Normativa sulla Privacy

Valamar Riviera d.d., con sede a Poreč, Croazia, (via) Stancija Kaligari 1, P. IVA (OIB): 36201212847 (di seguito definita: VALAMAR RIVIERA oppure “noi” oppure “nostro/a”), rispetta la privacy di ogni persona di cui raccoglie i dati personali. Nella nostra politica sulla privacy desideriamo informarLa su quali tipologie di dati personali VALAMAR RIVIERA raccoglie in qualità di titolare del trattamento, con quale scopo, su come proteggiamo i Suoi dati e sui Suoi diritti. In alcuni casi VALAMAR RIVIERA agisce come titolare del trattamento dei dati anche degli interessati i quali sono gli interessati di società terze con le quali VALAMAR RIVIERA ha stipulato dei contratti di collaborazione commerciale sulla base dei quali gestisce per queste ultime la parte turistica della loro attività, nell’ambito dei poteri conferitile sulla base di tali contratti.

Per le prenotazioni degli alloggi effettuate tramite il sito www.valamar.com il Suo titolare del trattamento è VALAMAR RIVIERA, ma potrebbe anche essere l’Imperial Riviera d.d., con sede a Rab, Croazia, (via) Jurja Barakovića 2, P. IVA (OIB): 90896496260 managed by Valamar, l’HELIOS FAROS d.d., con sede a Stari Grad (città di Stari Grad), Croazia, (via) Naselje Helios 5, P. IVA (OIB): 48594515409 managed by Valamar, la Valamar Obertauern GmbH, con sede a Obertauern, Austria, (via) Gamsleitenstraße 6, FN: 195893 d, managed by Valamar, la Kesselspitze GmbH & Co KG, con sede a Obertauern, Austria, (via) Alpenstraße 1, FN: 581638 a, managed by Valamar, a seconda della struttura nella quale alloggi.
Maggiori informazioni sul trattamento dei dati personali e sui Suoi diritti sono disponibili nella nostra politica sulla privacy di seguito riportata.

Valamar Riviera d.d. Helios Faros d.d. Imperial Riviera d.d. Valamar Obertauern GMBH Kesselspitze GmbH & Co KG Valamar Marietta GmbH

Valamar Riviera d.d. normativa sulla Privacy

Gennaio, 2024

La società Valamar Riviera dioničko društvo za turizam, con sede nella Repubblica di Croazia, Poreč, all’indirizzo Stancija Kaligari 1, è l’azienda croata leader del settore turistico e gestisce hotel, resort di villeggiatura e camping resort in rinomate destinazioni in Istria, sulle isole Krk, Rab e Hvar, a Makarska e Dubrovnik oltre che a Obertauern in Austria. Valamar Riviera tratta i dati personali nel pieno rispetto della privacy di ogni persona coinvolta. Con la presente Politica della privacy, vorremmo illustrarLe quali sono i dati personali che Valamar Riviera raccoglie e tratta, in qualità di titolare del trattamento, con quali finalità, le modalità della loro protezione e quali sono i Suoi diritti.

Per una gestione migliore e per un più veloce reperimento delle informazioni che sta cercando, può cliccare sul titolo dell’argomento di Suo interesse e andare direttamente a leggersi il contenuto desiderato. Nella parte generale sono esposte le nostre norme generali applicabili a qualsiasi trattamento dei dati personali, mentre nella parte specifica abbiamo illustrato i casi più frequenti di trattamento dei dati personali che rappresentano la maggior parte dei nostri trattamenti.

PARTE GENERALE

TITOLARE DEL TRATTAMENTO E QUADRO GIURIDICO

Valamar Riviera con sede a Poreč, Stancija Kaligari 1, N°PERS.ID (OIB): 36201212847 (di seguito: Valamar Riviera oppure noi o nostro), in qualità di titolare del trattamento dei dati, si impegna a proteggere i Suoi dati personali. La raccolta e la conservazione dei dati avviene in conformità a quanto previsto dal Regolamento UE 2016/679 del Parlamento Europeo e del Consiglio del 27 aprile 2016 relativo alla protezione delle persone fisiche con riguardo al trattamento dei dati personali, nonché alla libera circolazione di tali dati (di seguito: Regolamento), dalla Legge sull'attuazione del regolamento generale sulla protezione dei dati (GU croata 42/2018) e da altre norme che disciplinano la materia e si applicano nella Repubblica di Croazia.

AMBITO DI APPLICAZIONE

La presente Politica della privacy viene applicata a tutti i trattamenti di dati personali effettuati da Valamar Riviera in qualità di titolare del trattamento, a meno che, con un’altra Politica o un altro documento di Valamar Riviera, non sia stato disciplinato diversamente per un trattamento specifico. In alcuni casi, Valamar Riviera assume la qualità di titolare del trattamento anche per gli interessati che sono, al tempo stesso, soggetti interessati di aziende con le quali Valamar Riviera ha stipulato contratti sulla gestione di strutture turistiche e di servizi, nell’ambito delle proprie competenze e in base a tali contratti.

La presente Politica della privacy è divisa in due parti: Parte generale e Parte specifica. I principi basilari del trattamento dei dati personali, i dati di contatto del responsabile della protezione dei dati e altre disposizioni stabilite nella Parte generale della Politica della privacy vengono applicati senza alcuna eccezione a tutti i trattamenti di dati personali, indipendentemente se tale trattamento è stato sottoposto a un trattamento particolare nella Parte specifica della Politica della privacy oppure no. Nella Parte specifica della Politica della privacy sono trattati in dettaglio i casi specifici di trattamento dei dati che rappresentano la maggior parte di tutti i nostri trattamenti.

RESPONSABILE DELLA PROTEZIONE DEI DATI (DPO)

Valamar Riviera ha nominato un responsabile della protezione dei dati al quale si può rivolgere, in merito a domande sulla tutela dei dati personali e sull’esercizio dei diritti garantiti dal Regolamento, ogni giorno all’indirizzo: dpo@valamar.com oppure per posta all’indirizzo: Valamar Riviera d.d., Stancija Kaligari 1, Poreč, Repubblica di Croazia - alla c.a del DPO

PRINCIPI DI PROTEZIONE DEI DATI PERSONALI

Valamar Riviera riconosce i principi relativi al trattamento dei dati quali valori fondamentali che devono essere rispettati nel corso dell’intero ciclo di trattamento dei dati personali, dalla loro raccolta fino alla loro distruzione oppure altra cessazione del trattamento. Trattiamo i dati in modo:

  • Lecito – il trattamento sarà possibile se il medesimo è consentito dalla legge e comunque nei limiti consentiti dalla legge.
  • Corretto – prendendo in considerazione le specificità di tutti i rapporti, applicando tutte le misure adeguate per la tutela dei dati personali senza ostacolare l’interessato nell’esercizio dei suoi diritti.
  • Trasparente – informando gli interessati sul trattamento dei dati personali. Sin dalla raccolta dei dati, quando gli interessati vengono informati sugli aspetti del trattamento dei dati, fino alla cessazione del trattamento, agli interessati è assicurato l’accesso semplice e veloce ai propri dati. Determinate informazioni possono essere limitate solo quando ciò è richiesto dalla legge oppure quando è reso necessario per la tutela di terzi.
  • Con limitazione delle finalità – trattando i dati personali secondo le finalità per le quali sono stati raccolti, e per finalità diverse se sono soddisfatte le condizioni del Regolamento. I dati possono essere trattati per le finalità corrispondenti solo prendendo in considerazione: (a) ogni nesso tra le finalità per cui i dati personali sono stati raccolti e le finalità dell’ulteriore trattamento previsto; (b) il contesto in cui sono stati raccolti i dati personali, in particolare per quanto riguarda il rapporto tra noi e l'interessato; (c) la natura dei dati personali, specialmente se sono trattate categorie particolari di dati personali ai sensi dell’articolo 9 del Regolamento oppure se sono trattati dati relativi a condanne penali e a reati ai sensi dell’articolo 10 del Regolamento; (d) le possibili conseguenze dell’ulteriore trattamento previsto per gli interessati e (e) l’esistenza di garanzie adeguate.
  • Con limitazione della conservazione – conservando i dati in una forma che consenta l'identificazione dell'interessato solo per il tempo necessario alle finalità per le quali i dati personali sono trattati, e più a lungo solo se consentito dalle normative.
  • Nel rispetto del principio di minimizzazione dei – trattando i dati personali solo se sono adeguati, pertinenti e limitati a quanto necessario. Particolare attenzione è posta a non raccogliere dati per i quali non sussiste alcuna giustificata necessità di trattamento.
  • Tenendo conto dell'accuratezza – tenendo conto dell’accuratezza e dell'aggiornamento dei dati e cancellando i dati errati, se possibile.
  • Tenendo conto dell’integrità e della riservatezza – fornendo un’adeguata sicurezza dei dati personali con misure tecniche e organizzative, compresa la protezione da trattamenti non autorizzati o illeciti e dalla perdita, dalla distruzione o dal danno accidentale, mediante misure tecniche e organizzative adeguate. Le misure pertinenti vengono applicate tenendo conto del rischio di ciascun tipo di trattamento dei dati.

LICEITÀ DEL TRATTAMENTO DEI DATI PERSONALI

Il trattamento è lecito solo se e nella misura in cui ricorre almeno una delle seguenti condizioni:

  • Il trattamento è necessario all'esecuzione di un contratto di cui l'interessato è parte o all'esecuzione di misure precontrattuali adottate su richiesta del medesimo; questo rappresenta la finalità più frequente di trattamento dei dati dell’interessato dove la base è un rapporto contrattuale in essere oppure un rapporto contrattuale che si cerca di realizzare.
  • Il trattamento è necessario per adempiere un obbligo legale al quale è soggetto il titolare del trattamento. Valamar Riviera, in quanto persona giuridica, ha numerosi obblighi prescritti da diverse normative. Tali obblighi comprendono la raccolta e di frequente anche la trasmissione dei dati ad autorità nazionali. Per esempio, il trattamento dei dati personali degli azionisti che presentano domanda di adesione all'assemblea generale, il trattamento dei dati personali degli ospiti e l’inoltro tramite il sistema eVisitor.
  • Il trattamento è necessario per il perseguimento del legittimo interesse del titolare del trattamento o di terzi a condizione che non prevalgano gli interessi o i diritti e le libertà fondamentali dell'interessato che richiedono la protezione dei dati personali, in particolare se l'interessato è un minore. Nell’applicare questa base giuridica, valutiamo che il trattamento sia adeguato alle esigenze aziendali, che sia meno invasivo possibile e che gli interessi degli interessati non prevalgano sui nostri interessi legittimi o su interessi legittimi di parti terze. Un esempio di questo tipo di trattamento è il trattamento a fini amministrativi, a fini di preservare l’integrità e la sicurezza delle reti informatiche, ai fini di marketing diretto e di miglioramento della nostra attività aziendale. In situazioni come queste l’interessato ha il diritto di opporsi a tale trattamento.
  • Il trattamento è necessario per tutelare gli interessi chiave dell’interessato o di un’altra persona fisica. Il diritto alla tutela di dati personali non è un diritto assoluto e lo equipariamo ad altri diritti fondamentali secondo il principio di proporzionalità. Valamar Riviera riconosce la possibilità che in alcune situazioni sia necessario trattare i dati personali per tutelare gli interessi fondamentali dell'interessato o di altre persone fisiche. Un esempio di tale trattamento dei dati è costituito da casi eccezionali di malattia, lesione dell’ospite o di un’altra persona fisica per cui si rende talvolta necessario richiedere il documento personale dell’ospite e richiedere i dati relativi alla salute che rientrano in una categoria speciale di dati personali. Inoltre, in alcune situazioni straordinarie, per esempio in caso di epidemia, possiamo trattare i dati sulla base delle raccomandazioni dell’Ente croato per la sanità pubblica.
  • L’interessato ha fornito il consenso per il trattamento dei propri dati personali a una o più finalità specifiche. Nel trattamento dei dati personali basato sul consenso, prestiamo particolare attenzione a che si tratti di situazioni in cui non sussiste alcuna conseguenza, formale o informale, per la prestazione, il rifiuto o il diniego del consenso. Nel trattamento dei dati basato sul consenso, l'interessato può revocare il consenso in qualsiasi momento senza conseguenze negative. La revoca del consenso non pregiudica la liceità del trattamento basata sul consenso prima della revoca.

TIPOLOGIA DI DATI PERSONALI TRATTATI

Categorie particolari di dati personali: categorie particolari di dati personali sono trattate solo se sono stati soddisfatti i requisiti di cui all’articolo 9 del Regolamento. Per esempio, trattiamo i dati dei dipendenti che appartengono a categorie particolari, tra cui informazioni come l'appartenenza a un sindacato (ad esempio per l'esercizio di diritti speciali ai sensi delle pertinenti normative), le convinzioni religiose o filosofiche (ad esempio, quando si esercita il diritto a giorni non lavorativi aggiuntivi per festività religiose se l'individuo ha divulgato volontariamente tali informazioni per lo scopo dichiarato) oppure dati relativi alla salute (ad esempio, in base a norme particolari in materia di sicurezza sul lavoro o alla tenuta della documentazione sui lavoratori o quando per determinate mansioni sono richiesti particolari certificati sanitari).

Dati relativi alle condanne penali e reati: quando sussiste un’autorizzazione legale a ciò, trattiamo anche i dati personali relativi a condanne penali e reati penali, tra cui, per esempio, certificati che confermino l’assenza di precedenti penali in occasione di gare d'appalto pubbliche, se questo è un requisito della gara.

Dati personali che non appartengono ai due gruppi precedenti: tali dati personali rappresentano la maggioranza dei dati trattati, e si tratta, per la maggiore, di dati identificativi e di dati di contatto tra cui nome e cognome, N° Id. pers. (OIB), dati generati sulla base della circolazione in locali con video sorveglianza.

La maggior parte dei dati personali che raccogliamo ci vengono forniti dagli stessi interessati, La preghiamo di non fornire dati sensibili (per esempio razza o origine etnica, opinioni politiche, convinzioni religiose o filosofiche e simili) laddove non è necessario. Se invece fornisce dati sensibili per un motivo qualsiasi, così facendo dà il Suo esplicito consenso alla raccolta e all'utilizzo di tali informazioni secondo le modalità descritte nella presente Informativa sulla privacy o secondo le modalità descritte al momento della divulgazione di tali informazioni.

INVIO DI DATI A TERZI

Valamar Riviera condivide i dati personali con altri solo quando sussiste una base giuridica.

In determinati casi, i dati personali possono essere trasferiti al di fuori dell'Unione europea (UE) e dello Spazio economico europeo (SEE), precisamente in paesi verso i quali la Commissione Europea non ha adottato alcuna decisione di adeguatezza. In questi casi, garantiamo il rispetto di elevati standard di protezione dei dati personali, in conformità con le severe prescrizioni del Regolamento, e ogni trasferimento di dati personali in un paese terzo sarà eseguito in conformità con le disposizioni di cui al capitolo V del Regolamento. In tali occasioni i modelli più frequenti di trasferimento sono l’applicazione di clausole contrattuali standard approvate dalla Commissione Europea e con il consenso esplicito dell’interessato.

Obblighi giuridici
Nell'ambito dell'adempimento agli obblighi giuridici, siamo tenuti a fornire dati a terzi. Per esempio, l’invio dei dati degli ospiti tramite il sistema eVisitor, l’invio dei dati di dipendenti agli enti competenti: all’Istituto croato per l'assicurazione pensionistica, all’Istituto croato per l’assicurazione sanitaria, all’Agenzia delle entrate e al Registro centrale degli assicurati e delle imprese di previdenza. Inoltre, in determinati casi, siamo obbligati a trasferire oppure a mettere a disposizione dell’Ufficio di collocamento i dati relativi all’impiego in Croazia, per esempio ai fini di inserimento dei dipendenti nel programma di misure di politica attiva di impiego, alle stazioni di polizia competenti per gli affari interni, per esempio in caso di soggiorno di alti funzionari governativi nelle strutture e per emissione di permessi di lavoro, al ministero competente per gli affari nel turismo in caso di impiego di studenti con borsa di studio, al ministero competente per gli affari di economia e imprenditorialità quando si tratta di utilizzare sostegni agli investimenti, alle compagnie di assicurazione, alle banche e in altre situazioni quando la normativa lo impone. Inoltre, determinati dati dei dipendenti vengono trasmessi alle banche oppure ai fondi pensionistici nell’ambito del pagamento delle retribuzioni e i dati possono essere trasmessi anche ai creditori in conformità con le leggi che disciplinano la procedura esecutiva. Talvolta i dati vengono trasmessi in funzione degli obblighi contrattuali, ad esempio nel caso di alunni che adempiono all’obbligo di alternanza scuola-lavoro (tirocinio curricolare), i dati vengono scambiati con scuole e/o università.
Determinati dati personali vengono trasmessi anche a operatori economici con le finalità di fornitura di servizi specifici tra cui servizi di visite mediche dei dipendenti (medicina del lavoro convenzionata), poi alle istituzioni che organizzano l’istruzione obbligatoria (sicurezza sul lavoro, corsi di igiene, tossicologia) oppure a imprese di revisione contabile, a notai quando sussiste la necessità di autenticazione, Agenzia finanziaria per la gestione dei certificati commerciali, ai soggetti vincolati agli appalti pubblici quando partecipiamo a bandi per appalti pubblici, inoltre ai fini di assegnazione e utilizzo di carte di credito aziendali, telefoni cellulari aziendali oppure per l’acquisto di carburante.

Valamar Riviera in qualità di management company
Un caso particolare di trasmissione dei dati a terzi riguarda il fatto che Valamar Riviera vanta contratti a lungo termine circa la gestione di servizi turistici e di strutture ricettive con varie aziende turistiche. Questo significa che gestiamo le strutture Valamar costituite dalle nostre strutture ricettive (di nostra proprietà oppure quelle utilizzate su altre basi) come pure da strutture ricettive di aziende da noi gestite. In primo luogo, i servizi di gestione comprendono i servizi relativi agli ospiti delle strutture Valamar, ma anche le risorse umane. Alla luce di quanto sopra, talvolta condividiamo i dati personali degli ospiti, del candidato per un posto di lavoro ovvero dei dipendenti delle strutture Valamar con aziende di nostra gestione, ovvero gli interessati di tali società sono anche i nostri interessati, il tutto allo scopo di sviluppare attività e servizi delle strutture Valamar, divulgare le offerte relative alle strutture Valamar, identificare gli interessati aventi esigenze simili nonché analizzare i relativi movimenti di mercato. Tutti i principi della presente Politica si riferiscono anche agli interessati di tali società nell’ambito di segmenti che ci vedono coinvolti in qualità di titolare del trattamento. Tuttavia, anche tali società sono responsabili in qualità di titolari del trattamento dei dati dei propri interessati. Le Politiche della privacy di tutte le società di nostra gestione sono disponibili al sito Internet https://www.valamar.com/it/normativa-sulla-privacy.

Valamar Riviera in qualità di agenzia turistica
Dato che operiamo anche come agenzia turistica, trasferiamo i dati a terzi quando ciò è reso necessario per la realizzazione di servizi concordati. Per esempio, trasferiamo i dati dell’ospite che ha prenotato una struttura alla società che offre il servizio concreto di soggiorno oppure trasferiamo i dati di un acquirente di una determinata esperienza all’organizzatore di quest’ultima.

I partner di Valamar - responsabili del trattamento
È possibile che i dati siano trasferiti ad operatori economici, responsabili del trattamento, che trattano i dati per conto nostro, in qualità di titolare del trattamento. Solitamente, si tratta di nostri soci d’affari che ci forniscono determinati servizi, per esempio servizi informatici, di marketing, per la gestione dei pagamenti, servizi di protezione. Con tutti i soci stipuliamo un contratto dettagliato riguardo le loro competenze e gli obblighi nel trattamento dei dati personali, in conformità con i requisiti del Regolamento. Gli stessi hanno anche l’obbligo di utilizzare i dati a loro affidati esclusivamente in conformità con i contratti in essere e rigorosamente per lo scopo citato. Inoltre, hanno l’obbligo di proteggere i Suoi dati in modo corretto e di garantirne la riservatezza.

TERMINI DI CONSERVAZIONE DEI DATI

I dati dell’interessato vengono trattati e conservati in conformità con le disposizioni di legge vigenti, quando è prescritto l’obbligo di conservazione.

Nei casi in cui Valamar Riviera è autorizzata a stabilire autonomamente i termini di conservazione dei dati, essi vengono conservati per il tempo necessario per conseguire lo scopo per il quale sono trattati tenendo in considerazione la finalità del trattamento, il legittimo interesse di Valamar Riviera e gli interessi degli interessati. Laddove, nella presente Politica della privacy o altrove, per un determinato trattamento non è stato citato il termine di conservazione dei dati, La informiamo che tale termine è di 5 anni.

Dopo la scadenza del termine di conservazione previsto, i dati saranno cancellati, mentre laddove ciò non fosse possibile, i dati saranno resi illeggibili.

TRATTAMENTO DEI DATI PERSONALI DI BAMBINI

Trattiamo i dati personali dei bambini quando riguardano i nostri servizi, per esempio quando i bambini sono ospiti delle nostre strutture, della ludoteca Maro, ma anche in altri casi, per esempio quando alunni minorenni svolgono il programma di alternanza scuola-lavoro nelle nostre strutture (tirocinio curricolare). Talvolta non possiamo agire sull’utilizzo dei nostri servizi, per esempio quando i bambini appaiono come follower di nostri profili sui social network. Raccomandiamo ai genitori e ai tutori di insegnare ai bambini la gestione sicura e responsabile dei dati personali, in particolar modo quando usano Internet.

ORIGINE DEI DATI PERSONALI

Solitamente i dati personali ci vengono forniti da Lei. Quando fornisce i dati personali, in qualsiasi modalità (prenotazione di alloggio, domanda di assunzione, utilizzo dell’app mobile, utilizzo dei servizi di ristorazione, wellness e altro), ci garantisce che le informazioni date sono esatte, di essere legalmente capace e di essere autorizzato/a a disporre dei dati forniti nonché di essere pienamente consenziente alla raccolta e all’utilizzo dei Suoi dati in conformità con le norme positive e le condizioni della presente Politica della privacy.

Inoltre, i Suoi dati personali ci vengono forniti direttamente o indirettamente, da altre persone fisiche e giuridiche, per esempio: da agenzie turistiche che trasmettono i dati degli ospiti per esigenze di alloggio, da ospiti che prenotano un alloggio per persone con cui intendono soggiornare nelle strutture, da agenzie di intermediazione e somministrazione, assunzione e ricollocamento del personale, da soci d’affari che parteciperanno all’esecuzione di determinati contratti e quant’altro. Quando ci fornisce i dati di altre persone garantisce che le informazioni allegate sono esatte, di essere legalmente capace e di essere autorizzato/a a disporre delle informazioni fornite, che gli interessati dei quali ci fornisce i dati acconsentono al trattamento dei loro dati. Se ci fornisce i dati di altre persone, ha l’obbligo di mettere loro a conoscenza della nostra Politica della privacy.

In determinate situazioni, i dati personali ci vengono forniti da fonti pubbliche, per esempio dal registro del tribunale, dal Suo sito Internet, da annunci e similari.

PROTEZIONE DEI DATI FIN DALLA PROGETTAZIONE E PROTEZIONE PER IMPOSTAZIONE PREDEFINITA

Nella protezione dei dati adottiamo i più alti standard organizzativi e tecnici. Pertanto, tenuto conto dello stato dell’arte e dei costi di attuazione, nonché della natura, dell'ambito di applicazione, del contesto e delle finalità del trattamento, come anche dei rischi aventi probabilità e gravità diverse per i diritti e le libertà delle persone fisiche derivanti dal trattamento di dati, sia al momento di determinare i mezzi del trattamento sia all'atto del trattamento stesso, mettiamo in atto misure tecniche e organizzative adeguate volte ad attuare in modo efficace i principi di protezione dei dati.

Inoltre, mettiamo in atto misure tecniche e organizzative adeguate per garantire che siano trattati, per impostazione predefinita, solo i dati personali necessari per ogni specifica finalità del trattamento. Applichiamo tale misura alla quantità dei dati personali raccolti, alla portata del loro trattamento, al periodo di conservazione e alla loro accessibilità. Precisamente, tali misure ci consentono di garantire che i dati personali non siano resi automaticamente accessibili a un numero illimitato di soggetti, senza l’intervento della persona fisica.

Per garantire un alto livello di sicurezza nel trattamento dei dati personali e per proteggere gli stessi dall’accesso non autorizzato, casuale o volontario, dalla perdita o modifica, garantiamo l’accesso ai sistemi, dove è custodita la maggioranza dei dati personali degli individui, soltanto a persone autorizzate nella misura necessaria all’espletamento delle loro mansioni lavorative e precisamente utilizzando un sistema multiplo di autenticazione, anch’esso protetto da accesso o utilizzo non autorizzato e soggetto ad aggiornamenti regolari.

VIOLAZIONE DEI DATI PERSONALI

Abbiamo adottato tutte le misure tecniche e organizzative adeguate per ridurre al minimo i rischi di violazione. Tuttavia, se dovesse notare una violazione dei dati personali, La preghiamo di denunciare senza esitazioni tale violazione all’indirizzo email: dpo@valamar.com. Abbiamo implementato i meccanismi interni per poter reagire tempestivamente e in modo appropriato in tali situazioni.

In conformità con il Regolamento, e con le norme interne, in caso di violazione dei dati personali, senza inutili esitazioni e, se fattibile, entro e non oltre le 72 ore dal momento in cui si è venuti a conoscenza di tale violazione, provvediamo a notificare la violazione di dati personali all’autorità di vigilanza, a meno che sia improbabile che la violazione dei dati personali presenti un rischio per i diritti e le libertà delle persone fisiche.

La relazione trasmessa all’autorità di vigilanza contiene tutte le informazioni ai sensi del Regolamento.

Nel caso in cui la violazione dei dati personali sia suscettibile di presentare un rischio elevato per i diritti e le libertà delle persone fisiche, comunichiamo la violazione al soggetto interessato senza ingiustificato ritardo. Talvolta, nei casi previsti dal Regolamento, non è obbligatoria darne notifica all’interessato.

DIRITTI DELL’INTERESSATO

Indipendentemente dalla base della raccolta dei dati, gli interessati possono esercitare gratuitamente, nei limiti previsti dal Regolamento, i seguenti diritti:

Diritto all'informazione: ha diritto di essere informato/a sul trattamento e sulle relative finalità. Prestiamo attenzione nel fornire all’interessato tutte le informazioni necessarie per garantire un trattamento corretto e trasparente, tenendo conto del contesto del trattamento.

Diritto alla cancellazione ("diritto all'oblio"): ha il diritto di richiedere la cancellazione dei dati personali che La riguardano, senza indugio, conformemente alle condizioni previste dal Regolamento.

Per farlo, deve inviare la Sua richiesta a noi, in qualità di titolare del trattamento, in forma cartacea, incluso il formato elettronico di comunicazione. Ricordiamo che nella richiesta deve essere specificato che cosa esattamente desidera che sia cancellato siccome possiamo conservare i Suoi dati sulla base di diversi fondamenti giuridici, per esempio, l’interessato può essere sia nostro ospite sia candidato all’assunzione. Ha il diritto di richiedere la cancellazione dei dati che La riguardano se è stata soddisfatta una delle seguenti condizioni:

  • i Suoi dati personali non sono più necessari in relazione allo scopo per il quale sono stati raccolti o trattati
  • ha revocato il consenso su cui si basa il trattamento e se non sussiste altro fondamento giuridico per il trattamento
  • si è opposto/a al trattamento dei Suoi dati personali e non sussiste alcun motivo legittimo prevalente per procedere al trattamento
  • i dati personali sono trattati in modo illecito
  • i dati personali devono essere cancellati per adempiere un obbligo giuridico.

In alcuni casi non sarà possibile soddisfare pienamente la richiesta di cancellazione, per esempio quando sussiste un obbligo giuridico di conservazione, quando l’interesse legittimo del titolare del trattamento prevale su quello dell’interessato, quando sussiste l’interesse del titolare del trattamento per l’accertamento, l’esercizio o la difesa di un diritto in sede giudiziaria.

Diritto di accesso ai dati: ha il diritto di accedere ai Suoi dati, oggetto del trattamento, e ha il diritto di richiedere informazioni dettagliate, specialmente in merito alla finalità del trattamento, tipologia/categoria di dati personali trattati, incluso il diritto di prenderne visione, ha altresì il diritto di conoscere i destinatari o categorie di destinatari e il periodo previsto di conservazione dei dati personali. L’accesso ai dati personali può essere limitato soltanto nei casi previsti dalla legge, ovvero quando tali restrizioni rispettano l'essenza dei diritti e delle libertà fondamentali altrui.

Diritto di rettifica: ha il diritto di ottenere dal titolare del trattamento la rettifica dei dati personali inesatti qualora non siano corretti, completi e aggiornati. Per farlo, deve inviare la Sua richiesta a noi, in qualità di titolare del trattamento, in forma cartacea, incluso il formato elettronico di comunicazione. Ricordiamo che nella richiesta deve essere specificato che cosa di preciso non risulta esatto, completo o aggiornato e in che modo tali dati dovrebbero essere corretti. Inoltre, occorre recapitare la documentazione necessaria da allegare alle proprie affermazioni.

Diritto alla portabilità dei dati: ha il diritto di ricevere i dati personali che La riguardano in un formato strutturato, di uso comune e leggibile da dispositivo automatico, nonché il diritto di trasmettere tali dati a un altro titolare del trattamento senza impedimenti da parte del titolare del trattamento cui li ha forniti, il tutto in conformità con le prescrizioni del Regolamento.

Diritto alla limitazione del trattamento: ha il diritto di ottenere la limitazione del trattamento nei seguenti casi:

  • quando contesta l’esattezza dei dati personali
  • quando il trattamento è illecito e si oppone alla cancellazione dei dati

quando il titolare del trattamento non necessita più dei dati personali ma ne ha bisogno Lei per accertare, esercitare o difendere un diritto in sede giudiziaria

quando si è opposto al trattamento dei Suoi dati personali ed è in attesa di verifica in merito all’eventuale prevalenza dei motivi legittimi del titolare del trattamento rispetto a quelli dell'interessato.

Diritto di opporsi al trattamento dei dati personali: quando trattiamo i dati in base a nostri interessi legittimi che prevalgono su quelli dell’interessato, quest’ultimo ha il diritto di opporsi al trattamento dei dati personali che lo riguardano, in base alla propria situazione specifica e in qualsiasi momento.

In ogni caso gli interessati hanno i seguenti diritti:

  • il diritto di presentare reclamo al Responsabile della protezione dei dati personali (DPO)
    Valamar Riviera d.d.,
    alla c/a del DPO
    Stancija Kaligari 1, Poreč
    e-mail: dpo@valamar.com
  • il diritto di presentare reclamo all’autorità di vigilanza se ritiene che i Suoi diritti di tutela dei dati siano stati violati.
    Agenzia per la protezione dei dati personali
    Selska cesta 136, HR – 10 000 Zagreb
    e-mail: azop@azop.hr

In qualità di titolare del trattamento, abbiamo il diritto di tutelare i nostri interessi nonché quelli degli interessati e, in conformità con ciò, abbiamo il diritto di effettuare attività volte all’attestazione dell’identità del richiedente.

Abbiamo anche il diritto di pubblicare il modulo che verrà usato per presentare la richiesta al fine della sua elaborazione nel modo più efficiente possibile.

In caso di presentazione della richiesta Le forniremo le informazioni sulle azioni intraprese riguardo l’esercizio dei Suoi diritti senza indugio e, in ogni caso, entro il termine di un mese dalla data di ricezione della richiesta. Tale termine, se necessario, può essere prolungato di ulteriori due mesi, prendendo in considerazione la complessità e il numero di richieste. In tal caso sarà nostra cura avvisarLa entro un mese dalla data di ricezione della richiesta, insieme al motivo del ritardo.

Se presenta la Sua richiesta in formato elettronico, Le forniremo le informazioni in tale formato, ove possibile, a meno che non sia richiesto diversamente.

Ricordiamo che, in caso di richiesta, tutte le domande e la relativa corrispondenza sono custodite al fine di dimostrare le relative procedure.

Le procedure legate alle richieste dell’interessato sono generalmente gratuite; tuttavia, se le richieste dell’interessato sono palesemente infondate o eccessive, in particolare per il loro carattere ripetitivo, possiamo addebitare un contributo spese ragionevole basato sui costi amministrativi o rifiutare di soddisfare la richiesta.

Tutte le richieste che non riguardano la protezione dei dati personali e sono state consegnate all'indirizzo del DPO, per esempio domande d’impiego di candidati, richieste di prenotazione nelle strutture Valamar, saranno reindirizzate direttamente agli uffici competenti di Valamar Riviera, senza l’invio di una specifica risposta al mittente da parte del DPO. In maniera analoga, tutte le richieste relative alla protezione dei dati personali, ricevute da altri nostri uffici a qualche altro nostro indirizzo di posta elettronica, possono essere inoltrate al nostro Responsabile per la protezione dei dati personali (DPO).

PARTE SPECIFICA

SOGGIORNO NELLE STRUTTURE VALAMAR (hotel, appartamenti, campeggi)

La nostra attività principale è fornire servizi di alloggio nelle strutture Valamar. A tale scopo stipuliamo con Lei contratti per la fornitura di servizi di ospitalità (servizi alberghieri, alloggio in appartamenti turistici e servizi di campeggio). Pertanto, raccogliamo e trattiamo i Suoi dati personali a scopi diversi con l’obiettivo finale di fornire un servizio di alloggio e di servizi complementari di qualità, in base ai più alti standard delle aziende operanti nel turismo.

Le strutture Valamar rappresentano le nostre strutture ricettive (di nostra proprietà oppure quelle utilizzate su altre basi) come pure le strutture ricettive di aziende gestite da Valamar.

Le strutture Valamar sono:

  • Hotel e appartamenti (ville, appartamenti, suite, case, camere)
  • Piazzole nei campeggi
  • Case mobili nei campeggi (ville, suite e camping home, tende glamping)

In caso di prenotazione di alloggio tramite i nostri canali di vendita - prenotazione tramite sito Internet, app mobile o telefonando al centro prenotazioni Valamar (in nome del legittimo interesse teniamo la registrazione delle chiamate) oppure tramite l’accettazione della nostra offerta per posta elettronica-, il Suo titolare del trattamento dei dati è Valamar Riviera, ma anche le altre società, in relazione alla struttura dove soggiorna.

I Suoi dati personali che è tenuto/a ad inviarci per consentirci di fornirLe il servizio di alloggio, sono custoditi nel nostro database per l’espletamento del contratto per la fornitura di servizi di ospitalità e per l’adempimento degli obblighi giuridici relativi ai servizi ricettivi. In caso di mancata trasmissione dei dati minimi per la prenotazione di un alloggio e al momento del soggiorno per la registrazione in tutti i registri competenti, non potremo fornirLe il servizio di prenotazione di alloggio, ovvero il servizio di soggiorno ai sensi del contratto e delle disposizioni di legge.

Alcuni dati sono necessari per intraprendere azioni su richiesta dell’interessato prima della conclusione del contratto di alloggio. Per esempio, prima di prenotare un alloggio, su richiesta di potenziali clienti, vengono inviate offerte per alloggi per la cui elaborazione e invio abbiamo bisogno di dati personali, quanto meno del nome, cognome e indirizzo email nonché di informazioni sul soggiorno desiderato.

I dati personali che raccogliamo per l’espletamento della prenotazione sono:

  • Nome e cognome del titolare della prenotazione
  • Indirizzo di residenza (cittadini croati)
  • Data di nascita
  • Numero, tipo di documento di identità e luogo di emissione
  • Cittadinanza
  • Nome della struttura
  • Numero di unità di alloggio, tipologia dell’unità di alloggio (tipologia della camera)
  • Data di arrivo e di partenza
  • Numero di persone per le quali viene prenotato l’alloggio e la disposizione per camera
  • Nomi delle persone minorenni
  • Eventuali altre caratteristiche in relazione alla richiesta della persona che sta prenotando l’alloggio
  • E-mail se la persona ne possiede una
  • Lingua
  • Telefono
  • Affiliazione al Programma fedeltà se influisce sul prezzo dell’alloggio o sulla raccolta punti
  • Modalità di pagamento ed eventuali dati aggiuntivi necessari per eseguire la transazione oppure per garantire il pagamento.

Considerando che è previsto che i dati di registrazione degli ospiti vengano inseriti basandosi sui dati riportati nella carta d’identità, ovvero nel documento di viaggio o di un altro documento personale, l’ospite è tenuto ad esibire tale documento e fornire tutte le informazioni necessarie per l’inserimento dei dati che non sono presenti in tale documento. In modo analogo, per esercitare alcuni diritti e benefici è necessario allegare (fotocopie di) documenti appropriati, certificati e documenti a conferma di tali diritti e benefici e per poterne usufruire. All’arrivo in una struttura di Valamar, solitamente gli ospiti fanno il check-in alla reception della struttura utilizzando la scheda di registrazione compilata ovvero verificata dall’ospite che conferma l’esattezza dei dati.

Diamo agli ospiti la possibilità di effettuare la registrazione all’arrivo in autonomia, utilizzando l’app Check-in grazie alla quale l’ospite inserisce in autonomia i suoi dati personali caricando la foto del suo documento d’identità che non viene salvata, bensì utilizzata dall’app per caricare soltanto i dati personali strettamente indispensabili.

In ogni caso, i dati vengono inseriti nel database degli ospiti da cui vengono inviati tramite un sistema automatico al sistema eVisitor (sistema unico informatizzato on-line per il Check-in e il Check-out degli ospiti) per adempiere ai nostri obblighi giuridici. Vengono raccolti i seguenti dati (i dati possono variare in funzione delle variazioni alle norme positive):

  • Nome e cognome
  • Luogo, stato e data di nascita
  • Cittadinanza
  • Numero e tipo di documento di identità
  • Residenza (domicilio) e indirizzo
  • Data e ora dell’arrivo, ovvero della partenza dalla struttura
  • Sesso
  • Base per l’esenzione dalla tassa di soggiorno ovvero per la riduzione della tassa di soggiorno.

I suddetti dati vengono trattati dall’ente per il turismo e dalle autorità pubbliche della Repubblica di Croazia per le seguenti finalità legali:

  • monitoraggio dell’espletamento dell’obbligo di check-in e check-out di turisti da parte di soggetti con obbligo di registrazione in entrata e in uscita (fornitore del servizio di alloggio)
  • registrazione, resoconto e riscossione della tassa di soggiorno
  • tenuta di libri o registri degli ospiti da parte del fornitore di servizi di alloggio e monitoraggio dell’espletamento del suddetto obbligo da parte degli organismi di controllo
  • registrazione di cittadini stranieri presso il ministero degli affari interni e monitoraggio dell’espletamento del suddetto obbligo da parte degli organismi di controllo
  • registrazione di turisti da parte degli enti per il turismo nonché elaborazione statistica e resoconti
  • monitoraggio della gestione aziendale di fornitori del servizio di alloggio nella parte dedicata alla legittimità dell’esercizio dell’attività ovvero della fornitura di servizi registrati nonché del rispetto di normative fiscali e di altre norme relative a contributi pubblici.

I dati sugli ospiti nel libro degli ospiti sono in formato elettronico e vengono conservati, come da normativa vigente, per due anni. Noi conserveremo alcuni dati delle persone che hanno richiesto un’offerta, prenotato un alloggio, disdetto un alloggio, i dati relativi agli ospiti al fine di comprovare il contenuto del rapporto con l’interessato, ovvero al fine di accertare, esercitare o difendere i diritti in sede giudiziaria, per un periodo di cinque anni dalla data dell’ultimo soggiorno presso le strutture Valamar. Ai fini sopraelencati conserveremo i dati necessari per la sola prenotazione, oltre agli altri dati a seconda dei singoli casi, per esempio: data di ricezione del reclamo dell’ospite e contenuto del reclamo, la corrispondenza e quant’altro. Inoltre, siamo tenuti a conservare tutte le fatture nonché le basi di emissione delle fatture a favore di clienti con i dati personali del cliente, ai sensi delle normative di legge.

Altri dati relativi alle circostanze del Suo soggiorno, tra cui le richieste per il lettino per bambini, saranno altresì raccolti e trattati soltanto durante il Suo soggiorno quando sono direttamente collegati alla fornitura del servizio concreto di alloggio.

LUDOTECHE MARO

In alcune strutture Valamar i nostri ospiti hanno la possibilità di utilizzare le ludoteche per i bambini. Per consentire a Suo figlio/a di usufruire della ludoteca MARO è necessario compilare il modulo/badge per la registrazione, il cosiddetto Passaporto dei bambini dove inserirà: nome ed età del bambino, periodo di permanenza nella struttura di Valamar, nome, cognome e numero di cellulare dei genitori/tutori, nome della struttura di Valamar dove soggiorna la famiglia e il numero di unità abitativa ed eventuali allergie del bambino, se presenti. In fondo al foglio di registrazione dell’ingresso/uscita Le verrà richiesto di apporre la Sua firma.

Lo scopo è tutelare e tenere il registro dei bambini che vi soggiornano mentre la base giuridica è il Suo consenso. Il passaporto di Valamar con i dati del bambino viene conservato per la durata effettiva del soggiorno nella struttura di Valamar.

CAMBIO VALUTE

Forniamo anche i servizi di cambio valute nei rispettivi punti, solitamente presso le reception delle strutture Valamar. Conformemente alla normativa vigente in materia di lotta contro il riciclaggio di denaro e il finanziamento del terrorismo, Valamar Riviera ha l’obbligo, in alcuni casi, di stabilire e verificare l’identità delle persone che utilizzano i servizi di cambio valute dietro presentazione del documento personale ufficiale del cliente in sua presenza ed eseguire un’analisi dettagliata. In caso di impossibilità di eseguire un’analisi approfondita quando la legge lo prevede, non ci è concesso istituire un rapporto di lavoro oppure eseguire una transazione. In altre parole dobbiamo interrompere il rapporto di lavoro già istituito e valutare se è necessario informare le autorità competenti circa la natura dubbia di transazioni, fondi e persone.

Inoltre, secondo la normativa, è obbligatoria anche la videosorveglianza degli uffici di cambio. I dati vengono conservati in conformità con le leggi e per ottemperare ai nostri obblighi di legge.

AFFILIAZIONE AL PROGRAMMA FEDELTÀ

Valamar Riviera è il titolare del Programma fedeltà Valamar Plus Club (di seguito: Programma fedeltà). Le condizioni dell’affiliazione sono riportate nel Regolamento del Programma fedeltà consultabile al link www.valamar.com/hr/program-vjernosti/valamar-plus-club/pravilnik-programa. L’affiliazione al Programma fedeltà viene eseguita esclusivamente su richiesta dell’interessato, e ciò in primo luogo degli ospiti di strutture Valamar. Ogni affiliato al programma fedeltà (di seguito: membro loyalty) possiede un proprio account utente che richiede determinati dati.

Accettando l’affiliazione al programma, conferma di essere a conoscenza del trattamento dei Suoi dati e della creazione di un Suo profilo in qualità di affiliato del Programma fedeltà da parte di Valamar in qualità di titolare del trattamento.

Nella procedura di creazione del profilo, Valamar tratterà i seguenti dati personali:

  • i dati raccolti durante la compilazione del modulo di richiesta di adesione al programma ovvero l’apertura dell’account utente: nome, cognome, sesso, data di nascita, indirizzo email, numero di cellulare, indirizzo (via, numero civico, codice di avviamento postale, città e stato)
  • i dati relativi ad ogni prenotazione e soggiorno (data di arrivo e partenza, strutture, tipologia di unità di alloggio)
  • i dati raccolti durante il soggiorno (per esempio struttura, numeroità durante il soggiorno, modalità di viaggio, preferenze di alloggio, preferenze di destinazione, consumo e similari)
  • i dati raccolti completando il questionario di soddisfazione
  • i dati relativi all’affiliazione stessa (numero identificativo della tessera di affiliazione, numero di punti totali, numero di punti utilizzati, livello di affiliazione, modalità di utilizzo dei punti, utilizzo di benefici, lingua di comunicazione, titolo, tutti i dati che compila, aggiornando il Suo profilo nell’account utente tra cui: interessi, modalità di viaggio, animali da compagnia, struttura di alloggio desiderata, categoria di struttura di alloggio desiderata, destinazione desiderata, collegamento con i social network).

Tutte queste categorie di dati personali vengono considerate importanti e previste in quanto le utilizziamo per poter adempiere ai nostri impegni assunti con il programma fedeltà (per esempio, la data di nascita è importante per l’eventuale invio di informazioni circa i benefici di cui godere nel giorno del Suo compleanno, sotto forma di sconti e similari), proporre altri prodotti e informarLa sugli eventi che secondo noi potrebbero essere di Suo interesse.

L’affiliato non è obbligato a fornire tutti i dati citati, senza alcuna conseguenza sull’affiliazione, ma ciò nonostante alcuni dati personali sono indispensabili per l’affiliazione e per avere diritto ad alcuni benefici, per es.: nome, cognome, dati sui soggiorni in base ai quali sono raccolti i punti e similari. Inoltre, se ci dovessero mancare alcuni dati, è possibile che le newsletter che Le invieremo risponderanno in misura minore ai Suoi interessi, per esempio: se non abbiamo a disposizione dati circa la sua passione per il ciclismo, ciò non avrà alcuna conseguenza sull’affiliazione, ma non riceverà le newsletter con alcune informazioni sui benefici dedicati agli appassionati di ciclismo.

I suddetti dati vengono conservati nel database degli ospiti di Valamar per dieci anni, a partire dall’anno di affiliazione oppure dall’ultimo soggiorno presso le strutture Valamar.

Le finalità del trattamento di tali dati sono le seguenti:

  • esercizio dei diritti derivanti dall’affiliazione al Programma fedeltà;
  • invio di messaggi di servizio per fornire informazioni su stati rilevanti per l’affiliazione (saldo punti e livello di affiliazione, necessità di cambio password, novità nell’ambito del Programma fedeltà, modifiche al regolamento e similari);
  • migliore comprensione delle Sue esigenze e preferenze per poterLe inviare messaggi di marketing personalizzati con notifiche di benefici speciali, offerte speciali di nostri prodotti e servizi che potrebbero essere di Suo interesse. Può trovare maggiori informazioni in merito nella sezione MESSAGGI DI MARKETING.

In particolare, sottolineiamo che l’affiliato ha il diritto di opporsi a tale trattamento dei dati personali sia in merito al trattamento iniziale sia a quello successivo, in qualsiasi momento e gratuitamente.

L’affiliato ha la facoltà, in qualsiasi momento e senza indicarne il motivo, di interrompere la propria affiliazione inviando una notifica scritta all’indirizzo email info-loyalty@valamar.com oppure chiamando al numero di telefono +385 52 408 222.

VALAMAR EXPERIENCE CONCIERGE (VEC)

Valamar Riviera è anche un’agenzia turistica che promuove, raccomanda ma anche prenota e/o vende merce, servizi ed esperienze agli ospiti delle strutture Valamar e ad altre persone. A titolo esemplificativo ma non esaustivo: servizi wellness, noleggio di attrezzatura e terreni sportivi, posti al ristorante, gite, biglietti per concerti, servizio di trasporto, servizio di sci (congiuntamente di seguito: servizi VEC).

I servizi VEC sono acquistabili o prenotabili tramite

  • il sito Internet www.valamar-experience.com/it/ (di seguito: sito Internet VEC)
  • i punti vendita (guest relations, info desk e hospitality desk) nelle strutture Valamar
  • telefono
  • email
  • app My Valamar e Places [PLACESAPP]

In relazione al tipo di servizio VEC che desidera acquistare o prenotare, Le chiederemo di fornirci diversi dati, per esempio:

  • al momento di acquistare merce, servizi ed esperienze Le chiederemo di fornirci il Suo nome, cognome, indirizzo email, indirizzo, città, codice di avviamento postale, stato, numero di telefono cellulare
  • se richiede il servizio di navetta dall’aeroporto fino alla struttura Valamar o viceversa, oppure il servizio di navetta all’interno della Repubblica di Croazia, Le chiederemo di fornirci il Suo nome, cognome, numero di telefono cellulare, i dati relativi alla prenotazione dell’alloggio, numero e data di volo e, in caso di transfer transfrontaliero, anche la cittadinanza
  • se desidera effettuare l’acquisto di un’escursione transfrontaliera, Le chiederemo la Sua data di nascita, il tipo e il numero del documento d’identificazione
  • se desidera prenotare i servizi di sci e/o attrezzatura, Le chiederemo di fornirci nome, cognome, sesso, data di nascita, indirizzo email, numero di telefono, altezza, peso, circonferenza della testa e la misura del piede

Alcuni dei dati che ci ha fornito saranno riportati sui voucher e sulle conferme di prenotazione, laddove applicabile. La finalità del trattamento dei dati è fornire una risposta soddisfacente alla Sua richiesta, e poi la Sua identificazione, in veste di acquirente, nonché la stipula e l’espletamento del contratto e, se necessario, la possibilità di contattarLa all’indirizzo indicato. La base giuridica in primo luogo è l’adempimento agli obblighi giuridici e l’espletamento del contratto, ovvero il trattamento è indispensabile per intraprendere le attività su richiesta dell’interessato prima della stipula del contratto

Se utilizza il sito Internet VEC può creare il Suo account utente VEC. In tal caso, Le chiederemo i seguenti dati: nome, cognome, indirizzo email e password. Riceverà la notifica di registrazione per email. La finalità della creazione del profilo è consentirLe di visualizzare le Sue prenotazioni, lo storico degli acquisti, le liste desideri nonché i voucher in corso di validità o scaduti. La base giuridica per la creazione del profilo VEC è il Suo consenso. La creazione del profilo utente non rappresenta il presupposto per l’acquisto/prenotazione di servizi sul sito VEC.

In caso di chiamata telefonica, sulla base del legittimo interesse, teniamo la registrazione delle chiamate.

Se necessario, invieremo alcuni dei Suoi dati personali alle nostre società e partner che offrono determinati servizi e merce ovvero organizzano esperienze da Lei acquistate o prenotate, e in caso di consegna di merci li invieremo anche ai corrieri. In tal caso, quest’ultimi diventano i successivi titolari del trattamento perciò La invitiamo a consultare le loro Politiche della privacy.

I dati che raccogliamo durante la fornitura di servizi VEC saranno conservati per massimo cinque anni per eventuali reclami per i servizi forniti, mentre per un periodo più lungo se richiesto da specifiche leggi (contabili e similari).

In caso di compilazione di sondaggi sulla qualità delle esperienze e di pubblicazione di commenti sul sito Internet, esclusivamente con il Suo consenso, i suddetti dati vengono conservati per un anno.

Sulla base del legittimo interesse, abbiamo il diritto di raccogliere determinati dati di clienti e utilizzarli per finalità di marketing diretto come descritto nel capitolo MESSAGGI DI MARKETING.

VALFRESCO

Valfresco Direkt è il nostro sito Internet www.valfresco.com (di seguito: sito Internet Valfresco) dedicato alla fornitura di servizi e-commerce di generi alimentari e di altri prodotti e per l’ordinazione di cibo e bevande dalle strutture Valamar. Al momento dell’acquisto tramite il sito Internet Valfresco trattiamo i dati personali che ha inserito nel modulo web per il Suo account utente (nome, cognome, indirizzo email, numero di telefono, indirizzo, indirizzo di consegna) al fine di identificare l’interessato in qualità di acquirente, di stipulare ed espletare il singolo contratto di compravendita a distanza nonché al fine di contattarla per effettuare la consegna. Il contratto, ovvero l’espletamento del contratto di compravendita con l’acquirente nel ruolo di una delle parti, rappresenta la base giuridica. Inoltre, il trattamento è indispensabile per adempiere ai nostri obblighi giuridici.

Per adempiere al contratto, ma anche per adempiere ad un obbligo giuridico, ci è consentito inviare al cliente tramite email, SMS e/o tramite una piattaforma di instant messaging i cosiddetti messaggi di servizio - conferme di stipula del contratto, fatture, conferme d’ordine e altri avvisi strettamente correlati ad un acquisto concreto.

Inoltre, ad acquisto avvenuto e sulla base dell’interesse legittimo, abbiamo il diritto di inviare ai clienti questionari sulla soddisfazione tramite email, SMS e/o una piattaforma di instant messaging e chiedere loro di fornirci una valutazione del nostro servizio e dei nostri prodotti, se lo desiderano. Lo scopo primario del questionario sulla soddisfazione è raccogliere i dati sul servizio con l’interesse legittimo di migliorare i nostri servizi. Possiamo rendere anonimi i dati del sondaggio e trattarli a scopo statistico per finalità proprie di analisi dell’attività aziendale e miglioramento del servizio.

Con la chiamata al numero di telefono del negozio online possiamo raccogliere dati relativi alla tipologia di chiamata, per esempio se si tratta di un acquisto fatto raccoglieremo il nome, il cognome, il numero di ordine per poter rispondere alla richiesta. Inoltre, sulla base del legittimo interesse, teniamo la registrazione delle chiamate.

Sulla base del legittimo interesse, abbiamo il diritto di raccogliere determinati dati di clienti e utilizzarli per finalità di marketing diretto come descritto nel capitolo MESSAGGI DI MARKETING.

GIOCHI A PREMI E CONCORSI A PREMI

Periodicamente, Valamar Riviera può organizzare giochi e concorsi a premi e, in tal caso, raccoglierà i Suoi dati personali solo se desidera partecipare al gioco ovvero concorso a premi. I dati così raccolti, che sono indispensabili per la partecipazione al gioco/concorso a premi, saranno definiti dalle regole del gioco/concorso a premi e possono essere diversi. Sussiste anche la possibilità che i dati dei premiati ossia dei vincitori siano resi pubblici.

I dati così raccolti, sulla base di una specie di obbligo contrattuale, verranno utilizzati per lo svolgimento del gioco/concorso a premi, in conformità con le regole del gioco a premi pubblicate e verranno cancellati entro cinque anni dal termine del gioco.

Spesso si verificherà che gli ospiti che compilano il modulo per la valutazione della qualità del servizio presso le strutture Valamar abbiano la possibilità di partecipare anche al gioco a premi. Ciò sarà chiaramente indicato nel modulo stesso.

Sulla base del legittimo interesse, abbiamo il diritto di raccogliere determinati dati dei partecipanti ai nostri giochi e concorsi a premi, per finalità di marketing diretto come descritto nella sezione MESSAGGI DI MARKETING.

ANNUNCI PUBBLICI

Tramite i suoi siti Internet, i media, i profili sui social network, la rivista interna VIV (sia in formato cartaceo sia in quello elettronico), videopareti e bacheche nelle strutture, Valamar Riviera pubblica le informazioni d’interesse per dipendenti, ospiti, soci d’affari, sia attuali sia potenziali, quindi per il pubblico. Tali pubblicazioni possono contenere un numero limitato di dati personali tra cui nome e cognome, posizione, dati professionali, video, dichiarazioni e fotografie.

La base giuridica per il trattamento è l’interesse legittimo di informare il pubblico, oltre alle finalità di marketing. Durante il trattamento viene sempre posta l’attenzione sull’interesse degli interessati per cui non vengono pubblicati i dati personali se viene stabilito che l’interesse degli interessati di evitare la pubblicazione di determinati dati personali prevale sugli interessi di Valamar Riviera per la pubblicazione dei medesimi. In alcune situazioni, la pubblicazione di informazioni può basarsi sul consenso in conformità con i più alti standard.

Le pubblicazioni sono di carattere permanente per assicurare l’informazione su eventi attuali come pure la visualizzazione delle attività precedenti.

Il trattamento cesserà se, sulla base dell’opposizione dell’interessato, viene stabilito che tale opposizione è giustificata oppure se l’interessato ha revocato il consenso nelle situazioni in cui è applicabile, e precisamente nelle modalità di esecuzione previste.

MESSAGGI DI MARKETING (NEWSLETTER)

È nostro interesse trattare i dati personali a scopo di marketing diretto per l’invio di messaggi di marketing, a tal fine Valamar si avvale di modalità diverse:

  • email marketing (inclusi gli sms e/o piattaforme di instant messaging, tipo viber, whatsapp e similari) che implica l’invio di messaggi di marketing (newsletter)
  • i cosiddetti messaggi/notifiche push sul web e sull’app mobile (messaggi brevi e semplici che vengono inviati dal browser o dall’app al Suo dispositivo)
  • remarketing che consente la visualizzazione dell’annuncio agli utenti che in precedenza hanno visitato uno dei siti Internet di Valamar oppure di app mobili. Maggiori informazioni in merito sono disponibili nella Politica dei cookie disponibile in tutti i siti Internet.

Basi giuridiche per il trattamento dei dati personali a scopi di marketing diretto sono le seguenti:

INTERESSE LEGITTIMO nel caso di un rapporto rilevante e pertinente tra l’interessato e Valamar, ai sensi del punto 70 delle disposizioni preliminari del Regolamento, e precisamente:

per le newsletter di base (messaggi) che vengono inviate a determinate categorie di interessati come per esempio

  • agli ospiti di strutture Valamar che hanno,
  • richiesto un’offerta e/o prenotato un alloggio,
  • partecipato ad un gioco a premi,
  • compilato il questionario sulla, soddisfazione
  • compilato il modulo di registrazione nelle strutture per avere il Wi-Fi gratuito,
  • effettuato un acquisto nel negozio online

per le newsletter (messaggi) studiate appositamente per Lei che vengono inviate soltanto ai nostri membri loyalty

CONSENSO per:

  • newsletter di base (messaggi)
  • le newsletter (messaggi) studiate appositamente per Lei che vengono inviate soltanto agli interessati che hanno fornito il loro esplicito consenso per tali offerte (e allo stesso tempo non sono membri loyalty)
  • messaggi/notifiche push
  • dati aggiuntivi quando sono gli stessi interessati, al momento dell’aggiornamento del profilo sui siti Internet, a fornire autonomamente dati aggiuntivi,
  • remarketing dando il consenso all’utilizzo di cookie. In particolare sottolineiamo che in alcuni casi, oltre ai dati ricevuti da cookie e pixel per i quali viene fornito l’apposito consenso, vi è la possibilità di utilizzare i dati degli interessati dal database esistente di Valamar (per esempio dati sulle persone che hanno usufruito di un determinato alloggio). In alcuni casi di remarketing, con il Suo consenso, i dati, se necessario, vengono trasferiti in paesi terzi extra UE in cui potrebbe essere richiesto un livello diverso di protezione.

Le newsletter di base (messaggi) inviate sulla base del legittimo interesse vengono inviate solo agli interessati che hanno qualche rapporto con Valamar ovvero con le strutture Valamar. I dati trattati sono nome e cognome, email, numero di cellulare, indirizzo, sesso, stato/lingua di comunicazione e i dati fondamentali relativi al rapporto concreto con Valamar Riviera (per esempio: struttura, destinazione dove alloggia, dati sull’acquisto effettuato, sull’esperienza acquistata e similari). Tutte queste categorie di dati personali sono ritenute importanti in quanto consentono la creazione ragionata di newsletter in linea con gli interessi degli interessati.

Le newsletter di base (messaggi) inviate sulla base del consenso prevedono che il consenso venga fornito con la sottoscrizione alla newsletter. La sottoscrizione alla newsletter avviene attraverso un modulo da compilare online disponibile in alcuni dei nostri siti Internet. Per assicurarsi che al momento dell’inserimento dell’indirizzo email non si sia verificato un errore oppure un abuso, utilizziamo il cosiddetto processo di doppio Opt-in (doppia verifica): dopo l’inserimento dell’indirizzo email nella casella di sottoscrizione, Valamar Riviera invia al medesimo indirizzo il link di conferma. Solo dopo aver cliccato sul link di conferma, il Suo indirizzo email viene aggiunto nel database per l’invio di una determinata newsletter. Tali newsletter vengono inviate sulla base del consenso che Lei ci fornisce compilando e confermando il modulo sui siti Internet. Il contenuto della newsletter e lo scopo saranno citati al momento della Sua sottoscrizione (per esempio: notifiche sulle attuali offerte speciali nelle nostre strutture, offerte per posti di lavoro e similari). Se ha aggiornato il profilo e fornito altri dati, anche quest’ultimi saranno trattati.

I messaggi (newsletter) personalizzati per Lei sono messaggi che vengono inviati a tutti i membri loyalty come pure alle persone che hanno fornito l’apposito consenso per questo tipo di messaggi. Per l’invio di messaggi personalizzati per Lei, Valamar fa uso di questionari di profilazione con lo scopo di contattarLa e di inviarLe notifiche sulle offerte personalizzate. Per queste newsletter viene trattato un ampio raggio di dati personali che può includere: nome e cognome, indirizzo email, numero di cellulare, indirizzo, città, stato, codice di avviamento postale, sesso, lingua di comunicazione, titolo, data di nascita, anniversario di matrimonio, stato civile, numero ed età di figli, interessi (per esempio immersioni subacquee, ciclismo e similari), dati sulle richieste di offerte, prenotazioni e permanenze (destinazione, struttura, tipologia di unità di alloggio, data di arrivo e di partenza, numero di bambini), animali da compagnia, interessi, modalità di viaggio, destinazioni preferite, connessione alle reti sociali, dati sull’acquisto fatto sulle pagine Internet di Valamar, sull’esperienza acquistata, dati raccolti grazie alla compilazione del questionario sulla soddisfazione riguardo l’affiliazione loyalty, che comprende i dati raccolti al momento della compilazione del modulo di adesione al programma fedeltà e quelli relativi allo status dell’affiliato (numero identificativo della tessera di affiliazione, numero di punti, numero di punti utilizzati, livello di affiliazione, modalità di utilizzo di punti, utilizzo di benefici, dati legati all’attività nell’ambito del programma Ambasador).

La profilazione ha come unica conseguenza quella di ideare al meglio messaggi e offerte che rispondano ai Suoi interessi. In mancanza di tali dati è probabile che le newsletter che riceverà da parte nostra rispondano in misura minore ai Suoi interessi, per esempio se non disponiamo del dato circa il Suo interesse per il ciclismo, non riceverà le newsletter con alcune informazioni in merito ai benefici riservati agli appassionati di ciclismo.

Il termine per il trattamento dei dati personali al fine dell’invio di newsletter è pari a 10 anni a decorrere:

  • dal giorno dell’ultima permanenza ovvero di un altro tipo di rapporto d’affari con noi, quando l’invio delle newsletter è basato sul legittimo interesse,
  • dal giorno del Suo consenso, quando l’invio delle newsletter è basato sul Suo consenso.

Può succedere che in casi specifici utilizziamo anche i servizi di piattaforme di campaign management (per esempio Oracle Responsys) per la gestione multicanale di campagne che consente la creazione di messaggi personalizzati sulla base di singoli interessi e preferenze degli ospiti e di potenziali clienti. In questi casi si tratta di un trattamento automatizzato di dati e con questi partner stipuliamo appositi contratti.

Il termine per il trattamento dei dati che vengono raccolti utilizzando i cookie, dipende dal tipo di cookie e sono descritti su tutti i siti Internet che ne fanno uso.

In tutti i casi, quando l’interessato ha dato il proprio consenso, avrà il diritto di revocarlo in qualsiasi momento e in ogni istante, gratuitamente e senza fornire spiegazioni. La revoca del consenso non pregiudica la liceità del trattamento basata sul consenso prima della revoca.

In tutti i casi in cui il trattamento si basa sull’interesse legittimo, gli interessati hanno diritto all’opposizione, in qualsiasi momento, gratuitamente e senza fornire spiegazioni.

La revoca del consenso come pure l’opposizione possono essere inviati al seguente indirizzo email newsletter@valamar.com .

In ogni momento, gratuitamente e senza spiegazioni, e indipendentemente dalla base giuridica per la ricezione dei messaggi di marketing (newsletter), può annullare la sottoscrizione a qualsiasi newsletter cliccando sul link in fondo a tutte le newsletter, ovvero bloccando il mittente in conformità con le regole dei canali on-line che utilizza. In tal caso non riceverà più le newsletter ma i dati resteranno archiviati.

La cancellazione dalla newsletter non è correlata al legittimo interesse di Valamar Riviera di inviare agli interessati, per i quali esiste anche un’altra base giuridica (per esempio ospiti di strutture, candidati all’assunzione), messaggi di servizio e questionari sulla soddisfazione che riguardano un soggiorno in concreto, un’esperienza acquistata e similari, oltre ad altri messaggi di servizio.

La revoca del consenso fornito per l’utilizzo di cookie può essere fatta in qualsiasi momento, senza fornire spiegazioni e gratuitamente, ed è descritta nella Politica dei cookie.

MESSAGGI DI SERVIZIO E QUESTIONARI SULLA SODDISFAZIONE

I messaggi di servizio sono messaggi che possiamo inviare tramite email, SMS, messaggi push dell’app mobile e/o tramite la piattaforma di instant messaging (Viber, Whatsapp e similari), sono legati a un determinato rapporto che abbiamo con Lei e vengono inviati sulla base dell’interesse legittimo, ovvero del consenso quando lo richiediamo, per esempio:

  • prima, durante e dopo il soggiorno nelle strutture Valamar possiamo inviare messaggi di conferma di prenotazione, promemoria del soggiorno e altri avvisi strettamente legati ad un soggiorno specifico che ha prenotato.
  • al momento dell’acquisto/prenotazione di merce, servizi o esperienze in una delle nostre pagine Internet, possiamo inviare messaggi di conferma di stipula del contratto, fatture, conferme d’ordine, voucher e altri avvisi strettamente legati ad un determinato acquisto o prenotazione.

Inviamo i questionari sulla soddisfazione che sono correlati ad un determinato rapporto in essere con Lei, sulla base del legittimo interesse, per esempio:

  • durante e dopo il soggiorno nelle strutture Valamar abbiamo la facoltà di inviare questionari sulla soddisfazione riguardo il servizio fornito nelle strutture Valamar,
  • dopo l’avvenuto acquisto/prenotazione di merce, servizi o esperienze che ha acquistato tramite i nostri canali di vendita, ci è concesso inviarLe i sondaggi sulla soddisfazione del servizio fornito ovvero della merce acquistata.

Lo scopo primario del questionario sulla soddisfazione è raccogliere i dati per il legittimo interesse di migliorare il servizio. È possibile che siamo noi a trattare i dati oppure che ci appoggiamo a collaboratori.

I messaggi di servizio e i messaggi con i questionari sulla soddisfazione non sono considerati messaggi di marketing. Inoltre, sottolineiamo che, nel caso ci abbia chiesto di non inviarLe messaggi di marketing, e in seguito abbia prenotato un alloggio, è possibile che riceva messaggi di servizio e i questionari sulla soddisfazione.

In ogni caso, quando Le inviamo messaggi sulla base del legittimo interesse, ha diritto all’opposizione.

SITI INTERNET

Per fornirLe il miglior servizio possibile e per consentirLe un accesso più rapido e più semplice con i contenuti di Suo interesse, disponiamo di più siti Internet tra cui evidenziamo: www.valamar-riviera.com, www.valamar.com/it/, www.valamarcamping.com/it/, www.places-hotels.com/hr/, www.valamarlovesbike.com, www.blog.valamar.com, www.maroworld.valamar.com, www.valamar-experience.com/it/, www.dobarposaouvalamaru.com, www.valfresco.com. La presente Politica della privacy si riferisce ai nostri siti Internet con tutti i sottodomini.

Dai visitatori dei nostri siti Internet possiamo raccogliere i dati personali utilizzati agli scopi per i quali sono stati raccolti, il tutto in conformità con le informazioni riportate al momento della raccolta (oppure con la finalità evidente che può derivare dal contesto di raccolta). Gli utenti hanno il controllo sui dati personali che inseriscono nei moduli sul web. Per esempio, su alcuni dei nostri siti Internet ha la possibilità di effettuare la sottoscrizione alle nostre newsletter per ricevere informazioni o offerte. Inoltre, in alcuni siti Internet ha la possibilità di prenotare un alloggio, acquistare un’escursione e merce, fare domanda di assunzione, registrarsi a diversi eventi e similari. In ogni caso, i dati di cui necessitiamo per assolvere allo scopo di ogni singolo caso ci vengono forniti da Lei. Le informazioni sul trattamento dei dati personali sono disponibili anche su tutti i siti Internet dove vengono raccolti i dati.

Sui nostri siti Internet possiamo utilizzare una vasta gamma di strumenti nuovi al fine di migliorare l’esperienza utente utilizzando i cookie e diverse modalità di tracciamento di visitatori, per esempio Google ads, META ads, Dynamic Yield, Google Analytics, Hotjar e altri. Utilizziamo anche la piattaforma Usercentrics Consent Management Plattform per la gestione dei consensi per l’utilizzo di cookie. La invitiamo a leggere maggiori dettagli sui cookie e altre tecnologie nella nostra Politica dei cookie disponibile su tutti i nostri siti Internet.

Na svojim internetskim stranicama možemo koristiti i širok spektar novih alata u svrhu poboljšanja korisničkog iskustva i pritom upotrebljavamo kolačiće i različite druge načine praćenja posjetitelja, primjerice Google ads, META ads, Dynamic Yield, Google Analytics, Hotjar i druge. Koristimo i platformu za upravljanje privolama za kolačiće Usercentrics Consent Management Plattform. Više o kolačićima i drugim tehnologijama molimo da pročitate u našoj Politici kolačića koja se nalazi na svakoj našoj internetskoj stranici.

La base giuridica per il trattamento dei dati personali dei visitatori dei nostri siti Internet è il legittimo interesse, l’espletamento del contratto o il consenso se viene richiesto all’interessato.

I visitatori godono di tutti i diritti descritti nella sezione DIRITTI DEGLI INTERESSATI.

La presente Politica della privacy non copre le modalità di gestione di informazioni da parte di altre società e organizzazioni che, in alcuni casi, sono collegate ai nostri siti Internet, e che possono utilizzare i cookie e altre tecnologie per cui La invitiamo a consultare le loro regole di riservatezza e condizioni commerciali. Inoltre, la raccolta dei dati sui siti Internet aperti per eventi dove appariamo soltanto come sponsor, partner e similari, non è sotto la nostra responsabilità.

APP MOBILI

Disponiamo delle app mobili MyValamar e PLACES per rendere i nostri servizi più facilmente disponibili agli utenti.

Siccome è possibile utilizzare l’app mobile soltanto tramite Google play ovvero App store (in funzione del Suo telefono), sottolineiamo che in tal caso Google ed Apple registrano automaticamente alcuni dati tra cui: stato, lingua, età dell’utente, tipologia del dispositivo, durata dell’utilizzo dell’app, mentre noi, grazie alle nostre interfaccia con Google ed Apple, possiamo ottenere l’analisi di tali dati, ma ciò nonostante non possiamo associare tali dati ad una persona specifica. La presente Politica della privacy non si applica a Google e Apple che possiedono regole proprie sulla privacy. Maggiori dettagli su Google play sono disponibili al link https://policies.google.com/privacy, e su Apple storte https://www.apple.com/legal/privacy/data/en/app-store/ .

Al momento dell’utilizzo dell’app può condividere il dato, dunque soltanto con il consenso:

  • ho una prenotazione
  • sto già soggiornando nella struttura
  • Affiliazione al Valamar+club

In questi casi La assoceremo in qualità di utente dell’app con i dati in nostro possesso in merito a tale prenotazione e a tal punto saremo in grado di identificarla.

Tuttavia, per utilizzare l’app non è necessario inserire tale dato e può saltare tale passaggio e visualizzare le nostre pubblicazioni.

Può anche registrarsi al programma fedeltà di Valamar, e in tal caso la preghiamo di fare riferimento alla sezione AFFILIAZIONE AL PROGRAMMA FEDELTÀ.

Se desidera prenotare il soggiorno, verrà reindirizzato/a sul sito Internet Valamar appropriato.

Se ci consente di inviarLe notifiche, i cosiddetti messaggi push, dunque solo previo consenso, potremmo inviarLe anche messaggi di servizio e messaggi promozionali.

SOCIAL NETWORK

Per poter comunicare al meglio con gli utenti di social network e di piattaforme di streaming e per informarli delle nostre offerte, abbiamo profili/pagine sui seguenti social network: Facebook, Instagram, YouTube, Pinterest, Tik Tok e Spotify (congiuntamente di seguito: social network).

Utilizzando i social network accetta le nostre regole tra cui anche quelle che riguardano il trattamento dei dati personali, La invitiamo perciò a prendere visione delle medesime. L’utilizzo dei social network e delle loro funzioni è sotto la Sua responsabilità. Sottolineiamo che ad ogni interazione sui nostri social network come pure su altri profili, la rete registra il Suo comportamento utilizzando i cookie e altri tipi di tecnologia, ovvero la tipologia, l’ambito e le finalità del trattamento dei dati sui social network sono principalmente stabiliti dagli operatori di tali reti.

Di conseguenza, alcuni dati come per esempio il numero totale di visitatori o di visite del sito, le attività sul sito e i dati lasciati dai visitatori, le interazioni (per esempio i commenti, la condivisione, la valutazione), vengono trattati e ci vengono inviati dai social network. Non possiamo influire sulla creazione e sulla visualizzazione di tali dati.

Possiamo trattare i dati personali che riguardano le Sue attività utente sui social network ai fini di marketing esclusivamente con il Suo consenso all’utilizzo di cookie fornito da Lei sui nostri siti Internet. Può verificare con precisione di quali cookie si tratta e le loro finalità nelle impostazioni dei cookie per ognuno dei siti Internet. Maggiori informazioni sui cookie sono disponibili nella Politica dei cookie.

Inoltre, raccogliamo i dati ai fini statistici per l’ulteriore sviluppo e ottimizzazione dei contenuti e una formulazione più interessante delle nostre offerte. Ciò si riferisce in modo particolare all’uso delle funzioni interattive.

Per una migliore gestione dei social network ci avvaliamo anche dei servizi di partner con cui abbiamo stipulato appositi contratti.

Se per caso volessimo utilizzare uno dei Suoi commenti o una fotografia che ha pubblicato sul nostro profilo, chiederemo il Suo consenso.

Se è iscritto/a a un social network e non desidera che tale rete raccolga i dati su di Lei attraverso le nostre pagine su tale rete e che li associ con i Suoi dati di affiliazione che sono archiviati nel relativo social network,

  • prima di visitare la nostra pagina su tale social network, si disconnetta dalla stessa,
  • cancelli i cookie dal Suo computer,
  • chiuda il browser e lo riavvii.

Dopo un nuovo accesso, Lei è nuovamente riconoscibile per la rete come un determinato utente.

Non avendo l’accesso completo ai suoi dati personali sui social network, se desidera esercitare i Suoi diritti, si rivolga direttamente ai fornitori di servizi del social network perché ognuno di essi ha accesso ai dati personali dei suoi utenti ed è in grado di attuare le misure adeguate e a fornire informazioni.

Siccome ci avvaliamo dei servizi di social network che non operano sul territorio dell’Unione europea, siamo tenuti ad informarLa che le parti terze che gestiscono i social network possono trasferire il Suoi dati negli USA.

Di seguito riportiamo i link delle informative sulla privacy delle società che gestiscono i social network:
Facebook e (Meta Platforms Inc.) https://www.facebook.com/privacy/policy/
Instagram (Meta Platforms Inc.) https://privacycenter.instagram.com/policy/
Youtube (Google LLC) https://policies.google.com/privacy?hl=it
TikTok (TikTok Ireland, TikTok UK) https://www.tiktok.com/legal/page/eea/privacy-policy/en
Pinterest (Pinterest Europe Ltd. e Pinterest, Inc.) https://policy.pinterest.com/hr/privacy-policy
Spotify (Spotify AB) https://www.spotify.com/at/legal/privacy-policy/

CANDIDATI ALL’ASSUNZIONE E DIPENDENTI

Questa parte della Politica della privacy regola la protezione dei dati personali in primo luogo nelle procedure che riguardano l’assunzione, lo sviluppo e la formazione. In tal senso gli interessati sono in primo luogo dipendenti attuali ed ex dipendenti, persone in cerca di impiego, tirocinanti (alunni con alternanza scuola lavoro), persone che svolgono l’aggiornamento professionale, studenti che lavorano sulla base del cosiddetto contratto studentesco, alunni con borse di studio che lavorano sulla base del cosiddetto contratto degli alunni, lavoratori interinali e lavoratori ceduti, ed altre persone i cui dati vengono trattati nell’ambito del diritto del lavoro e dei rapporti connessi.

Nell’ambito del trattamenti dei dati che vengono svolti in relazione all’assunzione, abbiamo identificato le seguenti finalità di trattamento:

  • Selezione del personale: comprende la raccolta e il conseguente trattamento di documenti pertinenti i candidati che concorrono al posto di lavoro, lo svolgimento di test (con eventuali test psicologici on-line) e la valutazione, la raccolta e l’analisi delle informazioni sui candidati da fonti pubblicamente accessibili, incluse le informazioni che il candidato ha pubblicato autonomamente e che lo riguardano solo se questo è reso necessario a causa dei rischi che un determinato incarico lavorativo implica. La base giuridica è l’esecuzione di azioni preventive per la conclusione del contratto nonché il consenso.
  • Riduzione del rischio reputazionale: la raccolta e l’analisi delle informazioni riguardo i dipendenti e le persone in rapporti analoghi da fonti pubblicamente accessibili, incluse le informazioni pubblicate autonomamente dallo stesso interessato, solo se ciò è importante a causa del rischio che un determinato incarico lavorativo implica. La base giuridica è il legittimo interesse.
  • Stipula del contratto ed espletamento del contratto: il trattamento a scopo di stipula del contratto di lavoro, del contratto studentesco, dell’alternanza scuola lavoro (praticantato) oppure della formazione professionale, del contratto di borsa di studio con persone che non hanno un rapporto d’impiego oppure qualsiasi altro rapporto analogo. La base giuridica è anche l’adempimento degli obblighi giuridici per intraprendere le attività su richiesta dell’interessato prima della stipula del contratto come pure l’espletamento del contratto.
  • La tenuta dei registri di dipendenti, di persone in rapporti analoghi o di altre persone (per esempio bambini, coniugi oppure beneficiari di assicurazioni). La base giuridica è l’adempimento degli obblighi giuridici.
  • Il conteggio e il pagamento degli stipendi e l’esercizio di diritti materiali e di altri diritti: il trattamento è indispensabile per poter esercitare i diritti materiali ed altri diritti quali per esempio la realizzazione del diritto di adesione alle misure di politica attiva del lavoro (lavoratori stagionali fissi ed altri), la realizzazione di diritti supplementari dei dipendenti sulla base del contratto collettivo (per esempio: la nascita di un figlio) e quant’altro. La base giuridica è l’adempimento degli obblighi giuridici.
  • Registrazione dell’alloggio: il trattamento dei dati è indispensabile quando gli interessati soggiornano nelle strutture adibite ad ospitare i dipendenti al fine dare notifica della loro permanenza alle autorità competenti. La base giuridica è l’adempimento degli obblighi giuridici.
  • Gestione delle prestazioni: questa finalità comprende anche le informazioni sulla realizzazione di obiettivi stabiliti in precedenza, gli obiettivi tempestivamente raggiunti e l’ulteriore analisi con lo scopo di stabilire obiettivi futuri, di gestire le risorse umane, stabilire gli importi di premi ed altre misure pertinenti. La base giuridica è il legittimo interesse.
  • Remunerazioni: il trattamento comprende le remunerazioni ovvero i pagamenti di retribuzioni per cui tale trattamento può comprendere anche i dati sulle violazioni delle norme etiche e di altre regole interne, i dati dal sistema di gestione delle prestazioni, i dati sui corsi di formazione eseguiti, oltre a tutti gli altri dati pertinenti. La base giuridica è il legittimo interesse.
  • Formazione: il trattamento ai fini formativi dei dipendenti e delle persone in rapporti analoghi, incluso il riferimento alla formazione obbligatoria e a quella facoltativa, le verifiche delle conoscenze, incluse tutte le attività necessarie per l’analisi di conoscenze acquisite e tutte le altre informazioni pertinenti per l’organizzazione, esecuzione e ulteriore implementazione della formazione. La base giuridica è il legittimo interesse e il consenso, qualora richiesto.
  • Elaborazione di varie relazioni sui dipendenti: La base giuridica può essere l’espletamento di obblighi giuridici, ma anche il legittimo interesse (per esempio al momento dell’elaborazione di piani per periodi futuri e similari).
  • Istruzioni riguardo il lavoro e l’informazione: la raccolta e il trattamento di dati ai fini di un’informazione di qualità e tempestiva sulle posizioni aperte e sui concorsi, ovvero sulle possibilità di assunzione. La raccolta e il trattamento dei dati di tutti i dipendenti, di persone in rapporto analogo ai fini di un’informazione di qualità e tempestiva: sulle istruzioni relative all’esecuzione dell’obbligo lavorativo (per esempio: orario lavorativo, le segnalazioni sugli attacchi degli hacker e similari), le informazioni riguardo la formazione obbligatoria e quella facoltativa, le informazioni sull’esercizio dei diritti derivanti dal rapporto di lavorole informazioni sui benefici per i dipendenti, le informazioni sulla nostra gestione d’affari, su dipendenti, premi, attività chiave e iniziative, altre informazioni riguardo il rapporto di lavoro. A tal fine, e per un’informazione più rapida e migliore, possiamo inviare le informazioni tramite SMS, email e/o tramite le piattaforme di messaggistica istantanea (Viber, Whatsapp e similari), nonché tramite apposite applicazioni (che i dipendenti installano sui propri dispositivi mobili). La base giuridica è l’espletamento del contratto, l’interesse legittimo e il consenso, qualora richiesto.
  • Vantaggi per i dipendenti: Possiamo decidere di introdurre l’utilizzo di diversi strumenti al fine di realizzare diversi vantaggi per esempio fornire ai dipendenti tessere identificative per usufruire di sconti nelle strutture Valamar o in quelle dei nostri partner. La base giuridica è il legittimo interesse.
  • Protezione dei beni e delle persone: comprendono la registrazione di ingressi/uscite dai locali di lavoro, la possibilità di registrare e controllare l’utilizzo di dispositivi mobili aziendali, di apparecchiature informatiche, del traffico Internet e telefonico, di veicoli aziendali, locali e altri beni di nostra proprietà. La base giuridica è il legittimo interesse.
  • Cessazione del rapporto di lavoro: il trattamento dei dati per cessazione del contratto di lavoro o altro contratto analogo. La base giuridica è l’espletamento di obblighi giuridici e contrattuali.
  • Monitoraggio del comportamento etico: il trattamento comprende tutti gli approfondimenti riguardo il rispetto delle regole di comportamento etico o di regole che riguardano la tutela della dignità, ovvero quelle che rientrano in qualsivoglia azione disciplinare, indipendentemente se l’interessato è persona notificata o notificante. La base giuridica è l’interesse legittimo, mentre in alcuni casi è anche il nostro obbligo giuridico.
  • Sicurezza sul lavoro: il trattamento dei dati potrebbe rendersi necessario nei casi in cui risulta indispensabile per adempiere a disposizioni speciali in materia di sicurezza sul lavoro, inclusi gli alcol test, ai sensi della legge. La base giuridica è l’interesse legittimo, mentre in alcuni casi è anche il nostro obbligo giuridico.

In aggiunta alle suddette finalità, il trattamento dei dati personali è possibile anche a fini specifici diversi, tuttavia sempre nell’ambito stabilito dalla legge oppure qualora il trattamento sia reso necessario ai fini di esercitare i diritti e i doveri derivanti dal rapporto di lavoro, ovvero riguardanti il rapporto di lavoro e qualsiasi altro rapporto analogo.

Selezione del personale

Raccogliamo, trattiamo e conserviamo i dati dei candidati all’impiego nel registro dei candidati sulla base della loro iscrizione volontaria:

  • iscrizione dei candidati tramite il modulo d’iscrizione Internet sul sito www.dobarposaouvalamaru.com che funge a suo modo da curriculum vitae (CV)
  • iscrizione tramite messaggio di posta elettronica
  • mediante partecipazione alle audizioni organizzate e compilando i moduli d’iscrizione
  • in altre modalità.

I dati che di norma vengono raccolti sono: nome, cognome, data di nascita, indirizzo, cittadinanza, N° id. personale (OIB per i cittadini croati essendo il dato più affidabile per individuare i candidati), numero di telefono, indirizzo email (per essere contattato/a), sesso, titolo di studio, lingua, modalità preferita di comunicazione.

Di regola, riceviamo i dati dei candidati direttamente da loro, ma potremmo riceverli anche indirettamente, da agenzie interinali nazionali ed estere e, in tal caso, sono proprio queste ad avere l’obbligo di informare i candidati sul trattamento dei loro dati personali da parte nostra.

I candidati inviano le loro candidature:

  • come domande d’impiego aperte e in tal caso trattiamo i dati per contattare il candidato in merito all’assunzione per tre anni (se la persona non viene assunta da noi);
  • come domande d’impiego per un concorso specifico il cui termine di chiusura è indicato e, in tal caso, trattiamo i dati per la durata del concorso e per ulteriori cinque mesi dalla chiusura del concorso al fine di contattare il candidato in merito all’impiego. Tali domande vengono archiviate per un periodo di tre anni. Se i candidati che partecipano a un concorso specifico con indicato il termine di chiusura danno il consenso specifico, trattiamo i dati per poter contattare i candidati in merito all’impiego, per tre anni, allo stesso modo delle domande aperte (se la persona non viene assunta da noi).

Abbiamo il legittimo interesse di utilizzare gli indirizzi email privati, ma anche gli altri dati di contatto che ci sono stati forniti per contattare il candidato in merito all’assunzione. Per esempio, dopo l’iscrizione, i candidati possono ricevere una risposta automatica a conferma di ricezione della loro iscrizione e per avvisarli che saranno contattati i candidati in possesso delle qualifiche e dell’esperienza conformi a quelle richieste per determinati posti di lavoro. Inoltre, dopo l’iscrizione, i candidati possono ricevere un messaggio al loro numero di telefono con una proposta di colloquio, un messaggio in cui è citata la documentazione necessaria per l’assunzione e similari. In aggiunta, abbiamo il legittimo interesse di contattare le persone che erano state assunte a tempo determinato, in prevalenza per lavori stagionali, al fine di informarle e fornire loro informazioni importanti per la gestione operativa e le attività fondamentali presso la nostra società e presso quelle da noi gestite, il tutto per restare in contatto, al fine di un’eventuale collaborazione futura.

In ogni momento è libero/a di cancellarsi gratuitamente dalla sottoscrizione alla ricezione dei nostri aggiornamenti riguardo le assunzioni, inviando un messaggio di posta elettronica all’indirizzo ljudski.potencijali@valamar.com.

I dati che vengono conservati sono forniti dagli stessi candidati, anche se pure noi, sulla base del legittimo interesse per assicurarci i candidati migliori, generiamo i dati personali che riguardano le questioni relative alle assunzioni, tra cui i risultati dei colloqui di lavoro, l’esecuzione di test (incluso il test psicologico online) e le valutazioni. Inoltre, raccogliamo i dati anche da terzi, in primo luogo verificando i dati ricevuti durante il processo di reclutamento contattando le parti terze pertinenti (per esempio: le agenzie interinali, i fornitori di servizi di istruzione o di formazione) oppure utilizzando le fonti accessibili pubblicamente.

Rapporto di lavoro e altri rapporti analoghi

Noi, in veste di datore di lavoro, raccogliamo, trattiamo e conserviamo tutti i dati dei dipendenti nel registro dei dipendenti che è presente nel programma informatico e nei dossier fisici dei dipendenti. I dati che vengono raccolti sono presenti nel Regolamento sul contenuto e sulla modalità di tenuta del registro dei dipendenti, pubblicato dal ministero competente in materia di lavoro e di politiche sociali.

I dati necessari per la costituzione del rapporto di lavoro sono di regola i seguenti: fotocopia del documento d’identità, fotocopia delle coordinate del conto corrente oppure istruzioni per il pagamento dalla banca, fotocopia del conto protetto (se il dipendente ne possiede uno), N° id. personale (OIB), attestato del titolo di studio (fotocopia del diploma di maturità o di laurea), e-book: certificato di pensione (da richiedere presso il HZMO-Istituto croato per l’assicurazione pensionistica, oppure tramite il servizio e-Građani), registrazione elettronica del modulo del certificato di ritenuta d’imposta il cosiddetto modulo di ritenuta d’imposta (da richiedere presso l’Agenzia delle entrate oppure tramite il servizio e-Građani; le persone al primo impiego non in possesso di registrazione elettronica del modulo di ritenuta d’imposta per cui sono tenute a richiederne uno presso l’Agenzia delle entrate), certificato di nascita del figlio, se sotto i 15 anni. Inoltre, ai sensi della Legge sul lavoro, i dipendenti sono tenuti a far pervenire il certificato che confermi l’assenza di precedenti penali e a fornirci il consenso a che noi richiediamo, a nome loro, l’estratto dal casellario giudiziale, nel caso di assunzione per posizioni dove sono regolarmente in contatto con minorenni.

Tutti i dati dei dipendenti vengono conservati nel registro dei dipendenti in base alla data dell’inizio del rapporto di lavoro e vengono aggiornati fino alla cessazione del rapporto di lavoro. Gli stessi vengono conservati come documenti con validità permanente ai sensi delle leggi pertinenti.

Nel nostro database conserviamo i dati di altre persone con cui abbiamo rapporti analoghi a quello di lavoro e a quello di aggiornamento professionale e, precisamente dall’inizio del rapporto di lavoro. Aggiorniamo tali dati fino alla cessazione di tale rapporto e li conserviamo ai sensi delle leggi pertinenti. Un caso a parte sono i dati degli studenti che potrebbero essere minorenni e che vengono trattati con particolare attenzione. I loro dati vengono raccolti e conservati in conformità con i regolamenti speciali e su autorizzazione della scuola e dei genitori.

I dati sugli stipendi e il libro paga sono soggetti a regolamenti speciali sulla conservazione. In ogni caso, tutti i dipendenti e altre persone in rapporto commerciale analogo al rapporto di lavoro e all’aggiornamento professionale, godono degli stessi diritti degli interessati.

SOCI D’AFFARI

Nella sua gestione operativa, Valamar Riviera tratta i dati dei soci d’affari o di potenziali soci d’affari e precisamente di:

  • persone fisiche che sono, potrebbero diventare o sono state soci d’affari di Valamar Riviera, per esempio artigiani, liberi professionisti (per esempio avvocati, medici e altri), persone con cui vengono stipulati contratti per la fornitura di servizi (per esempio cantanti, pittori, fotografi e altri) e altre persone fisiche operanti in regime di imprenditoria
  • persone fisiche che in una parte della loro gestione operativa rappresentano persone giuridiche con cui Valamar Riviera ha instaurato, potrebbe instaurare oppure aveva instaurato un rapporto d’affari (per esempio persone che eseguono le consegne a nome dei propri datori di lavoro cioè di società commerciali, persone a cui vengono inviate le fatture per il loro datore di lavoro - persona giuridica, firmatari del contratto per una società commerciale rappresentata da persone che eseguono trasferimenti per la società commerciale, persone che per la propria persona giuridica organizzano congressi e similari).

Nell’ambito del trattamento dei dati degli interessati, Valamar Riviera ha identificato le seguenti finalità di trattamento:

  • Stipula del contratto: il trattamento al fine di stipula di un contratto di qualsiasi ambito della nostra attività operativa (per esempio: invio di richieste, invio di offerte speciali, ricerca dei dati circa i firmatari del contratto, invio di concorsi per persone giuridiche rappresentate dagli interessati e similari). È possibile che utilizziamo le app create per il proponente che desidera partecipare ai concorsi di Valamar e in tal caso Le sarà richiesto di registrarsi.
  • Espletamento del contratto: il trattamento dei dati è indispensabile ai fini dell’espletamento del contratto. Questo implica l’adempimento degli obblighi, il monitoraggio della loro esecuzione e la garanzia di tutte le misure rilevanti per la loro esecuzione (per esempio: per l’accordo su luogo e ora della consegna di attrezzatura in base al contratto, per l’invio di fatture e similari per i quali verranno scambiati i dati di contatto dei dipendenti tipo indirizzo email e numero di cellulare, esclusivamente al fine di espletare il contratto).
  • Informazione: la raccolta e il trattamento dei dati sono indispensabili al fine di un’informazione tempestiva e di qualità, per cui Valamar Riviera ha il diritto, sulla base del legittimo interesse, di raccogliere determinati dati e utilizzarli con finalità di marketing diretto come descritto nella sezione MESSAGGI DI MARKETING.

In aggiunta alle suddette finalità, il trattamento dei dati personali è possibile anche a fini specifici diversi, tuttavia sempre nell’ambito stabilito dalla legge oppure qualora il trattamento sia reso necessario ai fini di esercitare i diritti e i doveri derivanti dal rapporto di lavoro.

Tipi di dati personali dell’interessato che vengono raccolti:

  • nome e cognome
  • indirizzo e-mail
  • numero di telefo
  • i dati sulla posizione ricoperta per il soggetto giuridico che rappresenta (per esempio addetto alla vendita, segretaria amministrativa e similari)
  • professione quando l’interessato è una persona fisica con cui si stipula un rapporto contrattuale (per esempio: cantante, pittore, fotografo, avvocato, medico...)
  • talvolta le raccomandazioni o un breve curriculum vitae (in particolare per i consulenti)
  • dati indicati sui moduli dei vaglia cambiali in bianco, dei vaglia e della cambiale
  • numero di conto bancario (IBAN) se il socio d’affari è una persona fisica con cui si intraprende un rapporto contrattuale
  • altri dati in funzione alla natura del rapporto contrattuale.

Luoghi di raccolta dei dati personali degli interessati:

  • offerte ricevute dagli interessati per realizzare collaborazioni di lavoro
  • dati ricevuti da interessati nel contesto di vendita di prodotti/servizi o di acquisto di prodotti/servizi dal socio d’affari (per esempio: fiere, congressi e similari)
  • corrispondenza commerciale riguardo una determinata collaborazione di lavoro precedente o attuale (per esempio, corrispondenza intercorsa nell’ambito dell’espletamento del contratto)
  • dati resi pubblici (per esempio: registro del tribunale, siti Internet del partner d’affari, riviste, bollettini e similari).

In aggiunta alle suddette tipologie di dati e luoghi di raccolta, il trattamento dei dati personali è possibile anche a fini specifici diversi, tuttavia sempre nell’ambito stabilito dalla legge oppure qualora il trattamento sia reso necessario ai fini di esercitare i diritti e i doveri derivanti dal rapporto di lavoro.

VIDEO SORVEGLIANZA

Valamar Riviera, in qualità di titolare del trattamento, ha un legittimo interesse nell’adottare misure di video sorveglianza al fine di proteggere i beni e le persone, mentre, in alcuni casi (per esempio: uffici cambio valute situati alle reception delle strutture) ha anche l’obbligo giuridico di predisporre la video sorveglianza che registra tutte le persone che si muovono nel perimetro della videocamera di sorveglianza (ospiti, dipendenti, partner d’affari e altri).

Il trattamento dei dati personali dei dipendenti tramite il sistema di video sorveglianza viene effettuato anche nelle condizioni stabilite dalla legge che disciplinano la sicurezza sul lavoro.

Tutti i luoghi soggetti a video sorveglianza sono debitamente segnalati.

Siamo consapevoli che le registrazioni video contengono dati personali di tutte le persone che transitano nel perimetro della video camera per cui tali dati vengono conservati con particolare attenzione, con un sistema elaborato in termini di sicurezza e accessibilità e con una politica di cancellazione degli stessi che è disciplinata dal nostro regolamento interno sulla sicurezza.

Le video registrazioni vengono cancellate automaticamente al massimo dopo 15 giorni dalla data di registrazione. Nel caso di necessità di deroga (sovrascrizione), le registrazioni video vengono conservate al massimo per sei mesi, salvo che la legge non disponga un periodo di conservazione più lungo oppure che tali registrazioni fungano da prove in procedimenti giudiziari, amministrativi, arbitrali o altro analogo procedimento. Le video registrazioni soggette a deroga saranno archiviate nel sistema di notifica centrale con accessibilità estremamente limitata.

Nel caso di procedure giudiziarie e/o penali, possiamo utilizzare le suddette video registrazioni. L’accesso ai dati personali nelle video registrazioni è possibile anche a terzi, ai responsabili del trattamento, a nostri partner contrattuali registrati ed esperti nella fornitura di servizi per la tutela delle persone e dei beni e i quali non utilizzano in alcun modo i suddetti dati autonomamente ma curano la sicurezza dei sistemi centrali di monitoraggio e notifica. Per tutti gli altri dettagli relativi alla video sorveglianza vengono applicate apposite norme che disciplinano tale materia.

DISPOSIZIONI FINALI

La presente Politica della privacy è disponibile sui siti Internet https://valamar-riviera.com/en/gdpr-privacy-policies/, https://www.valamar.com/it/normativa-sulla-privacy, e su altri siti Internet di Valamar nonché negli uffici delle risorse umane e presso le reception delle strutture Valamar.

Viste le richieste di trasparenza, la presente Politica della privacy sarà revisionata regolarmente.

La presente Politica della privacy è stata pubblicata il giorno 1° gennaio 2024.

Helios Faros d.d. privacy policy

GENERAL PART

DATA CONTROLLER AND LEGAL FRAMEWORK

HELIOS FAROS, as the data controller, undertakes to protect your personal data. The collection and storage of data is carried out pursuant to provisions of EU Regulation 2016/679 of the European Parliament and of the Council as of April 27, 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter: Regulation), the Act on implementation of the General Data Processing Regulation (OG 42/2018) and other regulations governing the subject area, which are applicable in the Republic of Croatia.

SCOPE OF APPLICATION

This Policy applies to any processing of personal data by HELIOS FAROS as the controller, unless another HELIOS FAROS policy or other document provides otherwise for a particular processing. In some cases, HELIOS FAROS also acts as a data controller for respondents who are also respondents to companies with which HELIOS FAROS has concluded business contracts on the basis of which it manages the tourism part of its business within its powers under these contracts.

This Privacy Policy is divided into two parts: the General Part and the Special Part. The basic principles of personal data processing, contact details of personal data protection officers and other provisions set out in the General Part of the Policy apply without exception to any processing of personal data regardless of whether such processing is specifically processed in the Special Part of the Policy. The Special Part of the Policy deals in more detail with special cases of data processing, which represent the majority of all HELIOS FAROS processing.

HELIOS FAROS concluded on 16.08.2019 the Agreement with VALAMAR RIVIERA d.d. Contract in relation to the management of hotel and tourist facilities and contents on the basis of which VALAMAR RIVIERA d.d. manages certain business segments, i.e., performs certain tasks based on general powers on behalf and for HELIOS FAROS as a management company. In this sense, HELIOS FAROS and VALAMAR RIVIERA d.d. can act as joint managers of personal data of employees, guests and business partners for the purpose of managing the operational part of business, business process management and providing contracted services, providing appropriate information to employees, guests and business partners (hereinafter: access to personal data from management services).

DATA PROTECTION OFFICER

HELIOS FAROS has appointed a personal data protection officer who you can contact at any time via the following e-mail address: gdpr@heliosfaros.hr or by mail to the postal address Helios Faros d.d., Naselje Helios 21460 Stari Grad, Republic of Croatia - for DPO, for issues related to personal data protection and exercising the rights guaranteed by the Regulation.

All non-personal data protection requests submitted to the Data Protection Officer, such as offers of job candidates, inquiries for reservations at HELIOS FAROS facilities, etc., will be forwarded directly to the relevant HELIOS FAROS departments, without special replies to the sender from the data protection officer.

PRINCIPLES OF PERSONAL DATA PROTECTION

HELIOS FAROS has recognized the principles of data processing as basic values that must be respected throughout the cycle of personal data processing, from their collection to their destruction or other cessation of processing. HELIOS FAROS processes data:

  • Legally - processing will be possible if it is allowed by law, within the limits set by law.
  • Fair enough - respecting the specifics of each relationship, applying all adequate measures for protection of personal data and not preventing the respondent from exercising his rights.
  • Transparently - informing the respondents about the processing of personal data. From data collection when respondents are informed about all aspects of data processing until the end of data processing, respondents are provided with easy and fast access to their own data, which includes the ability to view and obtain a copy in accordance with the Regulation. Certain information may be restricted only when required by law or when necessary to protect third parties.
  • With purpose limitation - processing personal data for the purposes for which they were collected, and for others purposes if the conditions set out in the Regulation are met. Data may be processed for concurrent purposes only taking into account: (a) any link between the purposes of the collection of personal data and the purposes of the intended continuation of the processing; (b) the context in which personal data were collected, in particular as regards the relationship between the respondents and HELIOS FAROS; (c) the nature of personal data, in particular whether specific categories of personal data are processed in accordance with Article 9 of the Regulation or personal data relating to criminal convictions and criminal offenses in accordance with Article 10. Regulations; (d) the possible consequences of the intended continuation of processing for the respondents; and (e) the existence of appropriate safeguards.
  • With storage restriction - storing data in a form that allows the identification of respondents only for as long as necessary for the purposes for which personal data are processed, and longer only if permitted by regulations.
  • With a reduction in the amount of data - processing data if they are appropriate, relevant and limited to what is necessary. Particular care is taken not to collect data for which there is no justified need for processing.
  • Taking care of accuracy - taking into account the accuracy and timeliness of the data and deleting inaccurate data as far as possible.
  • Taking care of integrity and confidentiality- providing technical and organizational measures for adequate security of personal data, including protection against unauthorized use or illegal processing and from accidental loss, destruction or damage by the application of appropriate technical or organizational measures. Relevant measures are applied taking into account the risk of each type of data processing.

LEGALITY OF PERSONAL DATA PROCESSING

In order to respect the lawfulness of the processing of personal data, HELIOS FAROS processes personal data only if and to the extent that at least one of the following is met:

  • Processing is necessary for the execution of the contract in which the respondent is a party or to take action at the request of the respondent prior to the conclusion of the contract; this is the most common purpose of data processing of respondents where the backbone is an existing contractual relationship or a contractual relationship that is sought to be achieved. Processing is necessary to comply with the legal obligations of the data controller. HELIOS FAROS as a legal entity has a number of obligations prescribed by various regulations. This obligation includes the collection and often the provision of data to public authorities. For example, the processing of personal data of shareholders who apply for the General Assembly, the processing of personal data of participants in meetings held at the premises of HELIOS FAROS in accordance with anti-epidemic measures and the like.
  • Processing is necessary for the legitimate interests of the controller or a third party, except where those interests outweigh the interests or fundamental rights and freedoms of respondents requiring the protection of personal data, taking into account reasonable expectations of respondents based on their relationship with the controller, in particular if the respondent is a child. In applying this legal basis, HELIOS FAROS estimates that the processing is appropriate to business needs, that it is as invasive as possible and that the interests of the respondents do not outweigh the legitimate interests of HELIOS FAROS or a third party. Examples of such processing are processing for administrative purposes, the purpose of maintaining the security of computer networks, the purposes of direct marketing and improving our business. The respondent in these situations always has the right to object to such processing.
  • Processing is necessary to protect the key interests of the respondent or other natural person. The right to the protection of personal data is not an absolute right and HELIOS FAROS equates it with other fundamental rights in accordance with the principle of proportionality. HELIOS FAROS acknowledges the possibility that in some situations it is necessary to process personal data in order to protect the key interests of respondents or other natural persons.
  • The respondent consented to the processing of his personal data for one or more special purposes. When processing personal data on the basis of consent, HELIOS FAROS takes special care that these are situations in which there are no, formal or informal, consequences for granting, refusing to give or denying consent. When processing is based on consent, the respondent may withdraw consent at any time without negative consequences. Withdrawal of consent does not affect the lawfulness of processing based on consent prior to its withdrawal.

In some emergencies, HELIOS FAROS may process data that would not be processed in regular situations, such as collecting data based on the recommendations of the Croatian Institute of Public Health in the event of epidemics and the like.

TYPES OF PERSONAL DATA PROCESSED

Special categories of personal data: special categories of personal data are processed only if the conditions of Article 9 of the Regulation are met. For example, HELIOS FAROS processes employee data that fall into special categories of personal data, such as data on trade union membership (for example, when exercising special rights under relevant regulations), religious or philosophical beliefs (for example, when exercising the right to additional non-working days for religious holidays), if the individual has voluntarily disclosed such data for the stated purpose)or data related to health (for example according to special regulations on occupational safety or keeping records of workers or when special health certificates are required for certain jobs), etc.

Data on criminal convictions and criminal offenses: where there is legal authority to do so, HELIOS FAROS also processes personal data relating to criminal convictions and criminal offenses, such as certificates of impunity for workers.

Personal data that do not belong to the previous two groups: such personal data make up the largest part of the processed data, and these are most often identification and contact data such as name and surname, PIN, data generated on the basis of movement in the premises under video surveillance.

Most personal information that HELIOS FAROS is collected, provided by the respondents themselves, and please do not provide sensitive information (e.g., race or ethnic origin, political opinions, religious or philosophical beliefs, etc.) when not necessary. If you nevertheless provide sensitive information for any reason, you hereby give your express consent to the collection and use of this information in the ways described in this Policy or in the manner described at the time of disclosure of this information.

DELIVERY OF DATA TO THIRD ENTITIES

HELIOS FAROS shares personal information with others only when permitted.

As part of its legal obligations, HELIOS FAROS is obliged to provide data to third parties. For example, delivery of guest data via the eVisitor system, delivery of employee data to the competent institutions: the Croatian Pension Insurance Institute, the Croatian Health Insurance Institute, the Tax Administration and the Central Register of Insured Persons and pension companies. Also, in certain cases, HELIOS FAROS is obliged to submit or make available data related to employment to the Croatian Employment Service, for example to include workers in active employment policy measures, competent police stations or the ministry responsible for internal affairs, for example in the case of senior government officials. in HELIOS FAROS facilities, as well as for issuing work permits, to the ministry in charge of tourism in the case of employment of scholarship holders, the ministry in charge of economy and entrepreneurship when it comes to the use of investment aid, insurance companies, banks and in other cases when required by regulations.

Also, certain employee data is sent to banks or pension funds as part of payments, and data can also be sent to creditors in accordance with enforcement regulations. Sometimes data are sent with regard to contractual obligations, for example with students in practice, data are exchanged with schools, colleges.

Certain personal data are also provided to business entities for the purpose of providing specific services such as health examinations of workers (contracted occupational medicine), further, institutions that organize legally mandatory training (occupational safety, hygiene, toxicology) or audit firms in conducting statutory audit, public notaries when certifying, the Financial Agency for the purpose of obtaining business certificates, public procurement officers when HELIOS FAROS applies for public procurement tenders, further for the purposes of awarding and using official cards, official mobile devices or for the purchase of fuel.

It is possible to deliver data to business entities, executors of processing, who process data on behalf of HELIOS FAROS acting as data controller. Most often, these are HELIOS FAROS business associates who provide IT services, who keep them in their databases or have the possibility of accessing personal data until the end of processing. A detailed agreement is concluded with such entities regarding their powers and obligations in the processing of personal data, in accordance with the requirements of the Regulation.

In certain situations, it is possible for external entities together with HELIOS FAROS to jointly determine the purposes and methods of personal data processing, then these external partners and HELIOS FAROS are joint controllers. In these relations, the joint controllers shall determine in a transparent manner their responsibilities for compliance with the obligations under the Regulation, in particular with regard to the exercise of respondents' rights and their duties for compliance with processing transparency, unless responsibilities are established by law.

A special case of data delivery to third parties is the fact that HELIOS FAROS has concluded business contracts with companies on the basis of which it manages the tourism part of the business. This means that in certain cases, guests of HELIOS FAROSA can also receive from HELIOS FAROSA offers that contain information about other hotels and facilities managed by HELIOS FAROS. Also, based on entrepreneurial contracts, HELIOS FAROS has certain rights and obligations related to human resources. In these cases, HELIOS FAROS has the right to process the personal data of the respondents of these companies. All the principles from this Policy also apply to the respondents of those companies in the segments in which HELIOS FAROS was included as the data controller, however, these companies are also responsible as the controllers of their data processing of respondents.

If data is transferred to third countries as part of data processing, HELIOS FAROS ensures compliance with high standards of protection in order to comply with the highest possible standard of personal data protection, in accordance with the strict requirements of the Regulation. In this sense, when international transfers of personal data are in use, HELIOS FAROS will inform the respondent about the intention to disclose personal data to a third country or international organization and about the existence or non-existence of a European Commission decision on adequacy. Any transfer of personal data to third countries will be carried out in accordance with Chapter V of the Regulation.

DATA STORAGE TIME

Respondents' data are processed and stored in accordance with applicable legal regulations when the retention obligation is prescribed (e.g. payrolls, analytical records on salaries for which mandatory contributions are paid are kept permanently, and accounting documents based on which data are entered in the diary, the main book and auxiliary books are kept for at least eleven years), and in situations where HELIOS FAROS is authorized to determine the retention periods, the data are kept as long as necessary for the purposes for which personal data are processed taking into account the purpose of processing, legitimate interests of HELIOS FAROS and the interests of the respondents to have the data deleted.

RIGHTS OF RESPONDENTS

Regardless of the basis of data collection, respondents can exercise the following rights free of charge within the limits prescribed by the Regulation:

Right to information: the respondent has the right to be informed about the processing and its purposes. HELIOS FAROS takes care to provide all information to the respondent that is necessary to ensure fair and transparent processing taking into account the context of processing.

Right to delete („Right to oblivion“): the respondent has the right to ask HELIOS FAROS to delete personal data concerning him / her, without undue delay in accordance with the conditions set out in the Regulation. To do so, send us your request as a data controller in writing, including an electronic form of communication. Please note that the application needs to specify what exactly you want to be deleted because we may store your data on different legal grounds, for example the respondent may be both our guest and a candidate for employment. You have the right to request the deletion of personal data relating to you if one of the following conditions is met:

  • Your personal information is no longer necessary in the relationship for the purpose for which we collected or processed them
  • you have withdrawn the consent on which the processing is based even if there is no other legal basis for the processing
  • you have objected to the processing of your personal data and if there are no stronger legitimate reasons for our processing
  • personal data has been processed illegally
  • personal data must be deleted in order to comply with a legal obligation.

In some cases, it may not be possible to fully fulfil the deletion request, such as when there is a legal obligation to keep, when the legitimate interest of the data controller is stronger than the interest of the respondent, when there is an interest of the data controller to set, realize or defend legal claims.

Right of access to data: Upon the request of the respondent, HELIOS FAROS will issue him with a certificate as to whether his personal data are being processed and, if such personal data are being processed, access to personal data and purpose of processing, categories of data, potential recipients to whom personal data will be disclosed and other data in accordance with the requirements of the Regulation. The respondent is also entitled to receive a copy of the personal data being processed. Access to personal data may be restricted only in cases prescribed by law, i.e., when such restriction respects the essence of the fundamental rights and freedoms of others.

Right to correction: the respondent has the right to obtain from HELIOS FAROS, without undue delay, the correction of inaccurate personal data relating to him. Taking into account the purposes of processing, the respondent has the right to supplement incomplete personal data. To do so, send us your request as a data controller in writing, including an electronic form of communication. We note that in the request it is necessary to specify what is not accurate, complete or up-to-date and in what sense the above should be corrected and submit the necessary documentation in support of their allegations.

Right to data portability: The respondent has the right to receive personal data relating to him in a structured, commonly used and machine-readable format in accordance with the requirements of the Regulation.

Right to object: when HELIOS FAROS processes data on the basis of its legitimate interests which are stronger than the interests of the respondent, then the respondent has the right, based on his special situation, to object at any time to the processing of personal data relating to him.

Right to limit processing: the respondent has the possibility to ask HELIOS FAROSA to exercise the right to limit the processing in case he disputes the accuracy of personal data, considers the processing illegal and opposes the deletion of personal data and instead requests restriction of their use and the respondent objected to legitimate reasons of the leader processing the reasons of the respondents.

In any case, respondents also have the right to:

  • file a complaint with the Personal Data Protection Officer
  • file a complaint with the supervisory body (Personal Data Protection Agency) if they consider that their data protection rights have been violated.

Send your written request to the contact address of the Personal Data Protection Officer: katija.damijanic@heliosfaros.hr or by mail to Helios Faros d.d., Settlement Helios 21460 Stari Grad, Republic of Croatia - for DPO

HELIOS FAROS has the right to publish a form that will be used to submit the request in order to process the request as efficiently as possible.

Upon request, HELIOS FAROS shall provide information on the actions taken in relation to the exercise of the rights of the respondents without undue delay and in any case within one month from the date of receipt of the request. This period may be extended by an additional two months, as appropriate, taking into account the complexity and number of applications. HELIOS FAROS shall inform the respondent of any such extension within one month from the date of receipt of the request, together with the reasons for the postponement.

If the respondent submits the request electronically, HELIOS FAROS shall provide the information electronically, if possible, unless the respondent requests otherwise.

Respondents' requests are generally free of charge, but if respondents' requests are clearly unfounded or excessive, especially due to their frequent recurrence, HELIOS FAROS is entitled to charge a reasonable fee based on administrative costs or refuse to act on the request.

PROTECTION OF PERSONAL DATA OF CHILDREN

HELIOS FAROS advises parents and guardians to teach children (up to 18 years of age) about safe and responsible handling of personal data, especially on the Internet. HELIOS FAROS processes personal data of children only with the prior consent of parents / guardians (for example: scholarship holders, when children are guests of our facilities, visitors to Maro playrooms, etc.).

SOURCES OF PERSONAL DATA

HELIOS FAROS receives personal information most often from respondents. When providing personal information to HELIOS FAROS, in any way (booking accommodation, job application…), you guarantee that the information you provide is correct, that you are legally capable and authorized to dispose of the information and that you fully agree that HELIOS FAROS your information uses and collects in accordance with the positive regulations and terms of this Privacy Policy.

HELIOS FAROS also receives personal data from other natural and legal persons, for example: from travel agencies that forward guest data for accommodation purposes, guests who book accommodation for people with whom they will stay in facilities, employment agencies and employees . When giving personal data of other persons to HELIOS FAROS, you guarantee that the information you have provided is accurate, that you are legally capable and authorized to dispose of the given information, that respondents whose personal data you forward to HELIOS FAROS agree that HELIOS FAROS uses and collects their data in accordance with positive regulations. and the terms of this Privacy Policy.

TECHNICAL AND INTEGRATED DATA PROTECTION

As the data controller, HELIOS FAROS takes care of the highest organizational and technical standards of data protection. Therefore, taking into account the latest developments, cost of implementation and the nature, scope, context and purposes of processing, as well as risks of different levels of probability and seriousness for the rights and freedoms of individuals arising from data processing, appropriate technical and organizational measures to enable the effective application of data protection principles.

Also, HELIOS FAROS implements appropriate technical and organizational measures to ensure that only personal data necessary for each specific processing purpose are processed in an integrated manner. HELIOS FAROS applies this measure to the amount of personal data collected, the scope of their processing, the storage period and their availability. Specifically, such measures ensure that personal data are not automatically, without the intervention of an individual, available to an unlimited number of individuals.

TREATMENT OF PERSONAL DATA BREACHES

HELIOS FAROS, as the controller, ensures that in the event of a personal data breach without undue delay and, if possible, no later than 72 hours after learning of the breach, reports to the competent supervisory authority on the personal data breach, unless the personal data breach is likely to pose a risk. for the rights and freedoms of individuals.

The report submitted to the supervisory authority shall contain all information in accordance with the Regulation.

In the event of a personal data breach that is likely to pose a high risk to the rights and freedoms of individuals, HELIOS FAROS, as the controller, informs the respondent about the personal data breach without undue delay. Sometimes, in cases where the Regulation prescribes, informing respondents is not mandatory.

SPECIAL PART


STAY IN FACILITIES (hotels, apartments, camps)

The main business of HELIOS FAROS is the provision of accommodation services in hotels, apartments and camps. Therefore, HELIOS FAROS collects and processes your personal data for various purposes with the ultimate goal of providing quality accommodation and related services all according to the highest standards of tourist companies.

Your personal data, which you must provide in order to be provided with the service of HELIOS FAROS, as the data controller, keeps in its database for the purpose of fulfilling the accommodation contract and fulfilling the legal obligations related to the catering business. In case you do not provide HELIOS FAROS with the minimum data required for booking accommodation and during the registration stay with all competent registries, HELIOS FAROS will not be able to provide you with accommodation booking services or accommodation services in accordance with the contract and law.

Certain information is necessary in order to take action at the request of the respondent before concluding the accommodation contract. For example, before booking accommodation, at the request of potential guests, offers for accommodation are sent, for the creation of which HELIOS FAROS needs personal data, at least the name, surname and e-mail address in order to send an offer.

Personal information that HELIOS FAROS collects when booking accommodation (reservations via the web or reservations by phone by calling the call centre or reservations by accepting the offer by e-mail) in order to fulfil the reservation obligation are:

  • name and surname of the reservation holder
  • residence address (Croatian citizens)
  • date of birth
  • number, type of identification document and place of issue
  • citizenship
  • object name
  • number of accommodation units, type of accommodation unit (room type)
  • date of arrival and departure
  • number of persons for whom accommodation and accommodation by rooms are reserved
  • which persons are minors
  • eventually other specifics depending on the request of the person booking the accommodation
  • email address if the person has it
  • language
  • phone
  • membership in the Loyalty Program if it affects the price of accommodation or the collection of points
  • method of payment and possibly additional information necessary for the purpose of executing transactions or securing payments.

In case of cancellation, we must save your data for the purpose of proving the reservation or cancellation.

Upon arrival at the facility, guests usually check in at the reception of the facility via a registration card that the guest fills out or reviews and confirms the accuracy of the data or check in using self-check-in applications. In any case, the data is entered into the guest database from which the data is automatically sent to the eVisitor system (unique online information system for check-in and check-out of guests) in order to comply with legal obligations.HELIOS FAROS Data to be collected (data subject to change due to changes in positive regulations):

  • name and surname
  • place, country and date of birth
  • citizenship
  • number and type of identification document
  • residence and address
  • date and time of arrival or departure from the facility
  • sex
  • basis for exemption from payment of tourist tax or reduction of tourist taxes.

These data are processed by tourist boards and public authorities of the Republic of Croatia for the following legal purposes:

  • monitoring the fulfilment of the obligation to register and deregister tourists by the person obliged to register and deregister (accommodation service provider)
  • records, calculation and collection of tourist tax
  • keeping a book or guest list by the accommodation service provider and monitoring the execution of stated obligations by inspection bodies
  • reports of aliens to the ministry responsible for the interior and monitoring the implementation of this obligation by inspection bodies
  • keeping a list of tourists by tourist boards and statistical processing and reporting
  • supervision over the operations of the accommodation service provider in the part related to the legality of performing activities or the provision of registered services and compliance with tax and other regulations on public benefits.

Considering that it is prescribed that guest registration data be entered on the basis of data from the identity card, i.e., travel or other identity document, the guest is obliged to provide HELIOS FAROS with such a document and provide all other information necessary for registration data and are not contained in such a document. Also, in order to exercise some rights and benefits, it is necessary to attach (copies) of appropriate documents, certificates and documents proving and exercising such rights and benefits.

Also, HELIOS FAROS is obliged to keep all invoices, as well as the basis for issuing invoices issued to guests with personal data of the guest in accordance with legal regulations.

Other data related to the circumstances of your stay, such as: mode of travel, who you are traveling with, marital status, number of children, pets, other interests, will also be collected and processed during your stay when directly related to the accommodation service.

Before, during and after your stay, HELIOS FAROS, as the data controller, has the right to send you, as a guest, a so-called service messages - booking confirmations, reminders of the stay and other information closely related to the specific stay you have booked.

Also, during and after the stay, HELIOS FAROS as the data controller has the right based on the legitimate interest of you as a guest by email, SMS and / or instant messaging platform (Viber, WhatsApp, etc.) to send satisfaction questionnaires that will process alone or through collaborators. The primary purpose of the satisfaction questionnaire is to collect data on the service for the legitimate interest of improving the service by HELIOS FAROS, and HELIOS FAROS can depersonalize and process the data from the questionnaire for statistical purposes.

HELIOS FAROS has the right, on the basis of a legitimate interest, to collect certain data and use it for direct marketing purposes as described in the Newsletters section.

Service messages and messages with satisfaction questionnaires related to the specific stay of the guest are not considered newsletters for the purpose of sending offers and news HELIOS FAROS.

In relation to the above information, VALAMAR RIVIERA d.d. provides access to personal data from management services.

CANDIDATES FOR EMPLOYMENT AND WORKERS

HELIOS FAROS is the employer of a large number of individuals and this part of the Policy regulates the protection of personal data primarily in the processes related to employment, development and education within HELIOS FAROS. In this sense, the respondents are primarily former and current workers, job seekers, interns (students), professional development, students who work on the basis of the so-called. student contract, scholarship holders and other persons whose data are processed within the framework of employment law and related relations.

As part of the processing of employment data, HELIOS FAROS identified the following processing purposes:

  • Personnel selection: includes the collection and further processing of relevant competition documents, testing and evaluation, the collection and analysis of information on candidates from publicly available sources, including information publicly disclosed by the candidate if relevant to the risks of the job.
  • Reputation risk reduction: collecting and analysing information on employees and persons in a comparable relationship from publicly available sources, including information publicly disclosed by the respondent if relevant because of the risk involved in the job.
  • Conclusion of the contract: processing for the purpose of concluding an employment contract, student contract, professional practice or professional training, scholarship contract with persons not employed in the IMPERIAL RIVIERA or any other comparable relationship.
  • Exercise of material and other rights: processing is necessary in order to exercise the material and other rights of workers, persons in a comparable relationship or other persons (e.g., children, spouses or insurance beneficiaries), for example to exercise the right to enter into active employment policy measures (permanent seasonal and others), for realization of additional rights of workers under the collective agreement HELIOS FAROS (for example: birth of a child) and others.
  • Fulfilment of the contract: data processing is necessary for the purpose of fulfilment of the contract by the respondents, which includes fulfilment of work obligations, monitoring of their execution and ensuring all relevant measures for their execution.
  • Accommodation registration: data processing is necessary in case the respondents stay in the facilities for personal accommodation of workers in order to register their stay with the competent authorities.
  • Performance management: this purpose includes information on the achievement of previously set goals, timely fulfilment of goals and further analysis to determine future goals, human resources management, determining the number of awards and other relevant measures.
  • Rewarding: processing includes rewarding or payment of fixed and variable part of the fee, where such processing may include data on violations of ethical and other internal rules, data from the performance management system, on attended training, as well as all other relevant data.
  • Education: processing for the purpose of educating persons acting under the guidance of HELIOS FAROS, including knowledge tests, which includes all necessary actions for candidacy and registration of respondents, analysis of acquired knowledge and all other relevant information for organizing, implementing and further action.
  • Preparation of various reports on workers: some reports are prepared for the legal obligation of HELIOS FAROS, some for the exercise of certain rights, fulfilment of obligations of HELIOS FAROS in case of contracting and realization of additional benefits for workers, budgeting, etc.
  • Informing: collection and processing of data for the purpose of quality and timely informing of candidates about open positions and competitions, i.e., employment opportunities within HELIOS FAROS. Collection and processing of data for the purpose of quality and timely informing all HELIOS FAROS employees about new changes or special notices important for the exercise of employment rights or important information in the field of general knowledge of events and activities in HELIOS FAROS related to employment rights or of every comparable relationship. For this purpose, for the sake of speed and better information, information is sent by phone and / or to official e-mail addresses, or private if the employee has given consent to use the e-mail address for this purpose. Furthermore,
  • Protection of property and persons: includes monitoring of entry / exit from business premises, use of official mobile devices, computer equipment, internet and telephone traffic, cars, premises, and other HELIOS FAROS property as well as access to guest property in accordance with internal acts.
  • Termination of employment: data processing due to termination of employment contract or other comparable contract, in order to fulfil legal and contractual obligations.
  • Monitoring ethical behaviour: processing includes all procedures in which compliance with ethical conduct or regulations related to the protection of dignity is investigated, or in the framework of any other disciplinary action, regardless of whether the respondent is a registered person or an applicant.
  • Safety at Work: data processing may also be required in cases where it is necessary to fulfil the purpose of special regulations on occupational safety, including alcohol testing in accordance with regulations.

HELIOS FAROS has a legitimate interest in realizing various benefits for its employees, as well as facilitating some business processes. In this sense, HELIOS FAROS can, based on a special decision, decide on various tools to achieve these purposes (for example, issuing employees ID cards that receive discounts, giving certain instructions via SMS, taking photos in certain cases, etc.) in which case inform all workers in a timely manner.

In addition to the stated purposes, it is possible to process personal data for other specific purposes, but always within the framework prescribed by law or if the processing is necessary for the exercise of rights and obligations arising from employment, or in relation to employment and any comparable relationship.

HELIOS FAROS database on former and current employees, candidates, interns (students), professional development, students working on the basis of the so-called. student contract, scholarship holders and other persons whose data are processed in the framework of labour law and related relations is kept in a special application. An appropriate contract has been concluded with the holder of maintenance and support of the application as the executor of personal data processing.

Personnel selection

HELIOS FAROS as a potential employer collects, processes and stores data of candidates for employment in HELIOS FAROS in the database of candidates on the basis of their voluntary application, in the following ways:

  • Candidate application via a web application form that serves as a CV
  • login via email
  • by attending organized auditions and filling out application forms
  • on the other way.

Data collected as a rule: name, surname, date of birth, address, citizenship, OIB (for Croatian citizens, given that OIB is the most reliable information that distinguishes candidates), mobile phone, e-mail address (for contact purposes), gender, education, language, preferred mode of communication.

Candidates may obtain information from HELIOS FAROS indirectly, from domestic and foreign employment agencies, in which case those agencies are obliged to inform candidates about the processing of their personal data by HELIOS FAROS.

Candidates send their job applications to:

  • as open applications in which case we process data to contact the candidate in connection with employment for five years
  • as applications for specific tenders that have a specified deadline in which case, we process the data during the competition and five months from the end of the competition in order to contact the candidate in connection with employment, and these applications are archived for five years.

In the event that candidates who apply for a specific competition that has a specified deadline give special consent, we process data to contact candidates in connection with employment for five years, as well as open applications.

HELIOS FAROS has a legitimate interest in using the obtained e-mail addresses, as well as other submitted contact information for contacting candidates related to employment. For example, after applying, candidates may receive an automatic reply that their application has been received and that candidates whose qualifications and experience are in line with those required for individual jobs will be contacted. Also, after applying, candidates can receive a message on the phone number with the proposed date of the interview, a message stating the documentation required for employment and the like. In addition, HELIOS FAROS has a legitimate interest in contacting temporary workers, mainly seasonal jobs, for information on information relevant to business and key activities in HELIOS FAROS, and to maintain contact for possible further cooperation.

The data is kept by the candidates themselves, but HELIOS FAROS creates personal data related to employment activities, such as the results of job interviews, tests and assessments, based on the legitimate interest of ensuring the best candidates, and collects personal data from third parties, primarily by verification data obtained during the recruitment process by contacting relevant third parties (for example: employment agencies, education and training providers) or using publicly available sources.

Employment relationship and other comparable relationships

HELIOS FAROS as an employer collects, processes and stores all employee data in the employee database kept in the IT program and in the physical files of employees. The data collected are listed in the Ordinance on the content and manner of keeping records of workers published by the ministry responsible for labour and the pension system.

Needed data for employment are usually: copy of ID card, copy of current account or instructions for payment from the bank, copy of protected account (if the employee has one), OIB, proof of education (copy of certificate or diploma), e-book: certificate of retirement, (obtain it from the HZMO or through the e-Citizens service), Electronic record of the tax card form, the so-called PK form (obtained from the Tax Administration or through the e-Citizens service, first-time employees do not have an electronic record of the tax card form and must open it at the Tax Administration), birth certificate of a child under 15 years of age.

Necessary data for concluding student contracts are usually: confirmation of the faculty for the current year as proof of student status or a copy of the index of enrolled current year, copy of ID card, certificate of enrolment for the Student Center (not all student centres), one photo or student card, PIN.

In addition to this information, HELIOS FAROS may keep in the employee's file other data collected during the employment process, as well as other data collected during the employment, determined by the regulations of HELIOS FAROS (for example: awards, warnings, certificates, etc.).

All employees' data are kept in the database of employees on the date of employment and are kept up to date until the termination of employment and they are kept as documentation of permanent value in accordance with relevant regulations.

In its database, HELIOS FAROS also stores data of other persons in a business relationship comparable to an employment relationship or persons in practice and professional development, starting from work and promptly leading them to termination of employment and kept in accordance with relevant regulations. A special case is the data of students in practice who may be minors, about whom special attention is paid and whose data are collected and stored in accordance with special regulations with the approval of the school and parents.

Salary data, payroll - subject to special storage regulations. Anyway, all employees and other persons in a business relationship comparable to an employment relationship or a person in practice and professional development have all the rights of the respondents.

In relation to the above information, VALAMAR RIVIERA d.d. provides access to personal data from management services.

BUSINESS PARTNERS

In its business operations, HELIOS FAROS also processes data from business partners or potential business partners, which are:

  • natural persons who are, may become or have been business partners of HELIOS FAROS, e.g., craftsmen, persons in the regime of independent professions (e.g., lawyers, doctors, etc.), persons with whom employment contracts are concluded (e.g., singers, painters , photographers, etc.) and other natural persons who have the status of entrepreneurs
  • natural persons who in some part of the business represent legal entities with which HELIOS FAROS has, may have or has had a business relationship (e.g., persons delivering for their employer company, persons to whom invoices are sent for their employer legal entity, signatories of contracts for companies representing persons who hand over the company, persons who organize congresses for their legal entity, etc.).

As part of the processing of respondents' data, HELIOS FAROS identified the following purposes of processing:

  • Conclusion of the contract: processing for the purpose of concluding contracts from any area of activity of HELIOS FAROS (for example: sending inquiries, sending special offers, requesting data on signatories of contracts, sending tenders for legal entities represented by respondents, etc.)
  • Fulfilment of the contract: data processing is necessary for the purpose of fulfilling the contract, which includes fulfilling obligations, monitoring their execution and ensuring all relevant measures for their execution (for example: to agree on the time and place of delivery of equipment under the contract, to send invoices, etc.).
  • Informing: data gathering and processing for the purpose of quality and timely information; HELIOS FAROS has the right, on the basis of a legitimate interest, to collect certain data and use it for direct marketing purposes as described in the Newsletters section.

In addition to the stated purposes, it is possible to process personal data for other specific purposes, but always within the framework prescribed by law or if the processing is necessary for the exercise of rights and obligations arising from the business relationship.

Type of personal data of the respondents that are collected are:

  • name and surname
  • email address
  • telephone number
  • data on the function within the legal entity he represents (e.g., sales officer, secretary of the administration, etc.)
  • occupation when the respondent is a natural person with whom he enters into a contractual relationship (for example: singer, painter, photographer, lawyer, doctor ...)
  • sometimes references and short CVs (especially for consultants)
  • data listed on the forms of blank promissory notes, debentures, bills of exchange
  • bank account number (IBAN) when the business partner is a natural person with whom a contract is entered into
  • other information depending on the nature of the business relationship.

Places of collecting personal data of respondents:

  • respondents' offers for business cooperation received
  • data received from respondents in the context of selling HELIOS FAROS products / services or buying products / services from a business partner (e.g., fairs, congresses, etc.)
  • business correspondence related to certain previous or current business cooperation (for example, correspondence performed as part of the execution of a contract)
  • publicly published data (for example: court register, websites of business partners, magazines, newsletters, etc.).

In addition to the above types of data and places of collection, it is possible to process personal data for other specific purposes, but always within the framework prescribed by law or if the processing is necessary to exercise the rights and obligations of the business relationship.

Storage time

Data of respondents who are natural persons in a business relationship with HELIOS FAROSOM are kept in accordance with the applicable legal regulations (for example, HELIOS FAROS is obliged to keep all invoices, as well as the basis for issuing invoices in accordance with legal regulations).

In situations when HELIOS FAROS is authorized to set deadlines for data retention, they are determined taking into account the purpose of processing and the interests of respondents to destroy data, and this is set at a maximum of five years from the termination of the contractual relationship (if any).

In relation to the above information, VALAMAR RIVIERA d.d. provides access to personal data from management services.

PUBLIC ANNOUNCEMENTS

HELIOS FAROS publishes information of interest to existing, but also potential employees, guests, business partners, i.e., the public, through its website, social media profiles, video walls and bulletin boards in the facilities. Such disclosures may contain a limited set of personal information, such as first and last names, functions, professional information, videos, statements and photographs.

The legal basis for processing is the legitimate interest of informing the public, but also marketing, during which processing always takes into account the interest of respondents, so personal data are not published if it is determined that the interest of respondents not to publish certain personal data is stronger than HELIOS FAROS publication of the same. In some situations, disclosure of information may be based on consent to the highest standards.

The announcements have a permanent character, which provides information on current events, as well as insight in previous activities.

Processing will stop on the basis of the respondent's objection; it is determined that such objection is justified or if the respondent has withdrawn the consent in situations where the consent is applicable and in a manner that can be enforced.

WEB-SITE, COOKIES AND INTERNET TECHNOLOGIES

Web site of HELIOS FAROS apply cookies, and the cookie policy is available at the link: www.heliosfaros.hr/cookie-policy/.

VALAMAR RIVIERA d.d., which acts as a management company in the name and on behalf of HELIOS FAROS (see introduction), has several websites (for example: www.valamar.com, https://www.valamar.com/en/hotels-hvar/hvar-places-hotel, www.camping-adriatic.com, www.valamar-experience.com, www.dobarposaouvalamaru.com, www.valfresco.com…) and it is possible that they will create them and more, all in order to provide the best possible service and provide users with easier and faster access to content that interests them.

The privacy policies of VALAMAR RIVIERA d.d. are available via the link: https://www.valamar.com/hr/izjava-o-privatnosti

VIDEO SURVEILLANCE

HELIOS FAROS as the data controller has a legitimate interest in implementing video surveillance measures to protect property and persons, and in some cases has a legal obligation to install surveillance cameras that record all persons moving around the perimeter of the surveillance camera (guests, employees, business partners, etc.).

The processing of personal data of employees through the video surveillance system is also carried out under the conditions determined by the regulations governing safety at work.

HELIOS FAROS in the prescribed manner indicates all places where video surveillance is installed.

HELIOS FAROS is aware that the videos contain personal data of all persons moving around the perimeter of the camera and therefore keeps them with special care, has a security system, availability and deletion policy, which is governed by internal security rules HELIOS FAROS.

Videos are automatically deleted after a maximum of 15 days from the date of recording. In case of the need for exemption (dubbing), videos are kept for a maximum of six months, unless another law prescribes a longer retention period or if the evidence is in court, administrative, arbitration or other equivalent proceedings. Excluded videos will be stored in an extremely restricted central alert system.

HELIOS FAROS may use the videos in court and / or criminal proceedings. Insight into personal data on videos may also have third parties, executors, contractors HELIOS FAROS registered and professional for the provision of services for the protection of persons and property, and who in no way use the data independently but take care of the security of central surveillance and reporting system. Special regulations governing this area apply to all other details related to video surveillance.

FINAL PROVISIONS

This Privacy Policy is available athttps://www.valamar.com/en/hotels-hvar/hvar-places-hotel and www.heliosfaros.hr and also in human resources offices and at the receptions of HELIOS FAROS facilities.

HELIOS FAROS reserves the right to change and / or amend these Privacy Policies at any time, and will update the updated Privacy Policy on the above media.

Imperial Riviera d.d. privacy policy

GENERAL SECTION

PROCESSING MANAGER AND LEGAL FRAMEWORK

As the processing manager, IMPERIAL RIVIERA, is committed to protecting your personal data. The collection and storage of data is carried out in accordance with the provisions of EU Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter: Regulation), of the Law on the application of the General regulation of data protection (NN 42/2018) and other regulations governing the subject area, which are applied in the Republic of Croatia.

SCOPE OF APPLICATION

This Policy applies to any processing of personal data performed by IMPERIAL RIVIERA as the processing manager, unless another policy or other IMPERIAL RIVIERA document prescribes otherwise for a particular processing.

This Policy is divided into two parts: the General Section and the Specific section. The basic principles of personal data processing, contact details of personal data protection officials and other provisions specified in the General Section of this Policy are applied without exception to any personal data processing regardless of whether such processing is specifically processed in the Specific Section of this Policy or not. The Specific Section of the Policy deals, in more detail, with specific cases of data processing which represent the majority of all processing by IMPERIAL RIVIERA.

DATA PROTECTION OFFICIAL

IMPERIAL RIVIERA has appointed a personal data protection official who you can contact at any time via e-mail: gdpr@imperial.hr or by mail to the address Imperial Riviera d.d., Jurja Barakovića 2, 51280 Rab, Republic of Croatia - for DPO, issues related to personal data protection and for exercising their rights guaranteed by the General Data Protection Regulation.

All requests not related to personal data protection, which are delivered to the address of the data protection official, e.g. offers of job candidates, booking inquiries in IMPERIAL RIVIERA properties, etc. will be provided directly to the relevant departments within IMPERIAL RIVIERA, without special response to the sender by the data protection official.

PERSONAL DATA PROTECTION PRINCIPLES

IMPERIAL RIVIERA has recognized the principles of data processing as basic values that must be respected throughout the cycle of personal data processing, from their collection to their destruction or other cessation of processing. IMPERIAL RIVIERA processes data:

  • Lawfully - by processing data only if allowed by law and within the limits prescribed by law.
  • Fairly - by taking into account the specifics of each relationship, applying all appropriate measures to protect personal information and privacy in general and not impeding data subjects in exercising their rights.
  • Transparently - by informing data subjects about the processing of personal data. From the start of the data collection process, when data subjects are informed about all aspects of data processing, until its termination, data subjects are provided easy and fast access to their own data, which includes the possibility of accessing and obtaining a copy in accordance with the provisions of the Regulation. Certain information may be restricted only when required by law or when necessary for the protection of third parties.
  • Purpose limitation - by processing personal data for the purposes they were collected for and for other purposes only if the conditions of the Regulation are met. Data may be processed for matching purposes only taking into account (a) any link between the purposes of the collection of personal data and the purposes of the intended continuation of the processing; (b) the context in which the personal data was collected, in particular concerning the relationship between the data subjects and IMPERIAL RIVIERA; (c) the nature of the personal data, in particular whether special categories of personal data are processed in accordance with Article 9. Regulations or personal data relating to criminal convictions and criminal offenses in accordance with Article 10. Regulations; (d) the possible consequences of the intended continuation of processing for the data subjects; and (e) the existence of appropriate protection measures.
  • Storage limitation - by storing data in a form which permits identification of data subjects for no longer than is necessary for the initial purposes, and longer only if permitted by the Regulation.
  • Data minimization - by processing data if it is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Particular attention is given to not collecting data for which there is no justifiable reason for processing.
  • Accuracy - by keeping data accurate and up-to-date, and erasing inaccurate data in the scope of possibility.
  • Integrity and Confidentiality - by using appropriate technical and organisational measures to ensure appropriate personal data protection, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. Relevant measures are applied taking into account the risk of each type of data processing.

LEGALITY OF PERSONAL DATA PROCESSING

In order to respect the lawfulness of processing personal data, IMPERIAL RIVIERA processes personal data only if and to the extent that at least one of the following is met:

  • Processing is necessary for the performance of the contract to which the data subject is a party or in order to take action at the request of the data subject prior to the conclusion of the contract; this is the most common purpose of data processing with an existing contractual relationship or a contractual relationship in negotiations as its basis.
  • Processing is necessary to comply with the legal obligations of the processing manager. As a legal entity, IMPERIAL RIVIERA has a number of obligations prescribed by various regulations. This obligation includes the collection and often the submission of data to public authorities. For example, the processing of personal data of shareholders who apply for the General Assembly, the processing of personal data of participants at meetings held at the premises of IMPERIAL RIVIERA in accordance with anti-pandemic measures and the like.
  • Processing is necessary for the legitimate interests of the processing manager or a third party, except where those interests are stronger than the interests or fundamental rights and freedoms of data subjects requiring the protection of personal data, taking into account reasonable expectations of data subjects based on their relationship with the processing manager, especially if the data subject is a child. In applying this legal basis, IMPERIAL RIVIERA assesses that the processing is appropriate to business needs, that it is the least invasive as possible and that the interests of the data subjects do not exceed the legitimate interests of IMPERIAL RIVIERA or a third party. Examples of such processing are processing for administrative purposes, the purposes of maintaining computer network security, direct marketing, and improving our business.The data subject always has the right to object to such processing in these situations.
  • Processing is necessary to protect key interests of the data subject or other natural person. The right to personal data protection is not an absolute right and IMPERIAL RIVIERA equates it with other fundamental rights in accordance with the principle of proportionality. IMPERIAL RIVIERA acknowledges the possibility that in some situations it is necessary to process personal data in order to protect the key interests of the data subjects or other natural persons.
  • The data subject has consented to the processing of his or her personal data for one or more specific purposes. When processing personal data on the basis of consent, IMPERIAL RIVIERA provides that these are situations in which there are no, formal or informal, consequences for giving, refusing or denying consent. When processing is based on consent, the data subject may withdraw consent at any time without negative consequences. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

In certain exceptional situations, IMPERIAL RIVIERA may process data that would not be processed in regular situations, for example data collection based on the recommendations of the Croatian Institute of Public Health in case of epidemics, etc.

TYPES OF PERSONAL DATA PROCESSED

Special categories of personal data: specific categories of personal data shall be processed only if the conditions set out in Article 9 of the Regulation are met. For example, IMPERIAL RIVIERA processes employee data that fall into specific categories of personal data, such as union membership data (for example, when exercising special rights under relevant regulations), religious or philosophical beliefs (for example, when exercising the right to additional non-working days for religious holidays, if the individual has voluntarily disclosed such data for the stated purpose), or health related data (for example according to special regulations on occupational safety or keeping records of workers or when special health certificates are required for certain jobs), etc.

Data on criminal convictions and criminal offenses: when there is a legal authority to do so, IMPERIAL RIVIERA also processes personal data relating to criminal convictions and offenses, such as certificates of impunity for workers.

Personal data that do not belong to the previous two groups: such personal data make up the largest part of the processed data, and these are most often identification and contact data such as name and surname, OIB, data generated by movement in rooms under video surveillance.

Most of the personal data that IMPERIAL RIVIERA collects is provided by the data subjects themselves and we ask that you do not provide sensitive information (such as race or ethnic origin, political opinions, religious or philosophical beliefs, etc.) when this is not necessary. If you nevertheless provide sensitive information for any reason, you hereby give your express consent to the collection and use of such information in the ways described in these Policy or in the manner described at the time of disclosure of that information.

THE ROLE OF VALAMAR RIVIERA d.d.

IMPERIAL RIVIERA concluded with the company Valamar Riviera d.d. with its registered office in Poreč, Stancija Kaligari 1 OIB: 36201212847 (hereinafter: Valamar) Contract in relation to the management of hotel and tourist facilities and contents (hereinafter: Management contract) based to which Valamar manages certain business segments of IMPERIAL RIVIERA. In this sense, IMPERIAL RIVIERA and Valamar may act as separate managers or as joint managers of personal data processing, or Valamar may act as the executor of personal data processing of respondents.

Due to such enterpreneur agreement, when managing hotel and and tourist facilities and contents, Valamar sometimes directly manages certain activities, including the management of some of the activities described in the Special Part of this Privacy Policy, and in addition Valamar sometimes receives data from IMPERIAL RIVIERA and has a rights to view the data in certain activities where it subsequently comes to personal data processing. For example, Valamar manages the reservation function through the Valamar reservation center (call center) and via the websites www.valamar.com and www.camping-adriatic.com, and in these cases Valamar is an independent processing manager, however, all this information related to IMPERIAL RIVIERA facilities are also processed by IMPERIAL RIVIERA as an independent processing manager. Furthermore, Valamar has a legitimate interest in processing of personal data carried out for the purposes of direct marketing, primarily for the purpose of sending marketing messages (newsletters) by e-mail, SMS and / or instant messaging platform (Viber, Whatsapp, etc.). Based on a legitimate interest, Valamar may send different newsletters depending on the relationship that respondents have with Valamar or the facilities under Valamar's management. For this purpose, personal data is collected from guests and persons who have asked for an offer or booked accommodation, persons who have participated in the prize game, joined the loyalty program, filled out a satisfaction questionnaire, persons who have filled in the application at free Wi-Fi, a person who made a purchase in a web store or otherwise had a relationship with Valamar. Following the above, in certain cases IMPERIAL RIVIERE guests can receive from Valamar newsletters containing information about other hotels and facilities managed by Valamar, as well as accommodation quality questionnaires and other service e-mails. For IMPERIAL RIVIERA´s guests, prize games can be organized from time to time, which can be organized by Valamar, in which case your personal data will be collected only if you decide to participate in the prize game. Valamar's Plus Club Loyalty Program is applied in the IMPERIAL RIVIERA. The conditions of membership are contained in Valamar's Rules of Loyalty Program, which can be found at www.valamar.com/hr/program-vjernosti/valamar-plus-club/pravilnik-programa. Also, based on the Management Agreement, Valamar has certain rights and obligations related to human resources, so in these cases Valamar has the right to process personal data of employees and candidates applying for employment in IMPERIAL RIVIERA, for example when sending applications through the website www.dobarposaouvalamaru.com.

When Valamar acts as the processing manager, the Valamar Privacy Policy applies, which can be found at: https://www.valamar.com/hr/izjava-o-privatnosti.

DATA DELIVERY TO THIRD ENTITIES

IMPERIAL RIVIERA shares personal information with others only when permitted.

IMPERIAL RIVIERA is obliged by law to provide data to third parties. For example, delivering guest data via the eVisitor system, delivering employee data to the competent institutions to the Croatian Pension Insurance Institute, to the Croatian Health Insurance Institute, the Tax Administration and the Central Register of Insured Persons and pension companies. Furthermore, in certain cases, IMPERIAL RIVIERA is obliged to submit or make available employment data to the Croatian Employment Service, for example to include workers in active employment policy measures, the competent police stations or the ministry responsible for internal affairs, for example in the case of senior government officials staying in IMPERIAL RIVIERA's properties, as well as for the issuance of work and residence permits, the ministry responsible for tourism in the case of employing scholarship holders, the ministry responsible for the economy and entrepreneurship when it comes to the use of investment subventions, insurance companies, banks and other cases required by law.

Also, certain employee data is sent to banks or pension funds as part of salary payments, and data can also be sent to creditors in accordance with enforcement regulations. Sometimes data is sent according to contractual obligations, for example with students in practice, data is exchanged with schools, colleges.

Certain personal data is also provided to business entities for the purpose of providing specific services such as the workers' health examinations (contracted ocupational medicine), further, to institutions that organize legally mandatory training (occupational safety, hygiene, toxicology) or audit companies when conducting mandatory audits, public notaries when certifying, the Financial Agency for the purpose of obtaining business certificates, public procurement payers when IMPERIAL RIVIERA applies for public procurement tenders, further for the purposes of awarding and using official cards, official mobile devices or for the purchase of fuel.

It is possible to deliver data to business entities, processors, who process the data on behalf of IMPERIAL RIVIERA, which acts as the processing manager. Most often, these are IMPERIAL RIVIERA's business associates who provide IT services, who store them in their databases or have the possibility of accessing personal data until the end of processing. A detailed contract is concluded with such subjects regarding their powers and obligations in the processing of personal data, in accordance with the requirements of the Regulation.

In certain situations, it is possible for external entities and IMPERIAL RIVIERA to jointly determine the purposes and methods of personal data processing, in which case these external partners and IMPERIAL RIVIERA are joint processing managers. In these relations, the joint processing managers shall transparently determine their responsibilities for complying with the obligations under the Regulation, in particular with regard to the exercise of data subjects' rights and their duties to respect the transparency of processing, unless responsibilities are established by law.

A special case of data delivery to third parties is the fact that IMPERIAL RIVIERA has an entrepreneurial contract with Valamar and the data is submitted to Valamar, i.e. Valamar has access to personal data of IMPERIAL RIVIERA respondents in accordance with Management and other agreements (see chapter: ROLE OF VALAMAR RIVIERA d.d.).

If data are transferred to third countries as part of data processing, IMPERIAL RIVIERA ensures compliance with high protection standards in order to comply with the highest possible standard of personal data protection, in accordance with the strict requirements of the Regulation. Hence, when international transfers of personal data are in use, IMPERIAL RIVIERA will inform the data subjects about the intention to disclose personal data to a third country or international organization and about the existence or non-existence of a European Commission's decision on adequacy. Any transfer of personal data to third countries will be carried out in accordance with Chapter V of the Regulation.

DATA STORAGE RETENTION

Data subjects' data are processed and stored, in accordance with applicable legal regulations when the retention obligation is prescribed (for example, payrolls, analytical records of salaries for which mandatory contributions are paid are kept permanently, and accounting documents on the basis of which data is entered in the journal, general ledger and auxiliary books are kept for at least eleven years), and in situations where IMPERIAL RIVIERA is authorized to set retention periods, data is stored as long as necessary for the purposes for which personal data is processed taking into account the purpose of processing, the legitimate interests of IMPERIAL RIVIERA and the interests of the data subjects to delete the data.

RIGHTS OF THE DATA SUBJECTS

Regardless of the basis for data collection, all users of our website can exercise the following rights free of charge within the limits prescribed by the Regulation:

Right to information: The data subject has the right to be informed about the processing and its purposes. IMPERIAL RIVIERA provides the data subjects with all the information necessary to ensure fair and transparent processing, taking into account the context of processing.

Right to deletion („right to forget“): The data subject has the right to request IMPERIAL RIVIERA to delete personal data relating to him/her, without undue delay in accordance with the terms of the Regulation. To do so, send your request to us (the processing manager) in writing, including an electronic form of communication. Please note that the request needs to specify what you wish to be deleted, since we can store your data on different legal bases, for example, the respondent can be both our guest and a candidate for employment. You have the right to request the deletion of personal data relating to you if one of the following conditions is met:

  • Your personal information is no longer necessary for the purpose for which we collected or processed it;
  • you have withdrawn the consent on which the processing is based and if there is no other legal basis for processing;
  • you have objected to the processing of your personal data and if there are no stronger legitimate reasons for our processing;
  • personal data has been processed illegally;
  • personal data must be deleted in order to comply with a legal obligation.

In some cases, it will not be possible to fully comply with the deletion request, for example when there is a legal obligation for retention, when the legitimate interest of the processing manager are stronger than the interest of the data subjects, when there is an interest of the processing manager to set, enforce or defend legal claims.

The right to access data: At the request of the data subject, IMPERIAL RIVIERA will provide him with confirmation whether his personal data is processed and if such personal data is processed, he will be granted access to personal data and the purpose of processing, data categories, potential recipients of the data to whom those data shall be disclosed, and other data in accordance with Regulation. The data subject is also entitled to receive a copy of the personal data being processed. Access to personal data may be restricted only in cases prescribed by law, i.e. when such restriction respects the fundamental rights and freedoms of others.

Right to rectification: The data subject has the right to obtain, without undue delay, the correction of incorrect personal data relating to him from IMPERIAL RIVIERA. Taking into account the purposes of processing, the data subject has the right to supplement incomplete personal data. To do so, send your request to us (the processing manager) in writing, including an electronic form of communication. We note that it is necessary to specify what is incomplete or not up-to-date in the request, and in what sense the above should be corrected and submit the necessary documentation in support of the allegations.

Right to data portability: The data subject has the right to receive personal data relating to him in a structured, commonly used and machine-readable format in accordance with the requirements of the Regulation.

Right to object: When IMPERIAL RIVIERA processes data on the basis of its legitimate interests which are stronger than the interests of the data subjects, then the data subject has the right to object to the processing of personal data related to him at any time.

Right to restricted processing: The data subject has the opportunity to ask IMPERIAL RIVIERA to exercise the right to restrict processing in case he disputes the accuracy of personal data, considers the processing to be illegal and opposes the deletion of personal data and instead requests restriction of their use, and has submitted a complaint and awaits confirmation as to whether the legitimate reasons of the processing manager go beyond the reasons of the data subject.

In any case, data subjects also have the right to:

  • submit a complaint to the Personal Data Protection Official,
  • file a complaint to the supervisory body (Personal Data Protection Agency) if they believe that their rights to data protection have been violated.

Send your written request to the contact address of the Personal Data Protection Official:gdpr@imperial.hr or by mail to the address Imperial Riviera d.d., Jurja Barakovića 2, 51280 Rab, Republic of Croatia - for DPO.

IMPERIAL RIVIERA as the Processing Manager has the right to protect the interests of the Processing Manager as well as the protection of the data subjects and accordingly has the right to carry out the activities of establishing the identity of the applicant.

IMPERIAL RIVIERA has the right to publish a form that will be used to submit a request in order to process the request as efficiently as possible.

On request, IMPERIAL RIVIERA provides information on the actions taken in relation to the exercise of data subject's rights without undue delay and in any case within one month from the date of receipt of the request. This period may be extended by an additional two months, taking into account the complexity and number of applications. IMPERIAL RIVIERA shall notify the data subject of any such extension within one month from the date of receipt of the request, together with the reasons for the postponement.

If the data subject submits the request electronically, IMPERIAL RIVIERA provides the information electronically if possible, unless the data subject requests otherwise.

The data subject's request is generally free of charge, but if the data subject's request is manifestly unfounded or excessive, and in particular because of their frequent repetition, IMPERIAL RIVIERA is entitled to charge a reasonable fee based on administrative costs or refuse to act on the request.

PROTECTION OF PERSONAL DATA OF CHILDREN

IMPERIAL RIVIERA advises parents and guardians to teach children (up to 18 years of age) about safe and responsible handling of personal data, especially on the Internet. IMPERIAL RIVIERA processes personal data of children only with the prior consent of parents/guardians (for example: scholarship holders, when children are guests at our properties, visitors to Maro playrooms, etc.).

PERSONAL DATA SOURCES

IMPERIAL RIVIERA receives personal data most often from data subjects. When providing personal data to IMPERIAL RIVIERA, in any way (booking accommodation, job application…) you guarantee that the information you have provided is correct, that you are legally capable and authorized to dispose of the given information and that you fully agree that IMPERIAL RIVIERA collects and uses your data in accordance with the positive regulations and terms of this Privacy Policy.

Also, IMPERIAL RIVIERA receives personal data from other natural and legal persons, for example: from Valamar as a company that manages certain business aspects of business, from travel agencies that forward guest data for accommodation, guests who book accommodation for people with whom they will stay in facilities, agency for employment mediation and assignment of workers, from the holder of accommodation reservations for others guests for whom the reservation is made. When providing personal data of other persons to IMPERIAL RIVIERA, you guarantee that the information you provide is accurate, that you are legally capable and authorized to dispose of the information, that respondents whose personal data you forward IMPERIAL RIVIERI agree that IMPERIAL RIVIERA uses and collects their data in accordance with positive regulations and the terms of this Privacy Policy.

TECHNICAL AND INTEGRATED DATA PROTECTION

IMPERIAL RIVIERA, as the processing manager, provides the highest organizational and technical standards of data protection. Therefore, considering the latest developments, the cost of implementation and the nature, scope, context and purposes of processing, as well as risks of different levels of probability and seriousness for the rights and freedoms of individuals arising from data processing, at the time of processing, appropriate technical and organizational measures to enable the effective application of the principles of data protection are applied.

Also, IMPERIAL RIVIERA implements appropriate technical and organizational measures to ensure that only personal data necessary for each specific purpose of processing are processed in an integrated manner. IMPERIAL RIVIERA applies this measure to the amount of personal data collected, the scope of their processing, the retention period and their availability. Specifically, such measures ensure that personal data is not automatically, without the intervention of an individual, available to an unlimited number of individuals.

TREATMENT OF PERSONAL DATA INFRINGEMENTS

As the data processing manager, IMPERIAL RIVIERA shall without undue delay and, where feasible, no later than 72 hours after discovering, notify the competent supervisory authority about the breach, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.

The report submitted to the supervisory authority shall contain all information prescribed by the Regulation.

In the event of a personal data breach that is likely to pose a high risk to the rights and freedoms of individuals, IMPERIAL RIVIERA, as the processing manager, shall inform the data subjects of the personal data breach without undue delay. Sometimes, in cases where the Regulation prescribes, informing data subjects is not mandatory.

SPECIFIC SECTION


STAY IN PROPERTIES (hotels, apartments, campings)

IMPERIAL RIVIERA'S main business activity is the provision of accommodation services in its hotels, apartments and campings. Therefore, IMPERIAL RIVERA collects and processes your personal data for various purposes with the ultimate goal of providing quality accommodation and related services all according to the highest standards of tourism companies.

IMPERIAL RIVIERA, as the processing manager, stores your personal data that you must provide for accommodation services in its database for the purpose of fulfilling accommodation contracts and fulfilling legal obligations related to the hospitality business. In case you do not provide IMPERIAL RIVIERA with the minimum data required for booking accommodation and for the registration to all competent registers, IMPERIAL RIVIERA will not be able to provide you with booking services or accommodation services in accordance with the contract and law.

Certain information is necessary in order to take action at the request of the data subject before concluding the accommodation contract. For example, before booking accommodation at the request of potential guests, we send accommodation offers, for which composition IMPERIAL RIVIERA needs personal data, at least name, surname and e-mail address in order to be able to send an offer.

The personal data that IMPERIAL RIVIERA collects when booking accommodation (reservations via the web or reservations by phone by via the call center or reservations by accepting the offer via e-mail) in order to fulfill the reservation obligation are:

  • name and surname of the reservation holder
  • residence address (Croatian citizens)
  • date of birth
  • number, type of identification document and place of issue
  • citizenship
  • property name
  • number of accommodation units, type of accommodation unit (room type)
  • date of arrival and departure
  • number of persons per accommodation unit
  • minors
  • possibly other specifics depending on the request of the person booking the accommodation
  • e-mail if the person has one
  • language
  • phone number
  • membership in the Loyalty program, if it affects the price of accommodation or collecting points
  • payment method and possible additional information needed to execute the transaction or secure payment

In case of cancellation, we must save your data for the purpose of proving the reservation or cancellation.

Upon arrival at the property, guests usually check in at the reception via a registration card that the guest fills out or reviews and confirms the accuracy of the data or checks in using the self-check-in applications. In any case, the data is entered into the guest database from which the data is automatically sent to the eVisitor system (a unique online information system for registration and deregistration of guests) in order to comply with the legal obligations of IMPERIAL RIVIERA. The data collected are (data is subject to change due to changes in positive regulations):

  • name and surname
  • place, country and date of birth
  • citizenship
  • number and type of identification document
  • residence and address
  • date and time of arrival or departure from the property
  • sex
  • basis for exemption from tourist tax payment or for reduction of tourist tax payment

This data are processed by tourist boards and public authorities of the Republic of Croatia for the following legal purposes:

  • monitoring the fulfillment of obligation to register and deregister tourists (accommodation service provider);
  • records, calculation and collection of tourist tax;
  • keeping a book or a list of guests by the service provider and monitoring the execution of the said obligation by the inspection bodies;
  • reporting foreigners to the ministry in charge of internal affairs and monitoring the execution of the stated obligation by inspection bodies;
  • keeping a list of tourists by tourist boards and statistical processing and reporting;
  • supervising the operations of the service provider in the part related to the legality of business conduct, i.e. the provision of registered services, and compliance with tax and other regulations concerning public liabilities.

Since it is prescribed that the data for guest registration is entered on the basis of data from the identity card, or travel or other identity document, the guest is obliged to provide IMPERIAL RIVIERA with such a document and provide all other information necessary for data entry, but are not contained in such a document. Also, in order to exercise certain rights and benefits, it is necessary to enclose (copies) of appropriate documents or certificates by which such rights and benefits are proven and exercised.

In addition, IMPERIAL RIVIERA is obliged to keep all invoices, as well as the basis for issuing invoices issued to guests with personal data of the guest in accordance with legal regulations.

Other data related to the circumstances of your stay such as: mode of travel, who you are traveling with, marital status, number of children, pets, other interests, will also be collected and processed during your stay when they have a direct connection with the accommodation service.

Before, during and after the stay IMPERIAL RIVIERA as the processing manager has the right based on the legitimate interest to send you so-called service messages - booking confirmations, reminders and other information closely related to the specific stay you have booked.

Also, during and after the stay, IMPERIAL RIVIERA as the processing manager has the right based on the legitimate interest to send to you as guest questionnaires about service satisfaction via e-mail, sms and/or instant messaging platforms (viber, whatsapp, etc.) which will be processed by us or through associates. The primary purpose of the service satisfaction questionnaire is to collect service data for the legitimate interest of service improvement by IMPERIAL RIVIERA, and IMPERIAL RIVIERA may depersonalize and process this data from the questionnaire for statistical purposes.

IMPERIAL RIVIERA has the right, based on a legitimate interest, to collect certain data and use it for direct marketing.

Service messages and messages with service satisfaction questionnaires related to a specific stay of the guest are not considered newsletters for the purpose of sending IMPERIAL RIVIERA offers and news.

EXCHANGE OFFICE

IMPERIAL RIVIERA also provides exchange services at its exchange offices, usually at the receptions of properties. IMPERIAL RIVIERA is obliged in accordance with applicable regulations on the prevention of money laundering and terrorist financing, in some cases to establish and verify the identity of the person using the exchange services by inspecting the official identity document of the party in his presence and perform in-depth analysis. In the event that we are unable to carry out in-depth analysis measures when required to do so, IMPERIAL RIVIERA must not establish a business relationship or perform a transaction, or must terminate an already established business relationship and consider whether to notify the competent authority of a suspicious transaction, funds and persons.

Also, in accordance with the regulations, video surveillance of exchange offices is mandatory. The data is stored in accordance with the regulations based on the legal obligation of IMPERIAL RIVIERA.

EXCURSIONS, CONCERTS, TRANSFERS AND OTHER EXPERIENCES

IMPERIAL RIVIERA is also a travel agency and provides or mediates additional services to its guests and other persons, being preciselly: sales of various excursions, concerts, other experiences, transport services, car rental services and, if necessary, other services.

If you wish to use these services, IMPERIAL RIVIERA may collect the following information if necessary:

  • Name and Surname
  • contact information (phone and/or e-mail address)
  • other information closely related to the services provided (for example: flight number if you are requesting a transfer from the airport to IMPERIAL RIVIERA; gender, citizenship, date of birth, type and number of identification document due to legal provisions related to border crossing if you want a cross-border trip).

The stated data, but also other depending on the specific service you are looking for, will be collected solely for the purpose of providing the service you want to use.

In the case of services organized by other associates, this information will be forwarded to the associate in charge of providing a particular selected service and they become the processing managers of the personal data and we kindly ask you to get yourselves familiar with their privacy policies.

In the case of sending personalized offers, at the request of the customer, the specified data is stored for two months.

Data collected by IMPERIAL RIVIERA during the provision of other services to guests or third parties (excursions, concerts, experiences, transport) requesting the services in question by phone, at receptions or via the web, will be kept for a maximum of 5 years for possible complaints about services provided, and longer only if it is so required by special regulations (accounting, etc.). For certain services (for example: rental of deck chairs, etc.) the data will be kept until the services are performed.

CANDIDATES FOR EMPLOYMENT AND EMPLOYEES

IMPERIAL RIVIERA is the employer of a large number of individuals and this part of the Policy regulates the protection of personal data primarily in the processes related to employment, development and education within IMPERIAL RIVIERA. In this sense, the data subjects are primarily former and current employees, job seekers, interns (students), professional development, students who work on the basis of the so-called student contract, scholarship holders and other persons whose data is processed within the framework of employment and related relations.

As part of the data processing carried out in connection with employment, IMPERIAL RIVIERA identified the following purposes of processing:

  • Personnel selection: includes the collection and further processing of relevant competition documents, testing and evaluation, collection and analysis of information on candidates from publicly available sources including information publicly disclosed about the candidate if relevant to the risks of the job.
  • Reputation risk reduction: collection and analysis of information about employees and persons in a comparable relationship from publicly available sources including information that the respondent has publicly disclosed about himself if this is important because of the risk that a particular job entails.
  • Conclusion of the contract: processing for the purpose of concluding an employment contract, student contract, professional internship or professional training, scholarship contract with persons not employed in IMPERIAL RIVIERA or any other comparable relationship.
  • Exercise of material and other rights: processing is necessary in order to exercise the material and other rights of workers, persons in a comparable relationship or other persons (e.g. children, spouses or insurance beneficiaries), for example to exercise the right to enter active employment policy measures (permanent seasonal and others), for the realization of additional rights of workers under the collective agreement IMPERIAL RIVIERA (for example: the birth of a child) and others.
  • Fulfilment of the contract: data processing is necessary for the purpose of fulfillment of the contract by the respondents, which includes fulfillment of work obligations, monitoring of their execution and ensuring all relevant measures for their execution.
  • Registration of accommodation: data processing is necessary in case the data subjects stay in the facilities for personal accommodation of workers in order to register their stay with the competent authorities.
  • Performance Management: this purpose includes information on the achievement of previously set goals, timely fulfillment of goals, and further analysis to determine future goals, human resources management, determining the amount of rewards and other relevant measures.
  • Rewarding: processing includes rewarding or payment of a fixed and variable part of the remuneration, where such processing may include data on violations of ethical and other internal rules, data from the performance management system, on attended trainings, as well as all other relevant data.
  • Education: processing for the purpose of educating persons acting under the guidance of IMPERIAL RIVIERA including knowledge tests, which includes all necessary actions for candidacy and registration of respondents, analysis of acquired knowledge and all other relevant information for organizing, implementing and further action in education process.
  • Preparation of various reports on employees: some reports are made for the legal obligation of IMPERIAL RIVIERA, some for the realization of certain rights, fulfillment of IMPERIAL RIVIERA's obligations in case of contracting and realizing additional benefits for workers, budgeting, etc.
  • Information: data collection and processing for the purpose of quality and timely informing candidates about open positions and competitions, i.e. employment opportunities within IMPERIAL RIVIERA. Collection and processing of data for the purpose of quality and timely informing all IMPERIAL RIVIERA employees about new changes or special notices important for the exercise of employment rights or important information in the field of general knowledge of events and activities in IMPERIAL RIVIERA regarding the exercise of employment rights or any comparable relationship. For this purpose, information is sent by phone and/or to official e-mail addresses, or private if the employee has given consent to use the e-mail address for this purpose. Furthermore, IMPERIAL RIVIERA may offer employees the use of applications that employees voluntarily install on their mobile devices through which they can find out various news related to IMPERIAL RIVIERA or its partners.
  • Protection of property and persons: includes monitoring of entry/ exit from business premises, use of official mobile devices, computer equipment, internet and telephone traffic, cars, premises, and other property of IMPERIAL RIVIERA as well as access to guest property in accordance with internal acts.
  • Termination of employment: data processing due to termination of employment contract or other comparable contract, in order to fulfill legal and contractual obligations.
  • Ethical Behavior Monitoring: processing includes all proceedings that investigate compliance with ethical conduct or dignity regulations, or in any other disciplinary action, whether the respondent is a reported person or a notifier.
  • Work Safety: data processing may be required in cases where it is necessary to fulfill the purpose of special work safety regulations, including alcohol testing in accordance with regulations.

IMPERIAL RIVIERA has a legitimate interest in realizing various benefits for its employees, as well as facilitating some business processes. In this sense, IMPERIAL RIVIERA can, based on a special decision, decide on various tools that achieve these purposes (for example, issuing ID cards to employees who receive discounts, giving certain instructions via SMS, taking photos in certain cases, etc.) in which case employees will be timely informed.

In addition to the stated purposes, it is possible to process personal data for other specific purposes, but always within the framework prescribed by law or if the processing is necessary for the exercise of rights and obligations arising from employment, or in relation to employment and any comparable relationship.

IMPERIAL RIVIERA's database on former and current employees, candidates, interns (students), professional training, students working on the basis of the so-called student contract, scholarship holders and other persons whose data is processed in the framework of employment and related relations is kept in a special application. An appropriate contract has been concluded with the application maintenance and support holder as the enforcer of personal data processing.

Personnel Selection

IMPERIAL RIVIERA as a potential employer collects, processes and stores the data of candidates for employment in IMPERIAL RIVIERA in the candidate database based on their voluntary application in the following ways:

  • application of candidates via a web application form that serves as a kind of CV,
  • Sign in via Email,
  • by coming to organized auditions and filling out application forms,
  • or otherwise.

Data which is usually collected is: name, surname, date of birth, address, nationality, personal identification number (OIB for Croatian citizens, as is it the most reliable data to differentiate candidates), mobile phone number, e-mail (for contacting), sex, qualifications, language, preferred manner of communication.

IMPERIAL RIVIERA may obtain information on candidates indirectly, from domestic and foreign employment agencies, in which case these agencies are obliged to inform candidates about the processing of their personal data by IMPERIAL RIVIERA.

Candidates send their job applications to:

  • open applications in which case we process data for the purpose of contacting candidates regarding employment for 5 years;
  • as applications for specific vacancies that have a specified deadline, in which case we process the data during the vacancy and 5 months from the end of the vacancy to contact candidates for employment, and these applications are archived for 5 years.

In the event that candidates who apply for specific vacancies that have a specified deadline give special consent, we process the data to contact candidates for employment for 5 years, as well as open applications.

IMPERIAL RIVIERA has a legitimate interest in using the obtained e-mail addresses, as well as other submitted contact information for contacting candidates related to employment. For example, after applying, candidates can receive an automatic response that their application has been received and that candidates whose qualifications and experience are in line with those required for individual jobs will be contacted. Also, after applying, candidates can receive a message on the phone number with the proposed date of the interview, a message stating the documentation required for employment and the like. Additionally, persons who have worked for a fixed period of time, predominantly seasonal jobs, IMPERIAL RIVIERA has a legitimate interest in contacting them in order to inform them on important issues concerning business and key activities in IMPERIAL RIVIERA and in order to maintain contact in case of future cooperation. You can unsubscribe from the list of recipients news from IMPERIAL RIVIERA for free, any time.

The data is kept provided by the candidates themselves, but IMPERIAL RIVIERA creates personal data related to employment activities, such as the results of job interviews, tests and assessments, based on the legitimate interest of ensuring the best candidates, and collects personal data from third parties, primarily by data verification obtained during the recruitment process by contacting relevant third parties (for example: employment agencies, education and training providers) or by using publicly available sources.

Employment relation and other comparable relations

As an employer, IMPERIAL RIVIERA collects, processes and stores all employee data in the employee database kept in the IT program and in the physical files of employees. The data collected is listed in the Regulation on the content and manner of keeping records on workers published by the ministry responsible for labor and pension system.

The necessary information for employment is usually: a copy of the ID card, a copy of the current account or payment instructions from the bank, a copy of the protected account (if the employee has it), PIN, proof of education (copy of certificate or diploma), e-book: certificate of pensionable service, (to be obtained from HZMO or via the e-Citizens service), Electronic record of the tax card form, so-called PK form (obtained from the Tax Administration or through the e-Citizens service, persons who are employed for the first time, do not have an electronic record of the tax card form and must open it at the Tax Administration), birth certificate of a child under 15 years, certificate of residence (obtained from the Ministry of the Interior or through the e-Citizens service), wedding certificate (obtained from the registry office or through the e-Citizens service).

The necessary data for concluding student contracts are usually: a certificate from the faculty for the current year as proof of student status or a copy of the index of the enrolled current year, a copy of the ID card, a certificate of enrollment for the Student Center (not all student centers), one photo or X -ica card, PIN.

In addition to these data, IMPERIAL RIVIERA may keep in the employee's file other data collected in the employment process, as well as other data collected during employment determined by IMPERIAL RIVIERA regulations (for example: awards, reminders, certificates, etc.).

All employee data is stored in the employee database on the date of employment and are kept up to date until the termination of employment and are kept as documentation of permanent value in accordance with the relevant regulations.

IMPERIAL RIVIERA also keeps in its database the data of other persons in a business relationship comparable to the employment relationship or persons in practice and professional development with the beginning of work and promptly leads them to termination of work and are stored in accordance with relevant regulations. A special case is the data of students in practice who may be minors of whom is taken special care and whose data is collected and stored in accordance with special regulations with the approval of the school and parents.

Salary data, payroll - are subject to special storage regulations. In any case, all workers and other persons in a business relationship comparable to the employment relationship or a person in practice and on professional development have all the rights of a data subject.

BUSINESS PARTNERS

In its business operations, IMPERIAL RIVIERA also processes data from business partners or potential business partners, which are:

  • natural persons who are, can become or have been business partners of IMPERIAL RIVIERA, e.g. craftsmen, persons who are in the regime of independent professions (e.g. lawyers, doctors, etc.), persons with whom work contracts are concluded (e.g. singers, painters, photographers, etc.) and other natural persons who have the status of entrepreneurs and
  • natural persons who in some part of the business represent legal entities with which IMPERIAL RIVIERA has, may have or had a business relationship (e.g. persons who deliver for their employer company, persons to whom invoices are sent for their employer legal entity, signatories of contracts for companies representing persons who hand over for the company, persons who organize congresses for their legal entity, etc.)

As part of the data processing of data subjects, IMPERIAL RIVIERA identified the following purposes of processing:

  • Conclusion of the contract: processing for the purpose of concluding the contract from any area of IMPERIAL RIVIERA's activity (for example: sending inquiries, sending special offers, requesting data on the signatories of the contract, sending tenders for legal entities represented by data subjects, etc.);
  • Fulfilment of the contract: data processing is necessary for the purpose of fulfilling the contract, which includes fulfilling obligations, monitoring their execution and ensuring all relevant measures for their execution (for example: to agree on time and place of delivery of equipment under the contract, to send invoices, etc.);
  • Information: data collection and processing for the purpose of quality and timely information; IMPERIAL RIVIERA has the right, based on legitimate interest, to collect certain data and use it for the purpose of direct marketing.

In addition to the stated purposes, it is possible to process personal data for other specific purposes, but always within the framework prescribed by law or if the processing is necessary for the exercise of rights and obligations arising from the business relationship.

Type of personal data collected from data subjects are:

  • Name and Surname,
  • E-mail,
  • Phone Number,
  • data on the function within the legal entity he represents (eg sales clerk, secretary of the administration, etc.),
  • occupation when the data subject is a natural person with whom a contractual relationship is entered into (for example: singer, painter, photographer, lawyer, doctor ...),
  • sometimes references and short CVs (especially for consultants),
  • data stated on the forms of blank promissory notes, promissory notes, bills of exchange,
  • bank account number (IBAN) when the business partner is a natural person with whom a contractual relationship is entered into, and
  • other information depending on the nature of the business relationship.

Places of personal data collection of data subjects:

  • received offers of data subjects for business cooperation,
  • data received from data subjects in the context of selling IMPERIAL RIVIERA products / services or purchasing products / services from a business partner (for example: fairs, congresses, etc.),
  • business correspondence related to certain previous or current business cooperation (for example, correspondence performed as part of the execution of a contract),
  • publicly published data (for example: court register, business partner websites, magazines, newsletters, etc.).

In addition to the stated type and place of data collection, it is possible to process personal data for other specific purposes, but always within the framework prescribed by law or if the processing is necessary for the exercise of rights and obligations arising from the business relationship.

Retention period

Data kept from data subjects who are natural persons in a business relationship with IMPERIAL RIVIERA are kept in accordance with applicable legal regulations (for example, IMPERIAL RIVIERA is obliged to keep all invoices, as well as the basis for issuing invoices in accordance with legal regulations. ).

In situations when IMPERIAL RIVIERA is authorized to set deadlines for data retention, they are determined taking into account the purpose of processing and the interests of data subjects to destroy the data, and this is set at a maximum of 5 years from the termination of the contractual relationship (if any).

PUBLIC ANNOUNCEMENTS

IMPERIAL RIVIERA can through its website,video walls, billboards in buildings and in other ways publish information that is of interest to existing but also potential workers, guests, business partners, and therefore the public. Such disclosures may contain a limited set of personal information, such as first and last names, functions, professional information, videos, statements and photographs.

The legal basis for processing is the legitimate interest of informing the public, but also marketing, during which the interest of the data subjects is always taken into account, so personal data is not published if it is determined that the interest of data subjects not to publish certain personal data is stronger than the interest of IMPERIAL RIVIERA to publish them. In some situations, the disclosure of information may be based on consent in accordance with the highest standards.

Announcements have a permanent character, which ensures information about current events as well as insight into previous activities.

Processing shall cease if, on the basis of the data subjects' objection, it is established that such objection is justified or if the data subject has withdrawn the consent in situations where the consent is applicable in a manner that can be enforced.

VIDEO SURVEILLANCE

IMPERIAL RIVIERA, as the processing manager, has a legitimate interest in implementing video surveillance measures to protect property and persons, and in certain cases (such as: exchange offices which are located at reception desks of the propertie), and has the legal duty to install surveillance cameras that record all persons moving around the perimeter of the surveillance camera (guests, employees, business partners, etc.).

The processing of personal data of employees via video surveillance is also enforced through conditions provided by provisions which regulate work safety.

IMPERIAL RIVIERA marks all places where video surveillance is installed in the prescribed manner.

IMPERIAL RIVIERA is aware that the videos contain personal data of all persons moving around the perimeter of the camera, and therefore keeps them with special care, has a regulated system of security, availability and deletion policy in accordance with IMPERIAL RIVIERA's internal safety rules.

Videos are automatically deleted after a maximum of 15 days from the date of recording. In case of exceptions (recording over), videos are kept for maximum period of 6 months, or longer in case law prescribes it or in case the tape is evidence in a legal, administrative, arbitration or other equivalent procedures. Videos being excepted shall be stored in centraly-informing system with extremely limited approach.

In the event of court and/or criminal proceedings, IMPERIAL RIVIERA may use these videos. Insight into personal data on videos may also be obtained by third parties, data processors, contractual partners of IMPERIAL RIVIERA registered and professional for the provision of services for the protection of persons and property, who in no way use the data independently but take care of the security of central surveillance and reporting system. Special regulations governing the area apply to all other details related to video surveillance.

FINAL PROVISIONS

This Privacy Policy is available at http://imperial-riviera.hr/uploads/privatnost/en/IR-PRIVACY-POLICY.pdf as well at the human resources offices and receptions of IMPERIAL RIVIERA's properties.

IMPERIAL RIVIERA reserves the right to change and / or amend these Privacy Policies at any time, and will update the Privacy Policy on the above media.

Valamar Obertauern GMBH privacy policy

Valamar Obertauern GmbH with its headquarters at Gamsleitenstrasse 6, 5562 Obertauern, Austria, FN 195893d, UID AT U50245104, (hereinafter: OBERTAUERN or we or our or controller) as owner of Valamar Obertauern Hotel 4*, respects the privacy of every person from whom collects personal data. We would like to inform you about what personal data we collect as the data controller, for what purpose, how we protect the data and what your rights are.

DATA CONTROLLER AND LEGAL FRAMEWORK

As the data controller, OBERTAUERN is committed to protect your personal data. The collection and storage of data is carried out in accordance with the provisions of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: Regulation), TKG (Telecommunications Law 2021) and other regulations governing the subject area, which are applied in the Republic of Austria.

SCOPE OF APPLICATION

This Policy applies to any processing of personal data performed by OBERTAUERN as the data controller, unless another policy or other OBERTAUERN document prescribes otherwise for a particular processing.

This Policy is divided into two parts: The General Section and the Specific section.

The basic principles of personal data processing, contact details and other provisions specified in the General Section of this Policy are applied without exception to any personal data processing regardless of whether such processing is specifically processed in the Specific Section of this Policy or not.

The Specific Section of the Policy deals, in more detail, with specific cases of data processing which represent the majority of all processing by OBERTAUERN.

CONTACT FOR DATA PROTECTION REQUESTS

Regarding issues related to personal data protection and for exercising their rights guaranteed by the Regulation please contact OBERTAUERN at any time via e-mail:dsgvo.obertauern@valamar.at or by mail to the address OBERTAUERN, 5562 Obertauern, Gamsleitenstrasse 6.

All requests not related to data protection, which are delivered to this address, e.g. offers of job candidates, booking inquiries in Hotel Valamar Obertauern 4*, etc. will be provided directly to the relevant departments.

PERSONAL DATA PROTECTION PRINCIPLES

OBERTAUERN has recognized the principles of data processing as basic values that must be respected throughout the cycle of personal data processing, from their collection to their destruction or other cessation of processing. OBERTAUERN processes data:

  • Lawfully - by processing data only if allowed by law and within the limits prescribed by law.
  • Fairly - by considering the specifics of each relationship, applying all appropriate measures to protect personal information and privacy in general and not impeding data subjects in exercising their rights.
  • Transparently - by informing data subjects about the processing of personal data. From the start of the data collection process, when data subjects are informed about all aspects of data processing, until its termination, data subjects are provided easy and fast access to their own data.
  • Purpose limitation - by processing personal data for the purposes they were collected for and for other purposes only if the conditions of the Regulation are met. Data may be processed for matching purposes only considering (a) any link between the purposes of the collection of personal data and the purposes of the intended continuation of the processing; (b) the context in which the personal data was collected, in particular concerning the relationship between the data subjects and OBERTAUERN; (c) the nature of the personal data; (d) the possible consequences of the intended continuation of processing for the data subjects; and (e) the existence of appropriate protection measures.
  • Storage limitation - by storing data in a form which permits identification of data subjects for no longer than is necessary for the initial purposes, and longer only if permitted by the Regulation.
  • Data minimization - by processing data if it is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Particular attention is given to not collecting data for which there is no justifiable reason for processing.
  • Accuracy - by keeping data accurate and up-to-date, and erasing inaccurate data in the scope of possibility.
  • Integrity and Confidentiality - by using appropriate technical and organisational measures to ensure appropriate personal data protection, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. Relevant measures are applied considering the risk of each type of data processing.

LEGALITY OF PERSONAL DATA PROCESSING

In order to respect the lawfulness of processing personal data, OBERTAUERN processes personal data only if and to the extent that at least one of the following is met:

  • Processing is necessary for the performance of the contract to which the data subject is a party or in order to act at the request of the data subject prior to the conclusion of the contract; this is the most common purpose of data processing with an existing contractual relationship or a contractual relationship in negotiations as its basis.
  • Processing is necessary to comply with the legal obligations of the data controller. As a legal entity, OBERTAUERN has a number of obligations prescribed by various regulations. This obligation includes the collection and often the submission of data to public authorities.
  • Processing is necessary for the legitimate interests of the data controller or a third party, except where those interests are stronger than the interests or fundamental rights and freedoms of data subjects requiring the protection of personal data, considering reasonable expectations of data subjects based on their relationship with the data controller, especially if the data subject is a child. In applying this legal basis, OBERTAUERN assesses that the processing is appropriate to business needs, that it is the least invasive as possible and that the interests of the data subjects do not exceed the legitimate interests of OBERTAUERN or a third party. Examples of such processing are processing for administrative purposes, the purposes of maintaining computer network security. The data subject always has the right to object to such processing in these situations.
  • Processing is necessary to protect key interests of the data subject or other natural person.The right to personal data protection is not an absolute right and OBERTAUERN equates it with other fundamental rights in accordance with the principle of proportionality.
  • The data subject has consented to the processing of his or her personal data for one or more specific purposes. When processing personal data on the basis of consent, OBERTAUERN provides that these are situations in which there are no, formal or informal, consequences for giving, refusing or denying consent. When processing is based on consent, the data subject may withdraw consent at any time without negative consequences. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

TYPES OF PERSONAL DATA PROCESSED

Specific categories of personal data: shall be processed only if the conditions set out in Article 9 of the Regulation are met.

Data relating to criminal convictions and offenses: shall be processed only under the control of official authority and in accordance with Article 10 of the Regulation.

Personal data that are not included in the previous two groups: that kind of data makes most of the processed data. The most common types of data are identification and contact data such as name, surname, e-mail address and data that are related with your relation with us (accommodation etc.).

Most of the personal data that we collect is provided by the data subjects themselves. Therefore, we kindly ask you that you do not provide sensitive information (such as race or ethnic origin, political opinions, religious or philosophical beliefs, etc.) when this is not necessary. If you nevertheless provide sensitive information for any reason, you hereby give your express consent to the collection and use of such information in the ways described in these Policy or in the manner described at the time of disclosure of that information.

THE ROLE OF VALAMAR RIVIERA d.d.

OBERTAUERN concluded with the company Valamar Riviera d.d. with its registered office in Poreč, Stancija Kaligari 1 OIB: 36201212847 (hereinafter: Valamar) Contract in relation to the management of hotel and tourist facilities and contents (hereinafter: Management contract) based on which Valamar manages certain business segments of OBERTAUERN.

Due to such Management contract, when managing Hotel Valamar Obertauern 4*, Valamar sometimes directly manages certain activities, including the management of some of the activities described in the Special Section of this Privacy Policy, in particular Valamar can process the personal data of the guests for providing the sales and marketing services. In addition, Valamar sometimes receives data from OBERTAUERN and has a right of access to relevant data base to perform certain activities where it subsequently comes to personal data processing.

For example, Valamar can manage the reservation function through the Valamar reservation center (call center) and via the websites www.valamar.com, and in these cases Valamar is an independent data controller (and data subjects will be informed on the spot about that fact) however, all this information related to Hotel Valamar Obertauern 4* are and have to be also processed by OBERTAUERN as an owner and independent data controller.

Furthermore, Valamar has a legitimate interest in processing of personal data carried out for the purposes of direct marketing, primarily for the purpose of sending marketing messages (newsletters) by e-mail, SMS and / or instant messaging platform (Viber, Whatsapp, etc.). Based on a legitimate interest, Valamar may send different newsletters depending on the relationship that respondents have with Valamar or the facilities under Valamar's management. For this purpose, personal data is collected from guests and persons who have asked for an offer or booked accommodation, persons who have participated in the prize game (if there will be any), joined the Valamar`s loyalty program, filled out a satisfaction questionnaire about accommodation in or otherwise had a relationship with Valamar.

Following the above, in certain cases Hotel Valamar Obertauern 4* guests can expect to receive from Valamar newsletters containing information about all other hotels and facilities managed by Valamar, as well as accommodation quality questionnaires and other service e-mails. For Hotel Valamar Obertauern 4* guests, prize games can be organized from time to time, which can be organized by Valamar, in which case guests personal data will be collected only if guests decide to participate in the prize game.

Valamar's Plus Club Loyalty Program can be applied for the OBERTAUERN. The conditions of membership are contained in Valamar's loyalty programme terms and conditions, which can be found at https://www.valamar.com/cmsmedia/loyalty/terms-conditions-en.pdf .

Also, based on the Management contract, Valamar has certain rights and obligations related to human resources, so in these cases Valamar has the right to process personal data of employees and candidates for employment in OBERTAUERN for the purpose of managing the business processes in the Hospitality Operations.

When Valamar acts as the data controller, the Valamar Privacy Policy applies, which can be found at: https://www.valamar.com/en/privacy-policy / https://www.valamar.com/hr/izjava-o-privatnosti.

DATA DELIVERY TO THIRD ENTITIES

OBERTAUERN shares personal information with others only when permitted.

OBERTAUERN is obliged by law to provide data to third parties. For example, delivering guest data and employee data to the competent institutions.

It is possible to deliver data to business entities, processors, who process the data upon instruction of OBERTAUERN, which acts as the data processor. Most often, these are OBERTAUERN's business partners who provide IT services, who store certain data in their databases or have the possibility of accessing personal data until the end of processing. In that cases a detailed contract shall be concluded with such subjects regarding their powers and obligations in the processing of personal data, in accordance with the requirements of the Regulation.

In certain situations, it is possible for external entities and OBERTAUERN to jointly determine the purposes and methods of personal data processing, in which case these external partners and OBERTAUERN are joint data controllers. In these relations, the joint data controllers shall transparently determine their responsibilities for complying with the obligations under the Regulation, in particular with regard to the exercise of data subject`s rights and their duties to respect the transparency of processing, unless responsibilities are established by law.

A special case of data delivery to third parties is the fact that OBERTAUERN has the Management contract with Valamar (see chapter: ROLE OF VALAMAR RIVIERA d.d.).

If data are transferred to third countries as part of data processing, OBERTAUERN ensures compliance with high protection standards in order to comply with the highest possible standard of personal data protection, in accordance with the strict requirements of the Regulation. Any transfer of personal data to third countries will be carried out in accordance with Chapter V of the Regulation.

DATA STORAGE RETENTION

Personal data are processed and stored for the period in accordance with applicable legal regulations when the retention obligation is prescribed (for example, accounting documents), and in situations where OBERTAUERN is authorized to set retention periods, data is stored as long as necessary for the purposes for which personal data is processed taking into account the purpose of processing, the legitimate interests of OBERTAUERN and the interests of the data subjects to delete the data.

RIGHTS OF THE DATA SUBJECTS

Regardless of the basis for data collection, all data subjects can exercise the following rights free of charge within the limits prescribed by the Regulation:

Right to information: The data subject has the right to be informed about the processing and its purposes. OBERTAUERN provides the data subjects with all the information necessary to ensure fair and transparent processing, considering the context of processing.

Right to erasure (“right to be forgotten”): The data subject has the right to request to delete personal data relating to him/her, without undue delay in accordance with the terms of the Regulation. To do so, please send your request to us in writing, including an electronic form of communication. Please note that the request needs to specify what you wish to be deleted, since we can store your data on different legal bases. You have the right to request the deletion of personal data relating to you where one of the following grounds applies:

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • the data subject withdraws consent on which the processing is based, and where there is no other legal ground for the processing;
  • the data subject objects to the processing pursuant and there are no overriding legitimate grounds for the processing, or the data subject objects;
  • the personal data have been unlawfully processed;
  • the personal data have to be erased for compliance with a legal obligation;
  • the personal data have been collected in relation to the offer of information society services.

In some cases, it will not be possible to fully comply with the deletion request, for example when there is a legal obligation for retention, when the legitimate interest of the controller is stronger than the interest of the data subjects, when there is an interest of the data controller to set, enforce or defend legal claims.

Right of access: The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
  • the right to lodge a complaint with a supervisory authority;
  • where the personal data are not collected from the data subject, any available information as to their source;
  • the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form. The right to obtain a copy shall not adversely affect the rights and freedoms of others.

Right to rectification: The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Considering the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Right to data portability: The data subject has the right to receive personal data relating to him in a structured, commonly used and machine-readable format in accordance with the requirements of the Article 20 of Regulation.

Right to object: The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on public interest and legitimate interests, including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.

Right to restriction of processing: The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:

  • the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;
  • the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
  • the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
  • the data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject.

In any case, data subjects also have the right to:

  • to submit a complaint time via e-mail: dsgvo.obertauern@valamar.at or by mail to the address OBERTAUERN Gmbh, Gamsleitenstrasse 6, 5562 Obertauern, Austria
  • to lodge a complaint with a supervisory authority (Austrian Data Protection Authority) if they believe that their rights to data protection have been violated.

OBERTAUERN as the data controller has the right to protect the interests of the data controller as well as the protection of the data subjects and accordingly has the right to carry out the activities of establishing the identity of the applicant. OBERTAUERN has the right to publish a form that will be used to submit a request in order to process the request as efficiently as possible.

On request, OBERTAUERN provides information on the actions taken in relation to the exercise of data subject's rights without undue delay and in any case within one month from the date of receipt of the request. This period may be extended by an additional two months, considering the complexity and number of applications. OBERTAUERN shall notify the data subject of any such extension within one month from the date of receipt of the request, together with the reasons for the postponement.

If the data subject submits the request electronically, OBERTAUERN provides the information electronically if possible, unless the data subject requests otherwise.

The data subject's request is generally free of charge, but if the data subject's request is manifestly unfounded or excessive, and in particular because of their frequent repetition, OBERTAUERN is entitled to charge a reasonable fee based on administrative costs or refuse to act on the request.

PROTECTION OF PERSONAL DATA OF CHILDREN

OBERTAUERN advises parents and guardians to teach children about safe and responsible handling of personal data, especially on the Internet. In relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.

PERSONAL DATA SOURCES

OBERTAUERN receives personal data most often from data subjects. When providing personal data to OBERTAUERN, in any way (booking accommodation, job application…) you guarantee that the information you have provided is correct, that you are legally capable and authorized to dispose of the given information and that you fully agree that OBERTAUERN collects and uses your data in accordance with the regulations and terms of this Privacy Policy.

Also, OBERTAUERN receives personal data from other natural and legal persons, for example: from Valamar as a company that manages certain business aspects of business, from travel agencies that forward guest data for accommodation, guests who book accommodation for people with whom they will stay in hotel, agency for employment mediation and assignment of workers, from the holder of accommodation reservations for others guests for whom the reservation is made.

When providing personal data of other persons to OBERTAUERN, you guarantee that the information you provide is accurate, that you are legally capable and authorized to dispose of the information, that respondents whose personal data you forward to us agree that OBERTAUERN uses and collects their data in accordance with positive regulations and the terms of this Privacy Policy.

TECHNICAL AND INTEGRATED DATA PROTECTION

OBERTAUERN, as data controller, provides the highest organizational and technical standards of data protection. Therefore, considering the latest developments, the cost of implementation and the nature, scope, context and purposes of processing, as well as risks of different levels of probability and seriousness for the rights and freedoms of individuals arising from data processing, at the time of processing, appropriate technical and organizational measures to enable the effective application of the principles of data protection are applied.

Also, OBERTAUERN implements appropriate technical and organizational measures to ensure that only personal data necessary for each specific purpose of processing are processed in an integrated manner. OBERTAUERN applies this measure to the amount of personal data collected, the scope of their processing, the retention period and their availability. Specifically, such measures ensure that personal data is not automatically, without the intervention of an individual, available to an unlimited number of individuals.

DATA BREACH

In the case of a personal data breach, as the data controller, OBERTAUERN shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.

The report submitted to the supervisory authority shall contain all information prescribed by the Regulation.

In the event of a personal data breach that is likely to pose a high risk to the rights and freedoms of individuals, OBERTAUERN, as the data controller, shall inform the data subjects of the personal data breach without undue delay. Sometimes, in cases where the Regulation prescribes, informing data subjects is not mandatory.

Special section

ACCOMMODATION

OBERTAUERN'S main business activity is the provision of accommodation services in its Hotel Valamar Obertauern 4*. Therefore, OBERTAUERN collects and processes your personal data for various purposes with the ultimate goal of providing quality accommodation and related services all according to the highest standards of tourism companies.

OBERTAUERN, as the data controller, stores your personal data that you must provide for accommodation services in its database for the purpose of fulfilling accommodation contracts and fulfilling legal obligations related to the hospitality business. In case you do not provide OBERTAUERN with the minimum data required for booking accommodation and for the registration to all competent registers, OBERTAUERN will not be able to provide you with booking services or accommodation services in accordance with the contract and law.

Certain information is necessary in order to act at the request of the data subject before concluding the accommodation contract. For example, before booking accommodation at the request of potential guests, you have to receive offer, for which personal data is needed, at least name, surname and e-mail address in order to be able to send an offer.

The personal data that OBERTAUERN collects when booking in order to fulfil the reservation obligation usually are:

  • Name and surname of the reservation holder
  • Date of birth
  • Number, type of identification document and place of issue
  • Citizenship
  • Number of accommodation units, type of accommodation unit (room type)
  • Date of arrival and departure
  • Number of persons per accommodation unit
  • Minors
  • Possibly other specifics depending on the request of the person booking the accommodation
  • e-mail if the person has one
  • Language
  • Phone number
  • Membership in the Valamar`s Loyalty program, if it affects the price of accommodation or collecting points
  • Payment method and possible additional information needed to execute the transaction or secure payment. In case of cancellation, we must save your data for the purpose of proving the reservation or cancellation.

Upon arrival at the Hotel OBERTAUERN 4*, guests have to check in and confirm data.

In addition, OBERTAUERN is obliged to keep all invoices, as well as the basis for issuing invoices issued to guests with personal data of the guest in accordance with legal regulations.

Other data related to the circumstances of your stay such as: mode of travel, who you are traveling with, marital status, number of children, pets, other interests, will also be collected and processed during your stay only when they have a direct connection with the accommodation service.

Before, during and after the stay OBERTAUERN as the data controller has the right based on the legitimate interest to send you so-called service messages – booking confirmations, reminders and other information closely related to the specific stay you have booked. Also, during and after the stay, OBERTAUERN as the data controller has the right based on the legitimate interest to send to you guest questionnaires about service satisfaction via e-mail, sms and/or instant messaging platforms (viber, whatsapp, etc.) which will be processed by us or through associates. The primary purpose of the service satisfaction questionnaire is to collect service data for the legitimate interest of service improvement by OBERTAUERN, and OBERTAUERN may depersonalize and process this data from the questionnaire for statistical purposes.

OBERTAUERN has the right, based on a legitimate interest, to collect certain data and use it for direct marketing.

Service messages and messages with service satisfaction questionnaires related to a specific stay of the guest are not considered newsletters for the purpose of sending OBERTAUERN marketing offers and news.

VIDEO SURVEILLANCE

OBERTAUERN as the data controller, has a legitimate interest in implementing video surveillance measures to protect property and persons. We marked all places where video surveillance is installed in the prescribed manner. We are aware that the videos contain personal data of all persons moving around the perimeter of the camera, and therefore we keep them with special care, we have a regulated system of security, availability and our internal safety rules. Special regulations governing the area apply to all other details related to video surveillance.

GETTING IN CONTACT WITH US

When you contact us via email or via one of the forms on our website, data are processed and stored, in accordance with the purpose of processing.

FINAL PROVISIONS

This Privacy Policy is available at Valamar Riviera d.d. website https://www.valamar.com/en/privacy-policy-valamar-obertauern and also at reception of Hotel Valamar Obertauern 4*, (when hotel is operating).

Kesselspitze GmbH & Co KG privacy policy

GENERAL SECTION

DATA CONTROLLER AND LEGAL FRAMEWORK

As the data controller, KESSELSPITZE, is committed to protecting your personal data. The collection and storage of data is carried out in accordance with the provisions of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: “the Regulation”), TKG (Telecommunications Law 2021) and other regulations governing the subject area, which are applied in the Republic of Austria.

SCOPE OF APPLICATION

This Policy applies to any processing of personal data performed by KESSELSPITZE as the data controller, unless another policy or other KESSELSPITZE document prescribes otherwise for particular processing.

This Policy is divided into two parts: the General Section and the Specific Section.

The basic principles of personal data processing, contact details and other provisions specified in the General Section of this Policy are applied without exception to any personal data processing, regardless of whether such processing is specifically processed in the Specific Section of this Policy or not.

The Specific Section of the Policy deals, in more detail, with specific cases of data processing that represent the majority of all processing by KESSELSPITZE.

CONTACT FOR DATA PROTECTION REQUESTS

Regarding issues related to personal data protection and for the exercising of rights guaranteed by the Regulation, please contact KESSELSPITZE at any time via e-mail: dsgvo.kesselspitze@valamar.at or by mail to the address Kesselspitze GmbH & Co KG, 5562 Obertauern, Alpenstraße 1.

All requests not related to data protection that are delivered to this address, e.g. offers of job candidates, booking inquiries for Hotel Kesselspitze 5*, etc. will be forwarded directly to the relevant departments.

PERSONAL DATA PROTECTION PRINCIPLES

KESSELSPITZE has recognised the principles of data processing as basic values that must be respected throughout the cycle of personal data processing, from their collection to their destruction or other cessation of processing. KESSELSPITZE processes data observing:

  • Lawfulness - by processing data only if allowed by law and within the limits prescribed by law.
  • Fairness – by considering the specifics of each relationship, applying all appropriate measures to protect personal information and privacy in general and not impeding data subjects in exercising their rights.
  • Transparency – by informing data subjects about the processing of personal data. From the start of the data collection process, when data subjects are informed about all aspects of data processing, until its termination, data subjects are provided easy and fast access to their own data.
  • Purpose limitation – by processing personal data for the purposes for which they were collected and for other purposes only if the conditions of the Regulation have been met. Data may be processed for matching purposes only considering (a) any link between the purposes of the collection of personal data and the purposes of the intended continuation of the processing; (b) the context in which the personal data was collected, in particular concerning the relationship between the data subjects and KESSELSPITZE; (c) the nature of the personal data; (d) the possible consequences for the data subjects of the intended continuation of processing; and (e) the existence of appropriate protection measures.
  • Storage limitation – by storing data in a form which permits identification of data subjects for no longer than is necessary for the initial purposes, and longer only if permitted by the Regulation.
  • Data minimisation – by processing data if adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Particular attention is given to not collecting data for whose processing there is no justifiable reason.
  • Accuracy – by keeping data accurate and up to date, and erasing inaccurate data within the scope of possibility.
  • Integrity and Confidentiality – by using appropriate technical and organisational measures to ensure appropriate personal data protection, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. Relevant measures are applied considering the risk of each type of data processing.

LEGALITY OF PERSONAL DATA PROCESSING

In order to respect the lawfulness of processing personal data, KESSELSPITZE processes personal data only if and to the extent that at least one of the following criteria is met:

  • Processing is necessary for the performance of the contract to which the data subject is a party or in order to act at the request of the data subject prior to the conclusion of the contract; this is the most common purpose of data processing, with an existing contractual relationship or a contractual relationship in negotiation as its basis.
  • Processing is necessary to comply with the legal obligations of the data controller. As a legal entity, KESSELSPITZE has a number of obligations prescribed by various regulations. These obligations include the collection and often the submission of data to public authorities.
  • Processing is necessary for the legitimate interests of the data controller or a third party, except where those interests take precedence over the interests or fundamental rights and freedoms of data subjects requiring the protection of personal data, considering reasonable expectations of data subjects based on their relationship with the data controller, especially if the data subject is a child. In applying this legal basis, KESSELSPITZE assesses that the processing is appropriate to business needs, that it is the least invasive possible and that the interests of the data subjects do not exceed the legitimate interests of KESSELSPITZE or a third party. Examples of such processing are processing for administrative purposes, or the purposes of maintaining computer network security. The data subject always has the right to object to such processing in these situations.
  • Processing is necessary to protect key interests of the data subject or other natural person. The right to personal data protection is not an absolute right and KESSELSPITZE equates it with other fundamental rights in accordance with the principle of proportionality.
  • The data subject has consented to the processing of his or her personal data for one or more specific purposes. When processing personal data on the basis of consent, KESSELSPITZE provides that these are situations in which there are no formal or informal consequences for giving, refusing or denying consent. When processing is based on consent, the data subject may withdraw consent at any time without negative consequences. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

TYPES OF PERSONAL DATA PROCESSED

Special categories of personal data: shall be processed only if the conditions set out in Article 9 of the Regulation are met.

Data relating to criminal convictions and offences shall be processed only under the control of an official authority and in accordance with Article 10 of the Regulation.

Personal data that are not included in the previous two groups: the kind of data that makes up most processed data. The most common types of data are identification and contact data such as name, surname, e-mail address and data that are related to your relation with us (accommodation etc.).

Most of the personal data that we collect is provided by the data subjects themselves. Therefore, we kindly ask you that you do not provide sensitive information (such as race or ethnic origin, political opinions, religious or philosophical beliefs, etc.) when this is not necessary. If you nevertheless provide sensitive information for any reason, you thereby give your express consent to the collection and use of such information in the ways described in this Policy or in the manner described at the time of disclosure of that information.

THE ROLE OF VALAMAR RIVIERA d.d.

KESSELSPITZE concluded with the company Valamar Riviera d.d. with its registered office in Poreč, Stancija Kaligari 1 OIB: 36201212847 (hereinafter: “Valamar”) a Contract in relation to the management of hotel and tourist facilities and contents (hereinafter: “Management Contract”) on the basis of which Valamar manages certain business segments of KESSELSPITZE.

As a result of the said Management Contract, when managing Hotel Kesselspitze 5*, Valamar sometimes directly manages certain activities, including the management of some of the activities described in the Special Section of this Privacy Policy, and in particular Valamar may process the personal data of the guests for providing sales and marketing services. In addition, Valamar sometimes receives data from KESSELSPITZE and has a right of access to relevant data bases to perform certain activities where it subsequently comes to personal data processing.

For example, Valamar may manage the reservation function through the Valamar reservation centre (call centre) and via the website www.valamar.com, and in these cases Valamar is an independent data controller (and data subjects will be informed on the spot about that fact); however, all this information related to Hotel Kesselspitze 5* is and has to be also processed by KESSELSPITZE as owner and an independent data controller.

Furthermore, Valamar has a legitimate interest in the processing of personal data carried out for the purposes of direct marketing, primarily for the purpose of sending marketing messages (newsletters) by email, SMS and/or instant messaging platform (Viber, Whatsapp, etc.). On the basis of legitimate interest, Valamar may send different newsletters depending on the relationship that respondents have with Valamar or the facilities under Valamar’s management. For this purpose, personal data is collected from guests and persons who have asked for an offer or booked accommodation, persons who have participated in a prize game (should there be one), joined the Valamar loyalty programme, filled out a satisfaction questionnaire about accommodation or otherwise had a relationship with Valamar.

Following the above, in certain cases Hotel Kesselspitze 5* guests can expect to receive from Valamar newsletters containing information about all other hotels and facilities managed by Valamar, as well as accommodation quality questionnaires and other service emails. For Hotel Kesselspitze 5* guests, prize games can be organised from time to time by Valamar, in which case guests’ personal data will be collected only if guests decide to participate in the prize game.

Valamar’s Plus Club Loyalty Programme can be applied for KESSELSPITZE. The conditions of membership are contained in Valamar’s loyalty programme terms and conditions, which can be found at https://www.valamar.com/cmsmedia/loyalty/terms-conditions-en.pdf .

Also, on the basis of the Management Contract, Valamar has certain rights and obligations related to human resources, so in these cases Valamar has the right to process personal data of employees and candidates for employment in KESSELSPITZE for the purpose of managing the business processes in its hospitality operations.

When Valamar acts as the data controller, the Valamar Privacy Policy applies, which can be found at: https://www.valamar.com/en/privacy-policy / https://www.valamar.com/hr/izjava-o-privatnosti.

DATA DELIVERY TO THIRD ENTITIES

KESSELSPITZE shares personal information with others only when permitted.

KESSELSPITZE is obliged by law to provide data to third parties, for example, delivering guest data and employee data to the competent institutions.

It is possible to deliver data to business entities – processors – who process the data upon the instruction of KESSELSPITZE, which acts as the data processor. Most often, these are KESSELSPITZE’s business partners who provide IT services, and who store certain data in their databases or have the opportunity to access personal data until the end of processing. In these cases a detailed contract shall be concluded with such subjects regarding their powers and obligations in the processing of personal data, in accordance with the requirements of the Regulation.

In certain situations, it is possible for external entities and KESSELSPITZE to jointly determine the purposes and methods of personal data processing, in which cases these external partners and KESSELSPITZE are joint data controllers. In these relations, the joint data controllers shall determine their responsibilities for complying with their obligations under the Regulation transparently, in particular with regard to the exercise of data subjects’ rights and their duties to respect the transparency of processing, unless such responsibilities are established by law.

A special case of data delivery to third parties is the fact that KESSELSPITZE has the Management Contract with Valamar (see chapter: ROLE OF VALAMAR RIVIERA d.d.).

If data are transferred to third countries as part of data processing, KESSELSPITZE ensures compliance with high protection standards in order to comply with the highest possible standard of personal data protection, in accordance with the strict requirements of the Regulation. Any transfer of personal data to third countries will be carried out in accordance with Chapter V of the Regulation.

DATA STORAGE PERIOD

Personal data are processed and stored for the period in accordance with applicable legal regulations when the retention obligation is prescribed (for example, accounting documents), and in situations where KESSELSPITZE is authorised to set retention periods, data is stored as long as necessary for the purposes for which personal data is processed taking into account the purpose of processing, the legitimate interests of KESSELSPITZE and the interests of the data subjects in the deletion of the data.

RIGHTS OF THE DATA SUBJECTS

Regardless of the basis for data collection, all data subjects can exercise the following rights free of charge within the limits prescribed by the Regulation:

Right to information: The data subject has the right to be informed about the processing and its purposes. KESSELSPITZE provides the data subjects with all the information necessary to ensure fair and transparent processing, considering the context of processing.

Right to erasure („right to be forgotten“): The data subject has the right to request the deletion of personal data relating to him/her, without undue delay, in accordance with the terms of the Regulation. Should you wish this to take place, please send your request to us in writing, including an electronic form of communication. Please note that the request needs to specify what you wish to be deleted, since we can store your data on different legal bases. You have the right to request the deletion of personal data relating to you where one of the following grounds applies:

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • the data subject withdraws the consent upon which the processing is based, and where there is no other legal ground for the processing;
  • the data subject objects to the processing pursuant and there are no overriding legitimate grounds for the processing, or the data subject objects ;
  • the personal data have been unlawfully processed;
  • the personal data must be erased for compliance with a legal obligation;
  • the personal data have been collected in relation to the offer of information society services.

In some cases, it will not be possible to fully comply with the deletion request, for example when there is a legal obligation for retention, when the legitimate interest of the controller takes precedence over the interest of the data subjects or when there is an interest of the data controller to set, enforce or defend legal claims.

Right of access: The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
  • where possible, the envisaged period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period;
  • the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
  • the right to lodge a complaint with a supervisory authority;
  • where the personal data have not been collected from the data subject, any available information as to their source;
  • the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form. The right to obtain a copy shall not adversely affect the rights and freedoms of others

Right to rectification: The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Considering the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Right to data portability: The data subject has the right to receive personal data relating to him or her in a structured, commonly used and machine-readable format in accordance with the requirements of Article 20 of the Regulation.

Right to object: The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time, to the processing of personal data concerning him or her that is based on public interest and legitimate interests, including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.

Right to restriction of processing: The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:

  • the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;
  • the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
  • the controller no longer needs the personal data for the purposes of processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
  • the data subject has objected to processing pending the verification of whether the legitimate grounds of the controller override those of the data subject.

In any case, data subjects also have the right:

  • to submit a complaint time via email: dsgvo.kesselspitze@valamar.at or by mail to the address Kesselspitze GmbH & Co KG, 5562 Obertauern, Alpenstraße 1
  • to lodge a complaint with a supervisory authority (Austrian Data Protection Authority) if they believe that their rights to data protection have been violated.

KESSELSPITZE as the data controller has the right to protect the interests of the data controller as well as maintain the protection of the data subjects and accordingly has the right to carry out the activities of establishing the identity of the applicant. KESSELSPITZE has the right to publish a form that will be used to submit a request in order to process the request as efficiently as possible.

On request, KESSELSPITZE provides information on the actions taken in relation to the exercise of data subject’s rights without undue delay and in any case within one month from the date of receipt of the request. This period may be extended by an additional two months, considering the complexity and number of applications. KESSELSPITZE shall notify the data subject of any such extension within one month of the date of receipt of the request, together with the reasons for the postponement.

If the data subject submits the request electronically, KESSELSPITZE provides the information electronically if possible, unless the data subject requests otherwise.

The data subject’s request is generally not charged, but if the data subject’s request is manifestly unfounded or excessive, and in particular in the event of its frequent repetition, KESSELSPITZE is entitled to charge a reasonable fee based on administrative costs or refuse to act on the request.

PROTECTION OF PERSONAL DATA OF CHILDREN

KESSELSPITZE advises parents and guardians to teach children about safe and responsible handling of personal data, especially on the internet. In relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.

PERSONAL DATA SOURCES

KESSELSPITZE receives personal data most often from data subjects. When providing personal data to KESSELSPITZE in any way (booking accommodation, job application, etc.), you guarantee that the information you have provided is correct, that you are legally capable and authorised to dispose of the given information and that you fully agree that KESSELSPITZE may collect and use your data in accordance with the regulations and terms of this Privacy Policy.

Also, KESSELSPITZE receives personal data from other natural and legal persons, for example from Valamar as a company that manages certain commercial aspects of business, from travel agencies that forward guest data for accommodation, guests who book accommodation for people with whom they will stay in the hotel, agencies for employment mediation and the assignment of workers, and from the holder of accommodation reservations for others’ guests, for whom the reservation is made.

When providing the personal data of other persons to KESSELSPITZE, you guarantee that the information you provide is accurate, that you are legally capable and authorised to dispose of the information, and that the respondents whose personal data you forward to us agree that KESSELSPITZE may use and collect their data in accordance with positive regulations and the terms of this Privacy Policy.

TECHNICAL AND INTEGRATED DATA PROTECTION

KESSELSPITZE, as data controller, provides the highest organisational and technical standards of data protection. Therefore, considering the latest developments, the cost of implementation and the nature, scope, context and purposes of processing, as well as risks of different levels of probability and seriousness for the rights and freedoms of individuals arising from data processing, at the time of processing, appropriate technical and organisational measures to enable the effective application of the principles of data protection are applied.

Also, KESSELSPITZE implements appropriate technical and organisational measures to ensure that only personal data necessary for each specific processing purpose are processed in an integrated manner. KESSELSPITZE applies this measure to the amount of personal data collected, the scope of their processing, the retention period and their availability. Specifically, such measures ensure that personal data is not automatically, without the intervention of an individual, available to an unlimited number of individuals.

DATA BREACH

In the case of a personal data breach, as the data controller, KESSELSPITZE shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the competent supervisory authority, unless the personal data breach is unlikely to result in risk to the rights and freedoms of natural persons.

The report submitted to the supervisory authority shall contain all information prescribed by the Regulation.

In the event of a personal data breach that is likely to pose a high risk to the rights and freedoms of individuals, KESSELSPITZE, as the data controller, shall inform the data subjects of the personal data breach without undue delay. Sometimes, in cases where the Regulation prescribes, informing data subjects is not mandatory.

SPECIAL SECTION


ACCOMMODATION

KESSELSPITZE’s main business activity is the provision of accommodation services in its Hotel Kesselspitze 5*. Therefore, KESSELSPITZE collects and processes your personal data for various purposes with the ultimate goal of providing quality accommodation and related services all according to the highest standards of tourism companies.

KESSELSPITZE, as the data controller, stores the personal data that you must provide for accommodation services in its database for the purpose of fulfilling accommodation contracts and fulfilling legal obligations related to the hospitality business. In the event you do not provide KESSELSPITZE with the minimum data required for booking accommodation and for the registration to all competent registers, KESSELSPITZE will not be able to provide you with booking services or accommodation services in accordance with the contract and law.

Certain information is necessary in order to act at the request of the data subject before concluding the accommodation contract. For example, before booking accommodation at the request of potential guests, you have to receive an offer, for which personal data is needed: at least name, surname and e-mail address.

The personal data that KESSELSPITZE collects when booking in order to fulfil the reservation obligation usually are:

  • Name and surname of the reservation holder
  • Date of birth
  • Number, type and place of issue of identification document
  • Citizenship
  • Number of accommodation units and type of accommodation unit (room type)
  • Date of arrival and departure
  • Number of persons per accommodation unit
  • Minors
  • Possibly other specifics depending on the request of the person booking the accommodation
  • email address, if the person has one
  • Language
  • Phone number
  • membership in the Loyalty program, if it affects the price of accommodation or collecting points
  • Payment method and possible additional information needed to execute the transaction or secure payment. In case of cancellation, we must save your data for the purpose of proving the reservation or cancellation.

Upon arrival at the Hotel Kesselspitze 5*, guests have to check in and confirm data.

In addition, KESSELSPITZE is obliged to keep all invoices, as well as the basis for issuing invoices issued to guests with the personal data of each guest in accordance with legal regulations.

Other data related to the circumstances of your stay, such as mode of travel, with whom you are travelling, marital status, number of children, pets, and other interests, will also be collected and processed during your stay only when they have a direct connection with the accommodation service.

Before, during and after your stay KESSELSPITZE as the data controller has the right based on legitimate interest to send you so-called service messages – booking confirmations, reminders and other information closely related to the specific stay you have booked. Also, during and after the stay, KESSELSPITZE as the data controller has the right based on legitimate interest to send to you guest questionnaires about service satisfaction via email, SMS and/or instant messaging platforms (Viber, Whatsapp, etc.) which will be processed by us or through associates. The primary purpose of the service satisfaction questionnaire is to collect service data for the legitimate interest of service improvement by KESSELSPITZE, and KESSELSPITZE may depersonalise and process this data from the questionnaire for statistical purposes.

KESSELSPITZE has the right, based on legitimate interest, to collect certain data and use it for direct marketing.

Service messages and messages with service satisfaction questionnaires related to a specific stay of the guest are not considered newsletters for the purpose of sending KESSELSPITZE marketing offers and news.

VIDEO SURVEILLANCE

KESSELSPITZE as the data controller has a legitimate interest in implementing video surveillance measures to protect property and persons. We have marked all places where video surveillance is installed in the prescribed manner. We are aware that the videos contain personal data of all persons moving around the perimeter of the camera, and therefore we keep them with special care: we have a regulated system of security, availability and our internal safety rules. Special regulations governing the area apply to all other details related to video surveillance.

GETTING IN CONTACT WITH US

When you contact us via email or via one of the forms on our website, data are processed and stored in accordance with the processing purpose.

WEBSITE, COOKIES AND INTERNET TECHNOLOGIES

Our website uses so-called cookies. A cookie is a small text file that is saved to your browser on your computer or mobile device, and retrieved from it on subsequent visits. They do not cause any damage. Cookies cannot be used to reveal your personal identity, that is your name and surname. We use cookies to provide you with the best usability. Some cookies remain stored on your device until you delete them. They enable us to recognise your browser during subsequent visits.

If you do not agree with this practice, you can adjust your browser settings so that it will inform you before cookies are set. This will also enable you to permit specific cookies.

We use different types of cookies:

Cookies by function

  • Essential cookies - they are necessary for the operation of the website, which cannot function without them. This means that a website cannot be opened or displayed without these cookies. These cookies are used for the purpose of transmitting communication or are necessary to provide an information society service that is explicitly required by the user of such a service. These cookies do not need and do not require your consent.
  • Statistics cookies - these cookies enable basic analysis of web pages with the aim of improving the work of web pages through data that is completely anonymised, i.e. not based on your personal data or data that can be linked to you in any way. These cookies are used to analyse user behaviour and, on the basis of the anonymous data, can determine what website visitors view and want, so KESSELSPITZE is then able to customise the website and make its content and functionality as easy to use. These cookies require your consent.
  • Marketing cookies - they are used to analyse your interests and wishes, and they serve the purpose of informing you about special and personalised offers, news and events organised through online channels (e-mail, internet, internet promotion). These cookies require your consent.

Cookies by source

  • First party cookies come from the internet site you are viewing, and can be permanent or temporary. With these cookies, internet sites can store data that will be used again upon the next visit to the internet site.
  • Third party cookies come from other internet sites, which are located on the internet site you are viewing. With these cookies, other internet sites can track internet usage on the internet site you are viewing for marketing or analytical purposes.

Cookies by duration

  • Persistent cookies - Persistent or saved cookies remain on your computer after you close your internet browser program. They help internet sites store information, such as login and password, language settings, or cookie settings, so you do not have to re-enter them each time you visit. Persistent cookies can stay on your computer or mobile device for days, months, even years.
  • Temporary cookies Temporary cookies or session cookies are removed from your computer when you close your internet browser. They use internet sites to store temporary information, such as the last few pages you opened on the internet site you visited, or items in your shopping cart if you are on an internet site that specialises in internet sales.

Cookies are stored in the user’s browser for a maximum of 2 years.

If you have changed your mind about the cookie settings on our website, you can alter them at any time.

You can always delete cookies stored on your computer, thus preventing further processing of your personal data through such technology. Each web browser has its own procedure for deleting cookies, and below are links to deletion procedures in the most popular web browsers:

Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en

Mozilla Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox

Microsoft Edge: https://support.microsoft.com/en-us/windows/microsoft-edge-browsing-data-and-privacy-bb8174ba-9d73-dcf2-9b4a-c582b4e640dd

You can find more about cookies on the following pages:

  • http://www.allaboutcookies.org/
  • http://www.youronlinechoices.com/en/
  • http://www.aboutads.info/choices/

Valamar Marietta GmbH privacy policy

Valamar Marietta GmbHwith its headquarters in Ringstraße 8, AT-5562 Obertauern (hereinafter: MARIETTA or we or our or controller) as owner of Obertauern Places hotel by Valamar – ex Marietta hotel (hereinafter: the Hotel), respects the privacy of every person from whom collects personal data. We would like to inform you about what personal data we collect as the data controller, for what purpose, how we protect the data and what your rights are.

DATA CONTROLLER AND LEGAL FRAMEWORK

As the data controller, MARIETTA is committed to protect your personal data. The collection and storage of data is carried out in accordance with the provisions of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: Regulation), TKG (Telecommunications Law 2021) and other regulations governing the subject area, which are applied in the Republic of Austria.

SCOPE OF APPLICATION

This Policy applies to any processing of personal data performed by MARIETTA as the data controller, unless another policy or other MARIETTA document prescribes otherwise for a particular processing.

This Policy is divided into two parts: The General Section and the Specific section.

The basic principles of personal data processing, contact details and other provisions specified in the General Section of this Policy are applied without exception to any personal data processing regardless of whether such processing is specifically processed in the Specific Section of this Policy or not.

The Specific Section of the Policy deals, in more detail, with specific cases of data processing which represent the majority of all processing by MARIETTA.

CONTACT FOR DATA PROTECTION REQUESTS

Regarding issues related to personal data protection and for exercising their rights guaranteed by the Regulation please contact MARIETTA at any time via e-mail: dsgvo.obertauern.places@valamar.at or by mail to the address Valamar Marietta GmbH with its headquarters in Ringstraße 8, AT-5562 Obertauern.

All requests not related to data protection, which are delivered to this address, e.g. offers of job candidates, booking inquiries in the Hotel, etc. will be provided directly to the relevant departments.

PERSONAL DATA PROTECTION PRINCIPLES

MARIETTA has recognized the principles of data processing as basic values that must be respected throughout the cycle of personal data processing, from their collection to their destruction or other cessation of processing. MARIETTA processes data:

  • Lawfully - by processing data only if allowed by law and within the limits prescribed by law.
  • Fairly - by considering the specifics of each relationship, applying all appropriate measures to protect personal information and privacy in general and not impeding data subjects in exercising their rights.
  • Transparently - by informing data subjects about the processing of personal data. From the start of the data collection process, when data subjects are informed about all aspects of data processing, until its termination, data subjects are provided easy and fast access to their own data.
  • Purpose limitation - by processing personal data for the purposes they were collected for and for other purposes only if the conditions of the Regulation are met. Data may be processed for matching purposes only considering (a) any link between the purposes of the collection of personal data and the purposes of the intended continuation of the processing; (b) the context in which the personal data was collected, in particular concerning the relationship between the data subjects and MARIETTA; (c) the nature of the personal data; (d) the possible consequences of the intended continuation of processing for the data subjects; and (e) the existence of appropriate protection measures.
  • Storage limitation - by storing data in a form which permits identification of data subjects for no longer than is necessary for the initial purposes, and longer only if permitted by the Regulation.
  • Data minimization - by processing data if it is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Particular attention is given to not collecting data for which there is no justifiable reason for processing.
  • Accuracy - by keeping data accurate and up-to-date, and erasing inaccurate data in the scope of possibility.
  • Integrity and Confidentiality - by using appropriate technical and organisational measures to ensure appropriate personal data protection, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. Relevant measures are applied considering the risk of each type of data processing.

LEGALITY OF PERSONAL DATA PROCESSING

In order to respect the lawfulness of processing personal data, MARIETTA processes personal data only if and to the extent that at least one of the following is met:

  • Processing is necessary for the performance of the contract to which the data subject is a party or in order to act at the request of the data subject prior to the conclusion of the contract; this is the most common purpose of data processing with an existing contractual relationship or a contractual relationship in negotiations as its basis.
  • Processing is necessary to comply with the legal obligations of the data controller. As a legal entity, MARIETTA has a number of obligations prescribed by various regulations. This obligation includes the collection and often the submission of data to public authorities.
  • Processing is necessary for the legitimate interests of the data controller or a third party, except where those interests are stronger than the interests or fundamental rights and freedoms of data subjects requiring the protection of personal data, considering reasonable expectations of data subjects based on their relationship with the data controller, especially if the data subject is a child. In applying this legal basis, MARIETTA assesses that the processing is appropriate to business needs, that it is the least invasive as possible and that the interests of the data subjects do not exceed the legitimate interests of MARIETTA or a third party. Examples of such processing are processing for administrative purposes, the purposes of maintaining computer network security. The data subject always has the right to object to such processing in these situations.
  • Processing is necessary to protect key interests of the data subject or other natural person. The right to personal data protection is not an absolute right and MARIETTA equates it with other fundamental rights in accordance with the principle of proportionality.
  • The data subject has consented to the processing of his or her personal data for one or more specific purposes. When processing personal data on the basis of consent, MARIETTA provides that these are situations in which there are no, formal or informal, consequences for giving, refusing or denying consent. When processing is based on consent, the data subject may withdraw consent at any time without negative consequences. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

TYPES OF PERSONAL DATA PROCESSED

Special categories of personal data: shall be processed only if the conditions set out in Article 9 of the Regulation are met.

Data relating to criminal convictions and offenses: shall be processed only under the control of official authority and in accordance with Article 10 of the Regulation.

Personal data that are not included in the previous two groups: that kind of data makes most of the processed data. The most common types of data are identification and contact data such as name, surname, e-mail address and data that are related with your relation with us (accommodation etc.).

Most of the personal data that we collect is provided by the data subjects themselves. Therefore, we kindly ask you that you do not provide sensitive information (such as race or ethnic origin, political opinions, religious or philosophical beliefs, etc.) when this is not necessary. If you nevertheless provide sensitive information for any reason, you hereby give your express consent to the collection and use of such information in the ways described in these Policy or in the manner described at the time of disclosure of that information.

THE ROLE OF VALAMAR RIVIERA d.d.

MARIETTA concluded with the company Valamar Riviera d.d. with its registered office in Poreč, Stancija Kaligari 1 OIB: 36201212847 (hereinafter: Valamar) Contract in relation to the management of hotel and tourist facilities and contents (hereinafter: Management contract) based on which Valamar manages certain business segments of MARIETTA.

Due to such Management contract, when managing the Hotel, Valamar sometimes directly manages certain activities, including the management of some of the activities described in the Special Section of this Privacy Policy, in particular Valamar can process the personal data of the guests for providing the sales and marketing services. In addition, Valamar sometimes receives data from MARIETTA and has a right of access to relevant data base to perform certain activities where it subsequently comes to personal data processing.

For example, Valamar can manage the reservation function through the Valamar reservation center (call center) and via the websites www.valamar.com, and in these cases Valamar is an independent data controller (and data subjects will be informed on the spot about that fact) however, all this information related to Hotel are and have to be also processed by MARIETTA as an owner and independent data controller.

Furthermore, Valamar has a legitimate interest in processing of personal data carried out for the purposes of direct marketing, primarily for the purpose of sending marketing messages (newsletters) by e-mail, SMS and / or instant messaging platform (Viber, Whatsapp, etc.). Based on a legitimate interest, Valamar may send different newsletters depending on the relationship that respondents have with Valamar or the facilities under Valamar's management. For this purpose, personal data is collected from guests and persons who have asked for an offer or booked accommodation, persons who have participated in the prize game (if there will be any), joined the Valamar`s loyalty program, filled out a satisfaction questionnaire about accommodation in or otherwise had a relationship with Valamar.

Following the above, in certain cases Hotel guests can expect to receive from Valamar newsletters containing information about all other hotels and facilities managed by Valamar, as well as accommodation quality questionnaires and other service e-mails. For Hotel guests, prize games can be organized from time to time, which can be organized by Valamar, in which case guests personal data will be collected only if guests decide to participate in the prize game.

Valamar's Plus Club Loyalty Program can be applied for the MARIETTA. The conditions of membership are contained in Valamar's loyalty programme terms and conditions, which can be found at https://www.valamar.com/cmsmedia/loyalty/terms-conditions-en.pdf.

Also, based on the Management contract, Valamar has certain rights and obligations related to human resources, so in these cases Valamar has the right to process personal data of employees and candidates for employment in MARIETTA for the purpose of managing the business processes in the Hospitality Operations.

When Valamar acts as the data controller, the Valamar Privacy Policy applies, which can be found at: https://www.valamar.com/en/privacy-policy / https://www.valamar.com/hr/izjava-o-privatnosti.

DATA DELIVERY TO THIRD ENTITIES

MARIETTA shares personal information with others only when permitted.

MARIETTA is obliged by law to provide data to third parties. For example, delivering guest data and employee data to the competent institutions.

It is possible to deliver data to business entities, processors, who process the data upon instruction of MARIETTA, which acts as the data processor. Most often, these are MARIETTA's business partners who provide IT services, who store certain data in their databases or have the possibility of accessing personal data until the end of processing. In that cases a detailed contract shall be concluded with such subjects regarding their powers and obligations in the processing of personal data, in accordance with the requirements of the Regulation.

In certain situations, it is possible for external entities and MARIETTA to jointly determine the purposes and methods of personal data processing, in which case these external partners and MARIETTA are joint data controllers. In these relations, the joint data controllers shall transparently determine their responsibilities for complying with the obligations under the Regulation, in particular with regard to the exercise of data subject`s rights and their duties to respect the transparency of processing, unless responsibilities are established by law.

A special case of data delivery to third parties is the fact that MARIETTA has the Management contract with Valamar (see chapter: ROLE OF VALAMAR RIVIERA d.d.).

If data are transferred to third countries as part of data processing, MARIETTA ensures compliance with high protection standards in order to comply with the highest possible standard of personal data protection, in accordance with the strict requirements of the Regulation. Any transfer of personal data to third countries will be carried out in accordance with Chapter V of the Regulation.

DATA STORAGE PERIOD

Personal data are processed and stored for the period in accordance with applicable legal regulations when the retention obligation is prescribed (for example, accounting documents), and in situations where MARIETTA is authorized to set retention periods, data is stored as long as necessary for the purposes for which personal data is processed taking into account the purpose of processing, the legitimate interests of MARIETTA and the interests of the data subjects to delete the data.

RIGHTS OF THE DATA SUBJECTS

Regardless of the basis for data collection, all data subjects can exercise the following rights free of charge within the limits prescribed by the Regulation:

Right to information: The data subject has the right to be informed about the processing and its purposes. MARIETTA provides the data subjects with all the information necessary to ensure fair and transparent processing, considering the context of processing.

Right to erasure (“right to be forgotten”): The data subject has the right to request to delete personal data relating to him/her, without undue delay in accordance with the terms of the Regulation. To do so, please send your request to us in writing, including an electronic form of communication. Please note that the request needs to specify what you wish to be deleted, since we can store your data on different legal bases. You have the right to request the deletion of personal data relating to you where one of the following grounds applies:

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • the data subject withdraws consent on which the processing is based, and where there is no other legal ground for the processing;
  • the data subject objects to the processing pursuant and there are no overriding legitimate grounds for the processing, or the data subject objects;
  • the personal data have been unlawfully processed;
  • the personal data have to be erased for compliance with a legal obligation;
  • the personal data have been collected in relation to the offer of information society services.

In some cases, it will not be possible to fully comply with the deletion request, for example when there is a legal obligation for retention, when the legitimate interest of the controller is stronger than the interest of the data subjects, when there is an interest of the data controller to set, enforce or defend legal claims.

Right of access: The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
  • the right to lodge a complaint with a supervisory authority;
  • where the personal data are not collected from the data subject, any available information as to their source;
  • the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form. The right to obtain a copy shall not adversely affect the rights and freedoms of others.

Right to rectification: The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Considering the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Right to data portability: The data subject has the right to receive personal data relating to him in a structured, commonly used and machine-readable format in accordance with the requirements of the Article 20 of Regulation.

Right to object: The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on public interest and legitimate interests, including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.

Right to restriction of processing: The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:

  • the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;
  • the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
  • the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
  • the data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject.

In any case, data subjects also have the right to:

  • to submit a complaint time via e-mail: dsgvo.obertauern.places@valamar.at or by mail to the address Valamar Marietta GmbH with its headquarters in Ringstraße 8, AT-5562 Obertauern
  • to lodge a complaint with a supervisory authority (Austrian Data Protection Authority) if they believe that their rights to data protection have been violated.

MARIETTA as the data controller has the right to protect the interests of the data controller as well as the protection of the data subjects and accordingly has the right to carry out the activities of establishing the identity of the applicant. MARIETTA has the right to publish a form that will be used to submit a request in order to process the request as efficiently as possible.

On request, MARIETTA provides information on the actions taken in relation to the exercise of data subject's rights without undue delay and in any case within one month from the date of receipt of the request. This period may be extended by an additional two months, considering the complexity and number of applications. MARIETTA shall notify the data subject of any such extension within one month from the date of receipt of the request, together with the reasons for the postponement.

If the data subject submits the request electronically, MARIETTA provides the information electronically if possible, unless the data subject requests otherwise.

The data subject's request is generally free of charge, but if the data subject's request is manifestly unfounded or excessive, and in particular because of their frequent repetition, MARIETTA is entitled to charge a reasonable fee based on administrative costs or refuse to act on the request.

PROTECTION OF PERSONAL DATA OF CHILDREN

MARIETTA advises parents and guardians to teach children about safe and responsible handling of personal data, especially on the Internet. In relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.

PERSONAL DATA SOURCES

MARIETTA receives personal data most often from data subjects. When providing personal data to MARIETTA, in any way (booking accommodation, job application…) you guarantee that the information you have provided is correct, that you are legally capable and authorized to dispose of the given information and that you fully agree that MARIETTA collects and uses your data in accordance with the regulations and terms of this Privacy Policy.

Also, MARIETTA receives personal data from other natural and legal persons, for example: from Valamar as a company that manages certain business aspects of business, from travel agencies that forward guest data for accommodation, guests who book accommodation for people with whom they will stay in hotel, agency for employment mediation and assignment of workers, from the holder of accommodation reservations for others guests for whom the reservation is made.

When providing personal data of other persons to MARIETTA, you guarantee that the information you provide is accurate, that you are legally capable and authorized to dispose of the information, that respondents whose personal data you forward to us agree that MARIETTA uses and collects their data in accordance with positive regulations and the terms of this Privacy Policy.

TECHNICAL AND INTEGRATED DATA PROTECTION

MARIETTA, as data controller, provides the highest organizational and technical standards of data protection. Therefore, considering the latest developments, the cost of implementation and the nature, scope, context and purposes of processing, as well as risks of different levels of probability and seriousness for the rights and freedoms of individuals arising from data processing, at the time of processing, appropriate technical and organizational measures to enable the effective application of the principles of data protection are applied.

Also, MARIETTA implements appropriate technical and organizational measures to ensure that only personal data necessary for each specific purpose of processing are processed in an integrated manner. MARIETTA applies this measure to the amount of personal data collected, the scope of their processing, the retention period and their availability. Specifically, such measures ensure that personal data is not automatically, without the intervention of an individual, available to an unlimited number of individuals.

DATA BREACH

In the case of a personal data breach, as the data controller, MARIETTA shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.

The report submitted to the supervisory authority shall contain all information prescribed by the Regulation.

In the event of a personal data breach that is likely to pose a high risk to the rights and freedoms of individuals, MARIETTA, as the data controller, shall inform the data subjects of the personal data breach without undue delay. Sometimes, in cases where the Regulation prescribes, informing data subjects is not mandatory.

Special section


ACCOMMODATION

MARIETTA'S main business activity is the provision of accommodation services in its Hotel MARIETTA 5*. Therefore, MARIETTA collects and processes your personal data for various purposes with the ultimate goal of providing quality accommodation and related services all according to the highest standards of tourism companies.

MARIETTA, as the data controller, stores your personal data that you must provide for accommodation services in its database for the purpose of fulfilling accommodation contracts and fulfilling legal obligations related to the hospitality business. In case you do not provide MARIETTA with the minimum data required for booking accommodation and for the registration to all competent registers, MARIETTA will not be able to provide you with booking services or accommodation services in accordance with the contract and law.

Certain information is necessary in order to act at the request of the data subject before concluding the accommodation contract. For example, before booking accommodation at the request of potential guests, you have to receive offer, for which personal data is needed, at least name, surname and e-mail address in order to be able to send an offer.

The personal data that MARIETTA collects when booking in order to fulfil the reservation obligation usually are:

  • Name and surname of the reservation holder
  • Date of birth
  • Number, type of identification document and place of issue
  • Citizenship
  • Number of accommodation units, type of accommodation unit (room type)
  • Date of arrival and departure
  • Number of persons per accommodation unit
  • Minors
  • Possibly other specifics depending on the request of the person booking the accommodation
  • e-mail if the person has one
  • Language
  • Phone number
  • Membership in the Valamar`s Loyalty program, if it affects the price of accommodation or collecting points
  • Payment method and possible additional information needed to execute the transaction or secure payment. In case of cancellation, we must save your data for the purpose of proving the reservation or cancellation.

Upon arrival at the Hotel guests have to check in and confirm data.

In addition, MARIETTA is obliged to keep all invoices, as well as the basis for issuing invoices issued to guests with personal data of the guest in accordance with legal regulations.

Other data related to the circumstances of your stay such as: mode of travel, who you are traveling with, marital status, number of children, pets, other interests, will also be collected and processed during your stay only when they have a direct connection with the accommodation service.

Before, during and after the stay MARIETTA as the data controller has the right based on the legitimate interest to send you so-called service messages – booking confirmations, reminders and other information closely related to the specific stay you have booked. Also, during and after the stay, MARIETTA as the data controller has the right based on the legitimate interest to send to you guest questionnaires about service satisfaction via e-mail, sms and/or instant messaging platforms (viber, whatsapp, etc.) which will be processed by us or through associates. The primary purpose of the service satisfaction questionnaire is to collect service data for the legitimate interest of service improvement by MARIETTA, and MARIETTA may depersonalize and process this data from the questionnaire for statistical purposes.

MARIETTA has the right, based on a legitimate interest, to collect certain data and use it for direct marketing.

Service messages and messages with service satisfaction questionnaires related to a specific stay of the guest are not considered newsletters for the purpose of sending MARIETTA marketing offers and news.

VIDEO SURVEILLANCE

MARIETTA as the data controller, has a legitimate interest in implementing video surveillance measures to protect property and persons. We marked all places where video surveillance is installed in the prescribed manner. We are aware that the videos contain personal data of all persons moving around the perimeter of the camera, and therefore we keep them with special care, we have a regulated system of security, availability and our internal safety rules. Special regulations governing the area apply to all other details related to video surveillance.

GETTING IN CONTACT WITH US

When you contact us via email or via one of the forms on our website, data are processed and stored, in accordance with the purpose of processing.

WEBSITE, COOKIES AND INTERNET TECHNOLOGIES

Our website uses so-called cookies. A cookie is a small text file that is saved to your browser on your computer or mobile device, and retrieved from it on subsequent visits. They do not cause any damage. Cookies cannot be used to reveal your personal identity meaning your name and surname. We use cookies to provide you with the best usability. Some cookies remain stored on your device until you delete them. They enable us to recognize your browser during subsequent visits.

If you do not agree with this practice, you can adjust your browser settings so that it will inform before setting cookies. This will also enable you to permit specific cookies.

We use different types of cookies:

Cookies by function

  • Essential cookies - they are necessary for the operation of the website, which cannot function without them. This means that a website cannot be opened or displayed without these cookies. These cookies are used for the purpose of transmitting communication or are necessary to provide an information society service that is explicitly required by the user of such a service. These cookies do not need and do not require your consent.
  • Statistics cookies - these cookies enable basic analysis of web pages with the aim of improving the work of web pages through data that is completely anonymised, i.e. not based on your personal data or data that can be linked to you in any way. These cookies are used to analyse user behaviour and, on the basis of the anonymous data, can determine what website visitors view and want, so KESSELSPITZE is then able to customise the website and make its content and functionality as easy to use. These cookies require your consent.
  • Marketing cookies - they are used to analyse your interests and wishes, and they serve the purpose of informing you about special and personalised offers, news and events organised through online channels (e-mail, internet, internet promotion). These cookies require your consent.

Cookies by source

  • First party cookies come from the internet site you are viewing, and can be permanent or temporary. With these cookies, internet sites can store data that will be used again upon the next visit to the internet site.
  • Third party cookies come from other internet sites, which are located on the internet site you are viewing. With these cookies, other internet sites can track internet usage on the internet site you are viewing for marketing or analytical purposes.

Cookies by duration

  • Persistent cookies - Persistent or saved cookies remain on your computer after you close your internet browser program. They help internet sites store information, such as login and password, language settings, or cookie settings, so you do not have to re-enter them each time you visit. Persistent cookies can stay on your computer or mobile device for days, months, even years.
  • Temporary cookies Temporary cookies or session cookies are removed from your computer when you close your internet browser. They use internet sites to store temporary information, such as the last few pages you opened on the internet site you visited, or items in your shopping cart if you are on an internet site that specialises in internet sales.

Cookies are stored in the user’s browser for a maximum of 2 years.

If you have changed your mind about the cookie settings on our website, you can alter them at any time.

You can always delete cookies stored on your computer, thus preventing further processing of your personal data through such technology. Each web browser has its own procedure for deleting cookies, and below are links to deletion procedures in the most popular web browsers:

Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en

Mozilla Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox

Microsoft Edge: https://support.microsoft.com/en-us/windows/microsoft-edge-browsing-data-and-privacy-bb8174ba-9d73-dcf2-9b4a-c582b4e640dd

You can find more about cookies on the following pages:

  • http://www.allaboutcookies.org/
  • http://www.youronlinechoices.com/en/
  • http://www.aboutads.info/choices/

In Obertauern, 01.07.2023.