Headquarters and company name - Canon d'Oro S.r.l. Via XX Settembre 131, 31015, Conegliano (TV)
Capital Stock - 24,000.00 Euro
Economic and Administrative Index of Treviso - no. TV 275438
VAT Number - 00898950266
Canon d’Oro Srl, in its capacity as Data Controller (hereinafter referred to as "Data Controller" or "Hotel"), provides you with the following information pursuant to and for the purposes of Regulation EU No. 2016/679 (hereinafter, "GDPR") regarding the processing of personal data collected during the room booking process and the purchase of its products and services.
In connection with room bookings and the purchase of the Hotel's products and services, the Data Controller processes personal and contact data (e.g., name, surname, email address, mobile phone number, nationality, etc.) of prospective guests, payment and credit card data, as well as any other information included in the "Notes" field. All such data is provided directly by the individual making the booking.
Regarding the "Notes" field, the Data Controller requests that no special categories of personal data be included, such as information related to health status (e.g., details on motor disabilities, allergies, intolerances, etc.), religious beliefs, sexual orientation, political, or philosophical opinions.
In the context of room bookings and the purchase of the Hotel's products and services, your data will be processed for the following purposes:
Data may be disclosed, for the purposes outlined above, to third parties such as public authorities, law enforcement agencies, legal firms, accountants, etc., who will process the data as independent Data Controllers for their own purposes. Additionally, access to the data may be granted to:
The data processed will be retained only for as long as necessary to fulfill the activities/purposes described above, specifically for the period required by tax law (10 years) or the statute of limitations for possible legal actions.
Data is stored and processed within the European Economic Area (EEA). If data is transferred to third countries outside the EEA, the Data Controller ensures that such transfers comply with Articles 44 and following of the GDPR, such as by adopting Standard Contractual Clauses approved by the European Commission, selecting parties participating in international data transfer programs, or operating in countries deemed safe by the European Commission, in line with the European Data Protection Board’s Recommendations 01/2020 of November 10, 2020.
In some cases, transfers may be based on exceptions under Article 49 of the GDPR, such as the data subject's informed consent, the execution of a contract between the data subject and the Data Controller, pre-contractual measures, significant public interest reasons, legal claims, or vital interests. Further details regarding transfers and associated safeguards are available from the Data Controller upon request.
You may exercise your rights or request information on the processing of your personal data by contacting the Data Controller. Under the GDPR, you are entitled to:
a) Withdraw consent previously given, without affecting the lawfulness of processing based on consent prior to withdrawal.
b) Access your personal data and obtain a copy, as well as information about the purposes of processing, data categories, recipients, data retention periods, and other related details.
c) Rectify or update inaccurate or outdated data.
d) Erase data when no longer necessary for the purposes for which it was collected, when you withdraw consent, or when processing is unlawful.
e) Restrict processing if the accuracy of the data is contested, processing is unlawful, or you object to processing based on legitimate interest.
f) Data portability, meaning the right to receive your data in a structured, commonly used, and machine-readable format, and to transfer it to another Data Controller.
g) Object to processing based on the legitimate interest of the Data Controller, subject to evaluation.
h) Lodge a complaint with the relevant supervisory authority (for Italy, the Data Protection Authority at www.garanteprivacy.it).
The contact details of the Data Controller and, if appointed, the Data Protection Officer, are available in the privacy policy accessible from the footer of the Hotel’s website.
I confirm that I have read and understood the privacy notice regarding the processing of personal data.
Publication date: 19 December 2024