Privacy Policy

PRIVACY POLICY – https://www.villadestelaboutique.com/

Information document pursuant to and for the purposes of art. 13 of Regulation (EU) 2016/679 (GDPR)

WHY THIS INFORMATION?

Pursuant to Regulation (EU) 2016/679 (hereinafter “GDPR”), this page describes the methods of processing personal data.  This information is provided pursuant to art. 13 GDPR. The information is not to be considered valid for other third-party websites, which may be consulted through links on this website, for which no responsibility is assumed. 

Processing personal data

  • Personal data: any information relating to an identified or identifiable natural person (“data subject“); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, or physical identity of that natural person.  genetic, psychological, economic, cultural or social (C26, C27, C30 GDPR).
  • Contractors/Users Data.
  • Navigation data: the computer systems and software procedures used to operate this site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes the IP addresses or domain names of the computers and terminals used by users, the URI/URL (Uniform Resource Identifier/Locator) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, successful,  error, etc.) and other parameters related to the user’s operating system and computer environment.
  • Data communicated voluntarily: the optional, explicit and voluntary sending of messages to the contact addresses indicated on this site and/or the compilation of data collection forms involves the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data entered.

Information about the processing of personal data carried out through Social Media platforms 

With regard to the processing of personal data carried out by the managers of the Social Media platforms used by the Data Controller, please refer to the information provided by the latter through their respective privacy policies. The Data Controller processes the personal data provided by users through the pages of dedicated Social Media platforms, to manage interactions with users (comments, public posts, etc.) and in compliance with current legislation.

Specific information

Specific information may be present on the pages of the Site in relation to particular services or data processing provided.

COOKIES AND OTHER TRACKING SYSTEMS. WHAT ARE THEY? WHAT ARE THEY FOR?

For Cookies and other tracking systems, see the cookies policy in the footer of the site and at the following link.

1. WHO IS THE DATA CONTROLLER? HOW TO CONTACT HIM?

The Data Controller is Villa D’Este S.p.A., with registered office in Via Regina, 40, 22012 Cernobbio (Como), in the person of its pro-tempore Legal Representative, who can be contacted for any information by telephone +39 031 348873, e-mail privacy@villadeste.it.

2. PURPOSE OF THE PROCESSING, LEGAL BASIS, DATA RETENTION PERIOD, NATURE OF THE PROVISION

PURPOSE OF THE PROCESSINGLEGAL BASISDATA RETENTION PERIODNATURE OF THE PROVISION
Navigation on this website. The data necessary for the use of web services are also processed for the purpose of:• obtain statistical information on the use of the services (most visited pages, number of visitors per time slot or day, geographical areas of origin, etc.);• check the correct functioning of the services offered.The processing is necessary for the purposes of the legitimate interests pursued by the data controller or by third parties, provided that the interests or fundamental rights and freedoms of the data subject which require the protection of personal data do not prevail, taking into account the reasonable expectations entertained by the data subject and the activities strictly necessary for the operation of the website and for navigation itself.(Art. 6, para. 1 letter f e C47 of the GDPR)Data subjects are guaranteed the opportunity to obtain, on request, information on the balancing test carried out.The storage of browsing data will take place for the duration of the browsing session.









The provision of data is necessary for navigation on the website.

















Use of cookies and equivalent technologies.See the cookies policy in the footer of the site.

For necessary non-technical cookies and comparable technologies, the processing is based on consent to the processing of personal data (Art. 6 para. 1 lit. a and C42, C43 GDPR).Consent is given through the banner and the cookie policy of the site.

See the cookies policy in the footer of the site.

See the cookies policy in the footer of the site.

In addition to browsing, personal data will be processed for:

PURPOSE OF THE PROCESSINGLEGAL BASISDATA RETENTION PERIODNATURE OF THE PROVISION
A) CONTACTS, sending contact requests, information.
The processing is necessary for the performance of a contract to which the data subject is a party or for the execution of pre-contractual measures adopted at the request of the same (C44).Art. 6 par. 1 light. b) share GDPR.Maximum 12 months.Disposal is necessary.Failure to provide the necessary data will make it impossible to be contacted and receive information.
B) DIRECT MARKETING, for sending advertising or direct sales material or for carrying out market research, commercial and promotional communication, newsletters, through automated means (e-mail, SMS) and traditional means (telephone and paper mail).Communications may contain promotional activities and/or logos of Villa d’Este S.p.A. partners. There will be no transfer of personal data.For the complete list of partners, Data subjects can write to privacy@villadeste.it.
The Data Controller uses systems with reports to compare and possibly improve the results of automated communications. Thanks to the reports, the Data Controller will be able to know, for example: the number of readers, openings, unique “clickers” and “clicks”; the devices and operating systems used to read the communication; details on the activity of individual users; the details of emails sent, delivered and undelivered, and forwarded emails. All this data is used for the purpose of comparing, and possibly improving, the results of the communications.
The processing is based on consent to the processing of personal data (C42, C43).Art. 6 pairs. It became 1. a) del GDPR.Until you revoke your consent (or opt-out).The provision is optional.
Failure to provide the necessary data will make it impossible to receive direct marketing communications.
C) NON-AUTOMATED PROFILING: PERSONAL DATA WILL BE ENTERED INTO COMPANY DATABASES/CRMs/platforms, in order to carry out analyses, evaluations and to divide data subjects into homogeneous groups according to specific characteristics of company activity for better management of services and for sending targeted promotional communications. The processing is based on consent to the processing of personal data (C42, C43).Art. 6 pairs. It became 1. a) del GDPR.Until consent is revoked and in any case a maximum of 12 months.The provision is optional.
Failure to provide the necessary data will make it impossible to carry out analyses and send targeted communications.
D) MANAGEMENT OF YOUR REQUESTS and requests from other data subjects, pursuant to art. 15 et seq. of the GDPR (rights of the data subject).The processing is necessary for compliance with a legal obligation to which the controller is subject (C45).Art. 6 par. 1 light. c) Part GDPR.5 years from the closure of the request, except for litigation.The provision of personal data is mandatory, as it is essential to be able to execute legal obligations.
E) CUSTOMER AREA, to access the reserved area The processing is necessary for the performance of a contract to which the data subject is a party or for the execution of pre-contractual measures adopted at the request of the same (C44).Art. 6 par. 1 light. b) share GDPR.Until the termination of the contract and for the technical time necessary to disable the credentials.Disposal is necessary.
Failure to provide the necessary data will make it impossible to access the reserved area.
F) ACTIVITIES OF AN ORGANIZATIONAL, ADMINISTRATIVE, FINANCIAL AND ACCOUNTING NATURE AND MANAGEMENT OF CUSTOMER/USER DATA.The processing is necessary for the performance of a contract to which the data subject is a party (C44) or for compliance with legal obligations (C45).  10 years or other legal obligation.The provision of personal data is mandatory, as it is essential to be able to execute legal obligations.

3. TO WHOM WILL PERSONAL DATA BE COMMUNICATED? DATA RECIPIENTS

Personal data will be communicated to subjects who will process the data as independent Data Controllers, or Data Processors (art. 28 GDPR) and processed by natural persons (art. 29 GDPR) who act under the authority of the Data Controller and the Data Processors on the basis of specific instructions provided regarding the purposes and methods of processing. The data will be communicated to recipients belonging to the following categories:

  • Entities based in Italy, who provide services for the website and communication networks, including e-mail, hosting and website management;
  • Subjects based in Italy, with whom the Data Controller has signed agreements and subject to consent, where required;
  • For direct marketing, subject to consent to subjects for the management of direct marketing activities; 
  • Competent authorities for the fulfilment of legal obligations and/or provisions of public bodies, upon request.

The list of Data Processors under Article 28 is available by writing to privacy@villadeste.it. or to the other addresses indicated above.

4. WILL THE DATA BE TRANSFERRED TO NON-EEA COUNTRIES?

Personal data will not be transferred to countries outside the EEA. It should be noted, in particular, that the data will be stored in Italy for hosting, management, development and maintenance services of the site. All third parties to whom the data may be communicated are based in Italy.

 5. IS THERE AN AUTOMATED PROCESS?

Personal data will be subjected to traditional, electronic and automated manual processing. Please note that fully automated decision-making processes are not carried out.

With reference to profiling activities, possibly carried out with the express consent of the data subject as indicated in the purposes, it will be carried out through the intervention of the operator who will process the profile of the data subject and analyse their consumption habits and choices, in order to improve the commercial offer and services of the data controller (non-automated profiling).

6. WHAT ARE YOUR RIGHTS? HOW CAN HE EXERCISE THEM?

Data subjects may assert their rights as expressed by Articles 15 et seq. GDPR, by contacting the Data Controller at the e-mail address: privacy@villadeste.it., or by writing to the contacts indicated above. 

The data controller guarantees data subjects the possibility to request, at any time, access to their personal data (art.15), rectification (art.16), erasure of the same (art.17), limitation of processing (art.18). The data controller shall notify (art. 19), to each of the recipients to whom the personal data have been transmitted, any corrections or deletions or limitations of processing carried out. The data controller shall notify the data subjects who request such recipients. 

The data controller guarantees the right to portability (art.20) and, in the event of requests pursuant to art.20, will provide the data subjects with the data in a structured, commonly used and machine-readable format. 

The data subjects have the right to object (art.21), at any time, to the processing of data based on legitimate interest, by writing to the contacts above with the subject “opposition”. In the event of exercising the right to object to processing based on legitimate interest, the Data Controller recognises that data subjects have the possibility of obtaining, upon request, information on the balancing test carried out.

Data subjects have the right to revoke the consent given, without prejudice to the lawfulness of the processing based on the consent given before the revocation. 

In order to no longer receive automated direct marketing communications (e-mail, SMS messages, instant messaging), data subjects are invited to write an e-mail to the privacy@villadeste.it. address with the subject “unsubscribe from automated” or to use our automatic cancellation systems provided for e-mails only (opt-out).  

In order to no longer receive traditional direct marketing communications (telephone calls with an operator and paper mail), Data subjects are invited to write an e-mail to privacy@villadeste.it.   with the subject “cancellation from traditional”. 

To stop receiving any marketing communication, data subjects are invited to write an e-mail to privacy@villadeste.it.   with the subject “marketing cancellation”. 

At any time, data subjects are free to revoke their consent to profiling (not automated) by writing an e-mail to privacy@villadeste.it.   with the subject “no profiling”.

In the event that data subjects believe that the processing of personal data carried out by the Data Controller is in violation of the provisions of Regulation (EU) 2016/679, they are free to lodge a complaint with the National Supervisory Authority, in particular in the Member State where they habitually reside or work, or in the place where the alleged violation of the Regulation occurred (Privacy Guarantor https://www.garanteprivacy.it/), or to bring the matter before the appropriate courts.

7. CHANGES TO THE POLICY

The owner may change, modify, add or remove any part of this Privacy Policy. In order to facilitate the verification of any changes, the policy will contain an indication of the date of update of the policy itself.
Date Updated: 19/12/2024