Privacy Policy

Data Controller

Zeta Holidays di Zordan Gianpaolo e C. s.a.s.
Via A. De Gasperi 13 - 25019 - Sirmione (BS)
PEC: zetaholidays@pec.it
VAT No. 04359710987
+39 030 91 90 05
Data Controller's Email Address: info@gardeniahotel.it

Types of Data Collected

Among the Personal Data collected by this Application, either independently or through third parties, there are: Tracking Tools; Usage Data; IP address; answers to questions; clicks; keypress events; motion sensor events; mouse movements; scrolling position; touch events.

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or through specific informative texts displayed prior to the collection of the Data.

Personal Data may be freely provided by the User, or, in the case of Usage Data, collected automatically when using this Application.

Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to provide it, it may be impossible for this Application to provide the Service. In cases where this Application specifically states that some Data is optional, Users are free not to communicate such Data without affecting the availability or functioning of the Service.

Users who have doubts about which Data is mandatory are encouraged to contact the Data Controller.

The possible use of Cookies - or other tracking tools - by this Application or the owners of third-party services used by this Application is aimed at providing the Service requested by the User, in addition to the other purposes described in this document and in the Cookie Policy.

The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application and confirms that they have the third party's consent to provide the Data to the Owner.

Methods and Place of Processing the Collected Data

Methods of Processing

The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of Personal Data.

The processing is carried out using IT and/or telematic tools, with organizational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the operation of this Application (administrative, sales, marketing, legal, system administrators) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communication agencies) may have access to the Data, if necessary, as Data Processors appointed by the Data Controller. The updated list of Data Processors can always be requested from the Data Controller.

Place

The Data is processed at the operational headquarters of the Data Controller and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.

The User's Personal Data may be transferred to a country different from the one in which the User is located. To obtain further information about the place of processing, the User can refer to the section detailing the processing of Personal Data.

Retention Period

Unless otherwise specified in this document, Personal Data is processed and stored for the time required by the purpose for which it was collected and may be stored for a longer period due to legal obligations or based on the Users' consent.

Purpose of Data Processing

The User's Data is collected to allow the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect their rights and interests (or those of Users or third parties), detect any malicious or fraudulent activity, and for the following purposes: Statistics and SPAM protection.

To obtain detailed information on the purposes of the processing and on the Personal Data processed for each purpose, the User can refer to the section "Details on the processing of Personal Data."

Details on the Processing of Personal Data

SPAM Protection

This type of service analyzes the traffic of this Application, potentially containing Users' Personal Data, to filter it from parts of traffic, messages, and content recognized as SPAM.

Google reCAPTCHA

Google reCAPTCHA is a SPAM protection service provided by Google LLC or by Google Ireland Limited, depending on how the Data Controller manages the Data processing. The use of the reCAPTCHA system is subject to the privacy policy and terms of use of Google. For an understanding of how Google uses the data, please consult Google's partner policies. Personal Data processed: clicks; Usage Data; keypress events; motion sensor events; touch events; mouse movements; scrolling position; answers to questions; Tracking Tools. Place of processing: United States; Ireland. Category of personal information collected according to the CCPA: information related to internet or other network activity; information inferred from other personal information.

Statistics

Google Analytics 4 (Google Ireland Limited)

Google Analytics is a statistics service provided by Google Ireland Limited ("Google"). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Website, compiling reports, and sharing them with other services developed by Google.

Google may use Personal Data to contextualize and personalize ads from its own advertising network.

In Google Analytics 4, IP addresses are used at the time of collection and then deleted before the data is logged in any data center or server. To learn more, you can consult Google's official documentation.

Personal Data processed: city, Usage Data, browser information, device information, latitude (of the city), longitude (of the city), number of Users, session statistics, and Tracking Tools.

Place of processing: Ireland – Privacy PolicyOpt Out.

Storage duration:

  • _ga: 2 years
  • ga*: 2 years

Cookie Policy

This Application uses Tracking Tools. To learn more, Users can consult the Cookie Policy.

Additional Information for Users

Legal Basis of Processing

The Data Controller processes Personal Data relating to the User if one of the following conditions applies:

  • The User has given consent for one or more specific purposes.
  • The processing is necessary for the execution of a contract with the User and/or for any pre-contractual obligations thereof.
  • The processing is necessary for compliance with a legal obligation to which the Data Controller is subject.
  • The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.
  • The processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.

It is always possible to ask the Data Controller to clarify the specific legal basis of each processing and, in particular, to specify whether the processing is based on the law, required by a contract, or necessary to conclude a contract.

Additional Information on Data Retention Period

Unless otherwise specified in this document, Personal Data is processed and stored for the time required by the purpose for which it was collected and may be stored for a longer period due to legal obligations or based on the Users' consent.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until such contract has been fully performed.
  • Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until such interest is satisfied. Users can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
  • When processing is based on the User's consent, the Data Controller may retain Personal Data for a longer period until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, Personal Data will be deleted. Therefore, the right of access, deletion, rectification, and the right to data portability can no longer be exercised after the expiration of the retention period.

User Rights Under the General Data Protection Regulation (GDPR)

Users may exercise certain rights regarding their Data processed by the Data Controller. In particular, within the limits provided by law, the User has the right to:

  • Withdraw consent at any time. The User can withdraw consent to the processing of their Personal Data previously given.
  • Object to the processing of their Data. The User can object to the processing of their Data when it is done on a legal basis other than consent.
  • Access their Data. The User has the right to obtain information about their Data processed by the Data Controller, certain aspects of the processing, and receive a copy of the Data processed.
  • Verify and request rectification. The User can verify the correctness of their Data and request its updating or correction.
  • Obtain the restriction of processing. The User can request the restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any purpose other than their storage.
  • Obtain the deletion or removal of their Personal Data. The User can request the deletion of their Data by the Data Controller.
  • Receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, if technically feasible, to have it transferred without hindrance to another controller.
  • Lodge a complaint. The User can lodge a complaint with the competent data protection supervisory authority or take legal action.

Users have the right to obtain information regarding the legal basis for the transfer of Data abroad, including to any international organization governed by public international law or constituted by two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect their Data.

Details on the Right to Object

When Personal Data is processed in the public interest, in the exercise of an official authority vested in the Data Controller, or for the purposes of the legitimate interests pursued by the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.

Users are informed that, where their Data is processed for direct marketing purposes, they can object to the processing at any time, free of charge and without providing any justification. Users can refer to the relevant sections of this document for details on how to exercise this right.

How to Exercise Your Rights

To exercise their rights, Users can direct a request to the contact details of the Data Controller indicated in this document. Requests are free of charge and processed by the Data Controller as soon as possible, always within one month.

Additional Information on Data Collection and Processing

Legal Defense

The User's Personal Data may be used by the Data Controller in court or in the stages leading to possible legal action arising from the improper use of this Application or the related Services.

The User declares to be aware that the Data Controller may be required to disclose Personal Data upon request of public authorities.

System Logs and Maintenance

For operation and maintenance purposes, this Application and any third-party services it uses may collect system logs, which are files that record interactions and may contain Personal Data, such as the User IP address.

Changes to this Privacy Policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, within this Application, as well as, if technically and legally feasible, by sending a notification to Users through the contact information available to the Data Controller. Therefore, it is strongly recommended to check this page often, referring to the date of the last modification indicated at the bottom.

Should the changes affect processing activities carried out on the basis of the User's consent, the Data Controller will collect new consent from the User, where required.

HOTEL GARDENIA

Via Brescia 40, 25019 Sirmione (BS) Italia
Telefono: +39 030 91 90 05
E-Mail: info@gardeniahotel.it

FOLLOW US ON

HOTEL TIMETABLES

  • Check-in: from 2 p.m. to 8 p.m.
  • Check-out: from 8 a.m. to 10 a.m.
  • Swimming pool: from 9 a.m. to 10 p.m.

© 2024 HOTEL GARDENIA • P.IVA 04359710987 • VIA BRESCIA 40, 25019 SIRMIONE (BS) ITALIA • PRIVACYCOOKIE

CIR 017179-ALB-00044 • 017179-ALB-00003