Area Tour s.r.l., as data controller (hereinafter referred to as the Controller), informs you, pursuant to Article 13 of Legislative Decree No. 196 of June 30, 2003 (hereinafter, the “Privacy Code”) and Article 13 of EU Regulation No. 2016/679 (hereinafter, the “GDPR”),
that your data will be processed in the following ways and for the following purposes:
1. Purpose of Processing
The Controller processes the personal, identifying data (e.g., name, surname, company name, address, telephone number, email address, bank and payment details – hereinafter, “personal data” or “data”) provided by you when entering into contracts for the Controller’s services.
2. Purpose of Processing
Your personal data is processed without your express consent (Article 24, letters a), b), and c), of the Privacy Code, and Article 6, letters c). b), e) GDPR), for the following Service Purposes:
- Enter into contracts for the Data Controller’s services;
- Fulfill pre-contractual, contractual, and tax obligations arising from existing relationships with you;
- Fulfill obligations established by law, regulation, EU legislation, or an order from an authority (such as anti-money laundering);
- Exercise the Data Controller’s rights, such as the right to defense in court.
3. Processing Methods
Your personal data is processed using the operations indicated in Article 4 of the Privacy Code and Article 4(2) of the GDPR, specifically: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, erasure, and destruction of data. Your personal data is subject to both paper-based and electronic and/or automated processing.
The Data Controller will process personal data for the time necessary to fulfill the aforementioned purposes and, in any case, for no longer than 10 years from the termination of the Service Purposes relationship.
4. Access to Data
Your data may be made accessible for the purposes referred to in Article 2:
- to employees and collaborators of the Data Controller, in their capacity as persons in charge and/or internal data processors and/or system administrators;
- to third-party companies or other entities (for example, credit institutions, professional firms, consultants, insurance companies for the provision of insurance services, etc.) that perform outsourced activities on behalf of the Data Controller, in their capacity as external data processors.
5. Data Communication
Without the need for express consent (pursuant to Article 24, letters a), b), and d) of the Privacy Code and Article 6, letters b) and c) of the GDPR), the Data Controller may communicate your data for the purposes referred to in Article 2 to supervisory bodies (such as IVASS), judicial authorities, insurance companies for the provision of insurance services, as well as to those parties to whom communication is required by law for the fulfillment of the aforementioned purposes. These parties will process the data in their capacity as independent data controllers.
Your data will not be disclosed.
6. Security
The data is stored and monitored by adopting appropriate preventive security measures, aimed at minimizing the risk of loss and destruction, unauthorized access, and unauthorized processing inconsistent with the purposes for which the processing is carried out.
7. Data Transfer
Personal data will be managed and stored within the European Union.
8. Rights of the data subject
As a data subject, you have the rights set forth in Art. 15 GDPR, specifically the rights to:
- Obtain confirmation of the existence or otherwise of personal data concerning you, even if not yet recorded, and communication of such data in an intelligible form;
- Obtain information on:
-
- the source of the personal data;
- the purposes and methods of processing;
- the logic applied in the event of processing carried out with the aid of electronic means;
- the identification details of the data controller, data processors, and the designated representative pursuant to Article 5, paragraph 2 of the Privacy Code and Article 3, paragraph 1 of the GDPR;
- the entities or categories of entities to whom the personal data may be communicated or who may become aware of it in their capacity as designated representative in the territory of the State, data processors, or persons in charge of processing;
- obtains:
- updating, rectification, or integration of data;
- the deletion, anonymization, or blocking of data processed unlawfully, including data whose retention is unnecessary for the purposes for which it was collected or subsequently processed;
- certification that the operations referred to in points 1) and 2) have been notified, including their content, to those to whom the data was communicated or disseminated, except where such compliance proves impossible or involves a manifestly disproportionate effort compared to the right being protected;
- oppose, in whole or in part, for legitimate reasons, to the processing of your personal data, even if pertinent to the purpose of the collection.
Where applicable, you also have the rights set forth in Articles 16-21 of the GDPR (right to rectification, right to be forgotten, right to restriction of processing, right to data portability, right to object), as well as the right to lodge a complaint with the Supervisory Authority.
9. How to exercise your rights
You may exercise your rights at any time by sending a communication to:
- via e-mail, at: info@areatour.it
- or via ordinary mail A.R., a Safariundmeer by Area Tour SRL – Via Giulio Tarra, 16 – 00151 Roma
10. Data Controller, Data Processor, and Persons in Charge
The Data Controller is Mario Cibrario.
The updated list of data processors and persons in charge of data processing is kept and available for consultation at the Data Controller’s headquarters.