PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA
(Guests – Customers ver. 1.8)
Castello La Leccia Società Agricola Srl, Loc. La Leccia, 53011 Castellina in Chianti (SI), Tax Code and VAT No. 00520660523 (hereinafter, the “Data Controller”), in its capacity as Data Controller, hereby informs you, pursuant to Legislative Decree 196/2003 and Legislative Decree 101/2018 (hereinafter, the “Privacy Code”) and Regulation (EU) No. 2016/679 (hereinafter, the “GDPR”), that your personal data will be processed according to the following methods and purposes:
1. Subject of the Processing
The Data Controller processes personal and identification data such as: first name, surname, company name, tax identification number, address, telephone number, e-mail address, banking and payment details, and records in systems required by law concerning data contained in identity documents, hereinafter referred to as “personal data” or “data”.
2. Purposes of Processing Personal Data
A) Personal data are processed for the following purposes:
requests for information, quotations, availability checks and reservations, restaurant services;
hosting you in our facilities following acceptance of requests and reservations;
management of the relationship between our facility and the customer (including administrative, accounting and tax management);
hosting you as our guest(s) following any event organized at the facility for which you are invited;
-informing you of the receipt of telephone calls, messages or mail addressed to you;
compliance with legal obligations arising from communications to Public Security Authorities;
reservation requests relating to our restaurant and/or tasting experiences;
management of purchases and shipments for any orders of our products through the on-site shop;
solely for the purpose of providing restaurant/tasting services, and without any recording or other form of processing, management during food preparation of any information provided by you regarding possible food intolerances;
compliance with obligations established by law, regulations or EU legislation.
A duly authorized video surveillance system is installed on the premises. The purposes are strictly related to security and protection of property. Floor plans showing the location and coverage area of the cameras are available from the Data Controller. Images will be recorded for a short period of time and subsequently overwritten and/or deleted. No external archiving and/or dissemination of images will take place. Only images strictly necessary for the purposes stated above will be recorded, avoiding details or zooming whenever possible. The collected material will not be used for other purposes nor disclosed to third parties, except in the event of intervention and/or request by Judicial Authorities or Public Security Authorities.
B) Subject to specific and separate consent, for the following marketing purposes:
sending advertising/promotional material and newsletters regarding products and commercial offers by the Data Controller via e-mail, letters, telephone, mobile phone/smartphone/tablet (SMS, messaging applications), social media, fax and other remote communication channels.
3. Methods of Data Processing and Retention
Data processing will be carried out in a manner that guarantees their security and may be performed through manual operations on paper documents and/or through the use of IT and telematic tools intended, among other things, to store, manage or transmit such data. The data will be retained for no longer than necessary to fulfill the purposes indicated above and, in particular, for the purposes referred to in section 2.A), for the entire duration of the relationship and, subsequently, for the time strictly necessary to comply with legal obligations. For the purposes referred to in section 2.B), data will be retained for a maximum period of 5 years for marketing purposes. After these periods, data will be deleted or anonymized and used exclusively for statistical purposes.
4. Access to Data
Data may be made accessible for the purposes referred to in section 2.A) to employees and/or third-party companies or other entities (for example: professional firms, accounting system management companies, booking software management companies, etc.). Data may be made accessible for the purposes referred to in section 2.B) to employees of the Data Controller.
5. Communication of Data
The Data Controller may communicate your data for the purposes referred to in section 2.A):
to entities, professionals, companies or other structures appointed by the Data Controller for the fulfillment of administrative, accounting, managerial and commercial obligations, hospitality services and, where necessary, restaurant services, including events and activities related to the ordinary conduct of business activities;
to public Authorities and Administrations for purposes connected with legal and contractual obligations;
to banks or other entities to whom communication of data is necessary for carrying out the activities of the Data Controller.
Your data may also be communicated for the purposes referred to in section 2.B) to external companies specifically appointed to send communications on behalf of the Data Controller.
6. Data Transfer
Personal data are stored at the company headquarters and on protected cloud servers. In addition, data stored on servers connected to web booking systems provided by third parties located within or outside the EU may include autonomous user registration functions. The Data Controller hereby guarantees that, where necessary and in compliance with applicable legal provisions, data transfers may be carried out through specifically appointed companies.
7. Nature of Data Provision and Consequences of Refusal
Providing data for the purposes referred to in section 2.A) is mandatory. Failure to provide such data may prevent us from guaranteeing the requested services. Providing data for the purposes referred to in section 2.B) is optional. You may therefore decide not to provide any data or subsequently deny the possibility of processing data already provided. In this case, you will not receive newsletters, commercial communications or advertising material relating to the services offered by the Data Controller.
8. Rights of the Data Subject
As a data subject, you have the rights provided for by the GDPR, including:
obtaining confirmation as to whether or not personal data concerning you exist and receiving such data in intelligible form;
obtaining information regarding:
the origin of personal data;
the purposes and methods of processing;
the logic applied in case of processing carried out with electronic tools;
the identification details of the Data Controller, processors and authorized persons;
the entities or categories of entities to whom personal data may be communicated;
obtaining:
updating, rectification or integration of data;
deletion, anonymization or blocking of data processed unlawfully;
certification that the operations described above have been notified to the entities to whom the data were communicated;
objecting, in whole or in part, for legitimate reasons to the processing of personal data concerning you, even if relevant to the purpose of collection;
objecting to the processing of personal data for advertising, direct sales, market research or commercial communication purposes;
where applicable, the rights provided for in Articles 16–21 GDPR (right to rectification, right to erasure, right to restriction of processing, right to data portability, right to object), as well as the right to lodge a complaint with the Supervisory Authority.
9. Methods for Exercising Rights
You may exercise your rights at any time by sending written communication to:
Loc. La Leccia 53011 Castellina in Chianti (Si)
E-Mail: info@castellolaleccia.com.
10. Data Controller, Processors and Authorized Persons
The Data Controller is: Castello La Leccia Società Agricola Srl Loc. La Leccia 53011 Castellina in Chianti (Si) c.f. e p.i. 00520660523.