Privacy Policy for the Processing of Personal Data
(pursuant to Article 13 of EU Regulation 2016/679)
Dear User,
pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR), we inform you that the personal data you provide by completing the form and sending identity documents will be processed in compliance with current legislation and the principles of fairness, lawfulness, transparency, and protection of confidentiality.
1. Data Controller
The Data Controller is:
Daniele Franzoi
Casa Maria – via Borgo San Pietro 8, 30173 Venice (VE)
Email: [email protected]
Phone: +39 041 978411
2. Purpose of Processing
The personal data collected (personal, contact, identity document) will be processed for the following purposes:
- Management of booking and/or stay requests;
- Fulfilment of legal obligations, including communication to public security authorities (Art. 109 of the T.U.L.P.S.);
- Verification of guests’ identity;
- Communications relating to the booking or stay.
3. Legal Basis of Processing
The processing is lawful because it is:
- necessary for the performance of pre-contractual and contractual measures (Art. 6, para. 1, letter b of the GDPR);
- necessary to comply with a legal obligation (Art. 6, para. 1, letter c of the GDPR);
- based on your explicit consent for the processing of special categories of data (Art. 9, para. 2, letter a of the GDPR), limited to the data contained in identity documents.
4. Processing Methods
The processing will be carried out using manual and electronic tools, with logic strictly related to the purposes indicated, in compliance with the security measures provided for by the GDPR.
5. Data Retention
The data will be retained:
- for the entire period necessary to provide the service;
- thereafter, for the period required by tax or regulatory obligations;
- copies of identity documents will be deleted within 24 hours of being sent to the public security authority, unless further obligations are required by law.
6. Communication and Disclosure
The data may be disclosed exclusively to authorised third parties (IT service providers, competent authorities) for the purposes stated above. The data will not be subject to dissemination.
7. Data Subject’s Rights
The data subject has the right to:
- access their data;
- rectify or delete it;
- limit its processing;
- object to processing;
- withdraw consent given (where applicable);
- lodge a complaint with the Data Protection Authority.
Requests should be addressed to the Data Controller at the contacts indicated above.