menu
altlogo
menu
Privacy Policy 2

Privacy Policy

This document describes how the website is managed with regard to the processing of personal data of users who consult it, and their confidentiality. This notice is also provided pursuant to Art. 13 of GDPR 679/2016 – the European Regulation on the Protection of Personal Data – for those who interact with the web services of Park Hotel San Michele, located at Viale Carella, 9, 74015 Martina Franca, Taranto (Italy), accessible online at the following address: sarasrl00197@gmail.com

https://www.parkhotelsanmichele.it/ – corresponding to the homepage of the hotel's website.

This notice applies only to this website and not to any other websites the user may access via links.

THE "DATA CONTROLLER"

Data relating to identified or identifiable individuals may be processed as a result of browsing this site. The "Data Controller" of any personal data processed as a result of browsing our site, and of any other data used to provide our services, is SARA SRL, with registered office at Via Francesco Paciotti 30, 00176 – Rome.

PLACE OF DATA PROCESSING – DATA DISCLOSURE

The processing activities related to the web services of this site, managed by Blastness S.r.l. ("www.blastness.com"), specifically appointed as Data Processor pursuant to Art. 28 of GDPR 679/2016, take place within the territory of the European Economic Area or in the United Kingdom, and are handled only by technical staff of the office in charge of processing, or by any staff carrying out occasional maintenance operations.

Personal data provided by users who submit hotel booking requests or requests to send/receive informational material (information, newsletters, registrations, etc.) is used solely to carry out the requested service and is not disclosed to third parties, except in the following possible cases:

The Hotel's business partners;
Service providers (e.g., booking service, email marketing, IT provider, hosting provider, etc.) that process data on behalf of the Data Controller in their capacity as data processors, under a specific contract pursuant to Art. 28 of GDPR 679/2016;
Individuals, companies, or professional firms that provide assistance and advisory services to the Data Controller in accounting, administrative, legal, tax, and financial matters;
Parties entitled to access the data under legal provisions or orders from authorities.

TYPES OF DATA PROCESSED

Browsing data

The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users connecting to the site, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's response (successful outcome, error, etc.), and other parameters relating to the user's operating system and computing environment, as well as any information relating to the use of the site and browsing behavior. For the processing of this data through the use of cookies, please refer to the information provided via the banner. The data may be used to establish liability in the event of hypothetical computer crimes against the site: barring this circumstance, web contact data is currently not kept for more than seven days.

Data provided voluntarily by the user

The optional, explicit, and voluntary sending of email to the addresses indicated on this site results in the subsequent acquisition of the sender's address, necessary to respond to requests, as well as any other personal data included in the message. The data will be retained only for any requested subscription to the sending of newsletters or special offers and will not be disclosed to anyone. Personal information relating to website visitors is not collected or used. Visitors remain anonymous. The only exception concerns personal identification information necessary to fulfill contractual booking obligations toward the user.

Data required for bookings

When booking hotel services offered through this site, the user is required to provide their first name, last name, email address, phone number, and, when requested, information on payment methods and credit card details. The Data Controller will use this information solely to process the booking and to send specific information relevant to confirming it, such as the receipt, booking code, and terms and conditions. The information provided will not be used for commercial purposes and will not be sold, transmitted, licensed, or otherwise forwarded to third parties. This is without prejudice to activities commissioned to our booking service provider, Blastness S.r.l. a Socio Unico, subject to the management and coordination of Blastness Group SRL, with registered office in 20121 Milan (MI), Piazza Castello no. 26, VAT No. 01195440118, represented by its legal representative pro tempore (hereinafter "Blastness").

For hotel bookings, the booking service provider ensures the adoption of rigorous procedures to protect browsing data and the use of particular care to protect the personal data provided, including credit card data provided during online bookings.

In particular, for the activities necessary to book the room and services through the site, our provider Blastness guarantees the use of encrypted SSL technology to safeguard confidential information such as Users' credit card details.

Newsletter

Site visitors can register for our newsletter service. Upon registration, the user's email address will automatically be added to a contact list, to which email messages may be sent containing periodic updates with information — including of a commercial and promotional nature — relating to initiatives, events, or promotions of the Data Controller.

To subscribe to the Newsletter, users can use the sign-up forms on the site, entering their first name, last name, phone number, and email address. The data entered will be used solely to send our newsletter by email and will not be disclosed to third parties.

DATA RETENTION PERIOD OR CRITERIA FOR DETERMINING THE PERIOD

In accordance with the provisions of Art. 5(1)(e) of EU Regulation 2016/679, the personal data collected will be kept in a form that allows the identification of data subjects for a period not exceeding that necessary to achieve the purposes for which the personal data is processed.

The retention periods for personal data provided through the website depend on the purpose of the processing carried out, in particular:

purposes relating to technical browsing data for the proper functioning of the website: retained only for the relevant session, at the end of which the data is deleted;
purposes of responding to requests for information/provision of requested services (maximum 12 months for contact requests; 10 years for any administrative/accounting/financial documentation relating to the provision of a service);
newsletters, marketing, or promotional communications generally via email (maximum 24 months – until consent is withdrawn);
administrative-accounting management purposes: 10 years, as required by law, for the retention of administrative/accounting/financial documentation.

OPTIONAL NATURE OF PROVIDING DATA

Aside from what is specified for browsing data, the user is free to provide the personal data requested in the request forms to the Data Controllers, or otherwise indicated in contacts with the Office, in order to make online bookings, request informational material, or other communications. Failure to provide this data may result in the inability to obtain what was requested.

PROCESSING METHODS

Personal data is processed using automated tools for the time strictly necessary to achieve the purposes for which it was collected. Specific security measures are observed to prevent data loss, unlawful or improper use, and unauthorized access. There is no automated decision-making process for data processing.

RIGHTS OF DATA SUBJECTS

You may contact the Data Controller at any time to exercise your rights as provided for in Chapter III of GDPR 679/2016, in particular the right to request access to personal data and its rectification or erasure ("right to be forgotten"), or restriction of the processing concerning you, or to object to its processing; the right to obtain a copy of the personal data being processed; and the right to data portability. The data subject has the right to receive the requested information without undue delay and, in any case, no later than one month from receipt of the request, which may be extended by two months if necessary; they also have the right to lodge a judicial appeal and a complaint with the Supervisory Authority, i.e. the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it: Piazza Venezia n. 11 - 00187 Rome; garante@gpdp.it, or protocollo@pec.gpdp.it).

The aforementioned rights may be exercised by submitting a request to the Data Controller at the following addresses: at the premises of Park Hotel San Michele, Viale Carella, 9, 74015 Martina Franca, Taranto (Italy), or by email at: sarasrl00197@gmail.com

TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES

Personal data is not transferred to countries outside the European Economic Area, in accordance with the provisions of Chapter V of GDPR 679/2016.

With regard to the site's hosting activities, servers located in the United Kingdom are also used; in this case, the transfer of personal data takes place on the basis of the adequacy decision adopted by the European Commission.

NOTICE UNDER ART. 13 OF EU REGULATION 2016/679 ("REGULATION") – SARA SRL – CHAT SERVICE (WHATSAPP)

We inform you that, pursuant to Art. 13 of EU Regulation 2016/679 (hereinafter, "Regulation" or "GDPR"), your Personal Data is processed by Sara Srl as data controller ("Sara Srl" or "Data Controller"). The Data Protection Officer (hereinafter, "DPO") can be reached at: sarasrl00197@gmail.com. Your personal data will be processed by the Data Controller to respond to your information requests. The legal basis for processing your data is Art. 6(1)(b) and (c) of the Regulation.

Your personal data may be shared with: individuals authorized by the Data Controller to process personal data pursuant to Art. 29 GDPR in the course of performing their job duties (e.g., employees and system administrators, etc.); service providers, who typically act as data processors pursuant to Art. 28 of the Regulation; parties, entities, or authorities to whom your personal data must be disclosed under legal provisions or orders from authorities.

Regarding any transfer of data to Third Countries, the Data Controller informs you that processing will take place in accordance with one of the methods permitted by current law, such as, for example, the data subject's consent, the adoption of Standard Contractual Clauses approved by the European Commission, or transfer to countries considered adequate by the European Commission.

Further information is available upon request from the Data Controller at the contact details indicated above. Your personal data will be kept only for as long as necessary for the purposes for which it was collected, in compliance with the principle of data minimization set out in Art. 5(1)(c) of the GDPR, and in any case no longer than 90 days from the date of provision, for legal evidentiary purposes. Further information is available from the Data Controller.

In relation to the stated purposes, personal data is processed using manual, computerized, and telematic tools, with logic strictly related to those purposes and, in any case, in a manner that ensures the security and confidentiality of the data, in addition to compliance with the specific obligations established by law.

You have the right to ask the Data Controller, at any time, for access to your personal data, its rectification or erasure, or to object to its processing; you have the right to request restriction of processing in the cases provided for by Art. 18 of the Regulation, and to withdraw consent given pursuant to Art. 7 of the GDPR at any time; to obtain, in a structured, commonly used, and machine-readable format, the data concerning you, in the cases provided for by Art. 20 of the Regulation; as well as to lodge a complaint with the competent supervisory authority pursuant to Art. 77 of the GDPR (the Italian Data Protection Authority), should you believe that the processing of your data is contrary to applicable law.

You may submit a request objecting to the processing of your data pursuant to Art. 21 of the GDPR, providing evidence of the reasons justifying the objection: the Data Controller reserves the right to evaluate your request, which will not be accepted if there are compelling legitimate grounds for processing that override your interests, rights, and freedoms.

Requests should be sent in writing to the Data Controller at sarasrl00197@gmail.com or to the DPO at the contact details indicated above.