menu
altlogo
Privacy Policy 1

Privacy Policy

Privacy Notice on the Processing of Personal Data

(Articles 13 and 14 of EU Regulation 2016/679 – “GDPR”, and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018)

Pursuant to the above-mentioned legislation, we provide you with information concerning the processing of your personal data collected in connection with your request for information, booking and/or stay at our property, including through our website.

1. Data Controller

The Data Controller is ANDREA DE LUCA AMALFI S.R.L. (Hotel Il Tipografo di Amalfi), with registered office at Via Mauro Comite 26, 84011 Amalfi (SA) – VAT No./Tax Code 06164930650 – REA SA-502152 – PEC andreadelucaamalfi@pec.cgn.it – tel. 0039 089 831333, represented by its Sole Director and legal representative De Luca Francesco Giuseppe.

2. Source and methods of data collection

Your personal data are collected directly from you on the occasion of: filling in the forms available on the property's website (request for information, online booking, newsletter subscription); telephone communications, communications by e-mail or through tourist intermediation platforms (OTAs); your physical presence at the property at check-in.


3. Purposes of processing and legal basis

Your personal data are processed for the following purposes:

a) management of requests for information and bookings — made in person, by telephone or through the website — including the pre-contractual measures requested by you and, in the event of confirmation, the performance of the contract — legal basis: performance of pre-contractual/contractual measures (Art. 6, para. 1, letter b, GDPR); provision of data is necessary and does not require consent;
b) fulfilment of administrative, accounting and tax obligations — legal basis: legal obligation (Art. 6, para. 1, letter c, GDPR); provision of data is necessary and does not require consent;
c) personalisation of the stay and additional customer care services (e.g. dedicated area for managing preferences) — legal basis: consent of the data subject (Art. 6, para. 1, letter a, GDPR); provision of data is optional;
d) sending promotional and marketing communications (e.g. newsletters, offers) relating to the services and initiatives of the Data Controller — legal basis: consent of the data subject (Art. 6, para. 1, letter a, GDPR); provision of data is optional and separate from the consent referred to in letter c);
e) processing of special categories of personal data (“sensitive” data), where voluntarily provided by you for specific needs (e.g. allergies, disabilities) — legal basis: explicit consent (Art. 9, para. 2, letter a, GDPR); provision of data is optional and exclusively intended to fulfil the specific request.

4. Nature of the provision of data and consequences of refusal

Failure to provide the data referred to in point 3, letters a) and b), will make it impossible to process the booking request or fulfil legal obligations. Refusal to provide consent for the purposes referred to in letters c), d) and e) will in no way affect the use of the main booking/stay service.


5. Methods of processing

Processing is carried out using paper-based, computerised and electronic tools — including the property's management system (PMS) and online booking engine — according to procedures strictly related to the purposes indicated and, in any case, in such a way as to ensure the security and confidentiality of the data, in compliance with the technical and organisational measures provided for by Articles 24 and 32 of EU Regulation 2016/679.


6. Browsing data and cookies

During its normal operation, the Data Controller's website acquires certain data whose transmission is implicit in the use of Internet communication protocols (e.g. IP addresses, browser type, operating system, pages visited, access times). Such data are used solely to obtain anonymous statistical information on the use of the website, to verify its correct operation and for security purposes; the relevant legal basis is the legitimate interest of the Data Controller (Art. 6, para. 1, letter f, GDPR), and such data are retained for the time strictly necessary for these purposes.
The website uses technical cookies, which are necessary for the operation of the pages and for which consent is not required. The website may also use profiling and/or third-party cookies (e.g. analytics, marketing cookies), for which consent is collected through a dedicated banner upon first access, in accordance with the provisions of the Privacy Authority's decision of 8 May 2014. For the detailed list of cookies used, their purposes and the methods for managing or withdrawing consent, please refer to the Cookie Policy published on the website.


7. Data recipients

The data may be disclosed, for the purposes indicated above, to:

• professional firms and consultants in accounting, tax, employment and legal matters;
• providers of management and booking systems (booking engine, PMS), website management/hosting providers and IT support companies;
• tourist intermediation platforms (OTAs), where the booking is made through such channels;
• persons authorised to process data and data processors appointed pursuant to Articles 28 and 29 of EU Regulation 2016/679.

The data are not subject to dissemination.


8. Transfer of data to non-EU countries

Where, for the provision of the services described above, the Data Controller uses providers based outside the European Economic Area (e.g. booking platforms or cloud services), the transfer will take place in compliance with the safeguards provided for by Articles 44 et seq. of EU Regulation 2016/679.


9. Data retention period

The data collected for the management of requests and bookings are retained for the time necessary for this purpose and, in any case, no longer than the end of the relevant tourist season, unless otherwise agreed between the parties. Data necessary for compliance with accounting and tax obligations are retained for the period required by applicable legislation (normally 10 years). Data processed on the basis of consent (point 3, letters c, d, e) are retained until consent is withdrawn.


10. Data relating to minors

Where the request or booking includes personal data of minors (e.g. minor children belonging to the family unit), such data are provided by the parent or person exercising parental responsibility, who guarantees their accuracy. Such data are processed exclusively for the purposes referred to in point 3, letters a) and b), and are not used for marketing purposes.


11. Data subject rights

At any time, you may exercise, against the Data Controller, the rights provided for by Articles 15-22 of EU Regulation 2016/679: access, rectification, erasure, restriction of processing, objection to processing and data portability. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), as the supervisory authority, in accordance with the procedures provided for by applicable legislation. To exercise the above-mentioned rights, you may write to: andreadelucaamalfi@pec.cgn.it 

12. Consent

Consent to the processing of your data for the optional purposes referred to in point 3, letters c), d) and e), is given by signing this form at check-in or, where data are collected through the website, by selecting the appropriate checkboxes in the online request/booking form. Consent is in all cases freely given, specific and may be withdrawn at any time, with effect on processing carried out after the withdrawal.