Privacy Policy and Data Use on Beinlivigno.com
Data confidentiality is a matter of trust, and your trust is important to Beinlivigno.com. It is therefore important to us that your personal data is protected and that its collection, processing and use in connection with Beinlivigno.com’s services in our app or on our website be in accordance with legal requirements. In this policy, we want to explain how we collect and use data in order to give you an overview of how your personal data will be used.
1. Overview
The following Privacy Policy contains information regarding the manner and scope of the processing of personal data by Beinlivigno.com. Personal data is information that may be directly or indirectly attributed or associated with you personally, such as your name or email address.
2. The name and contact details of the data controller and the company’s data protection officer
This privacy policy applies to the processing of data carried out by Beinlivigno.com – Hotel Galli S.N.C di Bordoli Carla & C with registered office in Livigno (SO), Via Saroch 569, CAP 23041, Italy (the “owner”, hereinafter “Beinlivigno.com”), who can be contacted by e-mail info@beinlivigno.com.
3. The purposes for which the data are processed, the legal basis and the legitimate interests pursued by Beinlivigno.com or third parties, as well as the categories of persons concerned
3.1 Access to our website
When you access our website, the browser used in your device automatically sends information to our website server and temporarily stores it in the so-called log file. We have no control over this step. The following information will also be collected without any action on your part and will be stored until it is automatically deleted:
- IP address of the requesting device with Internet access
- Date and time of access
- Name and URL of the recovered file
- Site/application from which you are logged in (Referrer URL)
- Browser you are using, and possibly the operating system of your computer with internet access, as well as the name of the device with internet access
- Device used (e.g. PC or smartphone)
- Language of the browser you are using
The legal basis for processing your IP address is Article 6 (1) (f) of the General Data Protection Regulations (GDPR). Our legitimate interest is based on the data collection purposes listed below. We would like to point out that we are unable to draw direct conclusions about your identity from the data that is collected, and we refrain from doing so.
We use the IP address of your device and the other data listed above for the following purposes:
- Ensure that a trouble-free connection is established
- Ensure efficient use of our site
- Evaluation of the security and stability of the system
The data will be deleted when they are no longer required by the purpose of their initial collection. In the case of data collection to make the website available, this is the case when the relevant session ends. The data is stored in log-files for a maximum period of 6 weeks, after which it is automatically deleted so that the user can no longer be located. We also use so-called cookies for our website, as well as tracking tools, targeted detection methods and social media plug-ins. The exact procedures applied and the use made of your data for this purpose are explained in detail below.
3.2. Create and use a user account, booking, booking requests
3.2.1. Create an account
When you create a user account with us, we process your personal data in the following alternative way:
- When you log in using Google (social login), your Gmail address and the information transmitted from your Google account (name, profile photo, link to your Google account and top-level domain, gender and hosted domain)
- When you log in using Facebook (social login: Facebook Connect), your email address and public Facebook account information (name, profile photo, age group, language, country and other public information)
- When you log in using your email, your email address
Similarly, a user account is created when you enter your email address and then make a reservation or booking request via our website (see paragraph 3.2.2.). These services require the installation of a user account for technical reasons, which stores the email address, name and dates of the accommodation. Each time you log in, technical information is stored on your device and browser, as well as information about your searches. This helps us to improve your overall user experience on the website, as well as services in general. The legal basis for this is Article 6 (1) (b) and (f) of GDPR. The data you provide to us is based on the contractual relationship between us. Our legitimacy also derives from the protection of your identity and the prevention of fraudulent activities. We will delete the data collected as soon as our platform use contract is terminated.
3.2.2. Reservations and booking requests
We offer travel services in first person. When we receive a booking request, we collect the following data:
- Indicated arrival and departure dates
- First and last name
- Number of guests
- Email address
- Your additional message (optionally)
When you make a reservation, we collect the following data:
- Arrival and departure dates
- First and last name
- Number of guests
- Address
- Email address
- Phone number
- Selected extras (optionally)
- The payment method, where payment processing is carried out by PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A).
With the exception of email address, name and dates of travel, we will retain all such data for security reasons. The collection of such data is a precontractual step necessary to conclude the contract between us and you (Article 6 (1) (b) GDPR).
3.4 Social access (login with Facebook or Google)
3.4.1. Facebook Connect
When you log in via Facebook Connect, you create a direct connection to Facebook servers, 1601 South California Avenue, Palo Alto, CA 94304, USA (“Facebook”). Facebook notices that your login information from Beinlivigno.com has been used as part of this process. If you have expressly given your consent to Facebook in accordance with Article 6 (1) of the GDPR, your personal data will be transmitted to us as part of the registration process via social access. We use the following information from the transmitted data, and store it until it is automatically deleted:
- Email address
- The name of your Facebook profile (first and last name)
- The profile and cover picture you use on Facebook
- Age group (over 18, over 21)
- A link to your Facebook profile
- Your gender
- Generic domain of your connected Facebook profile
- Time zone where you are on Facebook
This data is used for:
- identify you as our counterparty
- set up your user account
- check the plausibility of the data entered
The legal basis for the use of these data is Article 6 (1) (b) of the GDPR. By using this data we can fulfil our contractual obligations under our Terms of Service (Article 6 (1) (b) GDPR). We will delete the collected data at the latest upon termination of our contract of use of the platform. You can block the connection within your Facebook profile. Please refer to Facebook’s privacy policy for details about the purpose of data collection and the subsequent processing and use of data by our service provider, as well as about the associated rights and setting options you can use to protect your privacy (https://www.facebook.com/about/privacy/).
3.4.2. Access via Google
If you log in via Google by selecting “G continue with Google”, a direct connection is established with the servers of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google notices that your login information has been used by Beinlivigno.com as part of this process. We do not obtain any information regarding your Google account. Google therefore informs you that your Google account data will be made available to us and indicates the specific data in question. Registration through Google and use of Google are governed by Google’s privacy policy and terms of service (https://policies.google.com/privacy?hl). If you have expressly given your consent to Google in accordance with Article 6 (1) of the GDPR, your personal data will be transmitted to us as part of the registration procedure via Google. We use the following information from the transmitted data and store it until it is automatically deleted:
- email address
- the name in your Google account (first and last name)
- the profile image (or avatar) used on Google
- a link to your Google account
- your gender
- Generic domain of your linked Google account
- the user domain you manage on Google (hosted domain, HD)
This data is used for:
- allow us to identify you as our counterpart
- set up your user account
- check the plausibility of the data entered
The legal basis for the use of these data is Article 6 (1) (b) of the GDPR. By using this data we can fulfil our contractual obligations under our Terms of Service (Article 6 (1) (b) GDPR). We will delete the collected data at the latest upon termination of our contract of use of the platform. You can block the connection within your Google account. Please refer to Google’s privacy policy for details about the purpose of data collection and the subsequent processing and use of data by Google, as well as about the associated rights and setting options you can use to protect your privacy (https://policies.google.com/privacy?hl).
3.5. Processing of data for advertising purposes
3.5.1. Newsletter
On our website, we offer you the opportunity to subscribe to our newsletter. To make sure that no errors have occurred when entering your email address, we use the so-called double opt-in: after you have entered your email address in the registration field, a confirmation link will be sent to you. Your email will only be added to our mailing list after you click on this confirmation link. You can revoke the consent given in this way at any time with effect for the future only. To do so, simply click on the link to unsubscribe.
3.5.2. Recommended products
We send you emails containing recommended products. You will receive these recommended products regardless of whether you have subscribed to the newsletter. In this way we offer you information about products that may be of interest to you based on your recent research. If you do not wish to receive product recommendations from us, you can let us know at any time. You can find our contact details in paragraph 2. Of course, you will also find a link to unsubscribe in every e-mail message.
3.5.3. Advertising on the basis of interests
In order to receive information that may be of interest to you, we classify your user profile. For this purpose, we use information relating to your research to personalize the items in the newsletter and promotional messages we send you. The goal is to send you advertising oriented to your current needs and to avoid sending you unnecessary advertising. The legal basis for this procedure is Article 6 (1) (f) of the GDPR. Processing the data of an existing customer in the manner indicated for advertising purposes is considered a legitimate interest.
3.5.4. Right of opposition
You have the right, at any time and without paying anything, to object to the processing of data for the above purposes, separately for each individual communication channel, and with effect for the future. To do so, simply send an email to info@beinlivigno.com or send a letter to Beinlivigno.com at the address indicated in paragraph 2 above. If you object, the relevant contact address will be blocked for further promotional procedures. Please note that, in exceptional cases, advertising material may also be sent after receiving your objection. This is due to technical reasons regarding the execution time required for advertisements and does not mean that we will not respect your objection. Thank you for your understanding.
3.6. Cookies – General information
We use cookies on our website in accordance with Article 6 (1) (f) of GDPR. Our interest in optimizing our website is considered legitimate under the aforementioned provisions. Cookies are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our website or when you use our app. Cookies do not damage your device, they do not contain viruses, Trojans or other malicious software. The information stored in cookies is linked to the particular device used. However, this does not mean that we are immediately aware of your identity. In part, cookies are used to make the use of our service more enjoyable for you. For example, we use so-called session cookies to detect that you have already visited individual pages of our website or logged into your user account. These are automatically deleted after you leave our website. In addition, we also use temporary cookies, which are stored on your device for a certain period of time to ensure ease of use. If you visit our website again to use our services, it is automatically detected that you have already visited us, as well as what information you have entered and the settings you have used, so that you do not have to enter them again. If you already have an account and are logged in or have activated the “stay logged in” function, the information stored in cookies will be added to your user account.
On the other hand, we use cookies to statistically record the use of our website, to optimize our services and to show information that meets your needs. These cookies allow us to automatically detect whether you have visited us before when you return to our website. These cookies are automatically deleted after a certain period of time. Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or ensure that a message is always displayed before a new cookie is created. However, disabling cookies completely may mean that you will not be able to use all the features of our website. The length of time cookies are stored depends on their purpose and may therefore vary.
3.7. Analytical instruments
In order to continuously customize and optimize our websites in line with users’ needs, we have tools according to Article 6 (1) (f) GDPR that allow us to analyze the use of our website.
3.7.1. Google Analytics
We use Google Analytics, a web analysis service provided by Google. In doing so, usage profiles are created under a pseudonym and cookies are created. The information generated by cookies on the use of this website, for example:
- Browser type and version
- Operating system used
- Referrer URL (the page visited previously)
- Hostname of the computer with which you logged in (IP address)
- Server request time
are transmitted to Google’s servers in the USA and stored there. Google complies with the US Shield Privacy Policy and is registered with the US Shield Privacy Program of the US Department of Commerce. In addition, we have signed an agreement on data processing for the use of Google Analytics. In accordance with this agreement, Google guarantees that Google processes data in accordance with the General Data Protection Regulations and ensures the data protection of the data subject. The information is used to evaluate the use of the website, to compile reports on website activity, and to provide other services relating to website use and internet usage for market research purposes and to customize the style of these websites in line with users’ needs. This information may also be transferred to third parties if required by law or if third parties have been contracted to process the data. Under no circumstances will your IP address be combined with other data from Google. IP addresses are made anonymous, i.e. it is not possible to identify individual persons (“IP masking”). You can prevent the installation of cookies by setting your browser software accordingly. However, disabling cookies completely may mean that you will not be able to use all the functions of our website. You can also prevent the collection of data generated by cookies and relating to your use of the website (including your IP address) and the processing of data by Google by downloading and installing this browser add-on (https://tools.google.com/dlpage/gaoptout?hl=it). As an alternative to the browser add-on, especially for mobile browsers, you can prevent the collection of data by Google Analytics by clicking here link. An opt-out cookie will be installed to prevent future collection of your data when you visit this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete cookies from this browser, you must reset the opt-out cookie. For more information about the confidentiality of data relating to Google Analytics, please visit the Google Analytics website: https://support.google.com/analytics/answer/6004245?hl=it.
3.7.2. Google Tag Manager
We use the Google Tag Manager. This Google service allows you to manage website tags via a user interface. Only tags are implemented, i.e. no cookies are used and no personal data is collected. Tag Manager leads to the activation of other tags, which may collect data. Google Tag Manager has no access to this data. If the domain or cookie level has been deactivated, this setting will apply to all tracking tags implemented with Google Tag Manager. For more information, see the Google Tag Manager usage guidelines: https://www.google.com/intl/de/tagmanager/use-policy.html.
3.7.3. Google AdWords
Beinlivigno.com uses Google’s AdWords service, which uses conversion monitoring to assess the effectiveness of advertisements, offers and specific features. For this, a cookie is set as soon as you click on a Google ad. These cookies do not identify you personally, but rather make it possible to determine whether you return to the page with a specific offer during a 30-day period when the cookies are valid. Each AdWords advertiser receives a different cookie. As a result, cookies cannot be tracked via the AdWords advertisers’ website. The information obtained using conversion cookies is used to generate conversion statistics for AdWords advertisers who have opted for conversion tracking. We monitor the total number of users who clicked on the ad and were redirected to the website with a conversion tracking tag. You can permanently prevent the storage of Google conversion cookies by setting your browser software accordingly. The Conversion Tracking Privacy Policy can be found here: https://services.google.com/sitestats/en.html.
3.7.4. Remarketing dinamico di Google
We use these dynamic Google Remarketing features with cross-device features of Google AdWords and Google DoubleClick. This feature allows us to use the ad audience created with Google Dynamic Remarketing for the cross-device features of Google AdWords and Google DoubleClick. In this way, interest based and personalised advertisements that have been customised based on your past usage and browsing behaviour on one device (e.g. smartphones) can also be displayed on another device you use (e.g. tablet or PC). If you have given your consent to Google, Google will link your web browser and app history with your Google Account for this purpose. In this way, the same personalised advertisements may appear on every device you use to access your Google Account. To support this feature, Google Analytics collects user IDs authenticated by Google that are temporarily linked to your Google Analytics data to define and create recipients for advertising promotions on different devices. You can permanently disable remarketing / target identification by disabling custom advertising in your Google account. To do this, follow this link: https://adssettings.google.com/authenticated?hl. For more information, as well as data privacy measures, see Google’s Privacy Policy https://policies.google.com/technologies/ads?hl.
3.7.5. Google AdSense
On our website, we use Google AdSense to display advertisements. This way we can show you advertisements that may be of interest to you. These ads can be recognized by the reference “Google Ads”. To do this, Google uses web beacons and cookies (see section 3.6.). The information generated by cookies and web beacons about your use of the website (including your IP address) and the delivery of advertisements is transmitted to a Google server in the USA and stored there. Google may share this information with third parties. We have enabled Google AdSense ads from third parties. This data may be transferred to third parties (listed here https://support.google.com/dfp_sb/answer/94149). You can prevent Google AdSense from installing cookies by disabling ads based on your interest in Google via the link https://adssettings.google.com/authenticated?hl. For more information, as well as for data protection measures, see Google’s Privacy Policy https://policies.google.com/technologies/ads?hl.
3.7.6. Facebook Custom Audiences
We also use Facebook Custom Audiences. Facebook Custom Audiences is a Facebook marketing service. It allows us to show personalized and interest based ads on Facebook to certain groups of visitors under a pseudonym to our website who also use Facebook. A Facebook Custom Audiences pixel is integrated into our website. It is a Javascript code used to store non-personal information about your use of the site. It includes your IP address, the browser you use, and the source and destination pages. This information is transmitted to Facebook servers in the United States. One time, an automatic check is performed to see if you have saved Facebook cookies. Facebook cookies automatically determine whether you are part of a target group that is important to us. If it belongs to the target group, we will show you relevant ads on Facebook. You will not be personally identified by us or facebook as part of this process. You may object to the use of the Custom Audiences service on the Facebook website (https://www.facebook.com/ads/website_custom_audiences). After logging into your Facebook account, you will be able to change your Facebook ad settings. For more information on Facebook privacy, see the Facebook Privacy Policy (https://www.facebook.com/privacy/explanation).
3.7.7 Opzione di opporsi/disattivare
You can avoid the targeting technologies we have described by activating the appropriate cookie settings in your browser (see also section 3.6.). In addition, you have the option of deactivating preference-based listings with the help of the Favourites Manager available here: http://www.youronlinechoices.com/uk/your-ad-choices.
4. Third-party services and plugins
4.1. Google Maps
We use Google Maps API to display interactive maps directly on our website and to activate the simplified use of the map function. Your IP address is transmitted and stored on one of Google’s servers in the USA for the use of the Google Maps function (see Section 3.7.1 regarding the US Privacy Shield). The legal basis for this is Article 6 (1) (b) of the GDPR. See the Service Terms for Google Maps here: https://www.google.com/intl/it/help/terms_maps.html. You can find further information on data privacy in Google’s Privacy Policy here: https://policies.google.com/privacy.
4.2. Google Font
We use fonts (“Google fonts”) provided by Google on our website. Therefore your browser loads the required font into your browser cache when you open Beinlivigno.com. This allows the browser to display a visually better version of our texts. If your browser does not support this feature, your computer will use a default font. The integration of these fonts is completed with a server call, usually a Google server in the USA. This will tell the server which Beinlivigno.com websites you have visited. When you access the page, cookies are not sent by users to the Google Fonts API. Data transmitted in connection with the pageview are sent to resource-related domains such as fonts.googleapis.com or fonts.gstatic.com. You will not be associated with any information collected or used in connection with the parallel use of original Google services, such as Gmail. You can set your browser so that fonts on Google’s servers are not loaded. Beinlivigno.com uses Google fonts to ensure an attractive presentation of its services. The legal basis is Article 6 (1) (f) GDPR. You can find further information in Google’s Privacy Policy (https://policies.google.com/privacy).
5. Contact form
Ti forniamo un modulo di contatto che puoi usare per porci domande inserendo il tuo nome e il tuo indirizzo email. L’uso del modulo di contatto è volontario, e i tuoi dati sono trattati al fine di rispettare i nostri obblighi contrattuali (Articolo 6 (1) (b) GDPR). Le richieste e le informazioni che inserisci saranno trasferite al nostro sistema di assistenza.
6. Property
Beinlivigno.com is a platform owned by Hotel Galli S.N.C di Bordoli Carla & C, a general partnership subject to the laws of the Italian Republic and with registered office in Livigno (SO), Via Saroch 569, CAP 23041, Italy. We may share personal data with some of our business partners. The transfer of data with our business partners takes place for the following purposes:
- a) Provision of our brokerage services and our portal
- b) Provision of customer care services
- c) Send advertising with your consent or if permitted by applicable law
- d) Analysis, optimization and improvement of our website and app
- e) Identification and analysis of fraud and legal activities
- f) Compliance with laws and regulations
The legal basis for internal data transfer with our business partners is Article 6 (1) (a), (b) and (f) GDPR. In detail, the legal basis for the purposes a) and b) is Article 6 (1) (b) GDPR. Sharing such data enables us to fulfil our contractual obligations arising from our terms of service. The legal basis for the purpose c) is your express consent (Article 6 (1) (a) GDPR) which you may revoke at any time, or our legitimate interest in marketing to existing clients (Article 6 (1) (f) GDPR). The legitimacy of the data processing already carried out is not affected by the revocation. For purposes d), e) and f), our legitimate interest derives from the improvement of our services as well as the protection of your identity and the prevention of fraudulent activities (Article 6 (1) (f) GDPR).
7. Your rights
7.1. Overview
In addition to the right to revoke the consent you have given us, you are entitled to the following rights if the relevant legal provisions apply:
- The right of access to information about our stored data in accordance with Article 15 GDPR
- Right to correction of incorrect personal data and right to integration of incomplete personal data in accordance with Article 16 GDPR
- Right to the deletion of your personal data stored by us in accordance with Article 17 GDPR
- Right to limit the processing of your data in accordance with Article 18 GDPR
- Right of data portability in accordance with Article 20 GDPR
7.2. Right of opposition
In accordance with Article 21 (1) GDPR, it is possible to object to the processing of data for reasons relating to particular situations of the data subject. The aforementioned general right to object applies to all purposes of processing described in this Privacy Policy, which is based on Article 6 (1) GDPR. Contrary to the special right of objection for the processing of data for advertising purposes, under GDPR we are merely obliged to implement this general objection if we are given overriding reasons of overriding interest for this purpose (e.g. possible danger to life or health).
Version: n.1 – 01/11/2020
