This is the data privacy statement (“Privacy”) of this website xxx.it – which is operated and provided. We will process the personal data collected on this website solely as set out in this declaration. Further down we will inform you on how we will process your personal data, at which purpose we process them, with whom they will be shared and which rights of control and information you are entitled of.
I. Summary of our processing activities
The following summary provides you with a quick overview of the processing activities that are undertaken on our website. You will find more detailed information in the indicated sections further down.
- When you visit our website for informational reasons without setting up an account, only limited personal data will be processed to provide you with the website itself (see section III).
- If you are interested in our services (i.e. offers, bookings etc.) or subscribe to our newsletter, personal data will be processed within this framework (see IV and V).
- Furthermore, your personal data will be used for interesting advertising and products (see VI) as well as for statistical analysis in order to improve our website (see VII).
- If necessary, your personal data will be disclosed to third parties (see VIII).
- We have implemented appropriate safeguards to secure your personal data (see section IX) and retain your personal data only as long as necessary (see section XI).
- According to the circumstances of the concrete case, you are entitled to specific rights in relation to the processing of your personal data (see XI).
- Personal data means any information relating to a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier.
- Processing means any operation which is performed on personal data, such as collection, recording, organisation, structuring, storage, adaptation or any kind of disclosure or other use.
III. Informational use of the website
When you visit our website for informational reasons, i.e. without applying for a one of the services cited in section IV and without providing us with personal data in any other way we will, if necessary, automatically collect additional information about you which only in limited cases contain your personal data and are automatically recorded by our server such as:
- your device type, device name and screen resolution
- information on your browser version
- information on your operating system, including language settings
- date and time of your requests
- information on your requests
We use such information only to assist us in providing an effective service (e.g. to adapt our website to the needs of your device or to allow you to log in to our website), and to collect broad demographic information for an anonymised statistic about the use of our Website. The personal data automatically collected is necessary for us to provide the website, Article 6 sec. 1 sent. 1 lit. b GDPR, and for our legitimate interest to guarantee the website’s stability and security, Article 6 sec. 1 sent. 1 lit. f GDPR. Personal data that is collected automatically is stored one month and properly erased afterwards.
IV. Applying for our services
Our website provides you with the possibility to request offers, catalogues and the subscription to newsletters or general requests. In order to make use of the services mentioned above, you need to submit personal data. We process:
- information such as your name, address and e-mail address you provide when contacting us
Information required for us to provide the service are marked accordingly. All further data are given freely. We process the personal data provided by you for the following purposes:
- provide you with the services and information offered by the website or which you request
- to communicate with you
- (behavioral-based) advertising and profiling
The legal basis for this processing is Article 6 sec. 1 sent. 1 lit. b GDPR. We use your personal data for the purpose of behaviour-based adverstising and profiling for we have a legitimate interest to improve your user experience, Article 6 sec. 1 sent. 1 lit. f GDPR. We process the data provided by you on your registration in order to directly inform you about our other products and services. The use of your personal data to promote similar products and services in the framework of direct mailing poses a legitimate interest of us being the provider of this website, Article 6 sec. 1 sent. 1 lit. f GDPR. You may object at any time to the processing of your personal data for the purpose of direct mailing. We will withdraw from further processing for these purposes. You can send us your objection via e-mail – see below.
If you would like to receive our newsletter, we require a valid e-mail address. This newsletter informs you about our newest products and services should you agree to receive this newsletter. The legal basis for the processing operation is Art. 6 paragraph 1 section 1 lit. a of the GDPR. The service is provided by the “Double Opt In” procedure. You will receive an e-mail containing a link with which you can confirm that you are the owner of this e-mail address and that you want to be informed by our e-mail service. If you do not confirm the subscription to our e-mail service after requesting the confirmation mail, the personal data provided by you will not be processed but automatically disabled and deleted in the course of the next data examination (generally within a week). You may unsubscribe from our newsletter by clicking the link included in every newsletter.
VI. Automatised decision making
We do not process your personal data for automised decision making which take legal effects with respect to you or significantly comprise you in similar ways.
General information on analysis
For statistical analyses we use web analytics services to collect information about the use of this site.
The tools collect information such as
- device and browser information (device type, operating system information, browser version)
- IP address
- pages accessed, URL click stream (the chronological order of our internet sites you visited)
- geographic location
- date and time of visit
- referring site, application, or service
We use the information we get from the providers only to determine the most useful information you are looking for, and to improve and optimise this website. We do not combine the information collected through the use of the analytical tools with personal data. According to the provider, the data generated by your use of the website may possibly be stored in a state outside the European Economic Area (EEA) and processed there, i.e. in the United States. Further information on the possible risks of a trans-border data transmission can be found in section XII. The tools collect only the IP address assigned to you on the date you visit this site, rather than your name or any other identifying information. The provider will use this information in order to evaluate your use of the website, to compile reports on website activities and to provide other services relating to website and internet use to us. The legal basis for this processing is Art. 6 sec. 1 sent. 1 lit. f GDPR and represents our legitimate interest to analyse our website’s traffic to improve the user’s experience and to optimise the website in general.
We use Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). On our behalf Google will use the information generated by a cookie for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet activity in connection with the use of the website.
We have activated the IP anonymisation within the Google Analytics service, and your IP address will be truncated within the area of member states of the European Union or other parties to the Agreement on the European Economic Area. Only in exceptional cases the whole IP address will be first transferred to a Google server in the USA and truncated there. The IP-address your browser conveys within the scope of Google Analytics will not be associated with any other data held by Google. You may refuse the use of such cookies as follows:
- by selecting the appropriate settings on your browser that prevent the setting of cookies by third parties (however, please note that if you do this you may not be able to use the full functionality of this website)
- you may prevent the collection of the information generated by the cookie about your use of the website (including your IP address) and the processing of this data by Google if you download and install the browser plug-in available at the following link:
For further information on data protection and Google Analytics see the Google website: http://www.google.com/analytics/learn/privacy.html?hl=de
Links to third party websites
VIII. Transfer of Personal Data to Third Parties
Your personal data may be disclosed to contractors who assist us in providing our services. The data transfer takes place based on order processing agreements. Our contractors will use your personal information to the extent necessary to perform their duties. You are obliged contractually to process your personal data exclusively in your interest and according to your requests.
In the event of restructuring or sale of our company to a third party, any personal data we hold about you may be transferred to that re-organised entity or third party in compliance with applicable law.
We may disclose your personal data if legally entitled or required to do so (for example if required by law or by a court order).
We have reasonable state-of-the-art security measures in place to protect against the loss, misuse and alteration of personal data under our control. Our security and privacy policies are periodically reviewed and enhanced as necessary and only authorised personnel have access to personal data. Whilst we cannot ensure or guarantee that loss, misuse or alteration of information will never occur, we use reasonable efforts to prevent it. You should bear in mind that submission of information over the internet is never entirely secure. We cannot guarantee the security of information you submit via our website whilst it is in transit over the internet and any such submission is at your own risk.
X. Data retention
We strive to keep our processing activities with respect to your personal data as limited as possible. In the absence of specific retention periods set out in this policy, your personal data will be retained only for as long as we need it to fulfil the purpose for which we have collected it and, if applicable, as long as required by statutory retention requirements.
Depending on the circumstances in the specific case, you have the following data protection rights:
- to request access to your personal data and/or copy of such data. That includes information about the purpose of use, the category of the used data, their recipients and persons authorised to access them, and, where possible, the planned duration of data storage or, if this is not possible, the criteria for establishing this duration;
- to request that your personal data be corrected, deleted, or restricted in terms of processing if their use is impermissible under data protection law, particularly because (i) the data are incomplete or inaccurate, (ii) they are no longer needed for the purposes for which they were collected, (iii) the consent to processing was revoked, or (iv) you successfully made use of a right of revocation concerning data processing; in cases where the data are processed by third parties, we will forward your applications for correction, deletion, or restriction in terms of processing to such third parties unless this proves to be impossible or is associated with unreasonable effort;
- refuse to provide and – without impact to data processing activities that have taken place before such withdrawal – withdraw your consent to processing of your personal data at any time;
- not to be subjected to a decision based exclusively on automated processing that is legally effective against you or substantially interferes with you in a similar fashion;
- to request that you be provided with the personal data concerning you that you provided to us in a structured, common, and machine-readable format and to transmit such data to another data controller without interference by us; you may also have the right to request that we transmit the personal data directly to another data controller, if this is technically feasible;
- to take legal steps or to request the involvement of the responsible supervisory authorities if you believe that your rights were infringed as a result of your personal data being processed in a manner that is not in conformity with the requirements of data protection law.
In addition to the foregoing, you have the right to object at any time to the processing of your personal data:
- if we process your personal data for purposes of direct marketing; or
- if we process your personal data for the purposes of pursuing our legitimate interests and reasons exist that result from your special situation.
You may (i) exercise the rights referred to above or (ii) pose any questions or (iii) make any complaints regarding our data processing by contacting us. You will find our contact details further down.
For any questions, concerns or comments about this data protection or requests on your personal data you may always refer to our data protection officer via e-mail. See the e-mail address BELOW.
The information you are providing with your contact request is only processed in order to process your request. It will be deleted subsequently. Alternatively, we will restrict the processing of the respective information in accordance with statutory retention requirements.
Verantwortliche Person: Andreas Piok
St. Andrä, St. Leonharderstrasse Nr. 8
MwSt. Nr. 02327030215