POLICY AND REQUEST FOR CONSENT TO PERSONAL DATA PROCESSING PURSUANT TO ARTICLE 13 OF REGULATION (EU) 2016/679
We wish to inform you that, pursuant to article 13 of Regulation (EU) 2016/679 (the GDPR 2016/679), which contains provisions for the protection of persons and other subjects regarding the processing of personal data, the personal data provided by you will be processed in compliance with the abovementioned law and according to the principles of lawfulness, fairness, transparency and protection of your privacy and your rights, with particular reference to integrity, confidentiality, personal identity and right of personal data protection.
1) PURPOSE OF DATA PROCESSING
Personal data provided by you will be used for the following purposes:
to comply with legal requirements on our behalf regarding the administration, management and logistics of the courses in which you wish to enrol, including searching for accommodation;
to provide the required services, allow for effective management of relations with clients in order to respond to requests for information, assistance, suggestions and/or specific needs you have indicated;
to send communications regarding services offered, newsletters and personalised news, containing materials and promotions regarding our activities and services (e.g., invitations to courses, events, trips, conferences, etc.) via traditional (telephone calls with operator) or automated (email) methods.
2) SPECIAL CATEGORIES OF PERSONAL DATA
Pursuant to articles 9 and 10 of the GDPR 2016/679, you could provide Tenuta Santo Stefano with data qualifying as "special categories of personal data" (including data disclosing racial or ethnic origin, religion or beliefs and genetic or health status), which may be asked for during enrolment or a course. These categories of data may be processed by Tenuta Santo Stefano only with your consent, expressed in writing by signing this policy.
3) DATA PROCESSING METHODS
Data processing will be carried out automatically and/or manually using methods and tools that comply with security measures indicated in article 32 of the GDPR 2016/679 by subjects appointed in accordance with article 29 of the GDPR 2016/679. Security measures will be used to guarantee the confidentiality of the data subject to whom these data refer and to avoid undue access by third parties or unauthorised personnel.
4) DATA STORAGE
Pursuant to article 5 of the GDPR 2016/679 and in accordance with the principles of lawfulness, purpose limitation and data minimisation, the storage period of your personal data will not exceed either the time required to achieve the purposes for which they were collected and processed or the time limits prescribed by law.
5) PROVISION OF PERSONAL DATA
Data provision is voluntary and not mandatory; however, your refusal to provide them or give your consent for their use will make it impossible for Tenuta Santo Stefano to fully provide the services it offers.
6) COMMUNICATION AND DISSEMINATION Personal data collected will not be disseminated. In relation to the abovementioned purposes, your personal data may be communicated to the following categories of recipients:
external consultants appointed for processing and/or consulting regarding taxation;
public subjects to whom data must be communicated by law (social security and welfare institutions, financial offices, etc.);
subjects providing students with accommodations or logistics for excursions.
7) DATA TRANSFER TO THIRD COUNTRIES
The data controller will not transfer your personal data to third countries; however, we reserve the right to use cloud services. In this case, service providers will be selected from those who offer the best guarantees in accordance with article 46 of the GDPR 2016/679.
8) DATA CONTROLLER AND DATA PROTECTION OFFICER
The data controller is Tenuta Santo Stefano and, in particular, our acting legal representative pro tempore. No Data Protection Officer has been appointed.
To enforce the rights of the data subject and/or ask for further information, please contact the Data Controller of Tenuta Santo Stefano. Your personal data will be processed at our office in Via Vettigano, 26 SP30 - 42012 Campagnola Emilia (RE) . Our contact information is phone number +39-0522 665812 and e-mail email@example.com.
9) RIGHTS OF DATA SUBJECTS
Pursuant to articles 15 to 22 of the GDPR 2016/679, you may at any time exercise your right:
to request confirmation of the existence or absence of your personal data;
to obtain information on the purposes of processing, categories of personal data, recipients or categories of recipients to whom your personal data has been or will be disclosed and, if possible, regarding storage limit; Pg. 1 / 2
to modify or delete your personal data;
to ask for processing limitation;
to obtain data portability (i.e., receive your data from a data controller in a structured, commonly used format that is readable by any automatic device) and send your data to another data controller without limitations;
to oppose data processing at any time, including for direct marketing purposes;
to oppose the use of automated decision-making process concerning natural persons, including profiling.