This report is delivered pursuant to art. 13 of the European Regulation 2016/679 ("Regulation"), which establishes rules concerning the protection of individuals with regard to the processing of personal data, as well as rules concerning the free movement of such data.
This report only concerns the website www.simonettabiketours.it and does not cover other websites, which might be available via any links on the Website.
Personal and identification data
Personal data means any information concerning a natural person, identified or identifiable also indirectly by reference to any other information. In particular, the personal data, which may be collected through the Website, are the following: name, surname, date of birth, address, e-mail address, telephone number. Sensitive data (i.e. those concerning religious beliefs, union membership, sexual preferences and other information listed in Article 9 of the Regulation) are not processed through the Website. Should it be necessary to process data of this kind, we will request prior consent from the data subject /user.
The computer systems and software procedures used to operate the Website, acquire some kind of personal data whose transmission is implicit in the use of Internet communication protocols during their normal operation. This kind of information is not collected to be associated with identified interested parties, however due to its very nature, it might allow users to be identified by means of processing and association of data held by third parties. This category of data includes, for instance, the IP addresses or domain names of the computers used by the users connecting to the Website, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (success, error, etc.) and other parameters relating to the operating system and the IT environment of the data subject/user.
Data provided voluntarily by the data subject/user
Transmission (always optional and at the discretion of the data subject/user) of e-mails to the e-mail addresses indicated on the Website and/or through other interactions with the Website, entails the acquisition of the sender's address, necessary to respond to requests, as well as of any other personal data entered by the data subject/user. Specific information may be displayed on the pages of the Website with regard to particular services provided by the controller.
Purposes of the Processing and its Lawfulness
- management and execution of pre-contractual and contractual obligations: necessary for the implementation of a contract of which the data subject is a party (art. 6.1b of the Regulation)
- management of tax and accounting obligations: necessary to fulfill a legal obligation to which the controller is subject (art. 6.1c of the Regulation)
- direct marketing activities (es. via e-mail) regarding products/services similar to those already provided by the controller to the data subject/user: necessary for the pursuit if a legitimate interest of the controller (art. 6.1f and Recital n47 of the Regulation)
- direct marketing activities (es. via e-mail) regarding products/services other from those already provided by the controller to the data subject/user: processing for which the consent of the data subject/user is requested (art. 6.1a of the Regulation)
Each data subject/user is free to provide personal data in e-mails sent to the e-mail addresses indicated on the Website, or through other interactions with the Website. In the event in which the data required to subscribe to the newsletter or to provide a quotation has not been provided, we will be unable to follow up on the request.
The consent above indicated might be validly provided only by those who are older than 16. Younger subjects must collect the consent of the authorization of their parents or the person who exercises the parental authority.
Finally, for the sake of transparency we point out that the data collected through the Website might be used, in a strictly anonymous and/or aggregated form, to understand the behaviour or the preferences of the users. For example, to identify similar profiles based on browsing preferences.
The processing of personal data is carried out using paper and IT tools in compliance with the provisions on the protection of personal data and, in particular, the appropriate technical and organizational measures pursuant to art. 32.1 of the Regulation, and with the observance of every precautionary measure that guarantees their integrity, confidentiality and availability.
Categories of Addressees
Personal data may be communicated, in strict relation to the purposes indicated above, to the following subjects or categories of subjects:
a) addressees in relation to which the current legislation imposes the duty of communication, in compliance with the provisions of the tax and accounting legislation;
b) professionals and third-party companies with which the controller cooperates, should it be necessary for the functioning of the Website. With regard to paragraph b), we undertake to rely exclusively on subjects who provide adequate guarantees regarding data protection and to appoint such professionals and third parties as Data Processors pursuant to art. 28 of the Regulation. Upon request, the complete list of the Data Processors will be made available by the controller. Personal data will not be transferred outside the European Union.
Personal data are kept in the archives of the controller and are stored for a period of 10 (ten) years from the last interaction with the data subject/user, in consideration of the limitation period of any claims arising from the contact between the controller and the data subject/user, as set forth by law.
Rights recognized to the data subject
At any time, the data subject/user may assert the rights provided by the articles 15 to 22 of the Regulation against the controller, i.e. the right to request:
- access to personal data, i.e. the right to be acquainted with his/her personal data held by the controller, the purposes for which they are processed, their origin and other information required by art. 15 of the Regulation;
- rectification of personal data in case of inaccuracy of the same;
- erasure of personal data (so-called 'right to be forgotten');
- restraint of the processing of personal data, or the right to obtain the suspension of the processing of personal data for a period necessary to verify the request for rectification of personal data, or in other cases provided for by art.18 of the Regulation.
Furthermore, the data subject/user has the right to:
- data portability, i.e. the right to receive personal data in a structured, commonly used and machine-readable format - and to request the direct transfer to another controller;
- the right to lodge a complaint with the Italian Supervisory Protection Authority or with the Supervisory
Authority of the place of residence or work, or of the place where the violation occurred, where it considers that the processing of personal data violates the Regulation.
The controller reserves the right to amend, update, add or remove sections of this privacy statement, at his discretion and at any time. In order to facilitate examination of any revisions/updates, the statement will specify the update date.
Identity and contact details of the Controller
Contact details of the Data Protection Officer
The Data Protection Officer (DPO - Data Protection Officer) as required by art. 37 of the Regulation can be contacted at: [email protected]