Terms and conditions
Terms and conditions
The ‘summary’ paragraphs on this page only contain a short explanation and do not apply for legal purposes.
#1, 2. What kind of data do we process?
- full name
- date / place of birth
- contact details (telephone,e-mail)
- residence address
- copy of the document of identity
- banking data
- data useful for fiscal management
- state of health, allergies (if any), handicap
- religious convictions
- racial or ethnic origin
1. Personal data processed1.1. For the negotiation, establishment and management of the contractual relationship with the customer/ data subject, the Company/controller processes personal data of the customer/data subject, in particular of natural persons related to it, which include: full name, date and place of birth, details and/or copies of the identity documents and fiscal code, contact data (telephone, e-mail, address), residence address, banking data and other data necessary or useful for the management, also from a fiscal perspective, of the relations with the customer/data subject. Each subject with whom the Company/ controller interacts, declares to be authorized or, in any case, to have the power to lawfully transmit to the Company/ controller, personal data necessary for the establishment, management and execution of the travel contract, in particular those of the other travellers.
2. Particular categories of personal data2.1. The Company / controller, always with the purpose of the establishment and management of the contractual relationship with the data subject, may process information belonging to the particular categories of personal data described in art. 9 of the Regulation, which include: a. The state of health - for example in the case in which the customer / data subject communicates particular allergies or food intolerances that the Company / controller must take into account in the management of the travel package, or other needs related to health issues; b. Data revealing religious or philosophical beliefs - for example in the event that the customer/ data subject communicates particular nutritional needs related to religion, or requires that the days off coincide with specific religious holidays; c. Data revealing the racial or ethnic origin - as may appear, for example, from identity documents or other material provided by the customer/data subject for the signature, management and fulfillment of the contract with the Company. 2.2. With regard to employees, as for data processed by the occupational doctor who is responsible for carrying out the tasks provided for by Legislative Decree 81/08 and the other provisions on hygiene and safety in the workplace, for fulfilling the prior and periodic medical assessments, such data will be processed only by the same doctor as an independent data controller.
#3, 4. Why?
- To organize and managecyour trip, answeringcalso to particular needsc(e.g special diets for food allergy)
- To contact you before and during the trip (e.g sending a quote, sending of info material)
- To fulfill legal and fiscal obligations (e.g archive of accounting documents)
- To send you communications regarding other trips (e.g sending newsletters or paper promotional material)
3. Purposes of the processing and its lawfulness3.1. Pursuant to the principles of correctness, lawfulness and transparency, the Company/controller collects personal data for the management of the relationship with the customer/data subject in the pre-contractual and contractual phases, for the purposes and on the basis of the conditions of lawfulness indicated below. Management and execution of pre-contractual and contractual obligations, , stemming from the travel contract with the customer/data subject, including but not limited to, the management of the personal data file, the organization and the support to the customer/data person during the trip. Legal Basis: Processing permitted as necessary for the implementation of a contract of which the data subject is a party, or for the execution of precontractual measures adopted at the request of the same - art. 6.1. (b) of the Regulation. Fulfillment of legal obligations (i.e. processing and filing of accounting documents relating to the relationship with the customer/data subject, communications to the competent bodies) to which the Company/controller is subject to, according to national and international, regulations relating, for instance, to tax, administrative accounting and anti-money laundering matters. Legal Basis: Processing permitted as necessary to fulfill a legal obligation to which the controller is subject to - art. 6.1 (c) of the Regulation. Direct marketing activities by sending communications or material (eg via e-mail) regarding products / services similar to those already provided by the Company / controller to the customer / data subject. Legal Basis: Processing permitted, as necessary for the pursuit of a lawful interest of the controller - art. 6.1. (f) of the Rules. The lawful interest of the controller is represented by the promotion of its activity through direct marketing - see Recital no. 47 of the Regulation.
4. Mandatory or optional processing4.1. The provision of personal data by the customer/data subject, or by the natural persons connected to it for the purposes described in articles 3 .1 (a) and 3.1. (b) is optional but is necessary for establishing, managing and executing the contractual relationship with the Company/controller. Any refusal to supply the data, in whole or in part, may cause the impossibility for the Company/controller to give rise to, or execute the contract, or to correctly perform all the obligations related to the contract. 4.2. The provision of personal data by the customer/data subject, or by the natural persons connected to it, for the purposes referred to in art. 3.1.c., is optional. Any refusal to supply them in whole or in part does not adversely affect the possibility for the Company/controller to give rise to, or execute the contract, or to correctly perform all the obligations related to the contract.
#5, 6. To whom we provide data
- To employees and collaborators of Girolibero srl (e.g. reservation staff, tourist guides)
- To service providers of Girolibero srl (e.g hotels, baggage carriers, transfer company, bike rental)
- To professionals who support the management of Girolibero srl (e.g. accounting firm, insurer)
5. Categories of recipients5.1. Personal data may be communicated, exclusively for the purposes indicated above, to the following subjects or categories of subjects: subjects to whom the communication is necessary for the establishment, management and fulfillment of the contract by the Company/controller: a. natural persons authorized in writing by the Company/controller pursuant to art. 29 of the Regulation in order to perform their job responsibilities (e.g. employees, system administrator, etc.); b. professionals and collaborators which support the Company for the activities performed for the data subject (eg tourist guides / tour leaders, companies that deal with transportation, hotels, business partners of the Company / controller who have organized all or part of the trip); c) professionals and service companies for the administration and management of the Company/controller, which operate on behalf of the Company/controller for its internal purposes (e.g. accountants, consultants); d) subjects, entities, authorities to whom is mandatory to communicate the data of customers /data subject, according to law provisions and orders of the authorities. 5.2. With regard to paragraphs a, b), c) of art. 5.1, the Company/controller undertakes to rely on subjects that provide adequate guarantees regarding data protection, and to appoint such subjects, to the extent this is advisable, as data processors under art. 28 of the Regulation.
#7, 8. How and for how long we store data
- The data is archived electronically and in paper, with access limited only to those who manage your trip and to the administration
- Data is stored for a duration of 10 years from your trip or last contact with us
7. Processing methods7.1. Personal data are stored in the archives of the Company/controller and are processed using paper and electronic means, without prejudice to the adoption of appropriate security measures to avoid unlawful processing. 7.2. Processing of personal data is based on the principles of minimization, correctness and transparency. Only personal data necessary for the purposes described will be processed, and will be accessible only to the staff involved in the activities necessary for the purposes described.
8. Term of conservation of personal data8.1. Personal data is kept for the entire duration of the contractual relationship with the customer/data subject, and also subsequently, for the 10-year term from the termination of this relationship, in consideration of the mandatory term for keeping the accounting records and of the expiration period of any claims arising from the relation between the Company / controller and the customer/data subject, as required by law. 8.2. In the event that litigation arises between the Company/controller and the customer/data subject, the retention period will be extended for the duration of the dispute and for the 10 years following its final settlement (e.g. settlement agreement or final judicial decision).
#9, 10. Your rights
- know which of your data we process
- ask us to modify or to delete them
- withdraw consent to marketing actions, if previously authorized
- report to the competent authorities, any eventual abuse or breach of personal data