.

The exercise of the rights as an interested party is free under Article 12 GDPR . However, in the case of requests manifestly unfounded or excessive, even for their repetitiveness, the Owner may charge a reasonable contribution expenses, in light of the administrative costs to handle the request, or deny the satisfaction of his request.

  • RIGHT OF WITHDRAWAL:

The individual has the right to withdraw consent at any time. The withdrawal of consent shall not affect the lawfulness of the processing based on consent before the withdrawal.​

 

How to exercise the rights

  • To exercise the rights of the article above, the User may, at any time, please contact the site owner via email  lachiccasiena@gmail.com  

 

Data Controller:

The data controller is Dario Salezzari
Email: lachiccasiena@gmail.com  

 

Informative Updates

Please note that this Privacy Policy will be subject to periodic updates of which will be given out on the Site.

Date last modified

This information was last updated on 20/05/2018.

CONTACTS

Tel: +39 0577280215

Via A. Pannilunghi 9 Siena, 53100 SI

©2020 La Chicca B&B Siena

  • Black TripAdvisor Icon
  • Black Facebook Icon
  • Black Instagram Icon