Privacy Notice for the Processing of Personal Data Pursuant to EU Regulation No. 2016/679 (GDPR)
This page describes how the website manages the processing of personal data of users who visit it. This notice is provided pursuant to Articles 13 and 14 of EU Regulation No. 2016/679 on data protection (GDPR) to those who interact with the website. This notice does not apply to other websites that may be accessed via links on the websites owned by the data controller, who shall not be held responsible in any way for third-party websites.
Stay Naples – Tourism & Events, headquartered at Via Domenico Padula, No. 121 – Naples, email: info@staynaplestourismandevents.com (hereinafter, the “Data Controller”), in its capacity as the data controller, informs you pursuant to Article 13 of Legislative Decree 30.06.2003 No. 196 (hereinafter, the “Privacy Code”) and Article 13 of EU Regulation No. 2016/679 (hereinafter, the “GDPR”) that your data will be processed in accordance with the principles of lawfulness, fairness, and transparency toward the data subject, using the methods and for the purposes described on this page.
1. Purpose of the Processing
The Data Controller processes personal, identifying, and non-sensitive data (for example but not limited to: first name, last name, company name, address, phone number, email – hereinafter referred to as “personal data” or simply “data”) that you provide when filling out electronic forms on the Website or submitting online requests.
2. Categories of Data Processed and Purposes
2.1. Browsing Data
The IT systems and software procedures that operate this website automatically collect some personal data during their normal operation, the transmission of which is implicit in the use of Internet communication protocols. The website may also transmit information that is not collected to be associated with identified individuals but, by its nature, could, through processing and association with data held by third parties, allow users to be identified.
This category of data includes IP addresses or domain names of computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the server’s response (successful, error, etc.), and other parameters related to the user’s operating system and IT environment.
These data are used solely to obtain anonymous statistical information about website usage and to verify its correct functioning and are immediately deleted after processing. The data could be used to ascertain liability in the event of hypothetical cybercrimes against the website; aside from this eventuality, web contact data are not retained for more than seven days.
2.2. Data Voluntarily Provided by the User and Purpose of Processing
The optional, explicit, and voluntary sending of emails to the addresses indicated on this website or the completion of contact forms results in the subsequent acquisition of the sender’s address, which is necessary to respond to requests, as well as any other personal data included in the message. The data are collected through our website and stored at our offices, partially on paper and partially electronically, for the following explicit and legitimate purposes:
responding to information requests sent by the user through electronic forms on the website;
providing assistance and consultancy;
fulfilling obligations required by law, regulation, EU legislation, orders from the Authority, or requests from the Italian or foreign government or the Italian Chamber of Commerce;
exercising the rights of the Data Controller, for example the right to assert a legal claim in court.
Providing personal data and giving consent for their processing is optional for the user but necessary to ensure the purposes described above. Consent to the processing of personal data is given by the user through the selection of the appropriate fields on the electronic forms available on the website.
3. Methods of Processing and Data Retention Period
The processing of your personal data is carried out through the operations indicated in Article 4 of the Privacy Code and Article 4, No. 2 of the GDPR, specifically: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion, and destruction of data.
Your personal data are processed both on paper and electronically and/or automatically, through the use of the website hosted on the server of the Data Controller or on external company servers that allow the Data Controller to provide its services (for example, to offer online assistance or to store files for the client, providing their email and name for download).
The Data Controller will process personal data for the time necessary to achieve the purposes described above, and in any case, for no longer than 10 years from the termination of the service relationship for service purposes, and no longer than 2 years from data collection for other purposes. In compliance with Article 5(1)(e) of EU Regulation 2016/679, the personal data collected will in any case be kept in a form that allows the identification of data subjects for no longer than the time necessary to achieve the purposes for which the personal data are processed.
4. Security
The Data Controller has adopted a wide range of security measures to protect your data against the risk of loss, misuse, or alteration. In particular, measures have been adopted in accordance with Articles 32-34 of the Privacy Code and Article 32 of the GDPR. When necessary for more secure communications, data encryption technology in compliance with AES (BCrypt) standards and protected data transmission protocols known as HL7 and HTTPS are used.
5. Access to Data
Your data may be made accessible for the purposes described to:
employees and collaborators of the Data Controller, in their capacity as internal data processors and/or system administrators;
third-party companies or other entities (e.g., web domain providers, web hosting providers, web agencies, etc.) that carry out outsourced activities on behalf of the Data Controller, in their capacity as data processors.
6. Data Disclosure
Without your explicit consent (pursuant to Article 24(a), (b), (d) of the Privacy Code and Article 6(b) and (c) of the GDPR), the Data Controller may disclose your data for the purposes referred to in Article 2 to supervisory bodies and judicial authorities, as well as to any other parties to whom disclosure is required by law. In any case, it is ensured that your personal data will never be made public on the Data Controller’s website.
7. Data Transfer
The management and storage of personal data will take place in Europe, on servers located in Europe belonging to the Data Controller and/or third-party companies, including those abroad, appointed as Data Processors for the provision of the requested services. Personal data provided may be transferred abroad, both within and outside the European Union, in compliance with Articles 44 et seq. of EU Regulation 2016/679, in order to fulfill purposes related to such transfers.
8. Nature of Data Provision and Consequences of Refusal to Provide Data
Providing data for the purposes referred to in Article 2 is necessary to guarantee the services described in Article 2.2. You may decide not to provide any data or subsequently deny the processing of data already provided. The provision of personal data by the user when filling out forms, as well as consent to the related processing, while left to the sole and autonomous discretion of the user, is necessary to allow the Data Controller to process the user’s requests. Therefore, failure to provide such data will prevent the fulfillment of any request made by the user.
9. Rights of the Data Subject
As a data subject, you have the rights provided under Article 7 of the Privacy Code and Article 15 of the GDPR, specifically the rights to:
I) obtain confirmation of the existence or non-existence of personal data concerning you, even if not yet recorded, and receive it in an intelligible form;
II) obtain information on:
a) the origin of the personal data;
b) the purposes and methods of processing;
c) the logic applied in case of processing carried out with the aid of electronic instruments;
d) the identifying details of the Data Controller, Data Processors, and the representative designated pursuant to Article 5(2) of the Privacy Code and Article 3(1) of the GDPR;
e) the entities or categories of entities to whom the personal data may be disclosed or who may become aware of them as the designated representative within the state, as processors, or as authorized individuals;III) obtain:
a) updating, rectification, or, where interested, integration of the data;
b) deletion, anonymization, or blocking of data processed unlawfully, including data that does not need to be retained in relation to the purposes for which the data were collected or subsequently processed;
c) certification that the operations described in letters a) and b) have been communicated, including their content, to those to whom the data were disclosed, except where such compliance is impossible or requires a manifestly disproportionate effort compared to the protected right;IV) object, in whole or in part:
a) for legitimate reasons, to the processing of personal data concerning you, even if relevant to the purpose of collection;
b) to the processing of personal data concerning you for sending advertising or direct sales material, or for carrying out market research or commercial communication, via automated calling systems without operator intervention, via email, and/or through traditional marketing methods by phone or postal mail. Please note that the right of opposition for direct marketing purposes through automated means also applies to traditional methods, and you may exercise your right of opposition fully or partially. Therefore, the data subject may choose to receive only traditional communications, only automated communications, or neither type of communication.
Where applicable, you also have the rights under Articles 16-21 of the GDPR (right to rectification, right to erasure, right to restriction of processing, right to data portability, right to object), as well as the right to lodge a complaint with the Supervisory Authority.
10. Withdrawal of Consent and Data Deletion
To exercise your rights, withdraw your consent, or request the complete deletion of your data, you may send a communication by registered letter with return receipt to the business address indicated at the beginning of this notice and/or by email to info@staynaplestourismandevents.com.
11. Minors
This Website and the services of the Data Controller are not intended for individuals under the age of 18, and the Data Controller does not knowingly collect personal information relating to minors. In the event that information about minors is inadvertently recorded, the Data Controller will promptly delete it upon request from the users.
12. Data Controller, Processor, and Authorized Personnel
The Data Controller / Processor (pursuant to Articles 4, 24, and 28 of EU Regulation 2016/679) is:
Stay Naples – Tourism & Events, headquartered at Via Domenico Padula, No. 121, Naples, email: info@staynaplestourismandevents.com
External Data Processor (as a web agency) is:
E26 Srls, located in Naples, Via Enzo Tortora 11 – 80125, Tel: 081.2451030, email: info@e26.studio
The updated list of Data Processors and authorized personnel is kept at the offices of the Data Controller.
13. Data Protection Officer (DPO)
A Data Protection Officer (DPO) has not been appointed as this role is not mandatory for this activity because the processing of personal data is NOT carried out by a public authority or body, the main activities of the organization do NOT involve processing that requires “regular and systematic monitoring” of data subjects, and the main activities of the organization do NOT involve “large-scale” processing of “special categories of data” or “judicial data” (i.e., personal data relating to criminal convictions and offenses).
14. Changes to This Privacy Notice
This Privacy Notice may be subject to changes. It is therefore recommended to regularly review this Notice and refer to the most up-to-date version.
For more information on behavioral advertising and the possibility to opt out of advertising and tracking via cookies, please visit: www.youronlinechoices.eu