Book
eng
eng

Privacy

Information document article 13 EU Reg. 2016/679-RGPD
Subject: Information for the processing of personal data collected from the interested party via the Website. In compliance with the provisions of EU Reg. 2016/679 (European Regulation for the protection of personal data) we provide you with the necessary information regarding the processing of the personal data provided. The information refers to the website www.sienahillsapartments.com, and is not to be considered valid for other websites that may be consulted via links on the Internet websites in the domain of the Data Controller, who is not to be considered in any way responsible for third party Internet websites. This information is provided pursuant to art. 13 of EU Reg. 2016/679 (European Regulation for the protection of personal data) and is also based on the provisions of Directive 2002/58/EC, as updated by Directive 2009/136/EC, regarding Cookies and in accordance with the Provision issued by the Personal Data Protection Authority of 08.05.2014 regarding cookies.

1 - PERSONS INVOLVED IN DATA PROCESSING
The DATA CONTROLLER, pursuant to articles 4 and 24 of EU Reg. 2016/679 is MITUS SIENA SRL with headquarters in Strada di Malizia, 57B - 53100 - Siena (SI), hereinafter (“Data Controller”)

2 - PURPOSE AND LEGALITY OF THE DATA PROCESSING
The personal data provided will be processed in compliance with the conditions of lawfulness pursuant to art. 6 EU Reg. 2016/679 for the following purposes:
Management of data processing pertinent to (art. 6 letter b):
- navigation on this website;
- possible completion of data collection forms for sending a request for information to the data controller;
- fulfilment of current administrative, accounting and tax obligations, as well as for complying with laws and regulations. For the purposes of applying the provisions regarding the protection of personal data, the processing carried out for administrative-accounting purposes is that linked to the carrying out of organisational, administrative, financial and accounting activities, regardless of the nature of the data processed.
The personal data provided voluntarily and optionally by users who forward requests to receive information on hotel services (prices, availability of rooms and conference rooms, etc.), who register for the newsletter, make online bookings or simply forward job applications by sending CVs in electronic format, are used for the sole purpose of carrying out the services requested and are not communicated to third parties unless the communication is imposed by legal obligations or is strictly relevant and necessary in order to fulfil the requests.

3 - NAVIGATION DATA
Like all websites, this website also makes use of log files in which information collected in an automated manner during user visits is stored.
The information collected may be the following:
- internet protocol (IP) address;
- type of browser and device parameters used to connect to the website;
- name of the internet service provider (ISP);
- date and time of visit;
- visitor’s web page of origin (referral) and of exit;
- possibly the number of clicks.

This information is not collected to be associated with identified users, but, due to its nature, it may, through processing or association with data held by third-parties, make it possible to identify the users.

4 - DATA PROVIDED VOLUNTARILY BY THE USER
The optional, explicit and voluntary sending of electronic mail to the addresses indicated on this website entails the subsequent acquisition of the sender's address, necessary in order to respond to requests, as well as any other personal data included in the message.

5 - RECIPIENTS OR CATEGORIES OF RECIPIENTS OF THE DATA
The personal data provided via email contacts or possibly via a CV sent spontaneously to the data controller may be communicated to recipients, who will process the data as managers and/or as individuals acting under the authority of the Data Controller, in order to comply with contracts or related purposes. 
Specifically, the data may be communicated to recipients belonging to the following categories:
- Persons who provide services for the management of the information system and communication networks of MITUS SIENA SRL (including e-mail);
- Studies or Companies in the context of assistance and consultancy relationships;
- Competent authorities for the fulfilment of legal obligations and/or provisions of public bodies, upon request;
- In case of administrative accounting purposes, the data may possibly be transmitted to commercial information companies for the evaluation of solvency and payment habits and/or to individuals for purposes of debt collection.
- In the case of spontaneous job application, your data will be stored at our headquarters and will be communicated exclusively to the competent persons in order to carry out the necessary services, with a guarantee of protection of the rights of the interested party.
Your data will only be processed by personnel expressly authorised by the Data Controller and, in particular, by the following categories of personnel: Management and Administration at MITUS SIENA SRL with functions of System Administrator and Personnel Management and Administration.

The individuals belonging to the aforementioned categories perform the function of Data Manager, or work in total autonomy as separate Data Controllers

6 - DATA CONTROLLER
The data collected by the website is processed at the Data Controller’s headquarters and at the Web Hosting data centre. The web hosting data centre, which is responsible for data processing, thereby processing the data on behalf of the data controller, is located in the European Economic Area and acts in accordance with European standards. The list of designated Data Managers is constantly updated and available at the headquarters of MITUS SIENA SRL

7. TRANSFER OF PERSONAL DATA TO A THIRD COUNTRY AND/OR AN INTERNATIONAL ORGANISATION
The personal data provided will not be transferred abroad within or outside the European Union.

8 - RETENTION PERIOD AND CRITERIA
The processing will be carried out in an automated and/or manual way, with methods and tools aimed at guaranteeing maximum security and confidentiality, by persons specifically appointed for this purpose. In compliance with the provisions of art. 5 paragraph 1 letter e) of EU Reg. 2016/679, the personal data collected will be stored in a form that allows identification of the interested parties for a period of time that does not go beyond the achievement of the purposes for which the personal data is processed. To learn about the criteria underlying the data retention period, write to info@sienahillsapartments.com.

9 - NATURE OF THE PROVISION AND REFUSAL
Apart from what is specified for navigation data, the user is free to provide personal data in dedicated areas on the website. The provision of personal data for the purposes referred to in this information document is necessary in order to perfect the specific functions and use the services offered to the Data Controller, for example to receive feedback on the request for information forwarded. Failure to provide personal data may make it impossible to obtain the requested service or use the services offered by the website.

10 - RIGHTS OF THE INTERESTED PARTIES
You will be able to assert your rights as expressed in articles 15 – right of access, 16 - right of amendment, 17 – right to deletion, 18 – right to limiting data processing, 20 – right to portability, 21 – right to object, 22 right to object to the automated decision-making process regarding RGPD 679/ 16 of EU Regulation 2016/679, by contacting the Data Controller, writing to the email address info@sienahillsapartments.com .

You have the right, at any time, to ask the Data Controller for access to your personal data, amendment or deletion of it and limiting its processing. Furthermore, you have the right to object, at any time, to the processing of your data (including automated processing, e.g. profiling) as well as to the portability of your data. Without prejudice to any other administrative and jurisdictional appeal, if you believe that the processing of data concerning you violates the provisions of EU Reg. 2016/679, pursuant to art. 15 letter f) of the aforementioned EU Reg. 2016/679, you have the right to lodge a complaint with the Personal Data Protection Authority and, with reference to art. 6 paragraph 1, letter a) and art. 9, paragraph 2, letter a), you have the right to revoke the consent given at any time. Link to the website of the Data Privacy Authority: http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524 .

In the event of a request for data portability, the Data Controller will provide you the personal data that concerns you, in a structured, commonly-used and readable format, via automatic device, except for paragraphs 3 and 4 of art. 20 of EU Reg. 2016/679.